惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
B
Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
S
SegmentFault 最新的问题
腾讯CDC
博客园 - 叶小钗
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
Jina AI
Jina AI
A
About on SuperTechFans
博客园 - 司徒正美
C
Check Point Blog
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
T
Tenable Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
小众软件
小众软件
Spread Privacy
Spread Privacy
阮一峰的网络日志
阮一峰的网络日志
Know Your Adversary
Know Your Adversary
NISL@THU
NISL@THU
K
Kaspersky official blog
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
D
DataBreaches.Net
A
Arctic Wolf
I
InfoQ
量子位
IT之家
IT之家
Security Latest
Security Latest
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Google DeepMind News
Google DeepMind News
The Hacker News
The Hacker News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
Google Developers Blog
P
Proofpoint News Feed
P
Privacy International News Feed
T
Threatpost
L
Lohrmann on Cybersecurity
P
Proofpoint News Feed
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
Martin Fowler
Martin Fowler
C
Cyber Attacks, Cyber Crime and Cyber Security
PCI Perspectives
PCI Perspectives
F
Full Disclosure

Privacy & Cybersecurity Law Blog

Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure U.S. Supreme Court FTC Ruling Prompts Fresh Scrutiny of EU-U.S. Data Privacy Framework China Issues New Measures for Network Data Security Risk Assessment China Issues Regulations on Internet Content Multi-Channel Network Distribution Services China’s First Regulatory Framework for Virtual Companions Soon to Take Effect UK Data Protection Complaints Obligations Take Effect Vermont Becomes 23rd State with Comprehensive Consumer Privacy Law Louisiana Enacts Comprehensive Consumer Privacy Law Connecticut Signs Comprehensive AI Bill into Law China CAC Issues Guidance on Conducting Audits Technology Companies Should Prepare for FTC Enforcement of Take It Down Act HHS Reorganizes Office for Civil Rights Oregon Prohibition on Public Body Disclosures to Data Brokers for Federal Immigration Purposes Now In Effect Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations NYDFS Warns of Cybersecurity Risks from Frontier AI Models UK and Australia Announce Memorandum of Understanding on AI Security FTC Announces Settlements With Three Marketing Firms Over Allegations of Deceptive Statements About Active Listening AI-Powered Services Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems Colorado AI Act Amended and Effective Date Delayed European Commission Releases Draft Guidelines on High-Risk AI Under the EU AI Act Texas AG Announces Lawsuit Against Netflix for Alleged Misrepresentations Regarding User Data UK ICO Recommends Targeted Changes to PECR Rules for Online Advertising California AG Announces Record $12.75M Settlement with GM over CCPA Data Minimization and Purpose Limitation Violations Illinois Department of Human Rights Issues Regulations Governing the Use of AI in Employment Decisions Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response Maryland Enacts First-of-its-Kind Ban on Surveillance Pricing for Grocery Sales UK ICO Publishes Guidance on Storage and Access Technologies CIPL Report Discusses Significant Alignment between GDPR and Global CBPR CalPrivacy Announces the Agenda for its April 30–May 1 Board Meeting CalPrivacy Requests Preliminary Comments on Notices & Disclosures, Employee Data COPPA Rule Amendment Compliance Deadline Approaches House Republicans Introduce Comprehensive Federal Privacy Bill: “SECURE Data Act” Kentucky Classifies Smart TV Data as Sensitive Alabama Becomes 21st State With Comprehensive Consumer Privacy Law CalPrivacy Director Expects CCPA Compliance Audits in 2026 Virginia Bans Sale of Geolocation Data HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data Washington State Enacts Law Regulating AI Companion Chatbots with Private Right of Action Guardrails for Legal AI: What California’s SB 574 Would Require of Attorneys and Arbitrators
Vermont Enacts Significant Amendments to Data Broker Legislation
2026-06-22 · via Privacy & Cybersecurity Law Blog

On June 16, 2026, Vermont Governor Phil Scott signed into law House Bill H. 211 (“the Act”), which significantly amends Vermont’s existing data broker registration law by expanding compliance obligations, creating new consumer rights, enhancing registration requirements, adding data breach notification requirements, and strengthening enforcement and penalties for non-compliance.

