EnglishEspañol
Vermont flag

Vermont

Vermont Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

Vermont Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Vermont business notify consumers of a data breach?

Vermont requires consumer notification within 45 days of discovering a security breach. However, before consumer notices go out, the entity must also file a preliminary notice with the Vermont Attorney General within 14 business days of discovery. The 14-business-day AG notice is confidential and allows the state to begin monitoring the situation before consumers are formally notified.

What is the 14-business-day preliminary notice requirement in Vermont?

Within 14 business days of discovering a security breach, the data collector must submit a preliminary notice to the Vermont Attorney General (or the Department of Financial Regulation for regulated financial entities). This notice is kept confidential by statute and provides the AG with early awareness of the breach. It is separate from and in addition to the full breach reporting form and consumer notification.

Does Vermont require notification if the breached data was encrypted?

No. Vermont provides an encryption safe harbor. If the personal information was encrypted, redacted, or otherwise rendered unreadable or unusable by unauthorized persons at the time of the breach, notification is not required. However, if the encryption keys were also compromised, the safe harbor does not apply. Encryption is not the only exception: under 9 V.S.A. 2435(d)(1), notice is also not required if the data collector establishes that misuse of the information is not reasonably possible and files that determination, with a detailed explanation, with the Attorney General or the Department of Financial Regulation.

What types of personal information trigger Vermont breach notification?

Vermont protects Social Security numbers, driver's license and other government identification numbers, financial account numbers, taxpayer identification numbers, passport numbers, military ID numbers, biometric data, genetic information, health records and health insurance policy numbers, and login credentials (username or email combined with a password or security question). The definition was expanded significantly by Act 89 of 2020 to include biometric data, genetic information, and several other categories.

What penalties does Vermont impose for failing to notify consumers of a data breach?

Penalties come from the Vermont Consumer Protection Act rather than from the breach statute. Under 9 V.S.A. 2458(b)(1), a court may impose a civil penalty of not more than $10,000 for each unfair or deceptive act or practice in commerce, and 9 V.S.A. 2461(a) adds a penalty of up to $10,000 for each violation of an injunction. The breach notification statute does not set a per-day or per-consumer multiplier, so the number of violations is argued case by case. There is no private right of action for individual consumers.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the federal-law section to state current law (the HIPAA deemed-compliance test carries no Attorney General notice condition until Act 138 takes effect on January 1, 2027, and financial institutions are exempt under the named 2005 interagency guidances rather than the Gramm-Leach-Bliley Act), added the omitted health-data category, the misuse-not-reasonably-possible exception and the credit-bureau reporting duty, clarified that the substitute-notice conditions are alternatives, and removed an unsourced per-day, per-consumer penalty multiplier.

Added a note that Act 138, signed June 16, 2026 and effective January 1, 2027, will amend Vermont's breach-notice statute and create a new parallel Data Broker Security Breach Notice Act for data brokers; today's 45-day consumer notice, 14-business-day AG notice, and $10,000-per-violation penalty are unchanged and remain current law.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the Vermont AG preliminary-notice deadline to 14 BUSINESS days (was stated as 14 calendar days in several spots), fixed the substitute-notice cost threshold to the statutory $10,000, removed a non-statutory 5,000-consumer substitute-notice trigger and a non-statutory third substitute-notice method (email), and replaced two non-statutory consumer-notice content items with the statutory requirement to disclose the approximate breach date.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. 9 V.S.A. 2430 Definitions(legislature.vermont.gov).gov
  2. 9 V.S.A. 2435 Notice of Security Breaches(legislature.vermont.gov).gov
  3. Act 89 of 2020 Full Text(legislature.vermont.gov).gov
  4. Vermont AG Security Breach Guidance(ago.vermont.gov).gov
  5. Vermont AG Preliminary Breach Reporting Form(ago.vermont.gov).gov
  6. Vermont AG Security Breach Reporting Form(ago.vermont.gov).gov
  7. Vermont AG Privacy and Data Security(ago.vermont.gov).gov
  8. Vermont DFR Data Breach Notifications(dfr.vermont.gov).gov
  9. HIPAA Information(hhs.gov).gov
  10. Gramm-Leach-Bliley Act(ftc.gov).gov
  11. Act 138 (H.211) - Data Brokers and Personal Information (Official Act Summary)(legislature.vermont.gov).gov
  12. 9 V.S.A. 2458 Restraining Prohibited Acts (civil penalty)(legislature.vermont.gov)
  13. Act 138 of 2026 (H.211) As Enacted(legislature.vermont.gov)
Share: