1 | 1 | | BILL AS INTRODUCED H.360 |
---|
2 | 2 | | 2025 Page 1 of 9 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | VT LEG #380622 v.1 |
---|
6 | 6 | | H.360 1 |
---|
7 | 7 | | Introduced by Representatives Priestley of Bradford, Arsenault of Williston, 2 |
---|
8 | 8 | | Berbeco of Winooski, Cina of Burlington, Cole of Hartford, 3 |
---|
9 | 9 | | Logan of Burlington, Masland of Thetford, McGill of Bridport, 4 |
---|
10 | 10 | | and White of Bethel 5 |
---|
11 | 11 | | Referred to Committee on 6 |
---|
12 | 12 | | Date: 7 |
---|
13 | 13 | | Subject: Motor vehicles; Department of Motor Vehicles; operator’s licenses; 8 |
---|
14 | 14 | | mobile identification; privacy 9 |
---|
15 | 15 | | Statement of purpose of bill as introduced: This bill proposes to establish 10 |
---|
16 | 16 | | specific requirements to protect the privacy of individuals who use mobile 11 |
---|
17 | 17 | | identification. 12 |
---|
18 | 18 | | An act relating to privacy protections for mobile identification 13 |
---|
19 | 19 | | It is hereby enacted by the General Assembly of the State of Vermont: 14 |
---|
20 | 20 | | Sec. 1. 23 V.S.A § 116 is amended to read: 15 |
---|
21 | 21 | | § 116. ISSUANCE OF MOBILE IDENTIFICATION 16 |
---|
22 | 22 | | (a) Definitions. As used in this section: 17 |
---|
23 | 23 | | (1) “Attribute authentication” means the verification of a specific quality 18 |
---|
24 | 24 | | of a data field on a mobile identification without revealing the underlying data 19 |
---|
25 | 25 | | in that field. Attribute authentication includes verifying that a mobile 20 BILL AS INTRODUCED H.360 |
---|
26 | 26 | | 2025 Page 2 of 9 |
---|
27 | 27 | | |
---|
28 | 28 | | |
---|
29 | 29 | | VT LEG #380622 v.1 |
---|
30 | 30 | | identification holder is legally permitted to purchase an age-restricted item 1 |
---|
31 | 31 | | without revealing the holder’s date of birth or actual age. 2 |
---|
32 | 32 | | (2) “Data field” means a discrete piece of information that appears on a 3 |
---|
33 | 33 | | mobile identification. 4 |
---|
34 | 34 | | (2)(3) “Full profile” means all the information provided on a mobile 5 |
---|
35 | 35 | | identification. 6 |
---|
36 | 36 | | (3)(4) “Limited profile” means a portion of the information provided on 7 |
---|
37 | 37 | | a mobile identification. 8 |
---|
38 | 38 | | (4)(5) “Mobile identification” means an electronic representation of the 9 |
---|
39 | 39 | | information contained on a nonmobile credential. 10 |
---|
40 | 40 | | (5)(6) “Mobile identification holder” means an individual to whom a 11 |
---|
41 | 41 | | mobile identification has been issued. 12 |
---|
42 | 42 | | (6)(7) “Nonmobile credential” means a nondriver identification card 13 |
---|
43 | 43 | | issued under section 115 of this title, a driver’s license issued under section 14 |
---|
44 | 44 | | 603 of this title, a junior operator’s license issued under section 602 of this 15 |
---|
45 | 45 | | title, a learner’s permit issued under section 617 of this title, a commercial 16 |
---|
46 | 46 | | driver’s license issued under section 4111 of this title, or a commercial 17 |
---|
47 | 47 | | learner’s permit issued under section 4112 of this title. 18 |
---|
48 | 48 | | (8) “Selective disclosure” means the disclosure through a verification 19 |
---|
49 | 49 | | system of only certain data fields from a mobile identification that are 20 BILL AS INTRODUCED H.360 |
---|
50 | 50 | | 2025 Page 3 of 9 |
---|
51 | 51 | | |
---|
52 | 52 | | |
---|
53 | 53 | | VT LEG #380622 v.1 |
---|
54 | 54 | | reasonably necessary for the purposes of the verification and the ability of the 1 |
---|
55 | 55 | | mobile identification holder to determine which data fields are disclosed. 2 |
---|
56 | 56 | | (b) Issuance. The Commissioner of Motor Vehicles may issue a mobile 3 |
---|
