Law / United States / Michigan
Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty
2025 S.B. 360, proposed MCL 445.71a and 445.85c (secs. 11a and 20c), as passed by the Senate
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Proposed: draft date not recorded.
A security baseline statutes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This bill has not been enacted and creates no duty today. It passed the Michigan Senate on August 26, 2025 (19-15) and was referred to the House Committee on Government Operations the same day, with no further recorded action since, as of September 14, 2026. It is a reintroduction of Senate Bills 888 through 892 of the 2023-2024 Regular Session, which also passed the Senate (December 12, 2024, 20-15) and stalled in the same House committee. Watch for further House action.
- If enacted as passed by the Senate, this would require a person (any private entity) or agency (a Michigan state government unit) that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a security coordinator, identify internal and external risks, include appropriate safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures for changed circumstances.
- Reasonableness would be judged by your size, the amount and type of personal information you own, possess, collect, or access, and the cost of the procedures relative to your resources. Conforming to the current NIST Cybersecurity Framework 2.0, or already being regulated by Michigan or the federal government and reasonably conforming to HIPAA, Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliance.
- As passed by the Senate, only the Attorney General could enforce this duty, by a civil action for injunctive relief and a fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures, separate from a further $2,000 fine proposed for a knowing failure to investigate a suspected breach and from the Act's own breach-notice fine.
If you get it wrong
Penalty structure
Proposed, not yet enacted. As passed by the Senate, a civil fine of not more than $2,000 would apply to a knowing failure to implement or maintain reasonable security procedures under proposed section 11a; a separate $2,000 fine is proposed for a knowing failure to investigate a suspected breach under proposed section 11b, and the bill separately revises the Act's existing breach-notice civil fine, which is this jurisdiction's privacy-topic row.
- Rule
- Fixed only
- As of
- 14 September 2026
- Currency
- USD
- Fixed cap
- 2,000
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
This bill has not been enacted and binds nothing today. Senate Bill 360 of the 2025-2026 Regular Session, as passed by the Senate on August 26, 2025 and pending in the House Committee on Government Operations, would add a new Section 11a to the Identity Theft Protection Act requiring a person or agency that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures.
Those procedures would have to designate a coordinator, identify internal and external risks, include safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures over time.
Reasonableness would turn on the entity's size, the amount and type of personal information involved, and the cost of the procedures relative to the entity's resources. An entity that reasonably conforms to the current NIST Cybersecurity Framework 2.0, or that is regulated by Michigan or the federal government and reasonably conforms to HIPAA, Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliant.
The bill would also add a duty to investigate a suspected breach under proposed Section 11b. Only the Attorney General could enforce this duty, by a civil action seeking injunctive relief and a fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures under proposed section 11a. No provision of the bill as passed by the Senate was located creating a private right of action.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
official Michigan Senate Bill 360 text as passed by the Senate, Michigan Legislature