Texas SB 2610 Cybersecurity Safe Harbor: What It Means for Your Organization
If your organization operates in Texas, has fewer than 250 employees and owns or licenses computerized data that includes sensitive personal information, SB 2610 gives you a reason to formalize your cybersecurity program. If you meet the program requirements at the time of a data breach, a person suing you over that breach cannot recover exemplary (punitive) damages. The law is voluntary, and ALCON DTS helps you build, run and document the program it describes.
This page answers:
At a glance
- Law: Texas Senate Bill 2610, 89th Legislature, Regular Session (Acts 2025, Ch. 1029)
- Passed by: the Texas Legislature. Signed by the governor on June 20, 2025.
- Code citation: Texas Business and Commerce Code, Chapter 542 (Cybersecurity Program), Sections 542.001 to 542.005
- Effective: September 1, 2025. Applies only to a cause of action that accrues on or after that date.
- Type: Voluntary safe harbor. No new mandate, no penalties, no filing or registration. No state agency enforces Chapter 542; it is a defense you raise in court.
- Who can use it: Business entities in Texas with fewer than 250 employees that own or license computerized sensitive personal information
- What it protects against: Exemplary damages in a lawsuit arising from a breach of system security
- Official text: Texas Business and Commerce Code, Chapter 542
- Last reviewed: September 30, 2026
What is SB 2610?
SB 2610 is a Texas law passed by the Texas Legislature in its 89th Regular Session. It added Chapter 542, “Cybersecurity Program,” to the Texas Business and Commerce Code, effective September 1, 2025.
What changed: SB 2610 created a specific defense tied to your cybersecurity program. If you qualify and you can show that, at the time of the breach, you had implemented and maintained a program that meets Sec. 542.004, a person harmed by the breach may not recover exemplary damages from you (Sec. 542.003).
SB 2610 does not order you to do anything. There is no regulator, no registration and no penalty under Chapter 542. It sets out what your cybersecurity program must look like if you want the protection, and it works as a defense in a lawsuit.
What does the safe harbor cover, and what doesn’t it?
It covers: exemplary damages. In a lawsuit arising from a breach of system security, a person harmed by the breach may not recover exemplary damages from a qualifying business (Sec. 542.003). Texas law defines exemplary damages as damages awarded as a penalty or punishment, not as compensation, and the term includes punitive damages (Civil Practice and Remedies Code Sec. 41.001).
It does not:
- Limit compensatory damages. The law addresses exemplary damages only.
- Create a private cause of action (Sec. 542.005).
- Change any existing common law or statutory duty (Sec. 542.005). Your breach notification duties and your duty to protect sensitive personal information stay the same.
- Apply automatically. You must demonstrate that your program was in place and maintained at the time of the breach.
Does SB 2610 apply to you?
Chapter 542 applies only to a business entity in Texas that meets both tests (Sec. 542.002):
- It has fewer than 250 employees.
- It owns or licenses computerized data that includes sensitive personal information.
“Sensitive personal information” uses the Texas definition in Business and Commerce Code Sec. 521.002. In plain terms, it covers:
- A person’s first name or first initial and last name, combined with a Social Security number, a driver’s license or government ID number, or a financial account or card number with the code needed to access it, when that data is not encrypted.
- Information that identifies a person and relates to their physical or mental health, the health care they receive, or payment for that care.
If you keep employee records, patient information or customer payment details in computerized form, you very likely own or license sensitive personal information.
Quick check: is SB 2610 relevant to you?
- You operate in Texas.
- You have fewer than 250 employees.
- You own or license computerized data that includes sensitive personal information (employee, patient, client or customer data).
If all three are true, the safe harbor is available to you, provided your cybersecurity program meets Sec. 542.004. Chapter 542 does not say how employees are counted. Talk with your attorney about how it applies to your staffing.
What do you need to have in place?
Every qualifying program must
- Contain administrative, technical and physical safeguards for personal identifying information and sensitive personal information.