Effective Date

Substantive provisions take effect January 1, 2027.

Expanded Scope

Updates to the definitions of “data broker,” “brokered personal information” and “sale” significantly expand the law’s reach, potentially subjecting businesses that previously did not consider themselves data brokers to its requirements.

  • Data Broker: The Act mirrors the California Delete Act in specifying that a data broker is a business that does not have a “direct relationship” with a consumer and defining the term to mean that a consumer “has intentionally interacted with a business for the purpose of accessing, purchasing, using, requesting, or obtaining information about the business’s products or services.” Additionally, the Act specifies that even if a business has a direct relationship with consumers, the business is still a data broker with respect to the brokered personal information the business sells about the consumer that it “collected outside of a first-party interaction with the consumer.”
  • Brokered Personal Information: The Act significantly broadens the definition of “brokered personal information,” replacing a specific list of data elements with a much broader definition aligned with the definition of “personal information” under many state consumer privacy laws. “Brokered personal information” means “any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or to a device that identifies, is linked to, or is reasonably linkable to one or more identified or identifiable individuals in a household.”
  • Sale: The Act introduces a new definition of “sale” that aligns with the approach taken in most comprehensive state consumer privacy laws, defining the term as the disclosure of brokered personal information to a third party in exchange for “monetary or other valuable consideration.” Consistent with those laws, the definition excludes certain disclosures, including transfers to processors and affiliates, as well as other specified exemptions.

Expanded Data Broker Registration and Disclosure Requirements

The Act significantly expands Vermont’s data broker registration regime. Data brokers must register with the state, pay an increased annual registration fee of $900, maintain a $20,000 surety bond, and provide detailed disclosures about their data collection, sharing and sales practices. Required disclosures include whether the broker collects sensitive categories of data (such as precise geolocation, biometric, reproductive health, immigration or government-issued identification information), shares data with government entities, foreign actors, law enforcement or generative AI developers, and maintains information about minors. Data brokers must also provide information about consumer opt-out and deletion rights, submit copies of their privacy policies and bonds, and report security breaches experienced during the prior year.

New Purchaser Credentialing Procedures

The Act requires data brokers to implement procedures ensuring that prospective users of brokered personal information identify themselves, disclose the purposes for which the information will be used and certify that the information will not be used for any other purposes. The Act also prohibits data brokers from disclosing brokered personal information to prospective users if the data broker has reasonable grounds for believing the information will be used for contrary purposes.

New Data Broker Security Breach Notification Requirements

The Act imposes new data breach notification obligations for the breach of brokered personal information. Following such breach, data brokers generally must notify affected consumers within 45 days and provide prompt notice to the Vermont Attorney General. Consumer notices must include key details about the incident, the categories of information involved, and steps consumers can take to protect themselves. The Act also establishes detailed requirements governing the timing, content, and method of breach notifications.

New Consumer Deletion Right

The Act creates a new right for consumers to request deletion of their brokered personal information. The Act requires each data broker to provide a dedicated webpage through which consumers can request deletion of their brokered personal information. Unlike the California Delete Act and other recently proposed state initiatives, the Act does not establish a centralized deletion mechanism; consumers must submit requests directly to individual data brokers. However, the Act does require the Vermont Secretary of State to conduct a feasibility study into the creation of a centralized single data broker deletion mechanism.

Data brokers generally must process valid deletion requests within 30 days and provide an appeals process for denied requests. While the law includes exceptions for legal compliance, fraud prevention, security, and other specified purposes, retained data must be segregated and cannot be used for unrelated activities.

Enhanced Enforcement and Penalties

The Act significantly strengthens enforcement of Vermont’s data broker registration requirements. Data brokers that fail to register may face administrative fines of $200 per day, in addition to unpaid registration fees and the state’s enforcement costs. The law also imposes substantial penalties for incomplete or inaccurate registration filings, including fines of $1,000 per day for failing to correct omitted information and a $25,000 penalty for submitting materially incorrect information, plus additional daily penalties if corrections are not timely made.