Vermont
Vermont Data Privacy Laws: Data Broker Registry & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 18 primary sources cited on this page. How we verify our legal content

Vermont requires all data brokers to register annually with the Secretary of State under 9 V.S.A. 2446, making it the first state in the nation to mandate this transparency. Act 171 became law without the Governor's signature on May 22, 2018, though the registration requirement itself did not take effect until January 1, 2019. Vermont enacted a comprehensive consumer data privacy law in 2026 (S.71, Act 145, effective January 1, 2028). That act sits alongside a set of older, separate protections already codified in Chapter 62 of Title 9: data broker registration, breach notification, student privacy, and Social Security number safeguards, none of which Act 145 created.
Vermont has earned a national reputation in one specific area of data privacy: regulating data brokers. With Act 171 of 2018, Vermont became the first state in the country to require data brokers to register with the government (the registration requirement took effect January 1, 2019), creating a public registry that gives consumers visibility into which companies buy and sell their personal information.
Vermont now has a comprehensive consumer data privacy law. An earlier sweeping privacy bill (H.121) passed the legislature in 2024 but was vetoed by Governor Phil Scott. The legislature revived the effort with S.71 in the 2025-2026 session, which the Senate passed in March 2025. Governor Phil Scott signed S.71 into law on June 16, 2026 as the Vermont Data Privacy and Online Surveillance Act (Act 145); its core provisions take effect January 1, 2028.
What Vermont does have is a growing patchwork of targeted protections: a data breach notification law with strict timelines, the pioneering data broker registry, new minors-focused design code requirements, student privacy protections, and Social Security number safeguards. This guide covers every major Vermont data privacy statute currently in force, the key bills pending in 2026, and what businesses and consumers need to know.

Vermont's Data Broker Registration Law (9 V.S.A. 2446-2447)
Vermont made history on May 22, 2018, when Act 171 (H.764) became law without the Governor's signature. The law created the nation's first mandatory registration requirement for data brokers, codified at 9 V.S.A. 2446; the registration requirement itself took effect January 1, 2019. As of the 2025-2026 registration cycle, 283 data broker companies are on the public registry. A June 2025 review by the Privacy Rights Clearinghouse identified approximately 309 additional companies registered as data brokers in other states that had not registered in Vermont, flagging a compliance gap that Attorney General Charity Clark is positioned to address.
Before Vermont acted, data brokers operated in a regulatory blind spot. These companies collected and sold personal information about millions of consumers, but no state required them to identify themselves publicly. Vermont changed that.
What Is a Data Broker Under Vermont Law?
Vermont defines a data broker as a business that "knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship," according to 9 V.S.A. 2430.
The key phrase is "no direct relationship." If you buy something from a retailer and that retailer shares your data with a marketing partner, the retailer is not a data broker under Vermont law because you have a direct relationship with them. A data broker is a company that gathers your information from public records, online tracking, purchased datasets, and other indirect sources without ever interacting with you directly.
"Brokered personal information" includes computerized data elements organized for dissemination to third parties, such as name, address, date of birth, Social Security number, and biometric data.
Registration Requirements
Every data broker that meets the statutory definition must register annually with the Vermont Secretary of State by January 31 of each year. The current registration fee is $100 per year.
Data brokers must disclose the following in their registration:
- Business name, physical address, email address, and website URL
- A description of opt-out methods available to consumers, if any
- Which data collection or sales activities consumers cannot opt out of
- Whether the broker uses purchaser credentialing (verifying who buys data)
- The number of data security breaches experienced in the prior year
- The total number of consumers affected by those breaches
- Whether the broker collects data on minors, and if so, the collection and opt-out practices for that data
This information becomes part of a public registry maintained by the Vermont Secretary of State.
Penalties for Failing to Register
A data broker that fails to register faces a civil penalty of $50 per day, capped at $10,000 annually for each year of noncompliance. The broker must also pay all back registration fees owed during the period of noncompliance. The Vermont Attorney General may pursue additional civil enforcement and injunctive relief.
Security Requirements for Data Brokers (9 V.S.A. 2447)
Beyond registration, Vermont imposes detailed security obligations on data brokers. Under 9 V.S.A. 2447, every data broker must "develop, implement, and maintain a comprehensive information security program" with safeguards appropriate to the business's size, resources, data volume, and the sensitivity of the information stored.
