1 | 1 | | BILL AS INTRODUCED H.211 |
---|
2 | 2 | | 2025 Page 1 of 31 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | VT LEG #378943 v.1 |
---|
6 | 6 | | H.211 1 |
---|
7 | 7 | | Introduced by Representatives Priestley of Bradford, Marcotte of Coventry, 2 |
---|
8 | 8 | | Arsenault of Williston, Austin of Colchester, Berbeco of 3 |
---|
9 | 9 | | Winooski, Bos-Lun of Westminster, Bosch of Clarendon, 4 |
---|
10 | 10 | | Boutin of Barre City, Boyden of Cambridge, Brown of 5 |
---|
11 | 11 | | Richmond, Burke of Brattleboro, Burrows of West Windsor, 6 |
---|
12 | 12 | | Campbell of St. Johnsbury, Carris-Duncan of Whitingham, 7 |
---|
13 | 13 | | Casey of Montpelier, Chapin of East Montpelier, Cina of 8 |
---|
14 | 14 | | Burlington, Cole of Hartford, Cordes of Bristol, Donahue of 9 |
---|
15 | 15 | | Northfield, Duke of Burlington, Eastes of Guilford, Goldman of 10 |
---|
16 | 16 | | Rockingham, Graning of Jericho, Greer of Bennington, Harple 11 |
---|
17 | 17 | | of Glover, Headrick of Burlington, Holcombe of Norwich, 12 |
---|
18 | 18 | | Krasnow of South Burlington, Lalley of Shelburne, Lipsky of 13 |
---|
19 | 19 | | Stowe, Masland of Thetford, McCann of Montpelier, McGill of 14 |
---|
20 | 20 | | Bridport, Micklus of Milton, Mihaly of Calais, Minier of South 15 |
---|
21 | 21 | | Burlington, Mrowicki of Putney, Nugent of South Burlington, 16 |
---|
22 | 22 | | O’Brien of Tunbridge, Ode of Burlington, Olson of Starksboro, 17 |
---|
23 | 23 | | Pezzo of Colchester, Pouech of Hinesburg, Rachelson of 18 |
---|
24 | 24 | | Burlington, Satcowitz of Randolph, Sibilia of Dover, Stevens of 19 |
---|
25 | 25 | | Waterbury, Surprenant of Barnard, Tomlinson of Winooski, 20 BILL AS INTRODUCED H.211 |
---|
26 | 26 | | 2025 Page 2 of 31 |
---|
27 | 27 | | |
---|
28 | 28 | | |
---|
29 | 29 | | VT LEG #378943 v.1 |
---|
30 | 30 | | Torre of Moretown, Waszazak of Barre City, and White of 1 |
---|
31 | 31 | | Bethel 2 |
---|
32 | 32 | | Referred to Committee on 3 |
---|
33 | 33 | | Date: 4 |
---|
34 | 34 | | Subject: Commerce and trade; protection of personal information; data brokers 5 |
---|
35 | 35 | | Statement of purpose of bill as introduced: This bill proposes to add various 6 |
---|
36 | 36 | | provisions to Vermont’s laws that protect the personal information of its 7 |
---|
37 | 37 | | residents, including requiring data brokers to provide notice of security 8 |
---|
38 | 38 | | breaches, to certify that the personal information it discloses will be used for a 9 |
---|
39 | 39 | | legitimate purpose, and to delete the personal information of consumers who 10 |
---|
40 | 40 | | make such a request through the use of an accessible deletion mechanism. 11 |
---|
41 | 41 | | An act relating to data brokers and personal information 12 |
---|
42 | 42 | | It is hereby enacted by the General Assembly of the State of Vermont: 13 |
---|
43 | 43 | | Sec. 1. 9 V.S.A. chapter 62 is amended to read: 14 |
---|
44 | 44 | | CHAPTER 62. PROTECTION OF PERSONAL INFORMATION 15 |
---|
45 | 45 | | Subchapter 1. General Provisions 16 |
---|
46 | 46 | | § 2430. DEFINITIONS 17 |
---|
47 | 47 | | As used in this chapter: 18 |
---|
48 | 48 | | (1) “Authorized agent” means: 19 BILL AS INTRODUCED H.211 |
---|
49 | 49 | | 2025 Page 3 of 31 |
---|
50 | 50 | | |
---|
51 | 51 | | |
---|
52 | 52 | | VT LEG #378943 v.1 |
---|
53 | 53 | | (A) a person designated by a consumer to act on the consumer’s 1 |
---|
54 | 54 | | behalf; 2 |
---|
55 | 55 | | (B) a parent or legal guardian that acts on behalf of the parent’s child 3 |
---|
56 | 56 | | or on behalf of a child for whom the guardian has legal responsibility; or 4 |
---|
57 | 57 | | (C) a guardian or conservator that acts on behalf of a consumer that is 5 |
---|
58 | 58 | | subject to a guardianship, conservatorship, or other protective arrangement. 6 |
---|
59 | 59 | | (2)(A) “Biometric data” means data generated from the technological 7 |
---|
60 | 60 | | processing of an individual’s unique biological, physical, or physiological 8 |
---|
61 | 61 | | characteristics that is linked or reasonably linkable to an individual, including: 9 |
---|
62 | 62 | | (i) iris or retina scans; 10 |
---|
63 | 63 | | (ii) fingerprints; 11 |
---|
64 | 64 | | (iii) facial or hand mapping, geometry, or templates; 12 |
---|
65 | 65 | | (iv) vein patterns; 13 |
---|
66 | 66 | | (v) voice prints; and 14 |
---|
67 | 67 | | (vi) gait or personally identifying physical movement or patterns. 15 |
---|
68 | 68 | | (B) “Biometric data” does not include: 16 |
---|
69 | 69 | | (i) a digital or physical photograph; 17 |
---|
70 | 70 | | (ii) an audio or video recording; or 18 |
---|
71 | 71 | | (iii) any data generated from a digital or physical photograph, or 19 |
---|
72 | 72 | | an audio or video recording, unless such data is generated to identify a specific 20 |
---|
73 | 73 | | individual. 21 BILL AS INTRODUCED H.211 |
---|
74 | 74 | | 2025 Page 4 of 31 |
---|
75 | 75 | | |
---|
76 | 76 | | |
---|
77 | 77 | | VT LEG #378943 v.1 |
---|
78 | 78 | | (3)(A) “Brokered personal information” means one or more of the 1 |
---|
79 | 79 | | following computerized data elements about a consumer, if categorized or 2 |
---|
80 | 80 | | organized for dissemination to third parties: 3 |
---|
81 | 81 | | (i) name; 4 |
---|
82 | 82 | | (ii) address; 5 |
---|
83 | 83 | | (iii) date of birth; 6 |
---|
84 | 84 | | (iv) place of birth; 7 |
---|
85 | 85 | | (v) mother’s maiden name; 8 |
---|
86 | 86 | | (vi) unique biometric data generated from measurements or 9 |
---|
87 | 87 | | technical analysis of human body characteristics used by the owner or licensee 10 |
---|
88 | 88 | | of the data to identify or authenticate the consumer, such as a fingerprint, retina 11 |
---|
89 | 89 | | or iris image, or other unique physical representation or digital representation 12 |
---|
90 | 90 | | of biometric data; 13 |
---|
91 | 91 | | (vii) name or address of a member of the consumer’s immediate 14 |
---|
92 | 92 | | family or household; 15 |
---|
93 | 93 | | (viii) Social Security number or other government-issued 16 |
---|
94 | 94 | | identification number; or 17 |
---|
95 | 95 | | (ix) phone number; or 18 |
---|
96 | 96 | | (x) other information that, alone or in combination with the other 19 |
---|
97 | 97 | | information sold or licensed, would allow a reasonable person to identify the 20 |
---|
98 | 98 | | consumer with reasonable certainty. 21 BILL AS INTRODUCED H.211 |
---|
99 | 99 | | 2025 Page 5 of 31 |
---|
100 | 100 | | |
---|
101 | 101 | | |
---|
102 | 102 | | VT LEG #378943 v.1 |
---|
103 | 103 | | (B) “Brokered personal information” does not include publicly 1 |
---|
104 | 104 | | available information to the extent that it is related to a consumer’s business or 2 |
---|
105 | 105 | | profession. 3 |
---|
106 | 106 | | (2)(4) “Business” means a controller, a consumer health data controller, 4 |
---|
107 | 107 | | a processor, or a commercial entity, including a sole proprietorship, 5 |
---|
108 | 108 | | partnership, corporation, association, limited liability company, or other group, 6 |
---|
109 | 109 | | however organized and whether or not organized to operate at a profit, 7 |
