Vermont
Vermont Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

Vermont does not have a standalone biometric privacy statute in effect today. Governor Phil Scott vetoed H.121, a comprehensive bill that would have created one, in June 2024. Since then, the legislature passed a narrower successor: the Vermont Data Privacy and Online Surveillance Act (Act 145, S.71), signed into law on June 16, 2026 and taking effect January 1, 2028. Act 145 classifies biometric data as sensitive data requiring opt-in consumer consent before it can be processed or sold. Until Act 145 takes effect, biometric data is protected narrowly through the breach notification statute (9 V.S.A. 2435) and the data broker registration law (9 V.S.A. 2446), with no private right of action.
Vermont occupies a unique position in the national biometric privacy landscape. The state came closer than almost any other to enacting one of the strongest comprehensive data privacy laws in the country, with robust biometric data protections and a private right of action. Governor Phil Scott's veto of H.121 in June 2024 stopped that effort, and the legislature failed to override the veto by a single Senate vote.
Despite that setback, Vermont is not without biometric data protections. The state's breach notification law explicitly covers biometric data, and Vermont's first-in-the-nation data broker registration law addresses biometric data collection and sale by data brokers. These protections, however, fall far short of the comprehensive framework that H.121 would have established.
For a broader overview of privacy protections in the state, see the parent guide to Vermont Data Privacy Laws.
The Vetoed Vermont Data Privacy Act (H.121)
Understanding what H.121 would have done is essential context for Vermont's current biometric privacy landscape. The bill passed the Vermont House with near-unanimous support and cleared the Senate before Governor Scott vetoed it on June 13, 2024.
What H.121 Would Have Done for Biometric Data
The bill as passed by both chambers would have:
- Classified biometric data as sensitive personal data requiring opt-in consent before processing
- Created a private right of action allowing individuals to sue for actual damages when companies mishandled sensitive data including biometric identifiers
- Required data minimization, limiting businesses to collecting only the biometric data necessary for a stated purpose
- Established purpose limitations preventing the use of biometric data beyond its original collection purpose
- Required businesses to conduct data protection assessments before processing biometric data
Why the Governor Vetoed It
In his veto letter, Governor Scott cited several concerns. He called the private right of action a provision that would make Vermont "a national outlier, and more hostile than any other state to many businesses and non-profits." He recommended Vermont instead adopt a framework similar to Connecticut's data privacy law, which does not include a private right of action.
The House voted 128-17 to override the veto, but the Senate fell short at 14-15, well below the 20 votes needed for a two-thirds override.
Vermont Attorney General Charity Clark issued a statement expressing disappointment with the veto and reaffirming her office's commitment to pursuing biometric data protections through other channels.

Current Biometric Data Protections
Without a comprehensive privacy law yet in effect, Vermont's biometric data protections come from two existing statutes: the breach notification law and the data broker registration law. That will change on January 1, 2028, when Act 145 takes effect.
Breach Notification Law (9 V.S.A. 2435)
Vermont's Security Breach Notice Act was expanded through Act 89 of 2020 to explicitly include biometric data within the definition of personally identifiable information (PII).
Under the law, biometric data means unique biometric data generated from measurements or technical analysis of human body characteristics used to identify or authenticate a consumer. Examples include:
- Fingerprints
- Retina or iris images
- Other unique physical or digital representations of biometric data
When a security breach exposes biometric data, the law triggers several requirements:
Consumer Notification: The data collector must notify affected Vermont residents within 45 days of discovering or being notified of the breach.
Regulator Notification: The regulator notice goes to one agency or the other, not to both. Under 9 V.S.A. 2435(b)(3)(A), a data collector regulated by the Vermont Department of Financial Regulation under Title 8 notifies the Department; every other data collector subject to the subchapter notifies the Attorney General.
