Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy Data Brokers topic

No spam. Unsubscribe anytime.

Vermont committee hears split testimony on H.342 data‑broker removal rules, experts urge narrower ‘Daniel’s law’ approach

2601414 · March 13, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Members of the Vermont House Committee on Commerce & Economic Development heard two hours of testimony March 13 on H.342, a bill that would let people petition data brokers and other holders of searchable databases to remove protected personal information.

Members of the Vermont House Committee on Commerce & Economic Development heard two hours of testimony March 13 on H.342, a bill that would let people petition data brokers and other holders of searchable databases to remove protected personal information.

Richard Varn, executive director of the Coalition for Sensible Public Records Access and a former Iowa state chief information officer, told the committee that the bill’s current language is “very broad” and could require removal of identifiers used for routine identity verification. “Redaction of a employee address is an ineffective response and amounts to security theater while doing real harm to the many beneficial uses of public records and public oversight,” Varn said. He urged the panel to consider narrower statutory designs used in other states, commonly called Daniel’s laws, and to pair those with operational threat‑management measures.

The testimony came as state lawmakers weigh how to balance the privacy and safety concerns of judges, law enforcement officers and other public employees against public access and commercial uses of data. Varn warned that H.342 as drafted could unintentionally disable systems that rely on unique identifiers for things such as auto safety recalls and fraud prevention, and he recommended exemptions patterned on existing federal laws like the Drivers Privacy Protection Act.

Varn told the committee the draft’s definitions would treat information as “disclosed” if it appears in any searchable database, and he said that interaction of definitions could be interpreted to require removal rather than merely halting future disclosure. “If it is present in a searchable database at all, it qualifies as being disclosed,” he said, adding that the bill’s current timing and authorization language could block later, legitimate identity‑verification transactions.

Committee members pressed Varn on alternatives. He recommended a three‑part strategy that separates (1) measures to obscure easily accessible public website listings, (2) criminal and civil approaches targeted at malicious “doxing” actors, and (3) compliance and auditing tools to find and punish bad actors. He proposed technical and administrative compliance tools — for example, secure, standardized electronic request forms, “salting” audits to detect improper disclosures, and administrative audits before private lawsuits — rather than relying first on a broad private right of action. “I just think this balancing test is out of whack when the first thing you do is let everybody sue each other,” Varn said.

Jeff Jokush, CXO of Obscure IQ, described the scale and industrial character of the data‑broker market and said H.342 is a needed response to threats he and clients face. “Through our work, we track over 8,600 organizations who are engaged in data collection, brokerage, mapping,” Jokush said, and he argued that the marketplace today routes personal data widely and that breaches and resale make sensitive information widely available to bad actors. “The reality today is pretty stark. Personal information has become a weapon,” Jokush said, and he recommended stricter regulation of broker activity and registry requirements to make the industry more transparent.

Witnesses and committee members also discussed operational details that would affect businesses and consumers. The draft includes a 10‑business‑day response window; witnesses urged clear technical standards for authenticated requests and secure delivery (for example, registered electronic addresses, standardized request payloads) so companies are given actionable requests rather than poorly formed mass submissions. Varn said that properly structured procedures and exemptions — for example, for the Drivers Privacy Protection Act, vehicle‑recall flows, credit reporting and fraud prevention — reduce friction for legitimate transactions while addressing the committee’s safety goals.

Several committee members raised concerns about litigation and “privacy troll” risk if the statute creates broad private rights of action. Varn and others said such litigation could impose large compliance costs on otherwise lawful commercial activity and recommended administrative enforcement or targeted civil remedies as lower‑cost alternatives. They also flagged potential First Amendment and constitutional challenges and said states that have followed Daniel’s law patterns have more defensible statutory structures in court‑testing so far.

Members also asked about law‑enforcement and criminal responses to malicious actors. Varn recommended reviewing existing criminal statutes and carefully drafting intent elements so that prohibitions do not unintentionally criminalize protected speech — a point he said the national doxing subcommittee and First Amendment experts are currently studying.

The committee heard repeated cautions that obscuring addresses alone will not eliminate targeted physical threats; witnesses recommended complementary threat‑management programs (surveillance monitoring, call‑screening, personal security measures and legal protections such as protective orders) for public employees at higher risk. Varn said those programs, paired with appropriately scoped statutory exemptions and auditing, are likeliest to reduce harm while preserving lawful access to records.

The panel did not vote on H.342 at the session. Members indicated they would return to the matter after floor business; committee leadership said some elements of the bill may be referred to money committees for further review.

The testimony and supporting materials submitted to the committee included comparative state examples (Oklahoma, Missouri and others were discussed) and legal memos on First Amendment and statutory exemptions. The committee’s next steps were not specified in the transcript.