Vermont Cybersecurity Laws You Should Know (2026)

Last Updated: August 25, 2026

Vermont cybersecurity laws include requirements covering data breach notification, data brokers, genetic information, insurance companies, consumer protection, and the handling of personal information. The state has also enacted major new privacy legislation that will create broader obligations for businesses beginning in 2028.

For organizations that collect, store, or process information about Vermont residents, understanding these requirements is becoming increasingly important. Businesses should know which laws already apply, which requirements are scheduled to take effect in the coming years, and how their cybersecurity programs can support compliance.

This guide provides an overview of the major Vermont cybersecurity laws businesses should know in 2026.

Vermont Cybersecurity Laws at a Glance

Law or Requirement Status in 2026 Primary Focus
Vermont Security Breach Notice Act In effect Data breach notification
Vermont Genetic Information Privacy Act In effect as of July 1, 2026 Genetic data privacy
Vermont Data Broker Law In effect Data broker registration and security
Vermont Insurance Data Security Law In effect Cybersecurity requirements for insurance licensees
Vermont Age-Appropriate Design Code Act Takes effect January 1, 2027 Privacy and online protections for minors
Vermont Data Privacy and Online Surveillance Act Takes effect January 1, 2028 Comprehensive consumer data privacy

What’s New with Vermont Cybersecurity Laws in 2026?

Vermont significantly expanded its privacy framework in 2026.

Two developments are particularly important.

First, Vermont enacted the Genetic Information Privacy Act, which took effect July 1, 2026. The law establishes requirements for companies that collect, use, maintain, or disclose certain types of consumer genetic data.

Second, Vermont enacted Act 145, the Vermont Data Privacy and Online Surveillance Act, on June 16, 2026. This is Vermont’s new comprehensive consumer privacy law, but businesses should note that the law does not take effect until January 1, 2028.

Vermont businesses should therefore distinguish between cybersecurity and privacy requirements that are currently enforceable and obligations that require preparation for future compliance.

Vermont Security Breach Notice Act

One of the most important existing Vermont cybersecurity laws is the Security Breach Notice Act, 9 V.S.A. § 2435.

The law applies to data collectors that own or license computerized personally identifiable information or login credentials involving Vermont consumers.

When a qualifying security breach occurs, affected consumers generally must be notified in the most expedient time possible and without unreasonable delay. Vermont law establishes an outside deadline of 45 days after discovery or notification of the breach, subject to certain circumstances involving law enforcement or the investigation and remediation of the incident.

Vermont Attorney General Breach Notification

Organizations may also have obligations to notify the Vermont Attorney General.

Guidance from the Attorney General states that covered data collectors generally must provide preliminary notice to the Attorney General within 14 business days after discovering or being notified of a security breach. Consumer notification generally must occur no later than 45 days after discovery or notification.

This means a business should not wait until its investigation is completely finished before determining whether state reporting requirements have been triggered.

An effective incident response plan should establish procedures for quickly:

  • identifying affected systems
  • determining what information was accessed
  • identifying affected Vermont residents
  • involving legal counsel when appropriate
  • documenting the investigation
  • determining regulatory notification requirements
  • preparing required consumer notifications

When notice is provided to more than 1,000 consumers at one time, the law also requires notice to nationwide consumer reporting agencies regarding the timing, distribution, and content of the consumer notice, subject to an exception for certain entities regulated by the Vermont Department of Financial Regulation.

What Information Is Protected Under Vermont’s Breach Law?

Vermont’s breach notification framework covers personally identifiable information and certain login credentials.

Businesses should therefore understand where sensitive information resides throughout their technology environment.

Potentially sensitive information can include combinations of identifying information with financial account information, government identifiers, authentication information, and other information that could expose individuals to identity theft or fraud.

This makes data inventory an important component of cybersecurity compliance. Organizations that do not know what information they maintain may struggle to determine the scope of a breach or meet notification deadlines after an incident.

Vermont Genetic Information Privacy Act

One of the most significant changes to Vermont privacy law in 2026 is the Genetic Information Privacy Act.

Governor Phil Scott approved H.639, which became Act 135, on June 15, 2026. The law took effect on July 1, 2026.

The law applies to certain businesses involved in collecting, using, maintaining, analyzing, or disclosing consumer genetic data.

Vermont broadly defines genetic data to include information resulting from the analysis of biological samples or other sources that reveal genetic information. This can include information related to DNA, RNA, genes, chromosomes, genomes, genetic variations, and information inferred from genetic material.

For businesses handling this type of information, the law makes privacy governance increasingly important.

Companies should review:

  • what genetic information they collect
  • why the information is collected
  • how consumer consent is obtained
  • which employees can access the information
  • whether data is shared with vendors or other third parties
  • how long the information is retained
  • how consumers can exercise applicable rights
  • how sensitive data is protected from unauthorized access

Businesses offering direct-to-consumer genetic testing or related services should pay particular attention to the new requirements.

Vermont Data Broker Requirements

Vermont was one of the first states to establish specific requirements for data brokers.

Under 9 V.S.A. § 2446, qualifying data brokers generally must register annually with the Vermont Secretary of State and provide information regarding their data collection and security practices.

Registration disclosures can include information about opt-out practices, data collection activities, whether the broker possesses information about minors, and security breaches experienced during the prior year.

Vermont goes beyond registration by imposing cybersecurity obligations on data brokers.

Under 9 V.S.A. § 2447, data brokers must develop, implement, and maintain a comprehensive written information security program containing appropriate administrative, technical, and physical safeguards.

The security program should account for factors such as:

  • the size and scope of the business
  • available resources
  • the amount of data stored
  • the sensitivity of the information
  • foreseeable internal cybersecurity risks
  • foreseeable external cybersecurity risks

This is an important example of how Vermont cybersecurity laws can move beyond breach notification and establish affirmative expectations for protecting information before an incident occurs.

Vermont Insurance Data Security Law

Insurance companies and other regulated insurance entities face additional cybersecurity requirements under the Vermont Insurance Data Security Law, 8 V.S.A. § 4728.

The law requires covered licensees to maintain a comprehensive written information security program based on their risk assessment. The program must include administrative, technical, and physical safeguards designed to protect nonpublic information and information systems.

Covered organizations are expected to identify reasonably foreseeable threats, evaluate security risks, and address third-party service providers that may have access to sensitive information.

The law also specifically requires organizations to consider the retention and destruction of nonpublic information.

For insurance organizations, cybersecurity therefore cannot be treated solely as an IT responsibility. Risk assessment, vendor management, governance, incident response, and information lifecycle management all play a role.

Vermont Age-Appropriate Design Code Act

Another major development businesses should prepare for is the Vermont Age-Appropriate Design Code Act, which takes effect January 1, 2027.

The law creates privacy and design requirements for certain online services, products, and features used by minors.

Among its requirements, covered businesses must configure privacy settings provided to minors at high levels of privacy and comply with transparency requirements concerning how minors’ personal information is used.

The law also restricts certain data and design practices involving minors.

For example, covered businesses generally may not collect, sell, share, or retain a minor’s personal data when that information is not necessary to provide the service, product, or feature being used. The law also contains restrictions involving recommendation systems, monitoring, location tracking, and certain push notifications.

Businesses providing websites, mobile applications, social media services, online platforms, or other digital products that may be used by Vermont minors should evaluate the law before the January 2027 effective date.

Vermont Data Privacy and Online Surveillance Act

The largest change on the horizon is Vermont’s new Data Privacy and Online Surveillance Act.

Act 145 was signed into law on June 16, 2026 and is scheduled to take effect January 1, 2028.

The law establishes a comprehensive consumer privacy framework governing how covered organizations process personal information.

Although businesses have time before the effective date, organizations that expect to fall within the law should begin evaluating their data practices well in advance.

