HB 1033 (Tennessee) creates a legal defense for businesses that experience a data breach, provided they maintained a cybersecurity program meeting specific standards at the time of the breach. It applies to "covered entities" - businesses handling personal information, health data, or sensitive restricted information - requiring them to have written security protocols aligned with industry frameworks (like NIST). If compliant, these entities can use this defense against lawsuits alleging negligence in data security, excluding breaches from law enforcement requests or authorized employee transmissions. The bill does not change breach notification rules but offers legal protection for businesses meeting its cybersecurity criteria.
HB 367 (Consumer Protection) prohibits vehicle manufacturers and third parties from sharing, selling, or distributing a vehicle's driving data - including information from infotainment, telematics, or sensors - without the vehicle owner's explicit, written consent. It requires entities to disclose data collection practices to owners, obtain annual consent renewals, and provide an easily accessible way to revoke consent. The bill applies to all vehicle owners in Tennessee and exempts sharing with government agencies like the National Highway Traffic Safety Administration under federal law. The bill was introduced in January 2025 but was withdrawn on February 6, 2025, and never advanced further.
HB 1209 updates Tennessee's Artificial Intelligence Advisory Council by defining "artificial intelligence" as machine systems that make decisions influencing environments, expanding the council's membership from 24 to 24-27 members, and adding requirements for AI expertise among appointees. The bill mandates the council to identify data privacy best practices for state agencies, reference existing AI policies, and compile an annual inventory of state and federal AI-related laws by December 31, 2025. This inventory must assess overlaps, gaps, and alignment with federal frameworks to reduce compliance burdens. The bill directly affects the council, state agencies managing AI systems, and entities developing AI technologies in Tennessee.
SB 494, the "Family Right to Educational Emancipation (FREE) Act," creates a new category of home schooling in Tennessee. Parents or guardians who choose this option for children aged 6-17 are exempt from mandatory school attendance laws, state testing requirements, and data reporting to schools or government. The bill also prohibits state agencies from denying driver’s licenses or permits based on a student’s school attendance or enrollment status. This directly affects families opting for this specific home education path, removing most state regulatory requirements while maintaining the parent’s authority over curriculum and instruction.
SB 390 allows Tennessee's comptroller of the treasury to publish certain survey data that was previously confidential, specifically aggregate survey results and individual responses that cannot identify participants. This affects the comptroller's office, which can now share anonymized survey information with the public, while still protecting identifiable details. The bill amends Tennessee law to explicitly permit this publication for surveys created, obtained, or compiled by the comptroller, excluding surveys from the office of open records counsel. It does not change how confidential data is handled for other state agencies. The policy change increases transparency around public surveys without revealing personal information.
SB 1362 redefines "artificial intelligence" in Tennessee law as machine-based systems that make predictions, recommendations, or decisions influencing environments. It expands the Tennessee AI Advisory Council from 24 to 24-27 members, requiring at least two members with AI research/development experience and allowing nonvoting experts to advise. The bill mandates the council to compile an annual inventory of state and federal AI-related laws by December 2025, identifying overlaps or gaps, and to recommend data privacy best practices aligned with state data policies. This directly affects the AI Advisory Council and state agencies managing AI systems and data.
SB 1421 creates an affirmative defense for businesses that experience data breaches if they maintained a written cybersecurity program meeting industry-recognized standards at the time of the breach. It applies to "covered entities" (businesses handling personal information, health data, or sensitive restricted information) and requires written security protocols based on frameworks like NIST, annual risk assessments, and employee training. Businesses using this defense must prove their program met these criteria when the breach occurred. This defense applies only to lawsuits alleging inadequate security controls, not to breaches resulting from known threats the business ignored.
SB 1297 prohibits using digital driver licenses for voter identification in Tennessee, requiring physical licenses instead at polling places. It regulates digital license systems by banning geolocation data collection, limiting data retention to 3 days, and restricting biometric data (like face scans) to verification only. The law affects all Tennessee residents using digital licenses, particularly voters who would otherwise rely on them for ID. It also mandates strict data security and prohibits selling personal information collected through the system.
SB 663 allows Tennessee consumers to appoint an authorized agent (like a family member or professional) to manage their data privacy requests on their behalf, directly affecting consumers and businesses (controllers) that collect personal data. It requires businesses to honor opt-out requests from these agents if they can verify both the consumer's identity and the agent's authority. The bill mandates clear opt-out links on business websites and requires a standardized, user-friendly "opt-out preference signal" by January 2026, which must be an active choice by the consumer, not a default setting. This law takes effect July 1, 2025, applying to all Tennessee businesses handling consumer data.
HB 1132 extends the time businesses have to respond to verified consumer data requests under Tennessee's Information Protection Act, increasing the deadline from 45 to 50 days. This change directly affects businesses (referred to as "controllers" in the law) that handle personal data and consumers who submit authenticated requests for data access or correction. The bill amends specific sections of Tennessee law to implement this 5-day extension, which applies to all covered requests. The change will take effect on July 1, 2025, as specified in the bill.