The law specifies ten minimum program requirements:
- Designate one or more employees responsible for maintaining the security program
- Conduct risk assessments that identify internal and external threats
- Establish employee policies for storing and transporting records outside business premises
- Implement disciplinary procedures for security policy violations
- Prevent terminated employees from accessing personal data
- Select third-party service providers capable of maintaining adequate safeguards and require contractual security obligations
- Maintain physical security controls, including locked storage for records
- Conduct regular monitoring to ensure program effectiveness
- Perform annual reviews of the security program scope
- Document all breach responses and conduct post-incident reviews
The law also mandates specific technical protections: secure authentication protocols, access controls limiting data to employees who need it, encryption for all data transmitted over external networks and stored on portable devices, firewall protection and current security patches, malware detection software, and employee training.
Violations of these security requirements constitute "unfair and deceptive acts" under Vermont consumer protection law, enforceable by the Attorney General.
H.211: The Vermont Delete Act (Enacted as Act 138)
In March 2026, the Vermont House of Representatives passed H.211, modeled after California's 2023 Delete Act. H.211 passed the House on March 25, 2026, and was referred to the Senate Committee on Economic Development, Housing and General Affairs. Governor Phil Scott signed H.211 into law on June 16, 2026 as Act 138, the same day he signed S.71.
As enacted, Act 138:
- Raises the annual data broker registration fee from $100 to $900 and adds a $20,000 surety bond requirement, both effective January 1, 2027
- Increases penalties effective January 1, 2027: $200 per day for operating unregistered, $1,000 per day for incomplete registration information, and a $25,000 civil penalty for materially incorrect filings
- Creates a Data Broker Security Breach Notice Act requiring data brokers to notify the Attorney General and affected consumers of breaches involving brokered personal information
- Requires data brokers that already permit deletion to disclose, in their registration, a webpage where consumers can request it; the law does not create a general right to demand deletion from every broker
- Directs the Secretary of State to study the feasibility of a centralized deletion mechanism that would let a consumer request deletion from every registered data broker at once, with a final report due December 1, 2028
The Senate removed H.211's original universal deletion right and centralized opt-out portal before passage. A mandatory, single-request deletion portal remains a study topic, not current Vermont law.

Vermont's Security Breach Notice Act (9 V.S.A. 2430, 2435)
Vermont's data breach notification law is codified at 9 V.S.A. 2435. The law applies to any "data collector," which the statute defines broadly as any person or entity that handles, collects, or disseminates personally identifiable information, including businesses, government agencies, universities, and retailers.
What Triggers a Notification
A notification is required when there is a "security breach," defined under 9 V.S.A. 2430 as the unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer's personally identifiable information.
"Personally identifiable information" under Vermont law means a consumer's first name or initial combined with their last name, plus one or more of the following data elements:
- Social Security number
- Driver's license or state ID number
- Financial account number, credit card number, or debit card number (combined with any security code or password needed to access the account)
- Passwords or personal identification numbers for financial accounts
- Biometric data (fingerprint, retina scan, or similar identifier)
- Health records or wellness program records
- Individual taxpayer identification number
Login credentials (username combined with password or security question) are also covered, though the notification requirements are slightly different.
Notification Timeline
Vermont requires notification "in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification" of the breach.
The data collector must also notify the Vermont Attorney General (or the Department of Financial Regulation for regulated financial institutions) within 14 business days of discovering the breach. This preliminary notice must include a description of the breach.
If the breach affects more than 1,000 consumers, the data collector must also notify consumer reporting agencies.
What the Notice Must Include
Breach notifications must be "clear and conspicuous" and include:
- A general description of the security incident
- The types of personal information that were compromised
- The protective measures the company has implemented in response
- A toll-free contact number for consumer inquiries
- Advice about monitoring accounts and credit reports
- The approximate date of the breach
How Notice Can Be Delivered
Data collectors may provide notice through direct methods: written mail, email (with certain conditions), or telephone. If the cost of direct notice would exceed $10,000, or if affected consumers' contact information is unavailable, the data collector may use substitute notice through prominent posting on the company's website and notification of major statewide media.
Exemptions
HIPAA-covered entities that comply with federal health privacy breach notification rules are deemed compliant with Vermont's law. Federally regulated financial institutions that comply with the March 7, 2005 Federal Interagency Guidance on Response Programs, or, for credit unions, the NCUA's April 14, 2005 guidance, are also exempt from Vermont's consumer notification requirement, though they must still notify the Department of Financial Regulation. Entities that can demonstrate to the Attorney General that misuse of the compromised information is "not reasonably possible" may also avoid consumer notification, though they must still notify authorities.
Enforcement
The Vermont Attorney General and State's Attorneys enforce the breach notification law. The Department of Financial Regulation handles enforcement for regulated financial institutions.
Brokered Personal Information Prohibitions (9 V.S.A. 2431)
Separate from the data broker registry, Vermont law under 9 V.S.A. 2431 prohibits specific harmful uses of brokered personal information.
It is illegal in Vermont to:
- Acquire brokered personal information through fraudulent means
- Use brokered personal information for stalking, harassment, fraud, or unlawful discrimination
Violations are treated as unfair and deceptive trade practices, enforceable by the Attorney General under Vermont's Consumer Protection Act (Chapter 63 of Title 9).
Social Security Number Protection (9 V.S.A. 2440)
Vermont's Social Security Number Protection Act under 9 V.S.A. 2440 restricts how businesses and state agencies can handle Social Security numbers.
Business Restrictions
Businesses operating in Vermont may not:
- Intentionally make an individual's Social Security number available to the general public
- Print Social Security numbers on access cards or identification cards
- Require transmission of a Social Security number over an unsecured internet connection without encryption
- Require a Social Security number as the sole login credential for online access without additional authentication
- Print Social Security numbers on mailed materials unless legally required, and they may never appear on postcards or through visible envelope windows
- Sell or disclose Social Security numbers to third parties without written consent, unless the disclosure serves a legitimate business purpose
State Agency Restrictions
State government entities face similar prohibitions on collecting, displaying, transmitting, and publicly disclosing Social Security numbers. State agencies must provide disclosure statements explaining why they collect SSNs and must segregate SSN information in their records.
Exemptions
The restrictions do not apply when Social Security numbers are part of enrollment documentation, used for administrative verification or fraud investigation, required for credit reporting under federal law, ordered by a court or law enforcement, obtained from public records, or used under grandfathered arrangements continuous since before January 1, 2007.
Vermont Age-Appropriate Design Code Act (S.69, Act 63)

Governor Phil Scott signed the Vermont Age-Appropriate Design Code Act (S.69) into law on June 12, 2025, as Act 63. The law takes effect January 1, 2027. The Vermont Attorney General's Office is conducting formal rulemaking in spring 2026 to develop implementing regulations.
Who the Law Covers
The AADC applies to "covered businesses" that operate online platforms, products, or services that are likely to be accessed by minors. It mirrors similar laws enacted in California and other states while reflecting Vermont-specific enforcement priorities.
Core Requirements
Covered businesses must:
- Default all privacy settings to the highest level of privacy available when the user is or is likely to be a minor
- Refrain from collecting or sharing a minor's personal data beyond what is strictly necessary to provide the requested service
- Avoid using design features that encourage minors to spend excessive time on the platform or to share more personal data than necessary
- Conduct data protection impact assessments for products and services likely to be accessed by minors before launching or significantly changing them
Enforcement
The Vermont Attorney General enforces the AADC. Violations are subject to civil penalties under Vermont consumer protection law. Because rulemaking is ongoing as of spring 2026, businesses have time to assess their compliance obligations before the January 1, 2027, effective date.
Student Privacy Protections (9 V.S.A. 2443-2443a)
Vermont added student privacy protections in 2019, codified at 9 V.S.A. 2443 (definitions) and 9 V.S.A. 2443a (operator prohibitions). These protections apply to PreK-12 education technology operators and complement the broader AADC requirements for minors online.
Who the Law Covers
The law applies to "operators," defined as entities running websites, online services, or applications with actual knowledge that their product is used primarily for PreK-12 school purposes and was designed and marketed for PreK-12 school purposes.
What "Covered Information" Includes
Covered information is broadly defined and includes personal data in any format that is either non-public or disclosed under FERPA. It encompasses discipline records, test results, special education data, juvenile dependency records, grades, evaluations, criminal records, medical records, health records, Social Security numbers, biometric information, disability status, socioeconomic information, food purchases, political affiliations, and religious information.