57 | 57 | | identification to an individual in addition to, and not instead of, a nonmobile 4 |
---|
58 | 58 | | credential. If issued, the mobile identification shall: 5 |
---|
59 | 59 | | (1) be capable of producing both a full profile and a limited profile; 6 |
---|
60 | 60 | | (2) satisfy the purpose for which the profile is presented; 7 |
---|
61 | 61 | | (3) allow the mobile identification holder to maintain physical 8 |
---|
62 | 62 | | possession of the device on which the mobile identification is accessed during 9 |
---|
63 | 63 | | verification; and 10 |
---|
64 | 64 | | (4) not be a substitute for an individual producing a nonmobile 11 |
---|
65 | 65 | | credential upon request. 12 |
---|
66 | 66 | | * * * 13 |
---|
67 | 67 | | (d) Administration. 14 |
---|
68 | 68 | | (1) The Commissioner may operate, or may operate through a third- 15 |
---|
69 | 69 | | party administrator, a verification system for mobile identifications. 16 |
---|
70 | 70 | | (2) Access to the verification system and any data field by a person 17 |
---|
71 | 71 | | presented with a mobile identification requires the credential mobile 18 |
---|
72 | 72 | | identification holder’s consent, and, if consent is granted, the Commissioner 19 |
---|
73 | 73 | | may release the following through the verification system: 20 BILL AS INTRODUCED H.360 |
---|
74 | 74 | | 2025 Page 4 of 9 |
---|
75 | 75 | | |
---|
76 | 76 | | |
---|
77 | 77 | | VT LEG #380622 v.1 |
---|
78 | 78 | | (A) for a full profile, all data fields that appear on the mobile 1 |
---|
79 | 79 | | identification; and 2 |
---|
80 | 80 | | (B) for a limited profile, only the data fields represented in the 3 |
---|
81 | 81 | | limited profile for appearing on the mobile identification that the mobile 4 |
---|
82 | 82 | | identification holder has consented to have released. 5 |
---|
83 | 83 | | (3) The Commissioner shall ensure that any verification system for 6 |
---|
84 | 84 | | mobile identifications meets the following requirements: 7 |
---|
85 | 85 | | (A) The verification system does not incentivize or require a person 8 |
---|
86 | 86 | | using the verification system to take possession of a mobile identification 9 |
---|
87 | 87 | | holder’s device while accessing data from the mobile identification. 10 |
---|
88 | 88 | | (B) The verification system does not share or retain any information 11 |
---|
89 | 89 | | regarding the persons that have accessed data from a particular mobile 12 |
---|
90 | 90 | | identification or the locations at which data from a particular mobile 13 |
---|
91 | 91 | | identification has been accessed. 14 |
---|
92 | 92 | | (C) The verification system requires attribute authentication or 15 |
---|
93 | 93 | | selective disclosure in all instances when access to a full profile is not 16 |
---|
94 | 94 | | reasonably necessary. The verification system shall ensure that the data fields 17 |
---|
95 | 95 | | being requested are first disclosed to the mobile identification holder and that 18 |
---|
96 | 96 | | the mobile identification holder may determine which data fields are released 19 |
---|
97 | 97 | | to the person requesting the data. 20 BILL AS INTRODUCED H.360 |
---|
98 | 98 | | 2025 Page 5 of 9 |
---|
99 | 99 | | |
---|
100 | 100 | | |
---|
101 | 101 | | VT LEG #380622 v.1 |
---|
102 | 102 | | (D) The verification system utilizes techniques, methodologies, or 1 |
---|
103 | 103 | | processes that ensure that data obtained from a mobile identification, including 2 |
---|
104 | 104 | | the fact that the verification system was accessed in relation to a specific 3 |
---|
105 | 105 | | mobile identification, cannot be linked together by one or more persons who 4 |
---|
106 | 106 | | access the verification system. 5 |
---|
107 | 107 | | (4)(A) The Commissioner shall adopt standards relating to: 6 |
---|
