Law / United States /
Texas
Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)
Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 September 2025.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This chapter applies only to a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information, as those terms are defined by Section 521.002.
- It is a safe harbor, not a duty: if such an entity is sued over a breach of system security and demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program meeting Section 542.004's requirements, the claimant may not recover exemplary damages from it. A qualifying program must contain administrative, technical, and physical safeguards; conform to a named industry-recognized cybersecurity framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, or a similar framework); and be scaled by headcount: simplified measures such as password policies and employee training below 20 employees, the CIS Controls Implementation Group 1 from 20 to 99 employees, and full conformance with a named framework from 100 to 249 employees.
- The chapter creates no duty to adopt a program and no cause of action of its own; it only removes exemplary-damages exposure for a qualifying entity that already has one at the time of a breach.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information may invoke a safe harbor from exemplary damages. In an action arising from a breach of system security, such an entity may not be held liable for exemplary damages if it demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program conforming to a named industry-recognized framework and scaled to its size. The chapter creates a safe harbor from a category of damages, not a freestanding duty to adopt a program.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Texas Business and Commerce Code, Cybersecurity Program (S.B. 2610, 2025)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.