Prohibited Activities
Education technology operators may not:
- Engage in targeted advertising based on information acquired through PreK-12 school use of their platform
- Build student profiles using persistent identifiers or gathered data outside of educational purposes
- Sell, barter, or rent a student's covered information
- Disclose covered information except for specific authorized purposes
Permitted Disclosures
Operators may share covered information only for: furthering educational purposes (with restrictions on how recipients can use the data), complying with legal or regulatory requirements, responding to judicial process, protecting user safety and security, or purposes requested by the student or parent. Operators may freely use information for "maintaining, developing, supporting, improving, or diagnosing" their own platform.
Federal Privacy Framework in Vermont
Because Vermont lacks a comprehensive state consumer privacy law, several federal statutes provide important baseline protections for Vermont residents.

TAKE IT DOWN Act (Pub. L. 119-12, 2025)
President Trump signed the TAKE IT DOWN Act into law on May 19, 2025. The law creates federal criminal prohibitions on publishing nonconsensual intimate images (NCII), including AI-generated deepfakes. Criminal penalties took effect immediately upon signing. Platform obligations (covered platforms must establish a notice-and-removal process and remove flagged NCII within 48 hours of receiving a valid notice) became effective May 19, 2026, and are enforced by the Federal Trade Commission. Vermont residents who are victims of NCII can request removal from covered platforms under this federal framework regardless of the absence of a comprehensive state privacy law.
HIPAA (Health Insurance Portability and Accountability Act)
HIPAA protects health information held by covered entities such as hospitals, insurers, and healthcare providers. Vermont's breach notification law explicitly recognizes HIPAA compliance as sufficient to meet state requirements for healthcare data breaches.
FERPA (Family Educational Rights and Privacy Act)
FERPA protects student education records at institutions receiving federal funding. Vermont's student privacy law (9 V.S.A. 2443) references FERPA and extends protections to education technology operators that FERPA does not directly regulate.
COPPA (Children's Online Privacy Protection Act)
COPPA requires websites and online services to obtain verifiable parental consent before collecting personal information from children under 13. This federal law applies in Vermont and complements the state's student privacy protections and the new AADC.
Gramm-Leach-Bliley Act (GLBA)
GLBA requires financial institutions to explain their information-sharing practices and to safeguard sensitive data. Vermont's breach notification law coordinates with GLBA by routing financial institution breach reports through the Department of Financial Regulation rather than the Attorney General.
FTC Act Section 5
The Federal Trade Commission enforces prohibitions against unfair or deceptive practices, including data privacy violations. The FTC has pursued enforcement actions against companies that mishandle consumer data, providing a federal backstop in states like Vermont that lack comprehensive privacy statutes.
Vermont's New Comprehensive Consumer Privacy Law
After two legislative cycles, Vermont enacted a comprehensive consumer data privacy law in 2026.
H.121 (2024): Vetoed. The Vermont legislature passed H.121 in 2024, a bill titled "An act relating to enhancing consumer privacy and the age-appropriate design code." Governor Phil Scott vetoed it on June 17, 2024, primarily objecting to its private right of action provision. The Senate sustained the veto.
S.71 (2025-2026 session): Enacted (Act 145). The legislature revived comprehensive consumer privacy legislation as S.71, titled "An act relating to consumer data privacy and online surveillance." The Senate unanimously passed an amended version in March 2025 after stripping the private right of action that doomed H.121. The bill would grant Vermont residents rights to access, correct, and delete their personal data, and to opt out of certain data processing activities. After the House passed an amended version, Governor Phil Scott signed S.71 into law on June 16, 2026 as Act 145. Act 145 applies to businesses that, in the preceding calendar year, controlled or processed the personal data of at least 35,000 Vermont consumers, controlled or processed the sensitive data of at least 3,000 consumers, or sold the personal data of at least 3,000 consumers; it exempts government entities, most HIPAA-covered entities, GLBA-regulated financial data, and most insurers, among others. Most provisions take effect January 1, 2028, with Attorney General enforcement and no private right of action. Once in force, the law will give Vermont residents rights to access, correct, and delete their personal data and to opt out of certain processing.
Note on H.342: H.342 in the 2025-2026 session is a narrower bill addressing the personal information of certain public servants, not a comprehensive consumer privacy measure.
How Vermont Compares to Other States
Vermont occupies an unusual position in the national data privacy landscape. It was a genuine pioneer with the data broker registry and the AADC, but it still lacks the comprehensive consumer rights framework that many other states have adopted.