---|
110 | 110 | | including a financial institution organized, chartered, or holding a license or 8 |
---|
111 | 111 | | authorization certificate under the laws of this State, any other state, the United 9 |
---|
112 | 112 | | States, or any other country, or the parent, affiliate, or subsidiary of a financial 10 |
---|
113 | 113 | | institution, but does not include the State, a State agency, any political 11 |
---|
114 | 114 | | subdivision of the State, or a vendor acting solely on behalf of, and at the 12 |
---|
115 | 115 | | direction of, the State. 13 |
---|
116 | 116 | | (3)(5) “Consumer” means an individual residing in this State. 14 |
---|
117 | 117 | | (6) “Consumer health data controller” means any controller that, alone 15 |
---|
118 | 118 | | or jointly with others, determines the purpose and means of processing 16 |
---|
119 | 119 | | consumer health data. 17 |
---|
120 | 120 | | (7) “Controller” means a person who, alone or jointly with others, 18 |
---|
121 | 121 | | determines the purpose and means of processing personal data. 19 |
---|
122 | 122 | | (4)(8)(A) “Data broker” means a business, or unit or units of a business, 20 |
---|
123 | 123 | | separately or together, that knowingly collects and sells or licenses to third 21 BILL AS INTRODUCED H.211 |
---|
124 | 124 | | 2025 Page 6 of 31 |
---|
125 | 125 | | |
---|
126 | 126 | | |
---|
127 | 127 | | VT LEG #378943 v.1 |
---|
128 | 128 | | parties the brokered personal information of a consumer with whom the 1 |
---|
129 | 129 | | business does not have a direct relationship. 2 |
---|
130 | 130 | | (B) Examples of a direct relationship with a business include if the 3 |
---|
131 | 131 | | consumer is a past or present: 4 |
---|
132 | 132 | | (i) customer, client, subscriber, user, or registered user of the 5 |
---|
133 | 133 | | business’s goods or services within the last five calendar years; 6 |
---|
134 | 134 | | (ii) employee, contractor, or agent of the business; 7 |
---|
135 | 135 | | (iii) investor in the business; or 8 |
---|
136 | 136 | | (iv) donor to the business. 9 |
---|
137 | 137 | | (C) The following activities conducted by a business, and the 10 |
---|
138 | 138 | | collection and sale or licensing of brokered personal information incidental to 11 |
---|
139 | 139 | | conducting these activities, do not qualify the business as a data broker: 12 |
---|
140 | 140 | | (i) developing or maintaining third-party e-commerce or 13 |
---|
141 | 141 | | application platforms; 14 |
---|
142 | 142 | | (ii) providing 411 directory assistance or directory information 15 |
---|
143 | 143 | | services, including name, address, and telephone number, on behalf of or as a 16 |
---|
144 | 144 | | function of a telecommunications carrier; 17 |
---|
145 | 145 | | (iii) providing publicly available information related to a 18 |
---|
146 | 146 | | consumer’s business or profession; or 19 |
---|
147 | 147 | | (iv) providing publicly available information via real-time or near-20 |
---|
148 | 148 | | real-time alert services for health or safety purposes. 21 BILL AS INTRODUCED H.211 |
---|
149 | 149 | | 2025 Page 7 of 31 |
---|
150 | 150 | | |
---|
151 | 151 | | |
---|
152 | 152 | | VT LEG #378943 v.1 |
---|
153 | 153 | | (D) The phrase “sells or licenses” does not include: 1 |
---|
154 | 154 | | (i) a one-time or occasional sale of assets of a business as part of a 2 |
---|
155 | 155 | | transfer of control of those assets that is not part of the ordinary conduct of the 3 |
---|
156 | 156 | | business; or 4 |
---|
157 | 157 | | (ii) a sale or license of data that is merely incidental to the 5 |
---|
158 | 158 | | business. 6 |
---|
159 | 159 | | (5)(9)(A) “Data broker security breach” means an unauthorized 7 |
---|
160 | 160 | | acquisition or a reasonable belief of an unauthorized acquisition of more than 8 |
---|
161 | 161 | | one element of brokered personal information maintained by a data broker 9 |
---|
162 | 162 | | when the brokered personal information is not encrypted, redacted, or 10 |
---|
163 | 163 | | protected by another method that renders the information unreadable or 11 |
---|
164 | 164 | | unusable by an unauthorized person. 12 |
---|
165 | 165 | | (B) “Data broker security breach” does not include good faith but 13 |
---|
166 | 166 | | unauthorized acquisition of brokered personal information by an employee or 14 |
---|
167 | 167 | | agent of the data broker for a legitimate purpose of the data broker, provided 15 |
---|
168 | 168 | | that the brokered personal information is not used for a purpose unrelated to 16 |
---|
169 | 169 | | the data broker’s business or subject to further unauthorized disclosure. 17 |
---|
170 | 170 | | (C) In determining whether brokered personal information has been 18 |
---|
171 | 171 | | acquired or is reasonably believed to have been acquired by a person without 19 |
---|
172 | 172 | | valid authorization, a data broker may consider the following factors, among 20 |
---|
173 | 173 | | others: 21 BILL AS INTRODUCED H.211 |
---|
174 | 174 | | 2025 Page 8 of 31 |
---|
175 | 175 | | |
---|
176 | 176 | | |
---|
177 | 177 | | VT LEG #378943 v.1 |
---|
178 | 178 | | (i) indications that the brokered personal information is in the 1 |
---|
179 | 179 | | physical possession and control of a person without valid authorization, such 2 |
---|
180 | 180 | | as a lost or stolen computer or other device containing brokered personal 3 |
---|
181 | 181 | | information; 4 |
---|
182 | 182 | | (ii) indications that the brokered personal information has been 5 |
---|
183 | 183 | | downloaded or copied; 6 |
---|
184 | 184 | | (iii) indications that the brokered personal information was used 7 |
---|
185 | 185 | | by an unauthorized person, such as fraudulent accounts opened or instances of 8 |
---|
186 | 186 | | identity theft reported; or 9 |
---|
187 | 187 | | (iv) that the brokered personal information has been made public. 10 |
---|
188 | 188 | | (6)(10) “Data collector” means a person who, for any purpose, whether 11 |
---|
189 | 189 | | by automated collection or otherwise, handles, collects, disseminates, or 12 |
---|
190 | 190 | | otherwise deals with personally identifiable information, and includes the 13 |
---|
191 | 191 | | State, State agencies, political subdivisions of the State, public and private 14 |
---|
192 | 192 | | universities, privately and publicly held corporations, limited liability 15 |
---|
193 | 193 | | companies, financial institutions, and retail operators. 16 |
---|
194 | 194 | | (7)(11) “Encryption” means use of an algorithmic process to transform 17 |
---|
195 | 195 | | data into a form in which the data is rendered unreadable or unusable without 18 |
---|
196 | 196 | | use of a confidential process or key. 19 |
---|
197 | 197 | | (8)(12) “License” means a grant of access to, or distribution of, data by 20 |
---|
198 | 198 | | one person to another in exchange for consideration. A use of data for the sole 21 BILL AS INTRODUCED H.211 |
---|
199 | 199 | | 2025 Page 9 of 31 |
---|
200 | 200 | | |
---|
201 | 201 | | |
---|
202 | 202 | | VT LEG #378943 v.1 |
---|