14-Business-Day Regulator Deadline: Whichever regulator applies must be told the date of the breach, the date of discovery, and a preliminary description within 14 business days of the data collector's discovery of the breach or of the date it notifies consumers, whichever is sooner. There is no minimum number of affected Vermonters: the duty attaches to the breach itself, not to a headcount. The only number-based trigger in the section is subsection (c), which requires notice to the nationwide consumer reporting agencies when a data collector notifies more than 1,000 consumers at one time.
Notice Content Requirements: Vermont's breach notice statute requires the notice letter itself to advise consumers to remain vigilant by reviewing account statements and monitoring their free credit reports. This advice requirement applies to breach notices generally, including biometric-only breaches. The law does not require the data collector to purchase or provide a credit monitoring service for any category of breach.
Data Broker Registration Law (9 V.S.A. 2446)

Vermont's data broker registration law, enacted in 2018 as Act 171, was the first state law in the nation requiring data brokers to register with the government. The law is relevant to biometric privacy because data brokers that collect and sell biometric data must comply with its requirements.
Under the chapter's definitions section, "brokered personal information" includes unique biometric data generated from measurements or technical analysis of human body characteristics used to identify or authenticate a consumer, such as fingerprints, retina or iris images, or other unique physical or digital representations.
Data brokers must:
- Register with the Vermont Secretary of State annually, on or before January 31 following a year in which the business met the definition of a data broker, and pay a $100 registration fee (rising to $900 annually effective January 1, 2027, under Act 138)
- Disclose whether they collect biometric data
- Describe their data collection, sale, and licensing practices
- Develop comprehensive written information security programs, a separate duty imposed by 9 V.S.A. 2447
- Disclose whether consumers may opt out and, if so, how to request an opt-out, along with a statement specifying the collection, databases, or sales activities from which a consumer may not opt out
That last item is a disclosure duty, not a substantive right. Section 2446(a)(3)(B) applies only "if the data broker permits a consumer to opt out," and 2446(a)(3)(C) expressly contemplates activities a consumer cannot opt out of. Vermont requires a data broker to tell the public whether an opt-out exists; it does not require the broker to offer one.
As of early 2026, approximately 283 data broker companies are registered with the Secretary of State.

What Vermont Law Does Not Cover
The gaps described below reflect the law in effect today. Most will close on January 1, 2028, when Act 145 requires opt-in consent, data minimization, and purpose limitation for biometric data as sensitive data. Until then, the gaps in Vermont's biometric privacy framework remain substantial.
No Collection Consent Requirements
Vermont has no law requiring businesses to obtain consent before collecting biometric data from consumers or employees. A company can implement fingerprint scanners, facial recognition systems, or voice authentication without prior notice or permission.
No Retention or Destruction Requirements
No Vermont law requires organizations to set retention schedules for biometric data or to destroy it when the purpose for collection has ended.
No Private Right of Action
Individuals cannot sue companies in Vermont for collecting, using, or selling their biometric data without consent. This was the most contentious provision in H.121 and the primary reason the governor vetoed the bill. Act 145, H.121's successor, also excludes a private right of action; enforcement remains exclusive to the Attorney General even after the new law takes effect January 1, 2028.
No Purpose Limitation
Businesses that collect biometric data in Vermont face no restrictions on how they use it, beyond the data broker registration requirements.
Enforcement
The Vermont Attorney General enforces biometric data protections primarily through the Vermont Consumer Protection Act (9 V.S.A. Chapter 63). The failure to maintain reasonable data security practices is considered an unfair or deceptive act under the Consumer Protection Act, and the AG can bring enforcement actions accordingly.
For breach notification violations, the Attorney General can seek injunctive relief and civil penalties. The Department of Financial Regulation also has enforcement authority over regulated financial entities.
Comprehensive Privacy Law Enacted: Act 145 (2026)
The veto of H.121 did not end the push for comprehensive privacy legislation in Vermont. Lawmakers broke the privacy agenda into separate bills, and both were signed into law on June 16, 2026.
