Vermont
Vermont Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

Vermont requires businesses to notify affected consumers of a data breach within 45 days of discovery under 9 V.S.A. 2435. Companies must also send a preliminary notice to the Vermont Attorney General within 14 business days of discovery, one of the few two-stage notification processes in the country.
Vermont operates one of the more protective data breach notification frameworks in the United States. While many states require a single notification to their attorney general alongside consumer notices, Vermont stands apart with its two-stage reporting process: a preliminary notice to the Attorney General within 14 business days, followed by consumer notification within 45 days.
The current law is codified at 9 V.S.A. 2430 (definitions) and 9 V.S.A. 2435 (notification requirements). Originally enacted in 2006, the statute underwent major revisions through Act 89 of 2020 (S.110), effective July 1, 2020, which expanded the definition of personal information, added login credentials protections, and created the 14-business-day preliminary AG notice requirement.
For a broader look at Vermont's privacy framework, see the parent guide to Vermont Data Privacy Laws.
Who Must Comply
Vermont's law applies to "data collectors," which the statute defines broadly. A data collector is any person, association, municipality, corporation, or other entity that, for any purpose, receives, stores, maintains, processes, or otherwise has access to personally identifiable information of Vermont residents.
This includes both private businesses and government entities. Third-party service providers that handle personal information on behalf of a data collector are also subject to the law.
Entities regulated by the Vermont Department of Financial Regulation (DFR), such as banks, insurance companies, and other financial institutions, must report breaches to DFR rather than the Attorney General. All other entities report to the AG.
What Qualifies as Personal Information
Under 9 V.S.A. 2430, "personally identifiable information" is defined as a consumer's first name or first initial and last name combined with any of the following unencrypted data elements:
- Social Security number
- Driver's license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction
- Financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords
- A password, personal identification number, or other access code for a financial account
- Unique biometric data generated from measurements or technical analysis of human body characteristics, such as a fingerprint, retina, or iris image
- Genetic information
- Health records or records of a wellness program or similar program of health promotion or disease prevention, a health care professional's medical diagnosis or treatment of the consumer, or a health insurance policy number
The 2020 amendments through Act 89 added several of these categories, including biometric data, genetic information, passport numbers, military IDs, and taxpayer identification numbers.
The health category matters beyond the list itself. It is the exact cross-reference that defines the scope of Vermont's HIPAA carve-out, discussed below, so a breach that reaches health data plus any other category falls outside that carve-out.
Login credentials are also independently protected. A consumer's username or email address combined with a password or security question answer that permits access to an online account qualifies as protected information, even without a name match.
Personal information does not include publicly available information lawfully made available to the general public from government records.
What Triggers the Notification Requirement
A "security breach" under Vermont law means the unauthorized acquisition of electronic data, or a reasonable belief of unauthorized acquisition, that compromises the security, confidentiality, or integrity of a consumer's personally identifiable information or login credentials maintained by a data collector.
When a data collector becomes aware of a potential breach, it must conduct an investigation. If the investigation determines that personal information has been or is reasonably believed to have been compromised, the notification requirements are triggered.
The discovery date is not the date the investigation is completed. It is the earliest date the entity became aware of, or had a reasonable belief of, unauthorized activity affecting personal information.
The Two-Stage Notification Timeline

Vermont's notification framework has two distinct deadlines, making it more demanding than most states.
Stage 1: Preliminary Attorney General Notice (14 Business Days)
Within 14 business days of discovering or being notified of a security breach, the data collector must submit a preliminary notice to the Vermont Attorney General.
This preliminary notice is kept confidential by statute. It allows the AG's office to begin monitoring the situation and provide guidance before consumer notifications go out. The preliminary form captures basic information about the breach, including what happened, what data was affected, and the estimated number of Vermont residents impacted.
For entities regulated by the Department of Financial Regulation, this preliminary notice goes to DFR instead.
Stage 2: Consumer Notification (45 Days)
The data collector must notify affected consumers as soon as possible and without unreasonable delay, but no later than 45 days after discovery or notification of the breach.
The 45-day clock starts from the date the entity discovered or was notified of the breach, not from the date the investigation concluded.
Law enforcement may request a delay in consumer notification if it would impede a criminal investigation. Notification must proceed as soon as law enforcement determines it will no longer compromise the investigation.
