Law / United States / Vermont

Vermont

United States law applies in Vermont Vermont is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Vermont, described on this page below, applies here too.

10 of 12 named instruments researched to a stage, across five of the six areas of law we track: 5 in force and 5 enacted but not yet in force. As of 15 September 2026.

When they take effect9 of 10 carry a date, 1 does not. Earlier is before 2016.
Before 2016: 2 instruments (2 in force) earlier 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments ’25 2026: 1 instrument (1 in force) 2027: 1 instrument (1 enacted but not yet in force) 2028: 4 instruments (4 enacted but not yet in force) ’28 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (270 words)

Vermont has no general AI-risk-management or automated-decision-disclosure statute reaching the private sector. Its two operative AI-specific duties are narrow: a sexual-deepfake ban folded into the state's existing nonconsensual-disclosure-of-intimate-images statute, and an election-deepfake disclosure duty enacted in 2026. The Synthetic Media in Elections Act (2026 Act No. 75, S.23) is codified at 17 V.S.A. §§ 2031-2033 and 2041-2042, not in 17 V.S.A. chapter 61 (Campaign Finance).

Vermont's child sexual abuse material statute, as currently codified, contains no provision reaching a wholly computer-generated depiction of a fictional minor; its "simulation" definition reaches conduct simulated by or involving an actual child, so no AI-generated-CSAM instrument is recorded for this jurisdiction.

Vermont's other AI governance is government-facing only and is an absence for this profile: the Division of Artificial Intelligence and its Advisory Council (3 V.S.A. §§ 5021 to 5023, established by 2022 Act No. 132 (Adj. Sess.), effective July 1, 2022) review only artificial intelligence systems developed, employed, or procured by State government.

A 2026 act (Act No. 101, H.814) creates no consumer-facing AI disclosure, health-insurer notification, or neural-data consent duty: it declares nonbinding neurological "rights" recognized by the State, extends the government-only Advisory Council's sunset to 2030, and directs the Council to study AI use in health care, human services, and education and report by January 15, 2027, so it imposes no private compliance duty.

In the 2025-2026 biennium, five further AI-focused bills reaching employee monitoring and automated-decision-system accountability (H.262, H.340), a duty of care for developers and deployers of dangerous AI systems (H.341), and chatbot disclosure (H.783, H.784) were introduced and did not advance out of committee before the legislature adjourned.

AI prohibited practices

Disclosure of sexually explicit images without consent, digitized and computer-generated images

13 V.S.A. § 2606official text, Vermont Statutes Online (legislature.vermont.gov)

In force since 6 June 2024. Binds public and private bodies.

What this law does

Section 2606 makes it a crime to knowingly disclose a visual image of an identifiable person who is nude or engaged in sexual conduct, without that person's consent, with intent to harm, harass, intimidate, threaten, or coerce them, where the disclosure would cause a reasonable person to suffer harm; a second, higher tier applies where the disclosure is made with intent to profit financially.

"Visual image" expressly includes an image created or altered by digitization, and "digitization" is defined as altering an image in a realistic manner using an image or images of a person, including images of a person other than the one depicted, or computer-generated images, so the statute reaches a realistic nonconsensual sexual deepfake of an identifiable person and not only an authentic recording.

Consent to the recording of an image does not by itself constitute consent to disclose it, and a website or app operator may not accept payment to remove or refrain from posting such an image on the depicted person's request.

The section carries statutory exceptions for voluntary public or commercial nudity, disclosures in the public interest (including reporting unlawful conduct), matters of public concern, and a Communications Decency Act section 230 style carve-out for interactive computer services hosting another person's content. The section was added in 2015 (Act No. 62) and most recently amended by 2023 Act No. 161 (Adj.

Sess.), section 45, effective June 6, 2024; whether the digitization definition specifically originated in the 2015 enactment or was introduced by the 2023 amendment is not confirmed against the uncodified session laws, so the amendment's effective date is used here for the section's current, in-force text.

What it requires

AI transparency

Vermont Synthetic Media in Elections Act

17 V.S.A. §§ 2031-2033, 2041-2042official enrolled act text, Vermont General Assembly (legislature.vermont.gov)

In force 7 months, effective 5 March 2026. Binds public and private bodies.

