Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Litigation Associate at Phelps Dunbar LLP
Chris Bach
Florida's Cybersecurity Liability Bill Faces Surprise Veto

In a surprising turn of events, Governor DeSantis has vetoed Florida’s Cybersecurity Incident Liability Act, HB 473. That bill would have provided immunity from civil liability in Florida to companies that suffered a data breach if they met certain conditions. The prevailing thought was that the Governor would sign the bill (or allow it to become law without his signature).
But in the early evening of June 26, 2024, Governor DeSantis formally vetoed the legislation. In doing so, he provided a letter that revealed his rationale. He noted that HB 473 would provide “broad liability protections for state and local governments and private companies.” However, he took issue with the bill because those governments and companies only had to “substantially comply with minimum cybersecurity standards in the event of a data breach or other cybersecurity event.”
Governor DeSantis argued that HB 473 'may result in a consumer having inadequate recourse if a breach occurs,' emphasizing the need for stronger protections amid rising data breach litigation.
If HB 473 had become law, it would have pushed the envelope on a growing trend among various states to enact greater protections for companies facing data breaches. Indeed, it would have provided immunity for substantially complying companies and a model for other states to follow. For now, that level of immunity appears to be out of reach within Florida. Governor DeSantis has removed that possibility with his veto. However, based on the Governor’s concluding remarks in his letter, Florida companies should expect him to be receptive to a similar if less powerful, bill in the future.