203 | 203 | | benefit of the data provider, where the data provider maintains control over the 1 |
---|
204 | 204 | | use of the data, is not a license. 2 |
---|
205 | 205 | | (9)(13) “Login credentials” means a consumer’s user name or e-mail 3 |
---|
206 | 206 | | email address, in combination with a password or an answer to a security 4 |
---|
207 | 207 | | question, that together permit access to an online account. 5 |
---|
208 | 208 | | (10)(14)(A) “Personally identifiable information” means a consumer’s 6 |
---|
209 | 209 | | first name or first initial and last name in combination with one or more of the 7 |
---|
210 | 210 | | following digital data elements, when the data elements are not encrypted, 8 |
---|
211 | 211 | | redacted, or protected by another method that renders them unreadable or 9 |
---|
212 | 212 | | unusable by unauthorized persons: 10 |
---|
213 | 213 | | (i) a Social Security number; 11 |
---|
214 | 214 | | (ii) a driver license or nondriver State identification card number, 12 |
---|
215 | 215 | | individual taxpayer identification number, passport number, military 13 |
---|
216 | 216 | | identification card number, or other identification number that originates from 14 |
---|
217 | 217 | | a government identification document that is commonly used to verify identity 15 |
---|
218 | 218 | | for a commercial transaction; 16 |
---|
219 | 219 | | (iii) a financial account number or credit or debit card number, if 17 |
---|
220 | 220 | | the number could be used without additional identifying information, access 18 |
---|
221 | 221 | | codes, or passwords; 19 |
---|
222 | 222 | | (iv) a password, personal identification number, or other access 20 |
---|
223 | 223 | | code for a financial account; 21 BILL AS INTRODUCED H.211 |
---|
224 | 224 | | 2025 Page 10 of 31 |
---|
225 | 225 | | |
---|
226 | 226 | | |
---|
227 | 227 | | VT LEG #378943 v.1 |
---|
228 | 228 | | (v) unique biometric data generated from measurements or 1 |
---|
229 | 229 | | technical analysis of human body characteristics used by the owner or licensee 2 |
---|
230 | 230 | | of the data to identify or authenticate the consumer, such as a fingerprint, retina 3 |
---|
231 | 231 | | or iris image, or other unique physical representation or digital representation 4 |
---|
232 | 232 | | of biometric data; 5 |
---|
233 | 233 | | (vi) genetic information; and 6 |
---|
234 | 234 | | (vii)(I) health records or records of a wellness program or similar 7 |
---|
235 | 235 | | program of health promotion or disease prevention; 8 |
---|
236 | 236 | | (II) a health care professional’s medical diagnosis or treatment 9 |
---|
237 | 237 | | of the consumer; or 10 |
---|
238 | 238 | | (III) a health insurance policy number. 11 |
---|
239 | 239 | | (B) “Personally identifiable information” does not mean publicly 12 |
---|
240 | 240 | | available information that is lawfully made available to the general public from 13 |
---|
241 | 241 | | federal, State, or local government records. 14 |
---|
242 | 242 | | (15) “Precise geolocation” means information derived from technology 15 |
---|
243 | 243 | | that can precisely and accurately identify the specific location of a consumer 16 |
---|
244 | 244 | | within a radius of 1,850 feet. 17 |
---|
245 | 245 | | (16) “Processor” means a person who processes personal data on behalf 18 |
---|
246 | 246 | | of a controller. 19 BILL AS INTRODUCED H.211 |
---|
247 | 247 | | 2025 Page 11 of 31 |
---|
248 | 248 | | |
---|
249 | 249 | | |
---|
250 | 250 | | VT LEG #378943 v.1 |
---|
251 | 251 | | (11)(17) “Record” means any material on which written, drawn, spoken, 1 |
---|
252 | 252 | | visual, or electromagnetic information is recorded or preserved, regardless of 2 |
---|
253 | 253 | | physical form or characteristics. 3 |
---|
254 | 254 | | (12)(18) “Redaction” means the rendering of data so that the data are 4 |
---|
255 | 255 | | unreadable or are truncated so that no not more than the last four digits of the 5 |
---|
256 | 256 | | identification number are accessible as part of the data. 6 |
---|
257 | 257 | | (13)(19)(A) “Security breach” means unauthorized acquisition of 7 |
---|
258 | 258 | | electronic data, or a reasonable belief of an unauthorized acquisition of 8 |
---|
259 | 259 | | electronic data, that compromises the security, confidentiality, or integrity of a 9 |
---|
260 | 260 | | consumer’s personally identifiable information or login credentials maintained 10 |
---|
261 | 261 | | by a data collector. 11 |
---|
262 | 262 | | (B) “Security breach” does not include good faith but unauthorized 12 |
---|
263 | 263 | | acquisition of personally identifiable information or login credentials by an 13 |
---|
264 | 264 | | employee or agent of the data collector for a legitimate purpose of the data 14 |
---|
265 | 265 | | collector, provided that the personally identifiable information or login 15 |
---|
266 | 266 | | credentials are not used for a purpose unrelated to the data collector’s business 16 |
---|
267 | 267 | | or subject to further unauthorized disclosure. 17 |
---|
268 | 268 | | (C) In determining whether personally identifiable information or 18 |
---|
269 | 269 | | login credentials have been acquired or is reasonably believed to have been 19 |
---|
270 | 270 | | acquired by a person without valid authorization, a data collector may consider 20 |
---|
271 | 271 | | the following factors, among others: 21 BILL AS INTRODUCED H.211 |
---|
272 | 272 | | 2025 Page 12 of 31 |
---|
273 | 273 | | |
---|
274 | 274 | | |
---|
275 | 275 | | VT LEG #378943 v.1 |
---|
276 | 276 | | (i) indications that the information is in the physical possession 1 |
---|
277 | 277 | | and control of a person without valid authorization, such as a lost or stolen 2 |
---|
278 | 278 | | computer or other device containing information; 3 |
---|
279 | 279 | | (ii) indications that the information has been downloaded or 4 |
---|
280 | 280 | | copied; 5 |
---|
281 | 281 | | (iii) indications that the information was used by an unauthorized 6 |
---|
282 | 282 | | person, such as fraudulent accounts opened or instances of identity theft 7 |
---|
283 | 283 | | reported; or 8 |
---|
284 | 284 | | (iv) that the information has been made public. 9 |
---|
285 | 285 | | * * * 10 |
---|
286 | 286 | | Subchapter 2. Security Breach Notice Act Breaches 11 |
---|
287 | 287 | | § 2435. NOTICE OF SECURITY BREACHES 12 |
---|
288 | 288 | | * * * 13 |
---|
289 | 289 | | (h) Enforcement. 14 |
---|
290 | 290 | | (1) With respect to all data collectors and other entities subject to this 15 |
---|
291 | 291 | | subchapter, other than a person or entity licensed or registered with the 16 |
---|
292 | 292 | | Department of Financial Regulation under Title 8 or this title, the Attorney 17 |
---|
293 | 293 | | General and State’s Attorney shall have sole and full authority to investigate 18 |
---|
294 | 294 | | potential violations of this subchapter and to enforce, prosecute, obtain, and 19 |
---|
295 | 295 | | impose remedies for a violation of this subchapter or any rules or regulations 20 |
---|
296 | 296 | | made pursuant to this subchapter as the Attorney General and State’s Attorney 21 BILL AS INTRODUCED H.211 |