What this law does

Enacted as 2026 Act No. 75 (S.23), this act adds a new subchapter to Title 17's elections law defining "synthetic media" as an image, audio recording, or video recording of a person's appearance, speech, or conduct created or intentionally manipulated using digital technology, including artificial intelligence, and "deceptive and fraudulent synthetic media" as synthetic media that appears realistic and either injures a candidate's reputation or provides materially false information to influence an election.

Within 90 days before a Vermont election, a person may not publish, communicate, or distribute synthetic media it knows is deceptive and fraudulent unless the media carries a specified disclosure stating that it has been manipulated or generated by digital technology and depicts speech or conduct that did not occur, shown for the full duration of a video or read at set intervals for an audio recording.

The act exempts a bona fide newscast or news broadcast that acknowledges questions about authenticity, a periodical of general circulation that states the media does not accurately represent the person, satire or parody, and a telecommunications or interactive computer service that only carries another person's content.

A knowing and intentional violation is a civil fine of not more than $1,000.00, escalating to $5,000.00 with intent to cause violence or bodily harm, $10,000.00 for a repeat violation within five years, or $15,000.00 where both aggravating factors apply; a misrepresented candidate may separately seek injunctive relief, and the Attorney General or a State's Attorney may investigate and enforce.

The enacted text adds subchapters 4 and 5 to 17 V.S.A. chapter 35, at sections 2031 to 2033 and 2041 to 2042; it is not part of chapter 61 (Campaign Finance). The act took effect on passage, when Governor Scott signed it on March 5, 2026.

What it requires

Privacy law5 instruments, 1 in force, 4 enacted but not yet in force

Research summary (154 words)

Vermont enacted a comprehensive privacy law, the Vermont Data Privacy and Online Surveillance Act (9 V.S.A. ch. 61A), as 2026 Vt. Acts and Resolves Act 145 (S.71), signed June 16, 2026, but the Act's own text sets its effective date at January 1, 2028, so nothing in it currently binds anyone. This is Vermont's second attempt: a 2024 predecessor, H.121, passed both chambers but was vetoed, and the Senate's override attempt fell one vote short.

Once in force, Act 145 will require opt-in consent for sensitive data, including any genetic or biometric data with no purpose qualifier, and will give consumers a broader rights list than New Hampshire, Kentucky, or Rhode Island, enforced solely by the Attorney General with no private right of action, a choice the Act's own uncodified text calls deliberate. Vermont's pre-existing Security Breach Notice Act, 9 V.S.A. sec. 2435, is already in force and unaffected by Act 145's delayed start.

Breach notification

Security Breach Notice Act

9 V.S.A. sec. 2435Vermont Statutes Online, 9 V.S.A. section 2435, unofficial codification maintained by the Vermont General Assembly

In force since 1 January 2007. Binds private bodies.

What this law does

A data collector that owns or licenses computerized personally identifiable information or login credentials must notify an affected Vermont consumer of a security breach in the most expedient time possible and without unreasonable delay, but not later than 45 days after discovery.

Notice to the Attorney General or the Department of Financial Regulation, as applicable, is faster, with a preliminary description due within 14 business days, faster than New Hampshire's, Kentucky's, or Rhode Island's regulator-notice timelines in this batch. The source page's own history note dates original enactment to 2005, No. 162 (Adj. Sess.), sec. 1, effective January 1, 2007, since amended in 2011, 2013 (twice), 2015, and 2019; the source page itself flags as an unofficial online copy.

The enforcement subsection ties Attorney General and State's Attorney remedies to those they hold under 9 V.S.A. chapter 63, Vermont's Consumer Fraud Act, which independently grants consumers a private right of action for practices barred by section 2453; whether that cross-reference extends a private cause of action to a section 2435 notice violation, rather than only borrowing the state's own enforcement remedies, is not resolved by the text read and is left unset here, unlike the express private right of action in RSA 359-C:21 (New Hampshire) or the express denial in Act 145's own sec. 2415j.