The law includes consumer rights and business obligations involving areas such as:

  • access to personal data
  • correction of inaccurate information
  • deletion of information
  • data portability
  • targeted advertising
  • sale of personal information
  • sensitive personal data
  • privacy notices
  • data processing practices
  • third-party relationships
  • consumer privacy requests

The statute also requires covered organizations to provide mechanisms that allow consumers to opt out of certain processing for targeted advertising or the sale of personal data.

Enforcement of Vermont’s New Privacy Law

The Vermont Attorney General will be responsible for enforcing the Data Privacy and Online Surveillance Act.

The law does not initially provide consumers with a general private right of action for violations. Vermont lawmakers specifically stated that enforcement responsibility will fall primarily on the Attorney General.

Between January 1, 2028 and June 30, 2029, the Attorney General must generally provide notice and an opportunity to cure certain violations when the Attorney General determines that a violation can be cured. The cure period is 60 days.

Businesses should not view the 2028 effective date as a reason to delay planning. Mapping data, reviewing vendor relationships, developing privacy request procedures, and improving data governance can take significant time.

Vermont Consumer Protection Act

Cybersecurity practices may also create risks under Vermont’s broader consumer protection laws.

Businesses should be careful about statements made to consumers regarding security, privacy, encryption, data sharing, monitoring, or other cybersecurity protections.

If an organization claims that customer information is protected in a particular way but does not actually implement those protections, the discrepancy can create regulatory and reputational risk.

This is one reason cybersecurity policies should accurately reflect the organization’s real-world practices.

Federal Cybersecurity Requirements Affecting Vermont Businesses

State law is only one part of cybersecurity compliance.

Depending on the industry and the type of information an organization maintains, Vermont businesses may also be subject to federal requirements.

Examples include:

HIPAA

Healthcare organizations and certain business associates may be subject to HIPAA’s Privacy and Security Rules when handling protected health information.

Gramm-Leach-Bliley Act

Financial institutions subject to GLBA may face requirements involving information security, privacy, risk assessments, safeguards, and service providers.

FTC Act

The Federal Trade Commission can pursue companies for unfair or deceptive practices involving cybersecurity and privacy.

COPPA

Online services that collect personal information from children under 13 may be subject to the Children’s Online Privacy Protection Act.

FERPA

Educational institutions and certain organizations handling student education records may have obligations under the Family Educational Rights and Privacy Act.

DFARS and NIST SP 800-171

Defense contractors and subcontractors handling controlled unclassified information may face contractual cybersecurity requirements based on DFARS and NIST SP 800-171.

Organizations should determine which state, federal, contractual, and industry requirements apply to their particular environment rather than relying on a single cybersecurity standard.

Vermont Cybersecurity Compliance Checklist

While specific requirements vary by organization, Vermont businesses can reduce risk by developing a structured cybersecurity and privacy program.

Consider the following steps:

  • Identify the personal and sensitive information your organization collects.
  • Document where sensitive information is stored.
  • Limit access according to job responsibilities.
  • Require multi-factor authentication for critical systems.
  • Encrypt sensitive information where appropriate.
  • Maintain current backups and regularly test recovery procedures.
  • Conduct periodic cybersecurity risk assessments.
  • Evaluate cybersecurity practices of third-party vendors.
  • Develop a written incident response plan.
  • Establish procedures for Vermont breach notification requirements.
  • Review privacy notices and consumer-facing cybersecurity claims.
  • Maintain policies governing data retention and secure destruction.
  • Train employees to recognize phishing, social engineering, and other threats.
  • Review whether new Vermont privacy laws taking effect in 2027 or 2028 apply to the organization.

Example: A Vermont Business Experiences Ransomware

Consider a Vermont manufacturer that experiences a ransomware attack.

Attackers gain access to a file server containing employee names, Social Security numbers, and financial information.

The company’s first priority is containing the attack and restoring operations, but regulatory responsibilities begin at the same time.

