Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Committee reviews S.71/S.93 data privacy bill: consumer rights, controller duties and AG enforcement outlined

2777085 · March 26, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislative counsel reviewed S.71 (with S.93 language) and described a Connecticut‑style data privacy framework that would give Vermont residents rights over personal data, require data protection assessments for high‑risk processing and assign primary civil enforcement to the Attorney General.

Legislative counsel and committee members reviewed S.71 (with S.93 language) in a detailed briefing that covered definitions, applicability thresholds, exemptions, consumers’ rights, duties for controllers and processors, data protection assessments and the Attorney General’s enforcement role.

"Consent means a clear affirmative act signifying the consumer's freely given, specific, informed, and unambiguous agreement to allow the processing of personal data," the legislative counsel said while reviewing the bill’s definitions and consent standard.

What the bill would do - Definitions and sensitive categories: Counsel walked through key definitions — biometric data, consumer health data, sensitive personal data (race, religion, health, sexual orientation, precise geolocation), de‑identified data and publicly available information — that shape the bill’s scope. - Applicability thresholds: The bill would generally apply to controllers that during the preceding calendar year processed the personal data of 100,000 Vermont residents or processed the data of at least 25,000 residents and derived more than 25% of gross revenue from selling personal data. The consumer‑health data controller category was described as having a lower threshold (the consumer health provisions can apply at much smaller scales). - Exemptions: The draft exempts public agencies, certain federally regulated financial institutions (GLBA coverage), HIPAA‑protected health information, FERPA (education) contexts, accredited research under protections, tribes, air carriers and several other narrowly defined categories — many of which mirror exemptions in other states’ laws. - Consumer rights: The bill would give Vermont residents the right to confirm processing, correct inaccuracies, obtain deletion, obtain a portable copy and opt out of targeted advertising and the sale of personal data. The draft also bars discrimination for exercising rights (with limited exceptions tied to product/service needs). - Controller and processor duties: Controllers would be required to limit collection to adequate, relevant and necessary data for a disclosed purpose; to implement reasonable administrative, technical and physical safeguards; to provide clear privacy notices; and to contractually bind processors. Processors must adhere to controller instructions and assist with controller obligations. - Data protection assessments: Controllers must document data protection assessments for processing that presents a heightened risk (targeted advertising, profiling, sensitive data processing and sales) and provide those assessments to the Attorney General on request. Assessments are exempt from public records disclosure to protect confidential material. - Enforcement: The Attorney General would have exclusive civil enforcement authority under the bill. The AG is required to issue a notice of violation and, during an initial transition period (through the end of 2026), provide a 60‑day cure period if the AG determines the violation is curable. The AG must weigh factors such as size of the controller, sensitivity of data and the public risk when deciding enforcement steps.

Consumer health data The draft imposes stricter requirements on controllers of consumer health data: it forbids sale without explicit consent, requires contractual confidentiality for employees and contractors who access the data, and includes geofencing restrictions tied specifically to consumer health data uses.

Committee questions and concerns Members asked about the scope of exemptions (for example, whether for‑profit colleges or certain financial entities would be covered), the impact on small businesses and implementation costs, whether Agency of Digital Services (ADS) should be involved, and how the bill interacts with federal law (HIPAA, GLBA, COPPA). The committee discussed regional consistency (the bill tracks Connecticut’s law in several places) and asked for more technical guidance on how consumers will exercise rights (in‑app controls, account settings, or preference signals).

Votes and procedural action - Committee members moved to register support for S.71 as amended by the institutions committee on the floor. The transcript records the motion being made and a subsequent voice poll; some senators raised reservations and at least one senator said he would vote no in committee on procedural grounds while planning to support the bill on the floor. The transcript does not record a detailed roll‑call tally of that committee motion.

Next steps and follow up Committee members asked that more technical implementation details be developed (consumer opt‑out mechanisms, ADS involvement, transitions for controllers/processors) and flagged the need for continued engagement during any conference committee. The Attorney General’s office and digital services staff were identified as likely follow‑up participants for drafting and implementation guidance.