What it requires

Comprehensive regime

Vermont Data Privacy and Online Surveillance Act, general applicability

9 V.S.A. secs. 2415a, 2415bofficial Vermont session law text, 2026 Vt. Acts & Resolves Act 145 (S.71) as enacted, Vermont Legislature website

In force in 465 days, effective 1 January 2028. Binds private bodies.

What this law does

This law does not currently bind anyone; it takes effect January 1, 2028.

As enacted, it will apply to a person conducting business in Vermont, or targeting products or services to Vermont residents, that in the preceding calendar year controlled or processed the personal data of at least 35,000 consumers, controlled or processed the sensitive data of at least 3,000 consumers, or offered for sale the personal data of at least 3,000 consumers, a materially broader sweep than New Hampshire's, Kentucky's, or Rhode Island's thresholds.

Sec. 2415b(c) sets a most-protective-law-controls rule against conflicting statutes, naming the Vermont Age-Appropriate Design Code Act. Act 145 (S.71) was signed June 16, 2026, following a 2024 predecessor, H.121, that passed both chambers but was vetoed and failed a Senate override by one vote.

What it requires

Data subject rights

Vermont Data Privacy and Online Surveillance Act, consumer rights

9 V.S.A. sec. 2415dofficial Vermont session law text, 2026 Vt. Acts & Resolves Act 145 (S.71) as enacted, Vermont Legislature website

In force in 465 days, effective 1 January 2028. Binds private bodies.

What this law does

This right and this deadline do not currently bind anyone; they take effect January 1, 2028.

As enacted, sec. 2415d will grant access (including a right to know about profiling used for legal or significant-effect decisions), correction, deletion, portability, opt-out of targeted advertising, sale, and profiling, a profiling-specific explanation and correction-and-reevaluation right for housing decisions, and a right to a list of third parties personal data was sold to, a broader rights list than New Hampshire, Kentucky, or Rhode Island.

A controller will have to respond without undue delay and not later than 45 days after receipt, with one 45-day extension available.

What it requires

Enforcement supervision

Vermont Data Privacy and Online Surveillance Act, Attorney General enforcement

9 V.S.A. sec. 2415j; 2026 Vt. Acts & Resolves Act 145, Secs. 2-3official Vermont session law text, 2026 Vt. Acts & Resolves Act 145 (S.71) as enacted, Vermont Legislature website

In force in 465 days, effective 1 January 2028. Binds private bodies.

What this law does

This enforcement scheme does not currently bind anyone; it takes effect January 1, 2028. As enacted, a violation will be a violation of the Vermont Consumer Protection Act, enforced solely by the Attorney General, with a mandatory 60-day cure notice from January 1, 2028 through June 30, 2029 under the Act's uncodified Sec. 3.

Sec. 2415j and the Act's uncodified Sec. 2 both state the Act creates no private right of action, and Sec. 2's intent language frames this as a deliberate legislative choice made contingent on the Attorney General receiving adequate enforcement resources, not an oversight. Secondary summaries describing the enacted law as including a limited private right of action for consumers are wrong: the Act's own text, quoted here, controls, and that claim is not carried.

What it requires

Sensitive categories

Vermont Data Privacy and Online Surveillance Act, sensitive data and biometric data definitions

9 V.S.A. sec. 2415a(b)(3), (47)official Vermont session law text, 2026 Vt. Acts & Resolves Act 145 (S.71) as enacted, Vermont Legislature website

In force in 465 days, effective 1 January 2028. Binds private bodies.

What this law does

This provision does not currently bind anyone; it takes effect January 1, 2028. As enacted, any genetic or biometric data (as defined) will be sensitive data, with no unique-identification qualifier, unlike New Hampshire's, Kentucky's, and Rhode Island's sensitive-data clauses.

"Biometric data" will list more enumerated modalities than those three states, including iris or retina scans, fingerprints, facial or hand geometry, vein patterns, voiceprints, and gait, and will exclude a photograph or recording, or data generated from one, only until that data is generated to identify a specific individual, the same clawback structure New Hampshire, Kentucky, and Rhode Island each use.

