Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Consumer Data Privacy topic

No spam. Unsubscribe anytime.

Vermont Senate committee hears mixed testimony on S71 (data privacy); witnesses back model tied to neighboring states, oppose private right of action

2643340 · March 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Three witnesses told the Senate Committee on Institutions on March 14 that Vermont should adopt a data-privacy law aligned with neighboring states, set thresholds to avoid ensnaring small businesses and nonprofits, and avoid a private right of action; witnesses also raised HIPAA overlap and record-count questions.

The Senate Committee on Institutions heard testimony March 14 on S71, an act relating to consumer data privacy and online surveillance, with witnesses urging lawmakers to adopt a law that mirrors neighboring states, set higher thresholds so small Vermont businesses and nonprofits are not swept in, and avoid creating a private right of action.

Robbie Adler, cofounder and chief strategy officer of Faraday, told the committee that Faraday — a 12-year-old Waterbury-based company with about 25 employees in Vermont — supports passage of state privacy law but urges Vermont to align with laws in Connecticut and New Hampshire rather than pursue novel provisions. "I do want to very clearly state I am in favor of Vermont passing a data privacy law," Adler said, adding that the company operates as a data processor and already spends significant legal and compliance resources to follow state laws where its clients operate.

Adler said a private right of action (PRA) would increase liability costs for businesses and insurers and would not clearly improve privacy protections for Vermonters. "A PRA would have immediate impacts on businesses, via increased insurance costs tied to increased liability," he said. Adler said Faraday has paid substantial legal fees to comply with earlier state laws and recommended Vermont adopt a threshold of 100,000 resident consumers rather than lower triggers that could ensnare small businesses doing routine digital activity.

Mary Hayden, executive director of the Vermont Association of Area Agencies on Aging, said the five area agencies on aging — which provide meals, case management and other services to older Vermonters and some disabled adults — already apply HIPAA-level protections across client records and are not data brokers. "We are not a data broker. We provide free services. We are not for profit," Hayden said. She warned that adding a separate layer of state compliance on top of HIPAA could be administratively and financially burdensome for smaller nonprofit agencies that lack dedicated compliance officers.

Hayden told senators the area agencies served over 40,000 people last year and that many agency programs are funded by Medicaid and the Older Americans Act. She urged the committee to consider outreach and education for nonprofits and small providers if the Legislature moves forward. Hayden asked the committee to clarify how records-retention accounting would affect threshold calculations for covered entities.

Nathaniel White Joy Au, president of Scout Digital, a Burlington-based digital marketing agency, said targeted online marketing is essential for small Vermont businesses and that low thresholds or a PRA could threaten their viability. "If we're giving people a private right to action and allowing ... muddy waters downtown, in Burlington to be sued by just anybody, it really is — they're just not going to survive," Au said. He supported a threshold near 100,000 residents and said that a 25,000-person trigger would not provide sufficient sample sizes for marketers to build a viable customer funnel.

Committee members asked witnesses about technical roles and compliance arrangements. Adler confirmed Faraday contracts with clients and uses data processing agreements to govern how client data is handled. Hayden said most area agencies treat their entire client record set to HIPAA standards and that only the largest agency employs a dedicated compliance officer; the others spread privacy duties across existing staff. Hayden and Au offered to provide written testimony and to participate in outreach or technical working groups.

The witnesses repeatedly urged lawmakers to avoid unique or novel state requirements that diverge from the approaches taken in Connecticut and New Hampshire, and to rely on the attorney general to enforce the law rather than creating a broad private right of action that could increase litigation risk for small businesses and nonprofits.

The committee did not take a formal vote during the portion of the hearing in this transcript and asked witnesses to submit written testimony for the record. Senators present clarified they intended to hold a possible committee vote before crossover deadline later that day.

Looking ahead, witnesses recommended that, if the Legislature adopts a privacy law, it include clear thresholds tied to population counts, explicit treatment of processors versus controllers, guidance on records-retention counting for threshold purposes, and state-provided education and outreach to aid compliance among small providers and nonprofits.