Strengths of Vermont's approach:
- First state to require data broker registration, creating public transparency since 2018
- Strong security requirements for data brokers with detailed technical standards under 9 V.S.A. 2447
- Relatively strict 45-day breach notification deadline with 14-day AG notification requirement
- Student privacy protections that extend beyond federal FERPA requirements
- Social Security number protections with specific use restrictions
- Age-Appropriate Design Code (Act 63) enacted June 2025, effective January 2027
- H.211 Delete Act, enacted as Act 138 (June 2026), raises data broker fees, penalties, and breach-notice duties; a centralized deletion mechanism remains under feasibility study
Gaps in Vermont's framework:
- No comprehensive consumer data privacy law in force yet (S.71/Act 145 enacted June 16, 2026; effective January 1, 2028)
- No universal opt-out right for the sale of personal information currently in force
- No private right of action for data privacy violations (only AG enforcement)
- Data broker registration penalties are modest ($50/day, capped at $10,000/year)
- No specific biometric privacy statute beyond the breach notification and AADC contexts
This article is for informational purposes only and does not constitute legal advice. Data privacy laws change frequently, and enforcement interpretations evolve over time. Consult a licensed attorney in Vermont for advice about your specific situation. Last reviewed: June 2026.
Related news
-
Vermont Passes Data Privacy and Online Surveillance Act (S.71)
-
Vermont H.211 Data Broker Overhaul Heads to the Governor (2026)
More Vermont Laws
Frequently Asked Questions
Does Vermont have a comprehensive consumer data privacy law?
Yes. Vermont enacted the Data Privacy and Online Surveillance Act (S.71, Act 145), which Governor Phil Scott signed on June 16, 2026. It creates broad consumer rights to access, correct, and delete personal data and to opt out of certain processing, enforced by the Attorney General with no private right of action. Most provisions take effect January 1, 2028, so Vermont residents will gain these statutory rights once the law is in force. The law applies to businesses that processed the personal data of at least 35,000 Vermont consumers, or the sensitive data or sale of the personal data of at least 3,000 consumers, in the preceding calendar year. Vermont's in-force privacy protections are targeted: data broker registration, breach notification, student privacy, Social Security number safeguards, and the Age-Appropriate Design Code.
What is Vermont's data broker registry and why is it significant?
Vermont's data broker registry, created by Act 171 in 2018 and codified at 9 V.S.A. 2446, requires any business that knowingly collects and sells personal information about consumers it has no direct relationship with to register annually with the Vermont Secretary of State. The registration fee is $100 per year and requires disclosure of opt-out policies, breach history, and practices regarding minors' data. Vermont was the first state in the nation to create this requirement. As of 2025-2026, 283 data brokers are registered. A June 2025 review identified approximately 309 additional companies that had registered in other states but not in Vermont, flagging a compliance enforcement opportunity.
How quickly must a business notify me of a data breach in Vermont?
Under 9 V.S.A. 2435, a business must notify affected Vermont consumers in the most expedient time possible and without unreasonable delay, but no later than 45 days after discovering the breach. The business must also notify the Vermont Attorney General within 14 business days with a preliminary description of the breach. If the breach affects more than 1,000 consumers, the business must additionally notify consumer reporting agencies.
What is the Vermont Age-Appropriate Design Code Act?
The Vermont Age-Appropriate Design Code Act (S.69, Act 63) was signed by Governor Phil Scott on June 12, 2025, and takes effect January 1, 2027. It requires covered online platforms likely to be accessed by minors to default to the highest available privacy settings, to collect only the personal data necessary to provide the requested service, and to avoid design features that encourage excessive data sharing or time on the platform. The Vermont Attorney General is conducting rulemaking in 2026 to develop implementing regulations. Businesses that operate platforms likely used by minors should monitor the rulemaking process.
What is H.211 and how did it change Vermont's data broker law?
H.211, known informally as the Vermont Delete Act, passed the Vermont House of Representatives on March 25, 2026, and Governor Phil Scott signed it into law as Act 138 on June 16, 2026. The enacted law raises the annual registration fee from $100 to $900, adds a $20,000 surety bond requirement, and increases noncompliance penalties, effective January 1, 2027. The Senate removed the bill's universal consumer deletion right and centralized opt-out portal before passage; instead, Act 138 directs the Secretary of State to study the feasibility of a centralized deletion mechanism, with a final report due December 1, 2028.