What it requires

Scraping law1 instrument, 1 in force

Research summary (154 words)

Vermont diverges from the federal baseline with its own Computer Crimes Act, which makes unauthorized access a crime under a bare knowing-and-intentional, without-lawful-authority test, with no built-in exception for the absence of malicious intent or deceptive means of the kind some other states carry.

Related, more serious offenses reach fraudulent access, alteration or damage, and theft or destruction, each with penalties tiered by the value of the loss, plus a private civil cause of action for anyone damaged by a violation.

No Vermont statute or reported appellate decision addresses terms-of-service enforceability, a state-specific database right, the legal weight of robots.txt for automated collection, or how the unauthorized-access statute applies to a public-facing website or automated collection specifically; those questions rest on ordinary Vermont contract and tort doctrine, untested against scraping.

Vermont's data broker act (9 V.S.A. chapter 62, subchapter 5) is a privacy-topic instrument already recorded for this jurisdiction and is not restated here.

Computer misuse

Vermont Computer Crimes Act, unauthorized access

13 V.S.A. § 4102official text, Vermont Statutes Online (legislature.vermont.gov)

In force. Binds public and private bodies.

What this law does

Section 4102 makes it unlawful for a person to knowingly and intentionally and without lawful authority access any computer, computer system, computer network, computer software, computer program, or data contained in one, punishable as a misdemeanor by up to six months' imprisonment or a $500.00 fine, or both.

Unlike Virginia's computer trespass statute, section 4102 carries no built-in exception for conduct that lacks malicious intent or a deceptive means; it is a bare without-lawful-authority test closer to the federal Computer Fraud and Abuse Act's own wording.

Related offenses in the same chapter reach access for fraudulent purposes (section 4103), alteration, damage, or interference (section 4104), and theft or destruction (section 4105), each requiring an additional element (a fraud scheme, or actual damage, deletion, or taking) that ordinary, non-disruptive automated collection does not supply on its own; penalties for those sections escalate with the value of the loss, up to ten years' imprisonment and a $25,000.00 fine where the loss or value exceeds $500.00.

A person damaged by a violation of the chapter may bring a civil action for damages, costs, and reasonable attorney's fees under section 4106.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (1,295 words)

Vermont's private-sector security posture rests on one enacted general-application statute, the Document Safe Destruction Act's disposal duty at 9 V.S.A. section 2445, plus two enacted but role-gated security-program duties, on data brokers and on insurance licensees, whose bound party the LexLint activity vocabulary cannot yet express and which are therefore deferred rather than flagged on a guess; Vermont has enacted no connected-device or product-security statute and no general private-sector duty to report an exploited vulnerability or a security incident to an authority.

9 V.S.A. section 2445, added by 2005, No. 162 (Adj.

Sess.), section 1, effective January 1, 2007, requires a business, defined broadly as any sole proprietorship, partnership, corporation, association, limited liability company or other group however organized, including a financial institution, but never the State, a State agency or a political subdivision of the State, to take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information (a signature, Social Security number, physical description, passport number, driver's license or State ID number, insurance policy number, or bank, credit or debit card number) once no longer retained, by shredding, erasing or otherwise rendering it unreadable, for the purpose of ensuring the security and confidentiality of the information, protecting against threats or hazards to its security or integrity, and protecting against unauthorized access; a business that itself disposes of personal financial information for others carries the same duty as to the personal information it handles on their behalf.

The duty does not reach a bank, credit union or other financial institution already subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a Health Insurance Portability and Accountability Act (HIPAA)-compliant health insurer or facility, or an FCRA-compliant consumer reporting agency, and it is a disposal duty only: the section imposes no ongoing obligation to safeguard personal information that remains in active use, so it is narrower than a full information-security-program mandate such as New York's SHIELD Act 899-bb or Massachusetts's 201 CMR 17.00.

No source read (9 V.S.A. section 2435, the Security Breach Notice Act, searched directly for "safeguard" and "reasonable security" and read in full) states any such ongoing safeguards duty on Vermont businesses generally; section 2435 is a pure breach-notification statute (already this jurisdiction's privacy row, the standing seam rule) and contains no affirmative security-program requirement of its own.

