惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
宝玉的分享
宝玉的分享
月光博客
月光博客
小众软件
小众软件
Jina AI
Jina AI
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
G
Google Developers Blog
M
MIT News - Artificial intelligence
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
MyScale Blog
MyScale Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
U
Unit 42
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Blog — PlanetScale
Blog — PlanetScale

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays
Vermont Enacts Significant Amendments to Data Broker Legi...
2026-06-22 · via Privacy & Cybersecurity Law Blog

On June 16, 2026, Vermont Governor Phil Scott signed into law House Bill H. 211 (“the Act”), which significantly amends Vermont’s existing data broker registration law by expanding compliance obligations, creating new consumer rights, enhancing registration requirements, adding data breach notification requirements, and strengthening enforcement and penalties for non-compliance.

Effective Date

Substantive provisions take effect January 1, 2027.

Expanded Scope

Updates to the definitions of “data broker,” “brokered personal information” and “sale” significantly expand the law’s reach, potentially subjecting businesses that previously did not consider themselves data brokers to its requirements.

  • Data Broker: The Act mirrors the California Delete Act in specifying that a data broker is a business that does not have a “direct relationship” with a consumer and defining the term to mean that a consumer “has intentionally interacted with a business for the purpose of accessing, purchasing, using, requesting, or obtaining information about the business’s products or services.” Additionally, the Act specifies that even if a business has a direct relationship with consumers, the business is still a data broker with respect to the brokered personal information the business sells about the consumer that it “collected outside of a first-party interaction with the consumer.”
  • Brokered Personal Information: The Act significantly broadens the definition of “brokered personal information,” replacing a specific list of data elements with a much broader definition aligned with the definition of “personal information” under many state consumer privacy laws. “Brokered personal information” means “any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or to a device that identifies, is linked to, or is reasonably linkable to one or more identified or identifiable individuals in a household.”
  • Sale: The Act introduces a new definition of “sale” that aligns with the approach taken in most comprehensive state consumer privacy laws, defining the term as the disclosure of brokered personal information to a third party in exchange for “monetary or other valuable consideration.” Consistent with those laws, the definition excludes certain disclosures, including transfers to processors and affiliates, as well as other specified exemptions.

Expanded Data Broker Registration and Disclosure Requirements

The Act significantly expands Vermont’s data broker registration regime. Data brokers must register with the state, pay an increased annual registration fee of $900, maintain a $20,000 surety bond, and provide detailed disclosures about their data collection, sharing and sales practices. Required disclosures include whether the broker collects sensitive categories of data (such as precise geolocation, biometric, reproductive health, immigration or government-issued identification information), shares data with government entities, foreign actors, law enforcement or generative AI developers, and maintains information about minors. Data brokers must also provide information about consumer opt-out and deletion rights, submit copies of their privacy policies and bonds, and report security breaches experienced during the prior year.

New Purchaser Credentialing Procedures

The Act requires data brokers to implement procedures ensuring that prospective users of brokered personal information identify themselves, disclose the purposes for which the information will be used and certify that the information will not be used for any other purposes. The Act also prohibits data brokers from disclosing brokered personal information to prospective users if the data broker has reasonable grounds for believing the information will be used for contrary purposes.

New Data Broker Security Breach Notification Requirements

The Act imposes new data breach notification obligations for the breach of brokered personal information. Following such breach, data brokers generally must notify affected consumers within 45 days and provide prompt notice to the Vermont Attorney General. Consumer notices must include key details about the incident, the categories of information involved, and steps consumers can take to protect themselves. The Act also establishes detailed requirements governing the timing, content, and method of breach notifications.

New Consumer Deletion Right

The Act creates a new right for consumers to request deletion of their brokered personal information. The Act requires each data broker to provide a dedicated webpage through which consumers can request deletion of their brokered personal information. Unlike the California Delete Act and other recently proposed state initiatives, the Act does not establish a centralized deletion mechanism; consumers must submit requests directly to individual data brokers. However, the Act does require the Vermont Secretary of State to conduct a feasibility study into the creation of a centralized single data broker deletion mechanism.

Data brokers generally must process valid deletion requests within 30 days and provide an appeals process for denied requests. While the law includes exceptions for legal compliance, fraud prevention, security, and other specified purposes, retained data must be segregated and cannot be used for unrelated activities.

Enhanced Enforcement and Penalties

The Act significantly strengthens enforcement of Vermont’s data broker registration requirements. Data brokers that fail to register may face administrative fines of $200 per day, in addition to unpaid registration fees and the state’s enforcement costs. The law also imposes substantial penalties for incomplete or inaccurate registration filings, including fines of $1,000 per day for failing to correct omitted information and a $25,000 penalty for submitting materially incorrect information, plus additional daily penalties if corrections are not timely made.