Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy Legislation topic
No spam. Unsubscribe anytime.
Senate Institutions continues walk-through of S.71, focusing on data‑protection assessments, de‑identified data and enforcement
Summary
The Senate Institutions Committee on Friday, Feb. 8 continued its line‑by‑line review of S.71, examining sections 24.21–24.24 that require data‑protection assessments for processing judged to present a high risk of consumer harm, set rules for the use and disclosure of de‑identified data, clarify duties and exemptions for controllers and processors, and establish enforcement procedures that include a limited private right of action.
Get email alerts on the Data Privacy Legislation topic
No spam. Unsubscribe anytime.
The Senate Institutions Committee on Friday, Feb. 8 continued its line‑by‑line review of S.71, examining sections 24.21–24.24 that require data‑protection assessments for processing judged to present a high risk of consumer harm, set rules for the use and disclosure of de‑identified data, clarify duties and exemptions for controllers and processors, and establish enforcement procedures that include a limited private right of action.
Rick Sagal, Office of Legislative Counsel, told the committee the bill requires "a controller shall conduct and document what's called a data protection assessment for each of their activities that presents a heightened risk of harm to a consumer," and then defines what the bill considers a high risk of harm. Sagal listed categories that trigger an assessment, including targeting advertising, the sale of personal data, profiling that creates a "reasonably foreseeable risk" of unfair or unlawful disparate treatment, and processing that could cause "financial, physical, or vocational injury" or other substantial consumer harms.
The bill would require an assessment to identify categories of personal data processed, the purposes of processing, whether data are transferred to third parties, and to weigh benefits of the processing "to the controller, the consumer, other stakeholders, and the public" against potential risks. Sagal said controllers must consider use of de‑identified data, "the reasonable expectations of consumers," contextual factors and "the relationship between the controller and the consumer." Assessments must be retained for at least three years.
On de‑identified data, Sagal summarized the draft language: "A controller in possession of de identified data shall take reasonable measures to ensure that the data cannot be used to re identify an identifiable individual or be associated with an individual or a device that identifies or is linked or reasonably likable to an individual or household." The controller also must "publicly commit to maintaining and using de identified data without attempting to re identify the data" and contractually obligate recipients to comply with the chapter; limited re‑identification for internal testing of de‑identification methods is permitted.
Committee members asked whether sharing de‑identified data would always require a contract. Sagal said the bill's intent appears to require contractual terms when a controller shares de‑identified data with a third party, and he noted the committee could clarify that point.
Sections the committee reviewed also list activities the chapter is not intended to restrict, including compliance with federal or state laws on health data, cooperation with law enforcement, responding to security incidents, fraud prevention, fulfilling contracts or consumer‑requested services, product safety recalls, and public‑interest research conducted under applicable protections. Sagal emphasized that controllers who rely on an exemption bear the burden of demonstrating that the exemption applies and that the processing complies with accompanying safeguards.
On enforcement, Sagal explained the attorney general (AG) would have primary enforcement authority and rulemaking power. The AG may offer a 60‑day cure period before initiating an enforcement action. The bill creates a private right of action only in narrow circumstances: violations of subsection 24.19(c) (sensitive‑data limits and anti‑discrimination provisions) or section 24.25 (consumer‑health data), and only against data brokers or "large data holders" as defined elsewhere in the draft. Sagal read the draft's limitations: no private action is available for other chapters of the bill, and the private remedy is unavailable against a controller "that is registered in the state and that earned less than 25,000,000 in revenue in the previous calendar year."
The proposed pre‑litigation process would require a consumer to notify the AG and provide a written demand to the alleged violator at least 65 days before filing suit; the AG then reviews the notice and may determine the claim is frivolous, in which case the consumer is barred from proceeding. If the AG does not issue a frivolous ruling within 65 days or determines the claim is nonfrivolous, the consumer may proceed. Remedies the draft mentions include actual damages or a statutory award "greater than $5,000," injunctive relief, punitive damages for intentional violations, and reasonable costs and attorney fees.
Sagal flagged constitutional and practical issues for the committee to consider, including a Dormant Commerce Clause concern tied to language that would exempt controllers registered in Vermont with under $25 million in revenue from the private right of action. "When a state discriminates against out of state businesses," he said, "that is largely to bring up the dormant commerce clause." Committee members also discussed ambiguity in the draft about what it means to be "registered" in the state and noted possible confusion between being a foreign entity registered to do business and having a physical presence.
Sagal closed by describing reporting requirements: the AG would file an annual report to the General Assembly, due each Feb. 1, listing notices of violation, cures, actions brought, and other enforcement data. The committee did not take votes during the recorded portion of the session and deferred further action to future meetings.
The committee will resume the walk‑through of S.71 in its next meeting; members signaled they plan targeted amendments to the enforcement, jurisdictional, and de‑identification provisions.