Separately, 9 V.S.A. section 2447, the Data Broker Duty to Protect Information, added by 2017, No. 171 (Adj.

Sess.), section 2, effective January 1, 2019, requires a data broker, defined at 9 V.S.A. section 2430(4)(A) as a business that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom it has no direct relationship, to develop, implement and maintain a comprehensive written information security program with administrative, technical and physical safeguards, and prescribes minimum program features (a designated responsible employee, a documented risk assessment, employee training, vendor oversight, physical access restrictions, annual review, and post-incident review) and minimum computer-system controls (secure authentication, access controls, encryption of transmitted and portable-device data, firewalls, patching, malware protection); a violation is deemed an unfair and deceptive act in commerce under 9 V.S.A. section 2453, enforced by the Attorney General.

Because a Vermont consumer who "sustains damages or injury as a result of any ... practices prohibited by section 2453" may sue under 9 V.S.A. section 2461(b), a violation of the data-broker security duty appears to carry a private remedy that the narrower section 2445 disposal duty, whose own enforcement clause borrows chapter 63's remedies without the same deeming language, does not.

The bound party, "data broker," is a defined business model (collecting and selling data about people with whom the business has no direct relationship) that no value in the LexLint activity vocabulary currently expresses, so no instrument is filed for section 2447 here, per the profile's standing rule for a regime whose bound party no declared activity can express; a data-broker document should add it once a profile fact for that role exists.

Act 138 (H.211), enacted in 2026 with multiple effective dates beginning July 1, 2026, revises this chapter's data-broker definitions, adds a duty to verify a recipient and its purposes before disclosing brokered personal information, adds a separate Data Broker Security Breach Notice Act (a breach-notification duty, already privacy-shaped under this topic's own seam rule), and substantially raises data-broker registration fees and registration-violation penalties; nothing in the Act's official summary indicates it rewrites the information-security-program duty in section 2447 itself, so that duty's content as described here is read from the current statute text rather than from the amending act.

Vermont also binds a defined sector through 8 V.S.A. section 4728, the Vermont Insurance Data Security Law, added by 2021, No. 139 (Adj.

Sess.), section 20, and operative January 1, 2023 (with a one- or two-year phase-in for particular subsections): a licensee, any person licensed, authorized or registered under Vermont's insurance laws, must develop, implement and maintain a comprehensive written information security program based on a documented risk assessment, with named administrative, technical and physical safeguards, board oversight, vendor due diligence, and a written incident response plan for a "cybersecurity event" (unauthorized access to, or disruption or misuse of, an information system or nonpublic information); the licensee must investigate a cybersecurity event, keep records of it for five years, and certify compliance to the Commissioner of Financial Regulation annually by April 15, but the section as read here contains no separate clock-bound duty to notify the Commissioner of an individual cybersecurity event the way many other states' adoptions of the NAIC Insurance Data Security Model Law do; a licensee with fewer than twenty employees is exempt, and the section "may not be construed to create or imply a private cause of action for violation of its provisions," enforced instead by the Commissioner under 8 V.S.A. sections 3661 and 4726.

Because "licensee" (an insurance-regulated entity) is, like "data broker," a role no current LexLint activity value expresses, no instrument is filed for section 4728 either, and it is recorded here only so a reader knows the duty exists; this mirrors how New York's DFS Part 500 is handled in this jurisdiction's own sibling document.

On product requirements, Vermont has enacted no connected-device or IoT security statute: H.630 (2026), "An act relating to adopting minimum security standards for connected devices," sponsored by Rep. Barbara Rachelson, was read a first time and referred to the House Committee on Commerce and Economic Development on January 9, 2026, had one recorded committee hearing (introduction only) on January 21, 2026, and shows no further recorded action or enactment as of this reading, so this is a researched absence rather than a gap in coverage, the same shape as New York's still-pending General Business Law 390-d. On vulnerability and incident reporting, Vermont has no general private-sector duty to report an exploited vulnerability or a security incident to an authority.