---|
297 | 297 | | 2025 Page 13 of 31 |
---|
298 | 298 | | |
---|
299 | 299 | | |
---|
300 | 300 | | VT LEG #378943 v.1 |
---|
301 | 301 | | have under chapter 63 of this title. With respect to a controller or processor 1 |
---|
302 | 302 | | other than a controller or processor licensed or registered with the Department 2 |
---|
303 | 303 | | of Financial Regulation under Title 8 or this title, the Attorney General has the 3 |
---|
304 | 304 | | same authority to adopt rules to implement the provisions of this section and to 4 |
---|
305 | 305 | | conduct civil investigations, enter into assurances of discontinuance, bring civil 5 |
---|
306 | 306 | | actions, and take other enforcement actions as provided under chapter 63, 6 |
---|
307 | 307 | | subchapter 1 of this title. The Attorney General may refer the matter to the 7 |
---|
308 | 308 | | State’s Attorney in an appropriate case. The Superior Courts shall have 8 |
---|
309 | 309 | | jurisdiction over any enforcement matter brought by the Attorney General or a 9 |
---|
310 | 310 | | State’s Attorney under this subsection. 10 |
---|
311 | 311 | | (2) With respect to a data collector that is a person or entity licensed or 11 |
---|
312 | 312 | | registered with the Department of Financial Regulation under Title 8 or this 12 |
---|
313 | 313 | | title, the Department of Financial Regulation shall have the full authority to 13 |
---|
314 | 314 | | investigate potential violations of this subchapter and to prosecute, obtain, and 14 |
---|
315 | 315 | | impose remedies for a violation of this subchapter or any rules or regulations 15 |
---|
316 | 316 | | adopted pursuant to this subchapter, as the Department has under Title 8 or this 16 |
---|
317 | 317 | | title or any other applicable law or regulation. With respect to a controller or 17 |
---|
318 | 318 | | processor that is licensed or registered with the Department of Financial 18 |
---|
319 | 319 | | Regulation under Title 8 or this title, the Department of Financial Regulation 19 |
---|
320 | 320 | | has the same authority to adopt rules to implement the provisions of this 20 |
---|
321 | 321 | | section and to conduct civil investigations, enter into assurances of 21 BILL AS INTRODUCED H.211 |
---|
322 | 322 | | 2025 Page 14 of 31 |
---|
323 | 323 | | |
---|
324 | 324 | | |
---|
325 | 325 | | VT LEG #378943 v.1 |
---|
326 | 326 | | discontinuance, bring civil actions, and take other enforcement actions as 1 |
---|
327 | 327 | | provided under Title 8 or this title or any other applicable law or regulation. 2 |
---|
328 | 328 | | * * * 3 |
---|
329 | 329 | | § 2436. NOTICE OF DATA BROKER SECURITY BREACH ES 4 |
---|
330 | 330 | | (a) Short title. This section shall be known as the “Data Broker Security 5 |
---|
331 | 331 | | Breach Notice Act.” 6 |
---|
332 | 332 | | (b) Notice of breach to consumers. 7 |
---|
333 | 333 | | (1) Except as otherwise provided in subsection (c) of this section, a data 8 |
---|
334 | 334 | | broker shall, following discovery or notification to the data broker of a security 9 |
---|
335 | 335 | | breach affecting a consumer, notify the consumer that there has been a data 10 |
---|
336 | 336 | | broker security breach. Notice of the security breach shall be made in the most 11 |
---|
337 | 337 | | expedient time possible and without unreasonable delay, but not later than 45 12 |
---|
338 | 338 | | days after the discovery or notification, consistent with the legitimate needs of 13 |
---|
339 | 339 | | the law enforcement agency, as provided in subdivisions (3) and (4) of this 14 |
---|
340 | 340 | | subsection, or with any measures necessary to determine the scope of the 15 |
---|
341 | 341 | | security breach and restore the reasonable integrity, security, and 16 |
---|
342 | 342 | | confidentiality of the data system. 17 |
---|
343 | 343 | | (2) A data broker shall provide notice of a breach to the Attorney 18 |
---|
344 | 344 | | General as follows: 19 |
---|
345 | 345 | | (A)(i) The data broker shall notify the Attorney General of the date of 20 |
---|
346 | 346 | | the security breach and the date of discovery of the breach and shall provide a 21 BILL AS INTRODUCED H.211 |
---|
347 | 347 | | 2025 Page 15 of 31 |
---|
348 | 348 | | |
---|
349 | 349 | | |
---|
350 | 350 | | VT LEG #378943 v.1 |
---|
351 | 351 | | preliminary description of the breach within 14 business days, consistent with 1 |
---|
352 | 352 | | the legitimate needs of the law enforcement agency, as provided in 2 |
---|
353 | 353 | | subdivisions (3) and (4) of this subsection (b), after the data broker’s discovery 3 |
---|
354 | 354 | | of the security breach. 4 |
---|
355 | 355 | | (ii) If the date of the breach is unknown at the time notice is sent 5 |
---|
356 | 356 | | to the Attorney General, the data broker shall send the Attorney General the 6 |
---|
357 | 357 | | date of the breach as soon as it is known. 7 |
---|
358 | 358 | | (iii) Unless otherwise ordered by a court of this State for good 8 |
---|
359 | 359 | | cause shown, a notice provided under this subdivision (2)(A) shall not be 9 |
---|
360 | 360 | | disclosed, without the consent of the data broker, to any person other than the 10 |
---|
361 | 361 | | authorized agent or representative of the Attorney General, a State’s Attorney, 11 |
---|
362 | 362 | | or another law enforcement officer engaged in legitimate law enforcement 12 |
---|
363 | 363 | | activities. 13 |
---|
364 | 364 | | (B)(i) When the data broker provides notice of the breach pursuant to 14 |
---|
365 | 365 | | subdivision (1) of this subsection, the data broker shall notify the Attorney 15 |
---|
366 | 366 | | General of the number of Vermont consumers affected, if known to the data 16 |
---|
367 | 367 | | broker, and shall provide a copy of the notice provided to consumers under 17 |
---|
368 | 368 | | subdivision (1) of this subsection (b). 18 |
---|
369 | 369 | | (ii) The data broker may send to the Attorney General a second 19 |
---|
370 | 370 | | copy of the consumer notice, from which is redacted the type of brokered 20 BILL AS INTRODUCED H.211 |
---|
371 | 371 | | 2025 Page 16 of 31 |
---|
372 | 372 | | |
---|
373 | 373 | | |
---|
374 | 374 | | VT LEG #378943 v.1 |
---|
375 | 375 | | personal information that was subject to the breach, that the Attorney General 1 |
---|
376 | 376 | | shall use for any public disclosure of the breach. 2 |
---|
377 | 377 | | (3) The notice to the Attorney General and a consumer required by this 3 |
---|
378 | 378 | | subsection shall be delayed upon request of a law enforcement agency. A law 4 |
---|
379 | 379 | | enforcement agency may request the delay if it believes that notification may 5 |
---|
380 | 380 | | impede a law enforcement investigation or a national or Homeland Security 6 |
---|
381 | 381 | | investigation or jeopardize public safety or national or Homeland Security 7 |
---|
382 | 382 | | interests. In the event law enforcement makes the request for a delay in a 8 |
---|
383 | 383 | | manner other than in writing, the data broker shall document the request 9 |
---|
384 | 384 | | contemporaneously in writing and include the name of the law enforcement 10 |