What the Consumer Notice Must Include

Vermont specifies the content of breach notification letters. Notices to affected consumers must include:
- A description of the incident in general terms
- The type of personally identifiable information that was compromised
- Steps the data collector has taken to protect the consumer's data from further breaches
- A telephone number for the data collector that the consumer may call for further information and assistance
- Advice directing the consumer to remain vigilant by reviewing account statements and monitoring free credit reports
- The approximate date of the security breach
For breaches involving login credentials specifically, the notice must direct the consumer to promptly change their password and security questions for the affected account and for any other account where the consumer used the same credentials.
Attorney General Reporting
In addition to the 14-business-day preliminary notice, the data collector must submit a completed Security Breach Reporting Form to the Attorney General once the investigation is complete and consumer notices have been sent.
The AG's office maintains a public list of security breach notices on its website, providing transparency about breaches affecting Vermont residents.
There is no minimum threshold for AG notification in Vermont. Even a single affected Vermont resident triggers the reporting requirement.
Notice to Consumer Reporting Agencies
Large breaches carry a third reporting duty that is easy to miss. Under 9 V.S.A. 2435(c), a data collector that provides notice to more than 1,000 consumers at one time must also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. 1681a(p).
That notice to the nationwide credit bureaus must cover the timing, distribution, and content of the consumer notice. It is a notice about the notice, not a transmission of the affected consumers' data.
This subsection does not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation.
Substitute Notice

Vermont allows substitute notice when direct notification is not feasible. Under 9 V.S.A. 2435(b)(6)(B)(i), a data collector may use substitute notice if either of the following is true:
- The data collector demonstrates that the lowest cost of providing direct notice to affected consumers, among written, e-mail, or telephonic notice, would exceed $10,000
- The data collector does not have sufficient contact information
Only one of those two conditions has to be met. The statute is written in the alternative.
Once substitute notice is available, the delivery method has two required parts: conspicuously posting the notice on the data collector's website if the data collector maintains one, and notifying major statewide and regional media.
Encryption Safe Harbor
Vermont provides an encryption safe harbor. Personal information that is encrypted, redacted, or protected by another method rendering it unreadable or unusable by unauthorized persons is not subject to the notification requirements.
The encryption must have been in place at the time of the unauthorized acquisition. If encryption keys were also compromised in the breach, the safe harbor does not apply.
Exception: Misuse Is Not Reasonably Possible
Encryption is not the only path out of the consumer notice duty. Under 9 V.S.A. 2435(d)(1), notice is not required if the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible.
That determination is not self-executing. To rely on it, the data collector must provide notice of the determination, along with a detailed explanation supporting it, to the Vermont Attorney General, or to the Department of Financial Regulation if the collector is a person or entity licensed or registered with the Department under Title 8 or Title 9. The collector may designate that filing as a trade secret if it meets the definition in 1 V.S.A. 317(c)(9).
The exception can also expire. Under 9 V.S.A. 2435(d)(2), if the data collector later obtains facts indicating that misuse of the information has occurred or is occurring, the duty to notify consumers under subsection (b) revives.
Interaction with Federal Regulations
Vermont's statute carves out two categories of federally regulated entities, and the two carve-outs work very differently.
HIPAA-covered entities. Under 9 V.S.A. 2435(e), a data collector subject to the privacy, security, and breach notification rules adopted in 45 C.F.R. Part 164 pursuant to HIPAA is deemed to be in compliance with Vermont's subchapter if two conditions are met: the security breach is limited to the health information specified in 9 V.S.A. 2430(10)(A)(vii), and the data collector provides notice to affected consumers under the federal breach notification rule in 45 C.F.R. Part 164, Subpart D. The statute as it stands today attaches no separate Vermont notice condition to that deemed compliance. If the breach reaches any other category of personal information, the carve-out does not apply and Vermont's requirements, including the 14-business-day preliminary notice, govern.
That changes on January 1, 2027. Act 138 adds a third condition at 9 V.S.A. 2435(e)(3): the data collector must also provide notice to the Attorney General or the Department of Financial Regulation under 9 V.S.A. 2435(b)(3)(B), along with a written certification of compliance with 45 C.F.R. Part 164, Subpart D.
Financial institutions. 9 V.S.A. 2435(g) exempts from the section entirely a financial institution that is subject to the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued March 7, 2005 by the Board of Governors of the Federal Reserve System, the FDIC, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, or to the National Credit Union Administration's Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued April 14, 2005. The exemption keys to those named interagency guidances, not to the Gramm-Leach-Bliley Act, which the section does not mention.
