ARTICLE
3 January 2019

US Breach Laws Are Coming: Vermont

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
On January 1, 2019 Vermont's breach notice law will include obligations specific to data brokers.
United States Privacy
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Cannabis & Hemp topic(s)

On January 1, 2019 Vermont's breach notice law will include obligations specific to data brokers. A "data broker" is defined as a business that "knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship." Under the law, data brokers must keep a record of "data broker breaches" and annually tell this information to the state. Brokers will need to provide this as part of a new annual registration process. The registration also requires data brokers to explain how they let individuals opt-out of having information collected, stored or sold. Finally, data brokers also have to develop and maintain a comprehensive information security program.

Data broker breaches are defined as unauthorized acquisition of "broker personal information." This is broader than personal information that triggers general breach notice obligations. For broker breaches, personal information also includes name, address, date of birth, place of birth, mother's maiden name, and name or address of family members. The "broker breach" definition (i.e., when there is a duty to notify the state) imposes notice obligations when there is an unauthorized acquisition. It does, though, contain encryption and good faith exceptions.

Putting it Into Practice: This law is one of the first to have specific disclosure obligations for data brokers, and will require telling the state about a broader category of data breaches than what exists under the general breach notice obligations.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More