---|
385 | 385 | | officer making the request and the officer’s law enforcement agency engaged 11 |
---|
386 | 386 | | in the investigation. A law enforcement agency shall promptly notify the data 12 |
---|
387 | 387 | | broker in writing when the law enforcement agency no longer believes that 13 |
---|
388 | 388 | | notification may impede a law enforcement investigation or a national or 14 |
---|
389 | 389 | | Homeland Security investigation or jeopardize public safety or national or 15 |
---|
390 | 390 | | Homeland Security interests. The data broker shall provide notice required by 16 |
---|
391 | 391 | | this subsection without unreasonable delay upon receipt of a written 17 |
---|
392 | 392 | | communication, which includes facsimile or electronic communication, from 18 |
---|
393 | 393 | | the law enforcement agency withdrawing its request for delay. 19 |
---|
394 | 394 | | (4) The notice to a consumer required in subdivision (1) of this 20 |
---|
395 | 395 | | subsection shall be clear and conspicuous. A notice to a consumer of a 21 BILL AS INTRODUCED H.211 |
---|
396 | 396 | | 2025 Page 17 of 31 |
---|
397 | 397 | | |
---|
398 | 398 | | |
---|
399 | 399 | | VT LEG #378943 v.1 |
---|
400 | 400 | | security breach involving brokered personal information shall include a 1 |
---|
401 | 401 | | description of each of the following, if known to the data broker: 2 |
---|
402 | 402 | | (A) the incident in general terms; 3 |
---|
403 | 403 | | (B) the categories of brokered personal information that was subject 4 |
---|
404 | 404 | | to the security breach; 5 |
---|
405 | 405 | | (C) the general acts of the data broker to protect the brokered 6 |
---|
406 | 406 | | personal information from further security breach; 7 |
---|
407 | 407 | | (D) a telephone number, toll-free if available, that the consumer may 8 |
---|
408 | 408 | | call for further information and assistance; 9 |
---|
409 | 409 | | (E) advice that directs the consumer to remain vigilant by reviewing 10 |
---|
410 | 410 | | account statements and monitoring free credit reports; and 11 |
---|
411 | 411 | | (F) the approximate date of the data broker security breach. 12 |
---|
412 | 412 | | (5) A data broker may provide notice of a security breach involving 13 |
---|
413 | 413 | | brokered personal information to a consumer by two or more of the following 14 |
---|
414 | 414 | | methods: 15 |
---|
415 | 415 | | (A) written notice mailed to the consumer’s residence; 16 |
---|
416 | 416 | | (B) electronic notice, for those consumers for whom the data broker 17 |
---|
417 | 417 | | has a valid email address, if: 18 |
---|
418 | 418 | | (i) the data broker’s primary method of communication with the 19 |
---|
419 | 419 | | consumer is by electronic means, the electronic notice does not request or 20 |
---|
420 | 420 | | contain a hypertext link to a request that the consumer provide personal 21 BILL AS INTRODUCED H.211 |
---|
421 | 421 | | 2025 Page 18 of 31 |
---|
422 | 422 | | |
---|
423 | 423 | | |
---|
424 | 424 | | VT LEG #378943 v.1 |
---|
425 | 425 | | information, and the electronic notice conspicuously warns consumers not to 1 |
---|
426 | 426 | | provide personal information in response to electronic communications 2 |
---|
427 | 427 | | regarding security breaches; or 3 |
---|
428 | 428 | | (ii) the notice is consistent with the provisions regarding electronic 4 |
---|
429 | 429 | | records and signatures for notices in 15 U.S.C. § 7001; 5 |
---|
430 | 430 | | (C) telephonic notice, provided that telephonic contact is made 6 |
---|
431 | 431 | | directly with each affected consumer and not through a prerecorded message; 7 |
---|
432 | 432 | | or 8 |
---|
433 | 433 | | (D) notice by publication in a newspaper of statewide circulation in 9 |
---|
434 | 434 | | the event the data broker cannot effectuate notice by any other means. 10 |
---|
435 | 435 | | (c) Exception. 11 |
---|
436 | 436 | | (1) Notice of a security breach pursuant to subsection (b) of this section 12 |
---|
437 | 437 | | is not required if the data broker establishes that misuse of brokered personal 13 |
---|
438 | 438 | | information is not reasonably possible and the data broker provides notice of 14 |
---|
439 | 439 | | the determination that the misuse of the brokered personal information is not 15 |
---|
440 | 440 | | reasonably possible pursuant to the requirements of this subsection. If the data 16 |
---|
441 | 441 | | broker establishes that misuse of the brokered personal information is not 17 |
---|
442 | 442 | | reasonably possible, the data broker shall provide notice of its determination 18 |
---|
443 | 443 | | that misuse of the brokered personal information is not reasonably possible and 19 |
---|
444 | 444 | | a detailed explanation for said determination to the Attorney General. The data 20 |
---|
445 | 445 | | broker may designate its notice and detailed explanation to the Attorney 21 BILL AS INTRODUCED H.211 |
---|
446 | 446 | | 2025 Page 19 of 31 |
---|
447 | 447 | | |
---|
448 | 448 | | |
---|
449 | 449 | | VT LEG #378943 v.1 |
---|
450 | 450 | | General as a trade secret if the notice and detailed explanation meet the 1 |
---|
451 | 451 | | definition of trade secret contained in 1 V.S.A. § 317(c)(9). 2 |
---|
452 | 452 | | (2) If a data broker established that misuse of brokered personal 3 |
---|
453 | 453 | | information was not reasonably possible under subdivision (1) of this 4 |
---|
454 | 454 | | subsection and subsequently obtains facts indicating that misuse of the 5 |
---|
455 | 455 | | brokered personal information has occurred or is occurring, the data broker 6 |
---|
456 | 456 | | shall provide notice of the security breach pursuant to subsection (b) of this 7 |
---|
457 | 457 | | section. 8 |
---|
458 | 458 | | (d) Waiver. Any waiver of the provisions of this subchapter is contrary to 9 |
---|
459 | 459 | | public policy and is void and unenforceable. 10 |
---|
460 | 460 | | (e) Enforcement. 11 |
---|
461 | 461 | | (1) With respect to a controller or processor other than a controller or 12 |
---|
462 | 462 | | processor licensed or registered with the Department of Financial Regulation 13 |
---|
463 | 463 | | under Title 8 or this title, the Attorney General has the same authority to adopt 14 |
---|
464 | 464 | | rules to implement the provisions of this section and to conduct civil 15 |
---|
465 | 465 | | investigations, enter into assurances of discontinuance, bring civil actions, and 16 |
---|
466 | 466 | | take other enforcement actions as provided under chapter 63, subchapter 1 of 17 |
---|
467 | 467 | | this title. The Attorney General may refer the matter to the State’s Attorney in 18 |
---|
468 | 468 | | an appropriate case. The Superior Courts shall have jurisdiction over any 19 |
---|
469 | 469 | | enforcement matter brought by the Attorney General or a State’s Attorney 20 |
---|
470 | 470 | | under this subsection. 21 BILL AS INTRODUCED H.211 |
---|
471 | 471 | | 2025 Page 20 of 31 |
---|
472 | 472 | | |
---|
473 | 473 | | |
---|
474 | 474 | | VT LEG #378943 v.1 |
---|
475 | 475 | | (2) With respect to a controller or processor that is licensed or registered 1 |