- Conform to an industry-recognized cybersecurity framework (see the list below).
- Be designed to protect the security of that information, protect against threats or hazards to its integrity, and protect against unauthorized access or acquisition that would create a material risk of identity theft or other fraud.
What scales with your size? (Sec. 542.004(a)(4))
| Employees | What the law expects | Example starting point |
|---|---|---|
| Fewer than 20 | Simplified requirements, including password policies and appropriate employee cybersecurity training | A written password policy with multifactor authentication, plus security awareness training for every employee with completion records |
| 20 to 99 | Moderate requirements, including the Center for Internet Security (CIS) Controls Implementation Group 1 | A gap assessment against CIS Controls Implementation Group 1, then a documented plan to close each gap |
| 100 to 249 | Compliance with the requirements of Sec. 542.004(b): conformity with a current version of one or more listed frameworks, plus the current version of HIPAA, GLBA Title V, FISMA or HITECH if you are subject to them, and PCI DSS if it applies to you | Choose a named framework that fits your industry, add any of those laws or PCI DSS that apply to you, assess against them and keep an evidence file that shows conformity |
If you have close to 100 employees, you may be near the line between the second and third tiers. If you are growing past 100 employees, plan your framework now so your program keeps pace.
Which frameworks does the law name? (Sec. 542.004(b))
Your program conforms to an industry-recognized framework if it conforms to a current version of one, or any combination, of these:
- NIST Framework for Improving Critical Infrastructure Cybersecurity (NIST Cybersecurity Framework)
- NIST Special Publication 800-171
- NIST Special Publications 800-53 and 800-53A
- FedRAMP Security Assessment Framework
- CIS Critical Security Controls for Effective Cyber Defense
- ISO/IEC 27000-series information security standards
- HITRUST Common Security Framework
- Secure Controls Framework
- SOC 2 (Service Organization Control Type 2 Framework)
- Other similar frameworks or standards of the cybersecurity industry
Your program must also conform to the current version of these laws if your organization is subject to them:
- HIPAA
- Gramm-Leach-Bliley Act, Title V
- Federal Information Security Modernization Act of 2014 (FISMA)
- HITECH Act
And, if it applies to you, the current version of the Payment Card Industry Data Security Standard (PCI DSS).
How do you keep the program current? (Sec. 542.004(c))
Frameworks change. When a listed framework is updated, your program still qualifies as long as you update it to the new version by the later of:
- the implementation date published in the updated standard, or
- one year after the updated standard is published.
That means a steady review cycle matters. A program that met the framework two versions ago may not qualify later.
How can ALCON DTS help you?
You keep the compliance decisions. We can run the controls. We can keep them current and document how they work, so you have a clear record of your program when your attorney, insurer or auditor asks. Our services help you build and maintain a program aligned to the framework you choose. Whether the safe harbor applies to a specific claim is a legal question decided on the facts.
| SB 2610 element | What ALCON DTS provides |
|---|---|
| Framework conformity and documentation (542.004(a)(2), (b)) | Compliance tracking against your chosen framework, with documented policies, procedures and an organized evidence file |
| Password policies (under 20 tier) | Identity and access management, including multifactor authentication, enforced password policies and secure credential storage |
| Employee cybersecurity training (under 20 tier) | Security awareness training with completion records |
| Technical safeguards: malware and endpoint defense | Endpoint detection and response, application control and managed administrator rights |
| Technical safeguards: email threats | Email security and filtering, plus email domain authentication (SPF, DKIM and DMARC) |
| Monitoring and detection | Centralized logging, security monitoring and alerting across devices and cloud apps |
| Asset inventory and secure configuration (CIS IG1) | Device management, managed patching and updates, and automated documentation of systems and configurations |
| Network safeguards | Managed firewalls, switching and secure Wi-Fi |
| Integrity and recovery | Tested backup and recovery |
| Staying current (542.004(c)) | Regular, documented program reviews against the current framework version, with changes recorded in your evidence file |
The exact controls in your environment depend on your ALCON DTS plan and any project work. We will show you which are in place today and which would close a gap.