The organization would need to determine:

  1. What systems were compromised?
  2. Was personally identifiable information accessed or acquired?
  3. Which Vermont residents were affected?
  4. When was the breach discovered?
  5. Does the Vermont Attorney General need to be notified?
  6. When must affected consumers receive notice?
  7. Are federal or industry regulations also triggered?
  8. Did a third-party service provider contribute to the incident?

A documented incident response plan makes it much easier to answer these questions within Vermont’s required timelines.

Frequently Asked Questions About Vermont Cybersecurity Laws

What is Vermont’s primary data breach law?

The Vermont Security Breach Notice Act, 9 V.S.A. § 2435, establishes notification requirements when certain personally identifiable information or login credentials are compromised.

How quickly must Vermont residents be notified of a data breach?

Consumer notification generally must occur in the most expedient time possible and without unreasonable delay, but no later than 45 days after discovery or notification of the breach, subject to statutory exceptions.

Does the Vermont Attorney General have to be notified of a breach?

In many cases, yes. Vermont Attorney General guidance states that covered organizations generally must provide preliminary notice within 14 business days after discovering or being notified of a breach.

Does Vermont currently have a comprehensive consumer privacy law?

Vermont has enacted a comprehensive privacy law, but it is not yet in effect. The Vermont Data Privacy and Online Surveillance Act takes effect January 1, 2028.

Did Vermont pass new privacy legislation in 2026?

Yes. Vermont enacted both the Genetic Information Privacy Act and the Vermont Data Privacy and Online Surveillance Act during 2026.

When did Vermont’s Genetic Information Privacy Act take effect?

The law took effect July 1, 2026.

Does Vermont regulate data brokers?

Yes. Vermont requires qualifying data brokers to register and imposes cybersecurity requirements, including maintaining a comprehensive information security program.

Are there special cybersecurity requirements for Vermont insurance companies?

Yes. The Vermont Insurance Data Security Law establishes cybersecurity requirements for covered insurance licensees, including written information security programs and risk assessments.

Are there new rules affecting businesses that collect data from minors?

Yes. Vermont’s Age-Appropriate Design Code Act takes effect January 1, 2027 and establishes privacy and design obligations for certain online services used by minors.

Does complying with Vermont law guarantee compliance with federal cybersecurity requirements?

No. Organizations may be subject to multiple state, federal, industry, and contractual cybersecurity requirements depending on the information they maintain and the industries they serve.

Preparing for Vermont Cybersecurity Laws

Vermont’s cybersecurity and privacy environment is becoming more complex.

Businesses already need to consider breach notification requirements, data broker rules, insurance cybersecurity requirements, and the state’s new Genetic Information Privacy Act. Organizations should also prepare for the Age-Appropriate Design Code Act in 2027 and the broader Vermont Data Privacy and Online Surveillance Act in 2028.

For many organizations, the underlying cybersecurity work is similar regardless of the regulation. Businesses need to understand their data, control access, manage vendors, protect sensitive systems, monitor for threats, prepare for incidents, and maintain documentation demonstrating that security controls are actually being followed.

Taking those steps can help organizations reduce cybersecurity risk while preparing for an evolving regulatory environment.

Official Vermont Resources

Businesses researching Vermont cybersecurity laws should consult primary government sources, including the Vermont General Assembly’s statutes and enacted legislation, along with guidance issued by the Vermont Attorney General.

Because cybersecurity and privacy requirements can change, organizations should periodically review these sources and consult qualified legal counsel regarding their specific compliance obligations.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Organizations should consult qualified legal counsel regarding laws and regulations applicable to their specific operations.

Mitch Wolverton

Mitch, Marketing Manager at PivIT Strategy, brings over many years of marketing and content creation experience to the company. He began his career as a content writer and strategist, honing his skills on some of the industry’s largest websites, before advancing to specialize in SEO and digital marketing at PivIT Strategy.