---|
476 | 476 | | with the Department of Financial Regulation under Title 8 or this title, the 2 |
---|
477 | 477 | | Department of Financial Regulation has the same authority to adopt rules to 3 |
---|
478 | 478 | | implement the provisions of this section and to conduct civil investigations, 4 |
---|
479 | 479 | | enter into assurances of discontinuance, bring civil actions, and take other 5 |
---|
480 | 480 | | enforcement actions as provided under Title 8 or this title or any other 6 |
---|
481 | 481 | | applicable law or regulation. 7 |
---|
482 | 482 | | * * * 8 |
---|
483 | 483 | | Subchapter 5. Data Brokers 9 |
---|
484 | 484 | | § 2446. DATA BROKERS; ANNUAL REGISTRATION 10 |
---|
485 | 485 | | (a) Registration. Annually, on or before January 31 following a year in 11 |
---|
486 | 486 | | which a person meets the definition of data broker as provided in section 2430 12 |
---|
487 | 487 | | of this title, a data broker shall: 13 |
---|
488 | 488 | | (1) register with the Secretary of State; 14 |
---|
489 | 489 | | (2) pay a registration fee of $100.00; and pay a registration fee in an 15 |
---|
490 | 490 | | amount determined by the Secretary of State which shall: 16 |
---|
491 | 491 | | (A) not exceed the reasonable costs of: 17 |
---|
492 | 492 | | (i) establishing and maintaining the informational website set forth 18 |
---|
493 | 493 | | in subsection (f) of this section; and 19 |
---|
494 | 494 | | (ii) establishing, maintaining, and providing access to the 20 |
---|
495 | 495 | | accessible deletion mechanism set forth in section 2446b of this title; and 21 BILL AS INTRODUCED H.211 |
---|
496 | 496 | | 2025 Page 21 of 31 |
---|
497 | 497 | | |
---|
498 | 498 | | |
---|
499 | 499 | | VT LEG #378943 v.1 |
---|
500 | 500 | | (B) be deposited by the Secretary of State into the Data Brokers 1 |
---|
501 | 501 | | Registry Fund established in section 2446b of this title; and 2 |
---|
502 | 502 | | (3) provide the following information to the Secretary of State: 3 |
---|
503 | 503 | | (A) the name and primary physical, e-mail email, phone number, and 4 |
---|
504 | 504 | | Internet internet addresses of the data broker; 5 |
---|
505 | 505 | | (B) if the data broker permits a consumer to opt out of the data 6 |
---|
506 | 506 | | broker’s collection of brokered personal information, opt out of its databases, 7 |
---|
507 | 507 | | or opt out of certain sales of data: 8 |
---|
508 | 508 | | (i) the method for requesting an opt-out; 9 |
---|
509 | 509 | | (ii) if the opt-out applies to only certain activities or sales, which 10 |
---|
510 | 510 | | ones; and 11 |
---|
511 | 511 | | (iii) whether the data broker permits a consumer to authorize a 12 |
---|
512 | 512 | | third party an authorized agent to perform the opt-out on the consumer’s 13 |
---|
513 | 513 | | behalf; 14 |
---|
514 | 514 | | (C) a statement specifying the data collection, databases, or sales 15 |
---|
515 | 515 | | activities from which a consumer may not opt out; 16 |
---|
516 | 516 | | (D) a statement whether the data broker implements a purchaser 17 |
---|
517 | 517 | | credentialing process; 18 |
---|
518 | 518 | | (E) the number of data broker security breaches that the data broker 19 |
---|
519 | 519 | | has experienced during the prior year, and if known, the total number of 20 |
---|
520 | 520 | | consumers affected by the breaches; 21 BILL AS INTRODUCED H.211 |
---|
521 | 521 | | 2025 Page 22 of 31 |
---|
522 | 522 | | |
---|
523 | 523 | | |
---|
524 | 524 | | VT LEG #378943 v.1 |
---|
525 | 525 | | (F) where the data broker has actual knowledge that it possesses the 1 |
---|
526 | 526 | | brokered personal information of minors, a separate statement detailing the 2 |
---|
527 | 527 | | data collection practices, databases, sales activities, and opt-out policies that 3 |
---|
528 | 528 | | are applicable to the brokered personal information of minors; and 4 |
---|
529 | 529 | | (G) whether the data broker collects: 5 |
---|
530 | 530 | | (i) precise geolocation of consumers; 6 |
---|
531 | 531 | | (ii) reproductive health care data of consumers; 7 |
---|
532 | 532 | | (iii) Social Security numbers of consumers; 8 |
---|
533 | 533 | | (iv) driver’s license information of consumers; 9 |
---|
534 | 534 | | (v) biometric data of consumers; 10 |
---|
535 | 535 | | (vi) immigration status of consumers; 11 |
---|
536 | 536 | | (vii) sexual orientation of consumers; or 12 |
---|
537 | 537 | | (viii) union membership status of consumers; 13 |
---|
538 | 538 | | (H) beginning on January 1, 2031, whether the data broker has 14 |
---|
539 | 539 | | undergone an audit pursuant to subsection 2449a(e) of this title and if so, the 15 |
---|
540 | 540 | | most recent year that the data broker has submitted a report resulting from the 16 |
---|
541 | 541 | | audit to the Secretary of State; 17 |
---|
542 | 542 | | (I) beginning on January 1, 2029, the following annual metrics 18 |
---|
543 | 543 | | pursuant to section 2449a of this title: 19 |
---|
544 | 544 | | (i) the number of deletion requests received; 20 |
---|
545 | 545 | | (ii) the number of deletion requests processed; 21 BILL AS INTRODUCED H.211 |
---|
546 | 546 | | 2025 Page 23 of 31 |
---|
547 | 547 | | |
---|
548 | 548 | | |
---|
549 | 549 | | VT LEG #378943 v.1 |
---|
550 | 550 | | (iii) the number of deletion requests denied because the consumer 1 |
---|
551 | 551 | | request cannot be verified; and 2 |
---|
552 | 552 | | (iv) the number of deletion requests denied because retention of 3 |
---|
553 | 553 | | the consumer’s brokered personal information is required by law; and 4 |
---|
554 | 554 | | (J) any additional information or explanation the data broker chooses 5 |
---|
555 | 555 | | to provide concerning its data collection practices. 6 |
---|
556 | 556 | | (b) Penalties. A data broker that fails to register pursuant to subsection (a) 7 |
---|
557 | 557 | | of this section is liable to the State for: 8 |
---|
558 | 558 | | (1) a civil penalty of $50.00 for each day, not to exceed a total of 9 |
---|
559 | 559 | | $10,000.00 for each year, it fails to register pursuant to this section; 10 |
---|
560 | 560 | | (2) an amount equal to the fees due under this section during the period 11 |
---|
561 | 561 | | it failed to register pursuant to this section; and 12 |
---|
562 | 562 | | (3) other penalties imposed by law. 13 |
---|
563 | 563 | | (1) A data broker that fails to register as required by subsection (a) of 14 |
---|
564 | 564 | | this section is liable to the State for: 15 |
---|
565 | 565 | | (A) an administrative fine of $200.00 for each day the data broker 16 |
---|
566 | 566 | | fails to register; 17 |
---|
567 | 567 | | (B) an amount equal to the fees that were due during the period the 18 |
---|
568 | 568 | | data broker failed to register; and 19 |
---|
569 | 569 | | (C) any reasonable costs incurred by the State in the investigation 20 |
---|
570 | 570 | | and administration of the action as the court deems appropriate. 21 BILL AS INTRODUCED H.211 |
---|
571 | 571 | | 2025 Page 24 of 31 |
---|
572 | 572 | | |
---|
573 | 573 | | |
---|
574 | 574 | | VT LEG #378943 v.1 |