Why work with ALCON DTS?
When you build a program you may one day need to show your attorney or insurer, you want a team that has done this work for years and documents it as it goes. Here is what you get with ALCON DTS.
- More than two decades in Texas. ALCON DTS has served Central Texas organizations since 2001, from our headquarters in Austin.
- A certified, specialized team. Our team holds a range of industry certifications, including certifications in implementing compliance frameworks, and works every day in cybersecurity, managed IT and regulatory compliance.
- Experience in regulated work. We support healthcare organizations and clinics that protect patient information, manufacturers and engineering firms, and law and professional services firms.
- Firsthand knowledge of the law. Eduardo Contreras led the effort to pass SB 2610, so we know the intent behind the law as well as its text.
ALCON DTS has earned awards and recognition from business and community organizations, a reflection of how we operate: plain answers, documented work and long-term relationships.
Ready to see where your program stands? We will compare your current controls with the SB 2610 tier that fits your headcount and show you what would close the gaps.
How does SB 2610 fit with other Texas and federal rules?
- Texas breach notification law (Bus. and Com. Code Sec. 521.053). SB 2610 does not change breach notification. If a breach involves sensitive personal information, you must notify affected individuals without unreasonable delay and no later than 60 days after determining the breach occurred. If at least 250 Texas residents are involved, you must also notify the Texas Attorney General no later than 30 days after that determination. If you notify more than 10,000 people at one time, consumer reporting agencies must also be notified. The Texas Attorney General enforces Chapter 521 and may bring an action for civil penalties for violations of it (Sec. 521.151).
- Texas duty to protect sensitive personal information (Sec. 521.052). Businesses must implement and maintain reasonable procedures to protect sensitive personal information and must securely destroy records they no longer keep. SB 2610 leaves this duty in place, and a framework-based program is a practical way to show reasonable procedures.
- HIPAA and HITECH. If your organization is subject to HIPAA or HITECH, SB 2610 requires your program to conform to the current version of those laws as well. For healthcare and imaging organizations, the HIPAA Security Rule work you already do becomes part of your SB 2610 program.
- Texas Data Privacy and Security Act (TDPSA, Bus. and Com. Code Ch. 541). TDPSA requires reasonable data security practices from businesses it covers. It does not apply to businesses that are small businesses under the U.S. Small Business Administration definition (with one exception for selling sensitive data), HIPAA covered entities and business associates, or nonprofit organizations (Sec. 541.002). If TDPSA does apply to you, a framework-based program supports both laws.
- PCI DSS. If you accept payment cards and PCI DSS applies to you, SB 2610 expects your program to conform to its current version.
Frequently asked questions
Is SB 2610 mandatory?
Who enforces SB 2610?
When did SB 2610 take effect?
Does SB 2610 protect you from all damages in a breach lawsuit?
Which frameworks count?
How quickly do you need to update when a framework changes?
How are employees counted for SB 2610?
What if you have 250 or more employees?
Can ALCON DTS guarantee the safe harbor applies to you?
Sources
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- SB 2610, 89th Legislature (R), enrolled bill text (Texas Legislature Online)
- SB 2610, 89th Legislature (R), bill history (Texas Legislature Online)
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information (Texas Constitution and Statutes)
- Texas Business and Commerce Code, Chapter 541, Consumer Data Protection (Texas Data Privacy and Security Act) (Texas Constitution and Statutes)
- Texas Civil Practice and Remedies Code, Chapter 41, Damages (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about Texas law, not legal advice for your situation.
Talk with ALCON DTS about your SB 2610 program
Want to know where your organization stands? We will review your current controls against the SB 2610 tier that fits your headcount, show you what is already in place, and give you a clear plan for the gaps.
Email: info@alcondts.com ยท Phone: 512-892-6900

