Security Breach Notice Act
VT SBNA
Breach notification
Requires businesses and other data collectors to tell Vermont consumers about a breach of their personally identifiable information or login credentials within 45 days of discovery, and to give the Attorney General (or DFR) a preliminary report within 14 business days. Notices must contain specified content, and large breaches require notice to the national credit bureaus.
- Where
- Vermont
- Citation
- 9 V.S.A. § 2435 (definitions at 9 V.S.A. § 2430)
- Status
- In force
- In force since
- 2007-01-01
- Last amended
- 2020-07-01
- Enforced by
- Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees
- People can sue
- No
- Penalties
- The AG and State's Attorneys have the remedies available under the Consumer Protection Act (9 V.S.A. ch. 63), including civil penalties of up to $10,000 per violation under 9 V.S.A. § 2458; DFR uses its Title 8 powers for its licensees. Enforcement authority is described as sole and full, and no private action is provided.
- Applies to
- Data collectors that own, license, maintain or possess computerized personally identifiable information or login credentials of Vermont consumers
- Entities licensed or registered with the Department of Financial Regulation report to that Department instead of the Attorney General
- Financial institutions subject to the 2005 federal interagency (or NCUA) breach guidance are exempt but must notify DFR
Breach duties
- Notify affected consumers in the most expedient time possible and no later than 45 days after discovery, subject to law enforcement delay.9 V.S.A. § 2435(b)(1), (b)(4)
- Give the Attorney General (or DFR) the breach date, discovery date and a preliminary description within 14 business days of discovery or when consumers are notified, whichever is sooner.9 V.S.A. § 2435(b)(3)(B)(i)
- When consumers are notified, send the regulator the number of Vermont consumers affected and a copy of the consumer notice.9 V.S.A. § 2435(b)(3)(C)
- Consumer notices must describe the incident, the type of information involved, protective steps taken, a contact phone number, advice to monitor accounts and credit reports, and the approximate breach date.9 V.S.A. § 2435(b)(5)
- Service providers that maintain data they do not own must notify the owner or licensee immediately after discovering a breach.9 V.S.A. § 2435(b)(2)
- Notify nationwide consumer reporting agencies when more than 1,000 consumers are notified at one time.9 V.S.A. § 2435(c) · Only if: More than 1,000 consumers notified
- A no-risk-of-harm determination requires a notice and detailed explanation to the AG or DFR.9 V.S.A. § 2435(d)(1) · Only if: Data collector concludes misuse is not reasonably possible
- A breach limited to email login credentials may not be reported through the compromised email account.9 V.S.A. § 2435(d)(4)
Sources
- Official text
- 9 V.S.A. chapter 62, full text (Vermont Statutes Online)
- 2020 Acts and Resolves No. 89 (S.110), as enacted, effective July 1, 2020
- 2026 Acts and Resolves No. 138 (H.211), as enacted
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: 2026 Act No. 138 makes technical amendments to § 2435 and the § 2430 definitions effective Jan. 1, 2027; the changes were not reviewed line by line, so last_amended reflects the latest amendment already in force (2020 Act 89).
Research reference, not legal advice.