Are there penalties for data brokers that do not register in Vermont?
Yes. Under 9 V.S.A. 2446, a data broker that fails to register faces a civil penalty of $50 per day of noncompliance, capped at $10,000 per year. The broker must also pay all unpaid registration fees for the period of noncompliance. The Vermont Attorney General may pursue additional civil enforcement and seek injunctive relief. Violations of the data broker security requirements under 9 V.S.A. 2447 are treated as unfair and deceptive trade practices, which carry additional penalties.
How does Vermont protect student data privacy?
Vermont protects student data under 9 V.S.A. 2443 and 2443a, enacted in 2019. The law applies to education technology operators whose products are used primarily for PreK-12 school purposes. These operators are prohibited from using student data for targeted advertising, building non-educational profiles using student information, selling or renting student data, and disclosing covered information except for specific authorized purposes. Covered information includes grades, test results, disciplinary records, health records, biometric data, and Social Security numbers. The 2025 Age-Appropriate Design Code Act (Act 63) adds an additional layer for online platforms used by minors more broadly.
Does the federal TAKE IT DOWN Act protect Vermont residents?
Yes. The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, applies nationwide, including Vermont. It creates federal criminal liability for publishing nonconsensual intimate images, including AI-generated deepfakes. Beginning May 19, 2026, covered online platforms must also maintain a notice-and-removal process and remove flagged images within 48 hours of receiving a valid request. The Federal Trade Commission enforces the platform obligations. Vermont residents who are victims of nonconsensual intimate image sharing can use this federal framework regardless of the state's lack of a comprehensive privacy law.
Updates
Clarified in the introduction that Vermont's data broker registry, breach notification, student privacy, and Social Security number rules are separate, pre-existing Chapter 62 statutes rather than parts of the 2026 comprehensive privacy act.
Corrected a fabricated claim that Governor Scott vetoed S.71 before signing it (he never vetoed it -- he signed it directly on June 16, 2026 as Act 145), updated H.211 from 'pending' to enacted (it too was signed June 16, 2026, as Act 138, with the Senate having stripped the universal consumer deletion right and centralized opt-out portal in favor of a feasibility study), fixed the data-broker registration law's effective date (Act 171 became law in 2018 but the registration duty itself started January 1, 2019), and added Act 145's consumer-count applicability thresholds and a financial-institution breach-notice exemption that the page had omitted.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
June 2026 correction: Governor Phil Scott signed S.71 into law on June 16, 2026 as Act 145, the Vermont Data Privacy and Online Surveillance Act (most provisions effective January 1, 2028; AG enforcement; no private right of action). Updated the intro, data-broker overview, key takeaways, comprehensive-law section, gaps list, FAQ, and the S.71 citation to reflect enactment.
May 2026 refresh: Added Vermont Age-Appropriate Design Code Act (S.69, Act 63, signed June 2025, effective Jan 1, 2027) as new H2 section. Updated data broker section with current registry count (283 registered), AG Clark compliance enforcement context, and H.211 Delete Act (passed House March 2026, pending Senate). Updated comprehensive privacy legislation section to accurately reflect S.71 (2025-2026 revival, passed Senate March 2025, in House committee spring 2026, not yet law). Corrected H.342 characterization (narrow public-servants bill, not comprehensive privacy revival). Added federal TAKE IT DOWN Act (signed May 2025, platform obligations effective May 2026). Updated all date references from March 2026 to May 2026. Added 6 new citations (S.71, H.211, S.69/Act 63, TAKE IT DOWN Act, AG rulemaking page). Expanded FAQ from 5 to 8 questions.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: SECURITY BREACH NOTICE ACT
§ 2435Notice of security breachesIn forcecited in 4 of our articles
(a) This section shall be known as the Security Breach Notice Act. (b) Notice of breach. (1) Except as otherwise provided in subsection (d) of this section, any data collector that owns or licenses computerized personally identifiable information or login credentials shall notify the consumer that there has been a security breach following discovery or notification to the data collector of the breach. Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency, as provided in subdivisions (3) and (4) of this subsection, or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.vermont.gov
Also relied on in: Vermont Biometric Privacy Laws: Collection, Consent & Penalties (2026), Vermont Identity Theft Laws: Penalties and Victim Rights, Vermont Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: DATA BROKERS
