Privacy Law Library

Security Breach Notice Act

VT SBNA

Breach notification

Requires businesses and other data collectors to tell Vermont consumers about a breach of their personally identifiable information or login credentials within 45 days of discovery, and to give the Attorney General (or DFR) a preliminary report within 14 business days. Notices must contain specified content, and large breaches require notice to the national credit bureaus.

Where
Vermont
Citation
9 V.S.A. § 2435 (definitions at 9 V.S.A. § 2430)
Status
In force
In force since
2007-01-01
Last amended
2020-07-01
Enforced by
Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees
People can sue
No
Penalties
The AG and State's Attorneys have the remedies available under the Consumer Protection Act (9 V.S.A. ch. 63), including civil penalties of up to $10,000 per violation under 9 V.S.A. § 2458; DFR uses its Title 8 powers for its licensees. Enforcement authority is described as sole and full, and no private action is provided.
Applies to
  • Data collectors that own, license, maintain or possess computerized personally identifiable information or login credentials of Vermont consumers
  • Entities licensed or registered with the Department of Financial Regulation report to that Department instead of the Attorney General
  • Financial institutions subject to the 2005 federal interagency (or NCUA) breach guidance are exempt but must notify DFR

Breach duties

  • Notify affected consumers in the most expedient time possible and no later than 45 days after discovery, subject to law enforcement delay.9 V.S.A. § 2435(b)(1), (b)(4)
  • Give the Attorney General (or DFR) the breach date, discovery date and a preliminary description within 14 business days of discovery or when consumers are notified, whichever is sooner.9 V.S.A. § 2435(b)(3)(B)(i)
  • When consumers are notified, send the regulator the number of Vermont consumers affected and a copy of the consumer notice.9 V.S.A. § 2435(b)(3)(C)
  • Consumer notices must describe the incident, the type of information involved, protective steps taken, a contact phone number, advice to monitor accounts and credit reports, and the approximate breach date.9 V.S.A. § 2435(b)(5)
  • Service providers that maintain data they do not own must notify the owner or licensee immediately after discovering a breach.9 V.S.A. § 2435(b)(2)
  • Notify nationwide consumer reporting agencies when more than 1,000 consumers are notified at one time.9 V.S.A. § 2435(c) · Only if: More than 1,000 consumers notified
  • A no-risk-of-harm determination requires a notice and detailed explanation to the AG or DFR.9 V.S.A. § 2435(d)(1) · Only if: Data collector concludes misuse is not reasonably possible
  • A breach limited to email login credentials may not be reported through the compromised email account.9 V.S.A. § 2435(d)(4)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: 2026 Act No. 138 makes technical amendments to § 2435 and the § 2430 definitions effective Jan. 1, 2027; the changes were not reviewed line by line, so last_amended reflects the latest amendment already in force (2020 Act 89).

Research reference, not legal advice.