---|
575 | 575 | | (2) A data broker that fails to provide all registration information 1 |
---|
576 | 576 | | required in subdivision (a)(3) of this section shall file an amendment that 2 |
---|
577 | 577 | | includes any omitted information not later than 30 days after receiving 3 |
---|
578 | 578 | | notification of the omission from the Secretary of State and is liable to the 4 |
---|
579 | 579 | | State for a civil penalty of $1,000.00 per day for each day thereafter that the 5 |
---|
580 | 580 | | data broker does not file an amendment providing the omitted information. 6 |
---|
581 | 581 | | (3) A data broker that files materially incorrect information in its 7 |
---|
582 | 582 | | registration: 8 |
---|
583 | 583 | | (A) is liable to the State for a civil penalty of $25,000.00; and 9 |
---|
584 | 584 | | (B) shall correct the incorrect information not later than 30 days after 10 |
---|
585 | 585 | | notification of the incorrect information, and, if it fails to correct the 11 |
---|
586 | 586 | | information, the data broker shall be liable for an additional civil penalty of 12 |
---|
587 | 587 | | $1,000.00 per day for each day the data broker fails to correct the information. 13 |
---|
588 | 588 | | (4) All penalties, fines, fees, and expenses recovered in an action 14 |
---|
589 | 589 | | pursuant to this section shall be deposited in the Data Brokers Registry Fund. 15 |
---|
590 | 590 | | (c) Enforcement. The Attorney General and the Secretary of State may 16 |
---|
591 | 591 | | maintain an action in the Civil Division of the Superior Court to collect the 17 |
---|
592 | 592 | | penalties imposed in this section and to seek appropriate injunctive relief. 18 |
---|
593 | 593 | | (d) Public web page. The Secretary of State shall create a publicly 19 |
---|
594 | 594 | | accessible page on its website where it lists the registration information 20 BILL AS INTRODUCED H.211 |
---|
595 | 595 | | 2025 Page 25 of 31 |
---|
596 | 596 | | |
---|
597 | 597 | | |
---|
598 | 598 | | VT LEG #378943 v.1 |
---|
599 | 599 | | provided by data brokers pursuant to this section and the accessible deletion 1 |
---|
600 | 600 | | mechanism set forth in section 2446a of this title. 2 |
---|
601 | 601 | | § 2446a. ACCESSIBLE DELETION MECHANISM 3 |
---|
602 | 602 | | (a) Creation of mechanism. On or before January 1, 2028, the Secretary of 4 |
---|
603 | 603 | | State shall establish an accessible deletion mechanism that: 5 |
---|
604 | 604 | | (1) implements and maintains reasonable security procedures and 6 |
---|
605 | 605 | | practices, including administrative, physical, and technical safeguards 7 |
---|
606 | 606 | | appropriate to the nature of the information and the purposes for which the 8 |
---|
607 | 607 | | brokered personal information will be used and to protect a consumer’s 9 |
---|
608 | 608 | | brokered personal information from unauthorized use, disclosure, access, 10 |
---|
609 | 609 | | destruction, or modification; 11 |
---|
610 | 610 | | (2) allows a consumer, through a single verifiable consumer request, to 12 |
---|
611 | 611 | | request that every data broker that maintains any brokered personal 13 |
---|
612 | 612 | | information about the consumer delete the brokered personal information; 14 |
---|
613 | 613 | | (3) allows a consumer to selectively exclude specific data brokers from 15 |
---|
614 | 614 | | a request made under subdivision (2) of this subsection; 16 |
---|
615 | 615 | | (4) allows a consumer to alter a previous request made pursuant to 17 |
---|
616 | 616 | | subdivision (2) of this subsection after at least 45 days have passed since the 18 |
---|
617 | 617 | | consumer last made a request; 19 BILL AS INTRODUCED H.211 |
---|
618 | 618 | | 2025 Page 26 of 31 |
---|
619 | 619 | | |
---|
620 | 620 | | |
---|
621 | 621 | | VT LEG #378943 v.1 |
---|
622 | 622 | | (5) allows a consumer to request the deletion of all brokered personal 1 |
---|
623 | 623 | | information related to that consumer all at once through a single deletion 2 |
---|
624 | 624 | | request; 3 |
---|
625 | 625 | | (6) permits a consumer to securely submit information in one or more 4 |
---|
626 | 626 | | privacy-protecting ways, as determined by the Secretary of State, to aid in the 5 |
---|
627 | 627 | | deletion request; 6 |
---|
628 | 628 | | (7) allows a data broker registered with the Secretary of State to 7 |
---|
629 | 629 | | determine whether a consumer has submitted a verifiable request to delete the 8 |
---|
630 | 630 | | brokered personal information related to that consumer as described in 9 |
---|
631 | 631 | | subdivision (2) of this subsection; 10 |
---|
632 | 632 | | (8) does not allow the disclosure of any additional brokered personal 11 |
---|
633 | 633 | | information of a consumer when the data broker accesses the accessible 12 |
---|
634 | 634 | | deletion mechanism, unless otherwise specified in this subchapter; 13 |
---|
635 | 635 | | (9) allows a consumer to make a request described in subdivision (2) of 14 |
---|
636 | 636 | | this subsection using a website operated by the Secretary of State; 15 |
---|
637 | 637 | | (10) does not charge a consumer to make a request described in 16 |
---|
638 | 638 | | subdivision (2) of this subsection; 17 |
---|
639 | 639 | | (11) is readily accessible and usable by consumers with disabilities; 18 |
---|
640 | 640 | | (12) supports the ability of a consumer’s authorized agents to aid in the 19 |
---|
641 | 641 | | deletion request; 20 BILL AS INTRODUCED H.211 |
---|
642 | 642 | | 2025 Page 27 of 31 |
---|
643 | 643 | | |
---|
644 | 644 | | |
---|
645 | 645 | | VT LEG #378943 v.1 |
---|
646 | 646 | | (13) allows the consumer or their authorized agent to verify the status of 1 |
---|
647 | 647 | | the consumer’s deletion request; and 2 |
---|
648 | 648 | | (14) provides a description of the following: 3 |
---|
649 | 649 | | (A) the deletion permitted by this section; 4 |
---|
650 | 650 | | (B) the process for submitting a deletion request pursuant to this 5 |
---|
651 | 651 | | section; and 6 |
---|
652 | 652 | | (C) examples of the types of information that may be deleted. 7 |
---|
653 | 653 | | (b) Data broker access. 8 |
---|
654 | 654 | | (1) Beginning on August 1, 2028, a data broker shall access the 9 |
---|
655 | 655 | | accessible deletion mechanism established in subsection (a) of this section at 10 |
---|
656 | 656 | | least once every 45 days and shall: 11 |
---|
657 | 657 | | (A) process all verifiable deletion requests the data broker has 12 |
---|
658 | 658 | | received from consumers in the previous 45 days and delete such brokered 13 |
---|
659 | 659 | | personal information; 14 |
---|
660 | 660 | | (B) process a request as an opt-out of the sale or sharing of the 15 |
---|
661 | 661 | | consumer’s brokered personal information; 16 |
---|
662 | 662 | | (C) direct all service providers and contractors associated with the 17 |
---|
663 | 663 | | data broker to: 18 |
---|
664 | 664 | | (i) delete all brokered personal information related to a consumer 19 |
---|
665 | 665 | | who has made a verifiable deletion request; and 20 BILL AS INTRODUCED H.211 |
---|