S.71, signed as Act 145, the Vermont Data Privacy and Online Surveillance Act, creates a comprehensive privacy framework that omits a private right of action, addressing Governor Scott's earlier objection. The law classifies biometric data as sensitive data and requires opt-in consumer consent before a business may process or sell it. It applies to organizations that process the data of at least 35,000 Vermont consumers, process the sensitive data (including biometric data) of at least 3,000 consumers, or sell the personal data of at least 3,000 consumers. Enforcement is exclusive to the Vermont Attorney General, with a temporary cure period, running from January 1, 2028 through June 30, 2029, that requires the AG to give a violator 60 days to fix a violation before bringing an action. Act 145 takes effect January 1, 2028.
H.211, signed as Act 138, is a companion law targeting the approximately 283 data broker companies registered with the Secretary of State that collect and sell personal information including biometric data. It raises the data broker registration fee from $100 to $900 annually and adds a new Data Broker Security Breach Notice Act, both effective January 1, 2027.
Until Act 145 takes effect on January 1, 2028, Vermont's only biometric data protections remain the breach notification law and the data broker registration law described above. Residents and businesses should monitor the Vermont Legislature website and the Vermont Attorney General's privacy page for compliance guidance as the effective date approaches.
Sources and References
This article references Vermont statutes available through the Vermont Legislature website. For information about the H.121 veto, see the Governor's veto letter and the Attorney General's statement. For consumer complaints, contact the Vermont Attorney General's Privacy and Data Security division. For data breach information, visit the Vermont Department of Financial Regulation.
This article provides general legal information about Vermont biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Vermont government sources.
More Vermont Laws
Frequently Asked Questions
Does Vermont have a biometric privacy law?
Not yet, but a comprehensive law is coming. Governor Scott vetoed an earlier bill, H.121, in June 2024. Its successor, the Vermont Data Privacy and Online Surveillance Act (Act 145), was signed June 16, 2026 and classifies biometric data as sensitive data requiring opt-in consent, but it does not take effect until January 1, 2028. Until then, biometric data receives limited protection through Vermont's breach notification law (9 V.S.A. 2435) and the data broker registration law (9 V.S.A. 2446).
Can my employer collect my fingerprints without consent in Vermont?
Yes. Vermont law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, or data retention schedules related to employer-collected biometric information. Federal laws like HIPAA may apply in specific health care employment contexts.
What happens if my biometric data is exposed in a data breach in Vermont?
Under Vermont's Security Breach Notice Act (9 V.S.A. 2435), the organization that experienced the breach must notify you within 45 days. It must also notify a state regulator within 14 business days: the Department of Financial Regulation if it is regulated by that department under Title 8, or otherwise the Attorney General. Notice goes to one regulator or the other, and no minimum number of affected Vermonters is required. The notice must also advise you to remain vigilant by reviewing your account statements and monitoring your free credit reports, but Vermont law does not require the business to purchase or provide a credit monitoring service for any type of breach, including biometric-only breaches.
Can I sue a company in Vermont for misusing my biometric data?
No. Vermont does not provide a private right of action for biometric data misuse. The vetoed H.121 bill would have created this right, but it was struck down, and its successor, Act 145 (effective January 1, 2028), also excludes a private right of action. The Vermont Attorney General can pursue enforcement actions under the Consumer Protection Act, and you can file a complaint with the AG's office at ago.vermont.gov.
What is Vermont's data broker registry and how does it relate to biometric data?
Vermont was the first state to require data brokers to register with the government. Under 9 V.S.A. 2446, data brokers that collect, buy, or sell personal information including biometric data must register annually with the Secretary of State by January 31, pay a $100 fee, and disclose their practices; 9 V.S.A. 2430 supplies the definitions those duties run on, and 9 V.S.A. 2447 requires a written information security program. Registration disclosures include whether a consumer may opt out and which activities a consumer cannot opt out of, but Vermont does not require a broker to offer an opt-out. About 283 data brokers are currently registered.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the data broker registration citation from 9 V.S.A. 2430 (definitions) to 9 V.S.A. 2446, removed an incorrect headcount threshold for Attorney General breach notice and added the statute's 14-business-day regulator deadline, and clarified that Vermont requires data brokers to disclose whether an opt-out exists rather than to provide one.