§ 2446Annual registrationIn forcecited in 2 of our articles
(a) Annually, on or before January 31 following a year in which a person meets the definition of data broker as provided in section 2430 of this title, a data broker shall: (1) register with the Secretary of State; (2) pay a registration fee of $100.00; and (3) provide the following information: (A) the name and primary physical, e-mail, and Internet addresses of the data broker; (B) if the data broker permits a consumer to opt out of the data broker’s collection of brokered personal information, opt out of its databases, or opt out of certain sales of data: (i) the method for requesting an opt-out; (ii) if the opt-out applies to only certain activities or sales, which ones; and (iii) whether the data broker permits a consumer to authorize a third party to perform the opt-out on the consumer’s behalf; (C) a statement specifying the data collection, databases, or sales activities from which a consumer may not opt out; (D) a statement whether the data broker implements a purchaser credentialing process; (E) the number of data broker security breaches that the data broker has experienced during the prior year, and if known, the total number of consumers affected by the…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Clearview Ai (Vermont Superior Court 2026)“…ed as a data broker in Vermont’s Data Broker Registry. See 9 V.S.A. § 2446. A data broker is “a business . . . tha…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to Opt Out of Data Brokers (2026)
§ 2447Data broker duty to protect information; standards; technical requirementsIn force
(a) Duty to protect personally identifiable information. (1) A data broker shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to: (A) the size, scope, and type of business of the data broker obligated to safeguard the personally identifiable information under such comprehensive information security program; (B) the amount of resources available to the data broker; (C) the amount of stored data; and (D) the need for security and confidentiality of personally identifiable information. (2) A data broker subject to this subsection shall adopt safeguards in the comprehensive security program that are consistent with the safeguards for protection of personally identifiable information and information of a similar character set forth in other State rules or federal regulations applicable to the data broker. (b) Information security program; minimum features.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: GENERAL PROVISIONS
§ 2430DefinitionsIn forcecited in 3 of our articles
As used in this chapter: (1)(A) “Brokered personal information” means one or more of the following computerized data elements about a consumer, if categorized or organized for dissemination to third parties: (i) name; (ii) address; (iii) date of birth; (iv) place of birth; (v) mother’s maiden name; (vi) unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data; (vii) name or address of a member of the consumer’s immediate family or household; (viii) Social Security number or other government-issued identification number; or (ix) other information that, alone or in combination with the other information sold or licensed, would allow a reasonable person to identify the consumer with reasonable certainty. (B) “Brokered personal information” does not include publicly available information to the extent that it is related to a consumer’s business or profession.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Clearview Ai (Vermont Superior Court 2026)“…relationship.” 9 V.S.A. § 2430(4). As a small start-up company…”
- Buksh v. Dr. William Sarchino DPM Foot and Ankle Surgeon (District Court, D. Vermont 2024)“…red by Vermont’s Security Breach Notice Act, 9 V.S.A. §§ 2430 and 2435. The correspondence…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 2431Acquisition of brokered personal information; prohibitionsIn force
(a) Prohibited acquisition and use. (1) A person shall not acquire brokered personal information through fraudulent means. (2) A person shall not acquire or use brokered personal information for the purpose of: (A) stalking or harassing another person; (B) committing a fraud, including identity theft, financial fraud, or e-mail fraud; or (C) engaging in unlawful discrimination, including employment discrimination and housing discrimination. (b) Enforcement. (1) A person who violates a provision of this section commits an unfair and deceptive act in commerce in violation of section 2453 of this title. (2) The Attorney General has the same authority to adopt rules to implement the provisions of this section and to conduct civil investigations, enter into assurances of discontinuance, bring civil actions, and take other enforcement actions as provided under chapter 63, subchapter 1 of this title. (Added 2017, No. 171 (Adj. Sess.), § 2, eff. Jan. 1, 2019.)