108 | 108 | | (i) security and communications requirements for devices on 7 |
---|
109 | 109 | | which mobile identifications are stored; 8 |
---|
110 | 110 | | (ii) procedures for requesting and accessing data from mobile 9 |
---|
111 | 111 | | identifications through the verification system; 10 |
---|
112 | 112 | | (iii) minimum requirements for the identification and 11 |
---|
113 | 113 | | authentication of the mobile identification holder prior to obtaining the 12 |
---|
114 | 114 | | identification holder’s consent to the disclosure of data fields on the mobile 13 |
---|
115 | 115 | | identification; and 14 |
---|
116 | 116 | | (iv) requirements providing for the storage of information 15 |
---|
117 | 117 | | regarding what data was requested and accessed from a mobile identification, 16 |
---|
118 | 118 | | which shall only be available to the mobile identification holder and may be 17 |
---|
119 | 119 | | retained or destroyed at the mobile identification holder’s discretion. 18 |
---|
120 | 120 | | (B) The standards, to the extent practicable, shall be based on widely 19 |
---|
121 | 121 | | accepted and publicly available national or international standards. 20 |
---|
122 | 122 | | (e) Privacy protections. 21 BILL AS INTRODUCED H.360 |
---|
123 | 123 | | 2025 Page 6 of 9 |
---|
124 | 124 | | |
---|
125 | 125 | | |
---|
126 | 126 | | VT LEG #380622 v.1 |
---|
127 | 127 | | (1) The verification system and mobile identifications shall not permit 1 |
---|
128 | 128 | | the Department or any State entity to obtain control over the device on which a 2 |
---|
129 | 129 | | mobile identification is stored or to deactivate a mobile identification stored on 3 |
---|
130 | 130 | | a mobile identification holder’s device. 4 |
---|
131 | 131 | | (2) A law enforcement officer shall not take physical possession of the 5 |
---|
132 | 132 | | device on which a mobile identification holder’s mobile identification is 6 |
---|
133 | 133 | | accessed for the purpose of accessing the mobile identification or verifying the 7 |
---|
134 | 134 | | mobile identification holder’s identity. 8 |
---|
135 | 135 | | (3) No person shall request more data from a mobile identification than 9 |
---|
136 | 136 | | is reasonably necessary to determine that the mobile identification holder 10 |
---|
137 | 137 | | meets the legal requirements to enter into the transaction with the person 11 |
---|
138 | 138 | | requesting the data. 12 |
---|
139 | 139 | | (4) No digital services provider, application developer, or administrator 13 |
---|
140 | 140 | | or operator of the verification system shall access, collect, retain, share, or use 14 |
---|
141 | 141 | | data from a mobile identification or data about the use of a mobile 15 |
---|
142 | 142 | | identification, except as necessary to comply with applicable State and federal 16 |
---|
143 | 143 | | law. 17 |
---|
144 | 144 | | (f) Right to choose whether to use mobile identification. 18 |
---|
145 | 145 | | (1) No person shall condition the offer or use of a good or service on 19 |
---|
146 | 146 | | access to an individual’s mobile identification or nonmobile credential except 20 |
---|
147 | 147 | | if: 21 BILL AS INTRODUCED H.360 |
---|
148 | 148 | | 2025 Page 7 of 9 |
---|
149 | 149 | | |
---|
150 | 150 | | |
---|
151 | 151 | | VT LEG #380622 v.1 |
---|
152 | 152 | | (A) the transaction requires proof of age, identity, residency, or 1 |
---|
153 | 153 | | another characteristic pursuant to State or federal law; 2 |
---|
154 | 154 | | (B) the identification or credential is requested in relation to financial 3 |
---|
155 | 155 | | or banking services to ensure that accounts, funds, financial instruments, or 4 |
---|
156 | 156 | | personally identifiable information or financial data is not accessed by an 5 |
---|
