Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Vermont committee reviews H.342 to limit data-broker disclosure of public servants' contact information
Summary
The Vermont House Commerce & Economic Development Committee on March 19 heard hours of testimony on H.342, a proposal to restrict commercial data brokers from disclosing home addresses, phone numbers and other personal identifiers for judges, law enforcement officers, prosecutors, public defenders and other designated public servants.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
The Vermont House Commerce & Economic Development Committee on March 19 heard hours of testimony on H.342, a proposal to restrict commercial data brokers from disclosing home addresses, phone numbers, license numbers and other personal identifiers for judges, law enforcement officers, prosecutors, public defenders and other designated public servants.
The bill drew support from privacy scholars and public-safety advocates who said easy access to personal data is being used to intimidate and threaten public servants. Industry representatives and some witnesses warned the measure, as currently written, could create unintended legal and operational consequences, including a surge of private lawsuits and gaps in fraud- and identity‑verification services.
H.342 would give a covered person — or an authorized agent acting on their behalf — the right to notify a data broker and require the broker to “cease disclosing” protected information within a set period. The House Judiciary Committee, which held prior hearings and forwarded recommendations to the Commerce & Economic Development Committee, flagged several technical and scope issues for lawmakers to consider before any final vote.
Rick Sadel of the Office of Legislative Counsel walked members through key definitions and mechanics in the draft. He said the bill would apply to businesses that “knowingly collect and sell, license, or otherwise broker personal information of a consumer with whom the business does not have a direct relationship,” and that government agencies would not be covered as data brokers. He explained the authorized‑agent provision and how it is intended to work: “So this allows a covered person to if they don't wanna deal with the paperwork or whatever else, of having their information removed, they could hire a person or a company to do that for them.”
Justin Sherman, a privacy and technology policy scholar, described the data‑broker industry as large and diverse and catalogued harms he said arise when aggregated datasets are sold. “Data broker industry is a multi billion dollar industry in The United States alone,” he said, and testified that brokers combine public records, consumer trackers and commercial sources to produce dossiers that have been used to stalk, harass and, in some cases, facilitate violence.
Rep. Martin Malone, chair of the House Judiciary Committee, summarized his committee's earlier session on H.342 and read the Judiciary members' principal recommendations and concerns. “We spent all afternoon yesterday taking testimony on H342,” he told the Commerce & Economic Development Committee, and relayed that “they all are in favor of anything that could be done to … create a barrier or barricade, from being able to get personal inner identifying information on the Internet.” Malone also listed areas Judiciary asked the committee to consider changing or clarifying, including adding victim advocates and court staff to the list of covered people, narrowing federal prosecutor language to those who work in Vermont, and rewording the judge definition to “any justice, judge, or magistrate in a state court located in Vermont.”
Committee members and witnesses raised several recurring technical issues:
- Scope of who is a “covered person.” Judiciary recommended adding victim advocates, court staff, some state‑level mental‑health crisis workers embedded with police, the attorney general, and possibly parole board members.
- Which businesses qualify as “data brokers.” Counsel and witnesses noted the Vermont registry (created in 2019) captures many—but not all—entities that package and sell personal information; some witnesses urged expanding the definition so search engines and other public‑posting businesses are not exempt.
- The remedy and enforcement window. The draft sets a compliance deadline of 10 business days after a broker receives notice to “cease disclosing”; witnesses described requests to extend that to 30 days or to adopt a “reasonable” time standard. The bill lists remedies including statutory damages of $1,000 per violation, actual damages, punitive damages for willful misconduct, and attorneys’ fees; several witnesses said the damages provisions could lead to large volumes of litigation.
- Deletion versus cessation of disclosure. Witnesses asked whether brokers must delete records or merely stop sharing them; committee counsel cautioned deletion may conflict with other retention obligations and suggested that provision needs more study.
- The bill’s language on available public sources. The draft includes a provision that “it shall not be a defense to liability … that the covered person's protected information is or was available to the public from other sources.” Some members warned that could create perverse incentives (for example, a broker could re‑publish information on a public site to evade obligations), and Judiciary recommended the committee consider that issue.
Industry witnesses argued the draft is too narrow in one respect and too broad in another. Sarah Owes, vice president of government relations at the Consumer Data Industry Association, said the bill currently focuses on a narrow set of companies as defined by Vermont law while leaving search engines and many other public‑posting services outside the regulatory reach. “This bill actually exempts the state from any liability or acting on this information,” she warned and urged lawmakers to focus on removal of information from public websites rather than creating a broad private right of action that she said has produced mass litigation in other states.
Owes cited New Jersey’s post‑Daniel’s Law litigation as an example, telling the committee that the New Jersey rollout led to hundreds of suits after an out‑of‑state assignee sent bulk requests. She cautioned that a broad private cause of action plus statutory damages could generate “legal fees, not to protect the public servants it purports to protect.”
By contrast, Debbie Reynolds, a privacy consultant who testified in favor of the bill, framed the measure as a public‑safety provision. “You can't take advantage of a service if you're dead,” she told the committee, arguing the bill is narrowly tailored to address threats to judges, law enforcement and others who face real‑world harms when personal information is readily available online.
Committee counsel and staff pointed to several drafting items members are likely to revisit: whether to require the Secretary of State to publish a standard opt‑out form (the draft sets a 90‑day deadline after a July 1, 2025 effective date), whether to harmonize “10 days” versus “10 business days” language in separate subsections, and how to define “immediate family” (the draft cross‑references 3 V.S.A. § 301).
No formal vote on H.342 occurred during the session. Members scheduled further testimony and plan to resume consideration; the committee chair said the panel will return the next morning for additional hearings and drafting work.
Looking ahead, Judiciary recommended including monitoring or oversight language so lawmakers can evaluate whether the statute is achieving its safety goals, and witnesses emphasized narrow, purpose‑based exemptions (for fraud prevention, law‑enforcement operations, or regulated credit‑reporting activities) if the committee narrows how the law applies to business‑to‑business exchanges.
The committee recessed after several hours of testimony and indicated it would continue H.342 work at a follow‑up session the next day.