One obligation survives that exemption. Under 9 V.S.A. 2435(g)(3), a financial institution regulated by the Department of Financial Regulation must notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. That is a promptness standard, not the 14-business-day deadline that applies to data collectors generally.
Upcoming Changes Effective January 1, 2027
Governor Scott signed Act 138 (H.211) into law on June 16, 2026. Act 138 amends the notice provisions of 9 V.S.A. 2435 and creates a new, parallel statute at 9 V.S.A. 2436, the Data Broker Security Breach Notice Act, both effective January 1, 2027.
The amendments to 9 V.S.A. 2435 tighten the telephonic notice method, requiring at least five attempts to reach the consumer for a live conversation before the data collector may leave a voicemail about the breach, and add the new HIPAA condition at subsection (e)(3) described above.
The new Data Broker Security Breach Notice Act requires data brokers specifically to notify affected Vermont consumers within 45 days and to submit a preliminary notice to the Attorney General within 14 business days, mirroring the timelines that already apply to data collectors generally under 9 V.S.A. 2435. Act 138 also updates related data broker definitions and registration requirements, including raising the data broker registration fee from $100 to $900 annually.
The 45-day consumer notice deadline, the 14-business-day preliminary AG notice, the encryption safe harbor, and the $10,000-per-violation penalty described in this article remain current law today. This section will be updated again once Act 138 takes effect.
Enforcement and Penalties
The Vermont Attorney General enforces the breach notification law under the authority of the Vermont Consumer Protection Act (9 V.S.A. Chapter 63). State's attorneys may also enforce the law within their jurisdictions. For a data collector that is licensed or registered with the Department of Financial Regulation under Title 8 or Title 9, enforcement authority sits with the Department instead, under 9 V.S.A. 2435(h)(2).
There is no private right of action under the breach notification statute. Only the AG, state's attorneys, and DFR for the entities it regulates can bring enforcement actions.
The penalty comes from the Consumer Protection Act rather than from the breach statute itself:
- Under 9 V.S.A. 2458(b)(1), a court may impose a civil penalty of not more than $10,000 for each unfair or deceptive act or practice in commerce
- Under 9 V.S.A. 2461(a), a person who violates the terms of an injunction issued under 9 V.S.A. 2458 pays a further civil penalty of not more than $10,000 for each violation
Neither 9 V.S.A. 2435 nor the Chapter 63 provisions it borrows sets a per-day or per-consumer multiplier. How many separate violations a late or missing notice produces is argued case by case, not fixed by the text of the statute.
The AG may also issue Civil Investigative Demands (civil subpoenas) to investigate potential violations and may seek injunctive relief to compel compliance.
More Vermont Laws
Frequently Asked Questions
How quickly must a Vermont business notify consumers of a data breach?
Vermont requires consumer notification within 45 days of discovering a security breach. However, before consumer notices go out, the entity must also file a preliminary notice with the Vermont Attorney General within 14 business days of discovery. The 14-business-day AG notice is confidential and allows the state to begin monitoring the situation before consumers are formally notified.
What is the 14-business-day preliminary notice requirement in Vermont?
Within 14 business days of discovering a security breach, the data collector must submit a preliminary notice to the Vermont Attorney General (or the Department of Financial Regulation for regulated financial entities). This notice is kept confidential by statute and provides the AG with early awareness of the breach. It is separate from and in addition to the full breach reporting form and consumer notification.
Does Vermont require notification if the breached data was encrypted?
No. Vermont provides an encryption safe harbor. If the personal information was encrypted, redacted, or otherwise rendered unreadable or unusable by unauthorized persons at the time of the breach, notification is not required. However, if the encryption keys were also compromised, the safe harbor does not apply. Encryption is not the only exception: under 9 V.S.A. 2435(d)(1), notice is also not required if the data collector establishes that misuse of the information is not reasonably possible and files that determination, with a detailed explanation, with the Attorney General or the Department of Financial Regulation.
What types of personal information trigger Vermont breach notification?
Vermont protects Social Security numbers, driver's license and other government identification numbers, financial account numbers, taxpayer identification numbers, passport numbers, military ID numbers, biometric data, genetic information, health records and health insurance policy numbers, and login credentials (username or email combined with a password or security question). The definition was expanded significantly by Act 89 of 2020 to include biometric data, genetic information, and several other categories.
What penalties does Vermont impose for failing to notify consumers of a data breach?
Penalties come from the Vermont Consumer Protection Act rather than from the breach statute. Under 9 V.S.A. 2458(b)(1), a court may impose a civil penalty of not more than $10,000 for each unfair or deceptive act or practice in commerce, and 9 V.S.A. 2461(a) adds a penalty of up to $10,000 for each violation of an injunction. The breach notification statute does not set a per-day or per-consumer multiplier, so the number of violations is argued case by case. There is no private right of action for individual consumers.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the federal-law section to state current law (the HIPAA deemed-compliance test carries no Attorney General notice condition until Act 138 takes effect on January 1, 2027, and financial institutions are exempt under the named 2005 interagency guidances rather than the Gramm-Leach-Bliley Act), added the omitted health-data category, the misuse-not-reasonably-possible exception and the credit-bureau reporting duty, clarified that the substitute-notice conditions are alternatives, and removed an unsourced per-day, per-consumer penalty multiplier.
Added a note that Act 138, signed June 16, 2026 and effective January 1, 2027, will amend Vermont's breach-notice statute and create a new parallel Data Broker Security Breach Notice Act for data brokers; today's 45-day consumer notice, 14-business-day AG notice, and $10,000-per-violation penalty are unchanged and remain current law.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the Vermont AG preliminary-notice deadline to 14 BUSINESS days (was stated as 14 calendar days in several spots), fixed the substitute-notice cost threshold to the statutory $10,000, removed a non-statutory 5,000-consumer substitute-notice trigger and a non-statutory third substitute-notice method (email), and replaced two non-statutory consumer-notice content items with the statutory requirement to disclose the approximate breach date.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: SECURITY BREACH NOTICE ACT
§ 2435Notice of security breachesIn forcecited in 4 of our articles
(a) This section shall be known as the Security Breach Notice Act. (b) Notice of breach. (1) Except as otherwise provided in subsection (d) of this section, any data collector that owns or licenses computerized personally identifiable information or login credentials shall notify the consumer that there has been a security breach following discovery or notification to the data collector of the breach. Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency, as provided in subdivisions (3) and (4) of this subsection, or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.vermont.gov
Also relied on in: Vermont Data Privacy Laws: Data Broker Registry & Consumer Rights (2026), Vermont Biometric Privacy Laws: Collection, Consent & Penalties (2026), Vermont Identity Theft Laws: Penalties and Victim Rights
Vermont Statutes Annotated, Title 9: Commerce and Trade, Chapter 62: Protection of Personal Information, Subchapter: GENERAL PROVISIONS
§ 2430DefinitionsIn forcecited in 3 of our articles
As used in this chapter: (1)(A) “Brokered personal information” means one or more of the following computerized data elements about a consumer, if categorized or organized for dissemination to third parties: (i) name; (ii) address; (iii) date of birth; (iv) place of birth; (v) mother’s maiden name; (vi) unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data; (vii) name or address of a member of the consumer’s immediate family or household; (viii) Social Security number or other government-issued identification number; or (ix) other information that, alone or in combination with the other information sold or licensed, would allow a reasonable person to identify the consumer with reasonable certainty. (B) “Brokered personal information” does not include publicly available information to the extent that it is related to a consumer’s business or profession.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.vermont.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Clearview Ai (Vermont Superior Court 2026)“…relationship.” 9 V.S.A. § 2430(4). As a small start-up company…”
- Buksh v. Dr. William Sarchino DPM Foot and Ankle Surgeon (District Court, D. Vermont 2024)“…red by Vermont’s Security Breach Notice Act, 9 V.S.A. §§ 2430 and 2435. The correspondence…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 9 V.S.A. 2430 Definitions(legislature.vermont.gov).gov
- 9 V.S.A. 2435 Notice of Security Breaches(legislature.vermont.gov).gov
- Act 89 of 2020 Full Text(legislature.vermont.gov).gov
- Vermont AG Security Breach Guidance(ago.vermont.gov).gov
- Vermont AG Preliminary Breach Reporting Form(ago.vermont.gov).gov
- Vermont AG Security Breach Reporting Form(ago.vermont.gov).gov
- Vermont AG Privacy and Data Security(ago.vermont.gov).gov
- Vermont DFR Data Breach Notifications(dfr.vermont.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- Act 138 (H.211) - Data Brokers and Personal Information (Official Act Summary)(legislature.vermont.gov).gov
- 9 V.S.A. 2458 Restraining Prohibited Acts (civil penalty)(legislature.vermont.gov)
- Act 138 of 2026 (H.211) As Enacted(legislature.vermont.gov)