666 | 666 | | 2025 Page 28 of 31 |
---|
667 | 667 | | |
---|
668 | 668 | | |
---|
669 | 669 | | VT LEG #378943 v.1 |
---|
670 | 670 | | (ii) process a request as an opt-out of the sale or sharing of the 1 |
---|
671 | 671 | | consumer’s brokered personal information; and 2 |
---|
672 | 672 | | (D) not use or disclose any information submitted by a consumer 3 |
---|
673 | 673 | | through the accessible deletion mechanism for any other purpose besides the 4 |
---|
674 | 674 | | authority provided in this subsection (b), including for marketing purposes. 5 |
---|
675 | 675 | | (2) A data broker may deny a consumer’s request to delete a consumer’s 6 |
---|
676 | 676 | | brokered personal information made pursuant to this section if retention of the 7 |
---|
677 | 677 | | consumer’s brokered personal information is required by law. 8 |
---|
678 | 678 | | (3) The Secretary of State may charge an access fee to a data broker to 9 |
---|
679 | 679 | | use the accessible deletion mechanism that does not exceed the reasonable 10 |
---|
680 | 680 | | costs of providing access. 11 |
---|
681 | 681 | | (4) Any fees collected pursuant to subdivision (3) of this subsection 12 |
---|
682 | 682 | | shall be deposited into the Data Brokers Registry Fund. 13 |
---|
683 | 683 | | (c) Continuing obligation to consumers. Beginning on August 1, 2028, 14 |
---|
684 | 684 | | once a data broker has processed a verifiable consumer request to delete a 15 |
---|
685 | 685 | | consumer’s brokered personal information, the data broker shall: 16 |
---|
686 | 686 | | (1) delete all brokered personal information of the consumer at least 17 |
---|
687 | 687 | | once every 45 days unless: 18 |
---|
688 | 688 | | (A) the consumer alters the consumer’s decision pursuant to 19 |
---|
689 | 689 | | subdivision (a)(4) of this section; or 20 BILL AS INTRODUCED H.211 |
---|
690 | 690 | | 2025 Page 29 of 31 |
---|
691 | 691 | | |
---|
692 | 692 | | |
---|
693 | 693 | | VT LEG #378943 v.1 |
---|
694 | 694 | | (B) retention of the consumer’s brokered personal information is 1 |
---|
695 | 695 | | required by law; and 2 |
---|
696 | 696 | | (2) not sell or share new brokered personal information of the consumer 3 |
---|
697 | 697 | | unless the consumer expressly requests otherwise in writing; 4 |
---|
698 | 698 | | (d) Audits. 5 |
---|
699 | 699 | | (1) A data broker shall undergo an audit by an independent third party to 6 |
---|
700 | 700 | | determine compliance with this section at least once every three years, with the 7 |
---|
701 | 701 | | first audit taking place on or before December 31, 2030. 8 |
---|
702 | 702 | | (2) For an audit completed pursuant to subdivision (1) of this 9 |
---|
703 | 703 | | subsection, the data broker shall submit the report resulting from the audit and 10 |
---|
704 | 704 | | any related materials to the Secretary of State within five business days of a 11 |
---|
705 | 705 | | written request from the Secretary of State. 12 |
---|
706 | 706 | | (3) A data broker shall maintain all reports and materials resulting from 13 |
---|
707 | 707 | | audits conducted pursuant to this subsection for at least six years. 14 |
---|
708 | 708 | | (e) Rules. The Secretary of State may adopt rules to implement the 15 |
---|
709 | 709 | | provisions of this subchapter, except it shall not be permitted to create a rule 16 |
---|
710 | 710 | | that establishes a new fee that is not authorized in this section. 17 |
---|
711 | 711 | | (f) Penalties. 18 |
---|
712 | 712 | | (1) A data broker that fails to comply with the requirements of this 19 |
---|
713 | 713 | | section is liable to the State for: 20 BILL AS INTRODUCED H.211 |
---|
714 | 714 | | 2025 Page 30 of 31 |
---|
715 | 715 | | |
---|
716 | 716 | | |
---|
717 | 717 | | VT LEG #378943 v.1 |
---|
718 | 718 | | (A) an administrative fine of $200.00 per day for each deletion 1 |
---|
719 | 719 | | request the data broker fails to complete as required by subsection (b) of this 2 |
---|
720 | 720 | | section; and 3 |
---|
721 | 721 | | (B) reasonable expenses incurred by the State in the investigation and 4 |
---|
722 | 722 | | administration of the action. 5 |
---|
723 | 723 | | (2) All penalties, fines, fees, and expenses recovered in an action 6 |
---|
724 | 724 | | pursuant to subdivision (1) of this subsection shall be deposited in the Data 7 |
---|
725 | 725 | | Brokers Registry Fund. 8 |
---|
726 | 726 | | § 2446b. DATA BROKERS REGISTRY FUND 9 |
---|
727 | 727 | | There is established the Data Brokers Registry Fund within the State 10 |
---|
728 | 728 | | Treasury. The Fund shall be administered by the Secretary of State. All 11 |
---|
729 | 729 | | moneys collected or received by the Secretary of State and the Attorney 12 |
---|
730 | 730 | | General pursuant to this subchapter shall be deposited into the Fund and shall 13 |
---|
731 | 731 | | be made available for expenditure by the Secretary of State upon appropriation 14 |
---|
732 | 732 | | by the General Assembly to offset the following costs: 15 |
---|
733 | 733 | | (1) the reasonable costs of establishing and maintaining the 16 |
---|
734 | 734 | | informational website as set forth in subsection 2446(d) of this title; 17 |
---|
735 | 735 | | (2) the costs incurred by State courts and the Secretary of State in 18 |
---|
736 | 736 | | connection with enforcing this subchapter; and 19 BILL AS INTRODUCED H.211 |
---|
737 | 737 | | 2025 Page 31 of 31 |
---|
738 | 738 | | |
---|
739 | 739 | | |
---|
740 | 740 | | VT LEG #378943 v.1 |
---|
741 | 741 | | (3) the reasonable costs of establishing, maintaining, and providing 1 |
---|
742 | 742 | | access to the accessible deletion mechanism described in section 2446a of this 2 |
---|
743 | 743 | | title. 3 |
---|
744 | 744 | | § 2446c. CREDENTIALING 4 |
---|
745 | 745 | | (a) A data broker shall maintain reasonable procedures designed to ensure 5 |
---|
746 | 746 | | that the brokered personal information it discloses is used for a legitimate and 6 |
---|
747 | 747 | | legal purpose. 7 |
---|
748 | 748 | | (b) These procedures shall require that prospective users of the brokered 8 |
---|
749 | 749 | | information identify themselves, certify the purposes for which the information 9 |
---|
750 | 750 | | is sought, and certify that the information shall be used for no other purpose. 10 |
---|
751 | 751 | | (c) A data broker shall make a reasonable effort to verify the identity of a 11 |
---|
752 | 752 | | new prospective user and the uses certified by the prospective user prior to 12 |
---|
753 | 753 | | furnishing the user brokered personal information. 13 |
---|
754 | 754 | | (d) A data broker shall not furnish brokered personal information to any 14 |
---|
755 | 755 | | person if it has reasonable grounds for believing that the brokered personal 15 |
---|
756 | 756 | | information will not be used for a legitimate and legal purpose. 16 |
---|
757 | 757 | | § 2447. DATA BROKER DUTY TO PROTECT INFORMATION; 17 |
---|
758 | 758 | | STANDARDS; TECHNICAL REQUIREMENTS 18 |
---|
759 | 759 | | * * * 19 |
---|
760 | 760 | | Sec. 3. EFFECTIVE DATE 20 |
---|
761 | 761 | | This act shall take effect on July 1, 2025. 21 |
---|