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Clearview Ai (Vermont Superior Court 2026)“…and II) and Vermont’s Fraudulent Acquisition of Data law (9 V.S.A. § 2431(a)(1)) (Count III). Clearview moves to…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: SOCIAL SECURITY NUMBER PROTECTION ACT
§ 2440Social Security number protectionIn force
(a) This section shall be known as the Social Security Number Protection Act. (b) Except as provided in subsection (c) of this section, a business may not do any of the following: (1) intentionally communicate or otherwise make available to the general public an individual’s Social Security number; (2) intentionally print or imbed an individual’s Social Security number on any card required for the individual to access products or services provided by the person or entity; (3) require an individual to transmit his or her Social Security number over the Internet unless the connection is secure or the Social Security number is encrypted; (4) require an individual to use his or her Social Security number to access an Internet website, unless a password or unique personal identification number or other authentication device is also required to access the internet website; (5) print an individual’s Social Security number on any materials that are mailed to the individual, unless State or federal law requires the Social Security number to be on the document to be mailed; (6) sell, lease, lend, trade, rent, or otherwise intentionally disclose an individual’s Social Security number…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: STUDENT PRIVACY
§ 2443aOperator prohibitionsIn force
(a) An operator shall not knowingly do any of the following with respect to its site, service, or application: (1) Engage in targeted advertising on the operator’s site, service, or application or target advertising on any other site, service, or application if the targeting of the advertising is based on any information, including covered information and persistent unique identifiers, that the operator has acquired because of the use of that operator’s site, service, or application for PreK-12 school purposes. (2) Use information, including a persistent unique identifier, that is created or gathered by the operator’s site, service, or application to amass a profile about a student, except in furtherance of PreK-12 school purposes. “Amass a profile” does not include the collection and retention of account information that remains under the control of the student, the student’s parent or legal guardian, or the school. (3) Sell, barter, or rent a student’s information, including covered information.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
§ 2443DefinitionsIn force
As used in this subchapter: (1) “Covered information” means personal information or material, or information that is linked to personal information or material, in any media or format that is: (A)(i) not publicly available; or (ii) made publicly available pursuant to the federal Family Educational and Rights and Privacy Act; and (B)(i) created by or provided to an operator by a student or the student’s parent or legal guardian in the course of the student’s, parent’s, or legal guardian’s use of the operator’s site, service, or application for PreK-12 school purposes; (ii) created by or provided to an operator by an employee or agent of a school or school district for PreK-12 school purposes; or (iii) gathered by an operator through the operation of its site, service, or application for PreK-12 school purposes and personally identifies a student, including information in the student’s education record or electronic mail, first and last name, home address, telephone number, electronic mail address or other information that allows physical or online contact, discipline records, test results, special education data, juvenile dependency records, grades, evaluations, criminal…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 9 V.S.A. Chapter 62: Protection of Personal Information (Full Chapter)(legislature.vermont.gov).gov
- 9 V.S.A. 2430: Definitions for Protection of Personal Information(legislature.vermont.gov).gov
- 9 V.S.A. 2431: Brokered Personal Information Prohibitions(legislature.vermont.gov).gov
- 9 V.S.A. 2435: Notice of Security Breaches(legislature.vermont.gov).gov
- 9 V.S.A. 2440: Social Security Number Protection(legislature.vermont.gov).gov
- 9 V.S.A. 2443: Student Privacy Definitions(legislature.vermont.gov).gov
- 9 V.S.A. 2443a: Student Privacy Operator Prohibitions(legislature.vermont.gov).gov
- 9 V.S.A. 2446: Data Broker Annual Registration(legislature.vermont.gov).gov
- 9 V.S.A. 2447: Data Broker Duty to Protect Information(legislature.vermont.gov).gov
- H.764 (Act 171, 2018): Data Broker Registration Law(legislature.vermont.gov).gov
- H.121 (2024): Consumer Privacy and Age-Appropriate Design Code (Vetoed)(legislature.vermont.gov).gov
- S.71 (Act 145, 2026): Vermont Data Privacy and Online Surveillance Act (Enacted June 16, 2026)(legislature.vermont.gov).gov
- H.211 (Act 138, 2026): An Act Relating to Data Brokers and Personal Information (Enacted June 16, 2026)(legislature.vermont.gov).gov
- S.69 (Act 63, 2025): Vermont Age-Appropriate Design Code Act(legislature.vermont.gov).gov
- Act 63 As Enacted: Vermont Age-Appropriate Design Code(legislature.vermont.gov).gov
- Vermont AG Office: Age-Appropriate Design Code Rulemaking(ago.vermont.gov).gov
- TAKE IT DOWN Act, Pub. L. 119-12 (S.146, 119th Congress)(congress.gov).gov
- Office of Governor Phil Scott: Action Taken on Legislation, June 16, 2026 (S.71 signed as Act 145)(governor.vermont.gov).gov