EnglishEspañol
Vermont flag

Vermont

Vermont Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

Vermont Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Vermont have a biometric privacy law?

Not yet, but a comprehensive law is coming. Governor Scott vetoed an earlier bill, H.121, in June 2024. Its successor, the Vermont Data Privacy and Online Surveillance Act (Act 145), was signed June 16, 2026 and classifies biometric data as sensitive data requiring opt-in consent, but it does not take effect until January 1, 2028. Until then, biometric data receives limited protection through Vermont's breach notification law (9 V.S.A. 2435) and the data broker registration law (9 V.S.A. 2446).

Can my employer collect my fingerprints without consent in Vermont?

Yes. Vermont law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, or data retention schedules related to employer-collected biometric information. Federal laws like HIPAA may apply in specific health care employment contexts.

What happens if my biometric data is exposed in a data breach in Vermont?

Under Vermont's Security Breach Notice Act (9 V.S.A. 2435), the organization that experienced the breach must notify you within 45 days. It must also notify a state regulator within 14 business days: the Department of Financial Regulation if it is regulated by that department under Title 8, or otherwise the Attorney General. Notice goes to one regulator or the other, and no minimum number of affected Vermonters is required. The notice must also advise you to remain vigilant by reviewing your account statements and monitoring your free credit reports, but Vermont law does not require the business to purchase or provide a credit monitoring service for any type of breach, including biometric-only breaches.

Can I sue a company in Vermont for misusing my biometric data?

No. Vermont does not provide a private right of action for biometric data misuse. The vetoed H.121 bill would have created this right, but it was struck down, and its successor, Act 145 (effective January 1, 2028), also excludes a private right of action. The Vermont Attorney General can pursue enforcement actions under the Consumer Protection Act, and you can file a complaint with the AG's office at ago.vermont.gov.

What is Vermont's data broker registry and how does it relate to biometric data?

Vermont was the first state to require data brokers to register with the government. Under 9 V.S.A. 2446, data brokers that collect, buy, or sell personal information including biometric data must register annually with the Secretary of State by January 31, pay a $100 fee, and disclose their practices; 9 V.S.A. 2430 supplies the definitions those duties run on, and 9 V.S.A. 2447 requires a written information security program. Registration disclosures include whether a consumer may opt out and which activities a consumer cannot opt out of, but Vermont does not require a broker to offer an opt-out. About 283 data brokers are currently registered.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the data broker registration citation from 9 V.S.A. 2430 (definitions) to 9 V.S.A. 2446, removed an incorrect headcount threshold for Attorney General breach notice and added the statute's 14-business-day regulator deadline, and clarified that Vermont requires data brokers to disclose whether an opt-out exists rather than to provide one.

Updated this page to reflect Vermont's enacted comprehensive privacy law, the Vermont Data Privacy and Online Surveillance Act (Act 145), signed June 16, 2026 and effective January 1, 2028, which classifies biometric data as sensitive data requiring opt-in consent; also flagged the data broker registration fee rising from $100 to $900 effective January 1, 2027 under the companion Act 138.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected a claim that Vermont law requires businesses to offer free credit monitoring after SSN/financial breaches; the statute actually only requires the breach notice letter to advise consumers to monitor their own free credit reports, and this advice requirement is not limited to SSN/financial breaches.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. H.121 - Vermont Data Privacy Act (Bill Status)(legislature.vermont.gov).gov
  2. Governor Scott Veto Letter - H.121(governor.vermont.gov).gov
  3. AG Clark Statement on H.121 Veto(ago.vermont.gov).gov
  4. 9 V.S.A. 2435 - Security Breach Notice Act(legislature.vermont.gov).gov
  5. 9 V.S.A. 2430 - Data Broker Definitions(legislature.vermont.gov).gov
  6. Act 89 of 2020 - Breach Notification Expansion(legislature.vermont.gov).gov
  7. Vermont DFR - Data Breach Notifications(dfr.vermont.gov).gov
  8. Vermont AG - Privacy and Data Security(ago.vermont.gov).gov
  9. Vermont DFR - Security Breach Notice Act Bulletin(dfr.vermont.gov).gov
  10. H.121 As Passed by Both Chambers(legislature.vermont.gov).gov
  11. Act 145 (S.71) - Vermont Data Privacy and Online Surveillance Act (Official Act Summary)(legislature.vermont.gov).gov
  12. Act 138 (H.211) - Data Brokers and Personal Information (Official Act Summary)(legislature.vermont.gov).gov
  13. 9 V.S.A. 2446 - Data Brokers: Annual Registration(legislature.vermont.gov)
  14. 9 V.S.A. 2447 - Data Broker Duty to Protect Information; Standards; Technical Requirements(legislature.vermont.gov)
Share: