Vermont Data Privacy Law: Data Broker Rules, Act 63, and Enforcement

The Vermont data privacy law is not a single statute but a set of rules in Title 9, Chapter 62 of the Vermont Statutes. The centerpiece, in effect since 2019, requires data brokers to register with the state, maintain a written security program, and disclose their practices publicly. A separate Security Breach Notice Act applies to any business holding personal information on Vermont residents. A newer Age-Appropriate Design Code, Act 63, adds design and data limits for online services used by minors starting in 2027. What Vermont does not yet have is a comprehensive consumer privacy statute giving residents the rights to access, correct, delete, or port their data that California, Colorado, and Connecticut have enacted.

What Vermont’s Law Actually Gives You

The data broker statute is a transparency law. It forces brokers to publish who they are and whether they let you opt out, but it does not require them to offer an opt-out in the first place. A broker can comply by disclosing that no opt-out is available for a given activity.1Vermont General Assembly. Vermont Code 09 – 2446 Annual Registration

Under this framework, Vermont residents do not have a statutory right to demand deletion of their data, get a portable copy, or correct inaccuracies held by a data broker. The law also creates no private right of action, so you cannot sue a broker directly for a registration or disclosure violation. Enforcement runs through the Attorney General’s office.1Vermont General Assembly. Vermont Code 09 – 2446 Annual Registration

What you can do is look up which companies have registered. The registrations are public records maintained by the Secretary of State, so you can see which brokers claim to hold data on people like you and whether any of them offer an opt-out.2Secretary of State. Data Broker

Who Counts as a Data Broker

Vermont’s law applies to any business, or unit of a business, that knowingly collects and sells or licenses personal information about consumers it has no direct relationship with.3Vermont General Assembly. Vermont Code 09 – 2430 Definitions The “no direct relationship” piece is the pivot. A company you have never interacted with that buys your purchasing patterns or location history from someone else and resells them is a broker. A retailer using its own customers’ data internally is not.

The law reaches companies wherever they are based, as long as they collect and sell data on Vermont residents. “Brokered personal information” covers anything that identifies you individually, including your name, contact details, financial account information, and Social Security number.3Vermont General Assembly. Vermont Code 09 – 2430 Definitions

Several activities fall outside the definition even when they involve consumer data: operating third-party online marketplaces or app platforms, providing 411 directory assistance for a telecommunications carrier, sharing publicly available business or professional information, and running real-time health or safety alert services. One-time asset sales tied to a business transfer and data sales that are merely incidental to a company’s main business are also excluded, as are state government entities and their vendors.3Vermont General Assembly. Vermont Code 09 – 2430 Definitions

What Data Brokers Must Do

Every data broker must register annually with the Vermont Secretary of State between January 1 and January 31 following any year in which it met the definition. The fee is $100. The registration must include the broker’s name, address, email, and website, along with a description of any opt-out options and the activities each opt-out covers, whether the broker screens buyers, and the number of security breaches it experienced in the prior year along with the number of consumers affected. Brokers that knowingly hold data on minors must file a separate statement describing those collection and sales practices.1Vermont General Assembly. Vermont Code 09 – 2446 Annual Registration

Brokers must also develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards. The statute lays out specific elements: at least one designated employee responsible for the program, a documented risk assessment, encryption of personal information both in transit and when stored on laptops or portable devices, secure user authentication and access controls, and reasonable monitoring for unauthorized access. Requirements scale with the size and complexity of the business and the sensitivity of the data.4Vermont General Assembly. Vermont Code 09 – 2447 Data Broker Duty to Protect Information Standards Technical Requirements

A broker that skips registration faces a civil penalty of $50 per day, capped at $10,000 per year, plus unpaid registration fees for the period it should have been registered.1Vermont General Assembly. Vermont Code 09 – 2446 Annual Registration

Breach Notification Rules

Vermont’s Security Breach Notice Act, at 9 V.S.A. ยง 2435, reaches further than the broker rules. It applies to any entity that owns or licenses computerized personally identifiable information on Vermont residents. A breach is the unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of personal information.5Vermont General Assembly. Vermont Code 09 – 2435 Notice of Security Breaches

When a breach happens, the business must notify affected consumers as soon as possible and no later than 45 days after discovery. It must also give preliminary notice to a state regulator within 14 business days of discovery. Companies regulated under Title 8, which covers banking, insurance, and financial services, report to the Department of Financial Regulation. Every other business reports to the Attorney General. The consumer notice must describe what happened, what type of information was involved, and what the business is doing about it.5Vermont General Assembly. Vermont Code 09 – 2435 Notice of Security Breaches

New Protections for Minors Under Act 63

Vermont enacted Act 63, the Age-Appropriate Design Code, in June 2025, with most provisions taking effect on January 1, 2027. It applies to any business whose online products, services, or features are reasonably likely to be accessed by someone under 18.6Vermont General Assembly. Act 63 As Enacted

At the core is a duty of care: covered businesses cannot use a minor’s personal data or design features in ways that cause reasonably foreseeable emotional distress, promote compulsive use, or discriminate based on protected characteristics. Compulsive use is defined as repetitive engagement that materially disrupts major life activities such as sleeping, eating, learning, or concentrating.6Vermont General Assembly. Act 63 As Enacted

The specific rules include:

  • Privacy settings for minors must default to the most protective level, and businesses cannot offer a single toggle that lowers all settings at once.
  • Businesses may only collect, sell, or retain data necessary to provide the service the minor is actively using.
  • A minor’s personal data cannot be used to select or recommend content unless the minor specifically requested it.
  • Push notifications to minors are prohibited between midnight and 6:00 a.m.
  • If a parent or guardian is monitoring a minor’s activity or location, the minor must see a visible signal that monitoring is occurring.

Enforcement and Filing a Complaint

The Vermont Attorney General enforces both the data broker law and the Security Breach Notice Act.7Office of the Vermont Attorney General. Privacy and Data Security The AG can bring civil actions in Superior Court to collect the $50-per-day registration penalties, obtain injunctive relief, and seek restitution for consumers harmed by a company’s data practices. Under the Vermont Consumer Protection Act, violating a court-ordered injunction on data practices can carry civil penalties of up to $10,000 per violation.8Vermont General Assembly. Vermont Code 09 – 2461

If you think a data broker has violated the law or a company mishandled a breach, the path is to file a complaint with the Attorney General’s office. Individual lawsuits under the data broker registration statute are not available.

Where Broader Consumer Privacy Rights Stand

Vermont’s data broker law was first of its kind, but it regulates only the companies that trade in data, not the wider set of businesses that collect it. Residents still lack the deletion, access, and portability rights available in several other states.

The legislature passed H.121 in 2024 to create a comprehensive data privacy act with rights to access, correct, delete, and port personal data, plus a limited private right of action for violations involving sensitive data and children’s data. Governor Phil Scott vetoed the bill on June 13, 2024. The House overrode the veto 128 to 17, but the Senate sustained it by one vote, 14 to 15.9Vermont General Assembly. Bill Status H.121

In the 2025 session, the legislature took up S.71 with similar provisions: rights to confirm data processing, correct inaccuracies, delete personal data, obtain portable copies, and opt out of targeted advertising, data sales, and automated profiling. The bill would apply to businesses that process data on at least 100,000 Vermont consumers, or 25,000 consumers if data sales account for more than 25 percent of gross revenue, with thresholds tightening in later years.10Vermont General Assembly. S.71 As Passed by the Senate Whether it becomes law will decide if Vermont moves from a broker-only regime to full consumer privacy rights.