157 | 157 | | unauthorized person; or 6 |
---|
158 | 158 | | (C) the identification or credential is requested in relation to medical 7 |
---|
159 | 159 | | services to ensure that goods, services, or private medical information are not 8 |
---|
160 | 160 | | provided to an unauthorized person. 9 |
---|
161 | 161 | | (2) No person shall charge different prices or rates for goods or services, 10 |
---|
162 | 162 | | provide different treatment or quality of goods or services, or condition access 11 |
---|
163 | 163 | | or entry to a location based on whether an individual presents mobile 12 |
---|
164 | 164 | | identification or an appropriate nonmobile credential, unless the use of mobile 13 |
---|
165 | 165 | | identification or an appropriate nonmobile credential is necessary for 14 |
---|
166 | 166 | | conducting a remote transaction or due to circumstances beyond the person’s 15 |
---|
167 | 167 | | control that prevent the person from accessing the verification system. 16 |
---|
168 | 168 | | (g) Enforcement. 17 |
---|
169 | 169 | | (1) The Attorney General or a State’s Attorney may bring an action 18 |
---|
170 | 170 | | against a private entity to enforce the provisions of this section by restraining 19 |
---|
171 | 171 | | prohibited acts, seeking civil penalties, obtaining assurances of discontinuance, 20 |
---|
172 | 172 | | and conducting civil investigations in accordance with the procedures 21 BILL AS INTRODUCED H.360 |
---|
173 | 173 | | 2025 Page 8 of 9 |
---|
174 | 174 | | |
---|
175 | 175 | | |
---|
176 | 176 | | VT LEG #380622 v.1 |
---|
177 | 177 | | established in 9 V.S.A. §§ 2458–2461 as though a violation of the provisions 1 |
---|
178 | 178 | | of this section is an unfair act in commerce. Any person complained against 2 |
---|
179 | 179 | | shall have the same rights and remedies as specified in 9 V.S.A. §§ 2458–3 |
---|
180 | 180 | | 2461. The Superior Courts are authorized to impose the same civil penalties 4 |
---|
181 | 181 | | and investigation costs and to order other relief to the State of Vermont or an 5 |
---|
182 | 182 | | aggrieved individual for violations of this section as they are authorized to 6 |
---|
183 | 183 | | impose or order under the provisions of 9 V.S.A. §§ 2458 and 2461 in an 7 |
---|
184 | 184 | | unfair act in commerce. 8 |
---|
185 | 185 | | (2) An individual who has been aggrieved by a violation of the 9 |
---|
186 | 186 | | provisions of this section may bring a civil action in the Superior Court 10 |
---|
187 | 187 | | seeking: 11 |
---|
188 | 188 | | (A) damages equal to: 12 |
---|
189 | 189 | | (i) for a negligent violation of the provisions of this section, 13 |
---|
190 | 190 | | $2,500.00 or the amount of actual damages, whichever is greater; and 14 |
---|
191 | 191 | | (ii) for an intentional violation of the provisions of this section, 15 |
---|
192 | 192 | | $5,000.00 or the amount of actual damages, whichever is greater; 16 |
---|
193 | 193 | | (B) restraint of prohibited acts; 17 |
---|
194 | 194 | | (C) reasonable attorney’s fees and costs; and 18 |
---|
195 | 195 | | (D) other appropriate relief. 19 |
---|
196 | 196 | | (3) For purposes of enforcing the provisions of this section, a repeated 20 |
---|
197 | 197 | | violation of the provisions of this section by the same person through identical 21 BILL AS INTRODUCED H.360 |
---|
198 | 198 | | 2025 Page 9 of 9 |
---|
199 | 199 | | |
---|
200 | 200 | | |
---|
201 | 201 | | VT LEG #380622 v.1 |
---|
202 | 202 | | use of the same individual’s mobile identification prior to enforcement under 1 |
---|
203 | 203 | | the provisions of this subsection shall not constitute separate violations of the 2 |
---|
204 | 204 | | provisions of this section. 3 |
---|
205 | 205 | | Sec. 2. EFFECTIVE DATE 4 |
---|
206 | 206 | | This act shall take effect on July 1, 2025. 5 |
---|