Law / United States / Michigan

Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty

2025 S.B. 360, proposed MCL 445.71a and 445.85c (secs. 11a and 20c), as passed by the Senate

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

Proposed: draft date not recorded.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This bill has not been enacted and creates no duty today. It passed the Michigan Senate on August 26, 2025 (19-15) and was referred to the House Committee on Government Operations the same day, with no further recorded action since, as of September 14, 2026. It is a reintroduction of Senate Bills 888 through 892 of the 2023-2024 Regular Session, which also passed the Senate (December 12, 2024, 20-15) and stalled in the same House committee. Watch for further House action.
  • If enacted as passed by the Senate, this would require a person (any private entity) or agency (a Michigan state government unit) that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a security coordinator, identify internal and external risks, include appropriate safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures for changed circumstances.
  • Reasonableness would be judged by your size, the amount and type of personal information you own, possess, collect, or access, and the cost of the procedures relative to your resources. Conforming to the current NIST Cybersecurity Framework 2.0, or already being regulated by Michigan or the federal government and reasonably conforming to HIPAA, Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliance.
  • As passed by the Senate, only the Attorney General could enforce this duty, by a civil action for injunctive relief and a fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures, separate from a further $2,000 fine proposed for a knowing failure to investigate a suspected breach and from the Act's own breach-notice fine.

If you get it wrong

Penalty structure

Proposed, not yet enacted. As passed by the Senate, a civil fine of not more than $2,000 would apply to a knowing failure to implement or maintain reasonable security procedures under proposed section 11a; a separate $2,000 fine is proposed for a knowing failure to investigate a suspected breach under proposed section 11b, and the bill separately revises the Act's existing breach-notice civil fine, which is this jurisdiction's privacy-topic row.

Rule
Fixed only
As of
14 September 2026
Currency
USD
Fixed cap
2,000

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

This bill has not been enacted and binds nothing today. Senate Bill 360 of the 2025-2026 Regular Session, as passed by the Senate on August 26, 2025 and pending in the House Committee on Government Operations, would add a new Section 11a to the Identity Theft Protection Act requiring a person or agency that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures.

Those procedures would have to designate a coordinator, identify internal and external risks, include safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures over time.

Reasonableness would turn on the entity's size, the amount and type of personal information involved, and the cost of the procedures relative to the entity's resources. An entity that reasonably conforms to the current NIST Cybersecurity Framework 2.0, or that is regulated by Michigan or the federal government and reasonably conforms to HIPAA, Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliant.

The bill would also add a duty to investigate a suspected breach under proposed Section 11b. Only the Attorney General could enforce this duty, by a civil action seeking injunctive relief and a fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures under proposed section 11a. No provision of the bill as passed by the Senate was located creating a private right of action.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official Michigan Senate Bill 360 text as passed by the Senate, Michigan Legislature

Back to the example  ·  Lint your app