Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the S71 Data Privacy topic

No spam. Unsubscribe anytime.

Committee reviews draft 3.3 of S.71, aligning Vermont data‑privacy language with Connecticut and California models

Vermont House Committee on Commerce & Economic Development · May 8, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislative counsel presented draft 3.3 of S.71, detailing changes to definitions (collect, consent, processor), removal/realignment of advertising terms, HIPAA exemptions for hybrid entities, a California‑style 'reasonable expectations' data‑minimization standard, and NIST security‑framework requirements.

Legislative counsel Rick Sagel presented draft 3.3 of S.71 to the House Commerce & Economic Development Committee on May 8 and walked members through a series of definition changes, deletions of some advertising provisions, and new duties for controllers and processors intended to align Vermont’s privacy law with aspects of Connecticut’s 2025 amendments and California rulemaking.

Sagel said the draft clarifies core definitions: it narrows and reorganizes the definition of ‘collect,’ updates the definition of ‘consent’ to require a freely given, specific, informed, and unambiguous indication of choice, and adjusts the distinction between ‘processor’ and ‘processing’ so collection and processing are distinct concepts. He described removing or revising several advertising‑related terms (contextual advertising, first‑party advertising, marketing measurements, unique persistent identifiers) to track national industry standards. “We are making it what everyone is already adhering to from a national perspective,” Sagel said, explaining the goal of reducing novel, state‑specific definitions that generated industry concern.

The draft also adds three HIPAA‑related exemptions for covered entities, health‑care components of hybrid entities, and business associates; Sagel said stakeholders from the health‑care community would review that language and return with suggested adjustments. On applicability the draft inserts a clause intended to resolve conflicts among overlapping privacy bills by providing that the law affording the greatest privacy protection should control in the event of conflict.

On data minimization, the draft adopts a California‑styled ‘reasonable expectations’ test to guide what is proportionate and necessary for the stated purpose and lists factors controllers should consider (relationship with the consumer, type and amount of data, source and method of collection, clarity of notice, and involvement of third parties). Sagel also proposed that controllers maintain reasonable administrative, technical and physical security measures aligned with recognized privacy and cybersecurity frameworks; the draft names the NIST Privacy Framework (v1.0) and Cybersecurity Framework (v2.0) as the baseline.

Contractual duties for processors were expanded in the draft: processor contracts should govern processing procedures, processors must adhere to a controller’s instructions, and — absent consumer consent — processors should be prohibited from combining controller data with data received on behalf of other controllers. Sagel said the contractual provisions are intended to protect small controllers (nonprofits and businesses) that rely on third‑party services (examples discussed included HubSpot, Mailchimp and Shopify) from unexpected downstream uses of data.

Committee members asked for clearer color‑coding in the draft to distinguish language borrowed from Connecticut and California and language unique to Vermont; Sagel offered to circulate a version with clearer highlights and to continue markup at the next scheduled meeting.

The committee did not take final action on S.71; members agreed to continue consideration next week and to solicit feedback from industry and health‑care stakeholders on the HIPAA exemptions and cure/enforcement provisions.