Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Consumer Data Privacy S71 topic
No spam. Unsubscribe anytime.
Committee begins detailed walkthrough of S.71, a consumer data privacy and online surveillance bill
Summary
Committee counsel and staff walked senators through S.71’s definitions, coverage tests, consumer rights and exemptions. Staff emphasized thresholds for applicability, a broad list of sensitive data, health‑data carveouts tied to HIPAA, and enforcement routed largely to the attorney general.
Get email alerts on the Consumer Data Privacy S71 topic
No spam. Unsubscribe anytime.
On Thursday, Feb. 27, the Senate Committee on Institutions and IT began a section‑by‑section walkthrough of S.71, described in committee as "an act relating to consumer data privacy and online surveillance." The committee heard extended explanation from its counsel of the bill’s definitions, consumer rights, exemptions and compliance mechanics.
Rick Sable, Office of Legislative Counsel, said the bill tracks many features in other state privacy laws while proposing a specific set of thresholds and carveouts for Vermont. "When you see the states that have this and which ones have decided to include a right to correct or right to delete...this bill has most of the consumer protections," Sable said, summarizing the bill’s components.
Sable and committee staff highlighted several central features of S.71 as introduced:
- Applicability thresholds: a person is covered if the person conducts business in Vermont or targets Vermont consumers and (a) controls or processes personal data of 25,000 or more Vermont consumers in the prior calendar year (excluding data processed solely to complete payment transactions), or (b) controls or processes personal data of at least 12,500 Vermont consumers and derives more than 25% of its gross revenue from the sale of personal data. Staff noted these numeric thresholds are higher than in some other state bills.
- Consumer rights and controller obligations: the bill grants consumers rights to confirm processing, access data, correct inaccuracies, delete personal data (subject to legal retention requirements), obtain a portable copy in a usable format, and opt out of targeted advertising, the sale of personal data, profiling and automated decisions that produce legal or similarly significant effects. Controllers must respond to requests "without undue delay" but no later than 45 days; the controller must provide an appeal process and notify consumers that they may file a complaint with the attorney general if appeals are denied.
- Sensitive data and special rules: S.71 defines a broad category of "sensitive data" that includes government IDs (Social Security, passports), biometric and genetic data, health and reproductive‑health data, precise geolocation and sexual‑orientation status, among other categories. Processing sensitive data typically triggers stricter requirements, including opt‑in consent for certain processing.
- Health‑data carveouts: staff explained multiple health‑related exemptions and cross‑references to federal HIPAA provisions. Sable said the bill references HIPAA and treats consumer health data and covered entities consistently with federal law in many parts of the bill. Committee staff identified several narrow public‑health, research and regulatory exemptions that would allow processing for those purposes when done by covered entities or business associates under HIPAA.
- Exemptions and preemption‑style references: the bill lists statutory exemptions for federal, state, tribal and local government entities; data subject to HIPAA; certain financial‑services data covered by federal law (including Gramm‑Leach‑Bliley Act protections); FERPA (educational records); the Driver’s Privacy Protection Act; and other targeted exemptions such as activities performed by victim‑services organizations and some press/publisher activities.
- Definitions and enforcement: Sable walked the committee through numerous definitions — controller, processor, de‑identified data, contextual vs. targeted advertising, unique persistent identifiers, geofencing and dark patterns. He said de‑identified data must meet specific technical criteria and contractual obligations if a controller claims data is de‑identified. On enforcement, counsel noted the bill relies on the attorney general for enforcement and that, unlike some other states, the Vermont draft does not create an unlimited private right of action; "Vermont does not have a private action," Sable said.
Senators asked for clarification on practical implications for businesses, including how geofencing and contextual advertising would be treated. Staff pointed to two numeric location thresholds used in the bill: (a) a definition of precise geolocation data that identifies location within a radius of 1,850 feet, and (b) a permitted contextual‑advertising use that may rely on a consumer’s "immediate presence in a geographic area with a radius not smaller than 10 miles or an area reasonably estimated to include online activity from at least 5,000 users," subject to limits that forbid making personal inferences.
Committee staff said they plan to continue the walkthrough at the committee’s next meeting to cover remaining sections and to answer follow‑up questions about health data, keystroke definitions and how certain exemptions operate in practice.
The committee recessed with the walkthrough unfinished and scheduled to resume the next day.