Updated this page to reflect Vermont's enacted comprehensive privacy law, the Vermont Data Privacy and Online Surveillance Act (Act 145), signed June 16, 2026 and effective January 1, 2028, which classifies biometric data as sensitive data requiring opt-in consent; also flagged the data broker registration fee rising from $100 to $900 effective January 1, 2027 under the companion Act 138.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected a claim that Vermont law requires businesses to offer free credit monitoring after SSN/financial breaches; the statute actually only requires the breach notice letter to advise consumers to monitor their own free credit reports, and this advice requirement is not limited to SSN/financial breaches.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: SECURITY BREACH NOTICE ACT
§ 2435Notice of security breachesIn forcecited in 4 of our articles
(a) This section shall be known as the Security Breach Notice Act. (b) Notice of breach. (1) Except as otherwise provided in subsection (d) of this section, any data collector that owns or licenses computerized personally identifiable information or login credentials shall notify the consumer that there has been a security breach following discovery or notification to the data collector of the breach. Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency, as provided in subdivisions (3) and (4) of this subsection, or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.vermont.gov
Also relied on in: Vermont Data Privacy Laws: Data Broker Registry & Consumer Rights (2026), Vermont Identity Theft Laws: Penalties and Victim Rights, Vermont Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: GENERAL PROVISIONS
§ 2430DefinitionsIn forcecited in 3 of our articles
As used in this chapter: (1)(A) “Brokered personal information” means one or more of the following computerized data elements about a consumer, if categorized or organized for dissemination to third parties: (i) name; (ii) address; (iii) date of birth; (iv) place of birth; (v) mother’s maiden name; (vi) unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data; (vii) name or address of a member of the consumer’s immediate family or household; (viii) Social Security number or other government-issued identification number; or (ix) other information that, alone or in combination with the other information sold or licensed, would allow a reasonable person to identify the consumer with reasonable certainty. (B) “Brokered personal information” does not include publicly available information to the extent that it is related to a consumer’s business or profession.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Clearview Ai (Vermont Superior Court 2026)“…relationship.” 9 V.S.A. § 2430(4). As a small start-up company…”
- Buksh v. Dr. William Sarchino DPM Foot and Ankle Surgeon (District Court, D. Vermont 2024)“…red by Vermont’s Security Breach Notice Act, 9 V.S.A. §§ 2430 and 2435. The correspondence…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- H.121 - Vermont Data Privacy Act (Bill Status)(legislature.vermont.gov).gov
- Governor Scott Veto Letter - H.121(governor.vermont.gov).gov
- AG Clark Statement on H.121 Veto(ago.vermont.gov).gov
- 9 V.S.A. 2435 - Security Breach Notice Act(legislature.vermont.gov).gov
- 9 V.S.A. 2430 - Data Broker Definitions(legislature.vermont.gov).gov
- Act 89 of 2020 - Breach Notification Expansion(legislature.vermont.gov).gov
- Vermont DFR - Data Breach Notifications(dfr.vermont.gov).gov
- Vermont AG - Privacy and Data Security(ago.vermont.gov).gov
- Vermont DFR - Security Breach Notice Act Bulletin(dfr.vermont.gov).gov
- H.121 As Passed by Both Chambers(legislature.vermont.gov).gov
- Act 145 (S.71) - Vermont Data Privacy and Online Surveillance Act (Official Act Summary)(legislature.vermont.gov).gov
- Act 138 (H.211) - Data Brokers and Personal Information (Official Act Summary)(legislature.vermont.gov).gov
- 9 V.S.A. 2446 - Data Brokers: Annual Registration(legislature.vermont.gov)
- 9 V.S.A. 2447 - Data Broker Duty to Protect Information; Standards; Technical Requirements(legislature.vermont.gov)