Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
House commerce committee reviews draft data-privacy bill, debates scope, enforcement and profiling rules
Summary
The Vermont House Committee on Commerce & Economic Development on May 13 reviewed draft 3.3 of S.71, a proposed data privacy law, hearing a detailed presentation from the Office of Legislative Council and debating conflict-of-law language, exemptions for health data, consumer rights, profiling impact assessments and Vermont‑specific enforcement provisions. No votes were taken; staff will prepare changes for the next draft.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
The Vermont House Committee on Commerce and Economic Development on May 13 reviewed draft 3.3 of S.71, a proposed data privacy statute, receiving a line‑by‑line, color‑coded presentation from Rick Seagel of the Office of Legislative Council and debating several substantive changes that distinguish the draft from other states’ models.
Seagel told the panel the draft uses color highlights to show language drawn from other states and to mark Vermont‑specific text. “It’s draft 3.3 because the highlights have changed but the content didn’t change,” he said, explaining green marks language unique to Vermont while turquoise, gray and magenta identify Connecticut 2025, California and Colorado material respectively.
Committee members pressed the presenter on several recurring issues. One focal point was a conflict‑of‑law provision that would instruct courts to apply the law affording the greatest privacy protection where two statutes collide. Seagel illustrated the concern with a data‑broker example: if a data‑broker law (referred to as 211 in committee discussion) and S.71 both apply to the same data, the draft language is intended to make the consumer‑protective rule govern.
Members also reviewed exemptions for health‑related data tied to HIPAA and related statutes. Seagel recommended holding detailed questions for the Attorney General’s office, noting several carve‑outs and the possibility of leaving implementation details to AG rulemaking.
On consumer rights, the draft incorporates Connecticut 2025 provisions that expand access rights (including the right to know inferences and profiling practices) and would prohibit controllers from conditioning rights by using misleading statements or dark patterns. Committee members suggested tightening that text for clarity; one member proposed deleting redundant terms to avoid ambiguity for controllers and courts.
The committee spent substantial time on data‑minimization and the phrase “reasonable expectations of the consumer.” The draft includes California‑style guidance about what those expectations mean; some members favored codifying more concrete examples in statute to give businesses clearer guardrails, while others preferred leaving specificity to AG rulemaking to avoid unintended hurdles for smaller controllers.
Profiling and automated decision‑making produced one of the most detailed exchanges. The draft follows Connecticut’s model requiring controllers that build profiles producing “legal or similarly significant effects” (for example, loan denials, housing or employment decisions, or dynamic pricing) to perform and retain impact assessments describing purpose, data inputs and outputs, risk analyses, mitigation steps and post‑deployment monitoring. Those assessments would be retained for at least three years and produced to the Attorney General on request during an investigation, not filed proactively.
The bill also includes language on independent validation for assessments that involve sensitive data and cross‑references compliance with recognized cybersecurity frameworks (NIST). The committee discussed practical burdens for small entities and whether validation requirements should be scaled to the size and risk profile of the controller.
Enforcement was a prominent concern. The draft makes violations an unfair practice enforceable by the Attorney General and preserves a narrow private right of action limited to entities with more than $1 billion in annual gross revenue. The draft further proposes Vermont‑specific civil penalties for knowingly including false information in required impact assessments — a measure some members said was intended to address a perceived enforcement gap in other states.
No formal votes or final decisions were recorded during the session. Committee members flagged several items for revision — including clearer definitions, refining non‑discrimination language, and fine‑tuning processor/subcontractor liability — and asked staff to incorporate those edits into the next draft. The chair invited interested parties to submit testimony or suggestions to committee staff before the next meeting.
The committee will consider amendments and additional drafts at upcoming sessions; staff and the Office of Legislative Council will provide updated language for further review.