The Cybersecurity Advisory Council, established under 20 V.S.A. chapter 208 (Act 71) and continued and expanded by Act 138 through 2033, is charged to develop a statewide cybersecurity strategic plan, evaluate readiness, share best practices "as a resource for State government, Vermont businesses, and the public," and "provide technical capabilities, training, and advice to local government and the private sector," but it imposes no compliance duty, reporting obligation or penalty on a private business and belongs with government-accountability material rather than as a row in this profile's private-sector scope.

On enforcement generally, the Attorney General and State's Attorneys enforce most of this chapter under the Vermont Consumer Protection Act, chapter 63 of Title 9, which carries a civil penalty of up to $10,000.00 for each unfair or deceptive act or practice in commerce (9 V.S.A. section 2458(b)(1)); no published enforcement record specific to a security-shaped duty in this chapter was located in the sources checked.

Security baseline statutes

Document Safe Destruction Act, safe destruction of records containing personal information

9 V.S.A. § 2445 (Added 2005, No. 162 (Adj. Sess.), § 1, eff. Jan. 1, 2007)Official statute text, Vermont Statutes Online, Title 9 chapter 62

In force since 1 January 2007. Binds private bodies.

What this law does

A business must take all reasonable steps to destroy or arrange for the destruction of a customer's records within its custody or control that contain personal information no longer to be retained, by shredding, erasing or otherwise modifying the personal information to make it unreadable or indecipherable, for the purpose of ensuring the security and confidentiality of the information, protecting against anticipated threats or hazards to its security or integrity, and protecting against unauthorized access to or use of it that could cause substantial harm or inconvenience to a customer.

A business is defined to include any sole proprietorship, partnership, corporation, association, limited liability company or other group however organized and whether or not operated for profit, including a financial institution, but never the State, a State agency or a political subdivision of the State.

An entity in the business of disposing of personal financial information that conducts business in Vermont, or that disposes of Vermont residents' personal information, carries the same duty as to the information it handles on another business's behalf, by implementing and monitoring policies and procedures that protect against unauthorized access during and after collection, transportation and disposal.

The duty is limited to disposal, imposing no ongoing obligation to safeguard personal information that remains in active use, and it does not apply to a bank, credit union or other financial institution already subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a health insurer or facility already compliant with Health Insurance Portability and Accountability Act (HIPAA)'s privacy and security standards, or a consumer reporting agency already compliant with the Fair Credit Reporting Act.

The Attorney General and State's Attorneys have sole enforcement authority over a business not licensed or registered with the Department of Financial Regulation, and the Department of Financial Regulation has authority over one that is; both prosecute a violation and obtain remedies as the Attorney General and State's Attorneys have under Vermont's Consumer Protection Act, chapter 63 of this title, which sets a civil penalty of up to $10,000.00 for each unfair or deceptive act or practice in commerce.

The section does not itself declare a violation an unfair and deceptive act under 9 V.S.A. section 2453 the way the data-broker security duty at section 2447 does, so whether the Consumer Protection Act's private right of action, 9 V.S.A. section 2461(b), reaching damages caused by practices prohibited by section 2453, extends to a violation of this section is not settled by the text read here.

What it requires

Age gating law1 instrument, 1 enacted but not yet in force

Research summary (98 words)

Vermont has enacted an Age-Appropriate Design Code Act (S.69, Act 63 of 2025, signed June 12, 2025), its second attempt after Governor Scott vetoed a similar 2024 bill (H.121) over First Amendment concerns. The Act takes effect January 1, 2027; the Attorney General's rulemaking authority took effect July 1, 2025, with rules on age assurance and prohibited design practices due by January 1, 2027. The Act has not yet been challenged in court as of this date.

Vermont has not enacted an adult content age verification law, a social media minor-access law, or an app store accountability law.

Age-appropriate design code

S.69 (2025), Vermont Age-Appropriate Design Code Act (Act 63 of 2025)

9 V.S.A. ch. 62, subch. 6official enrolled act text, Vermont General Assembly

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Requires covered businesses offering online services, products, or features reasonably likely to be accessed by minors under 18 to minimize collection and use of covered minors' personal data, refrain from using minors' data in algorithmic recommendation systems except at the minor's request, bar unsignaled monitoring or location tracking of minors, prohibit push notifications to minors between midnight and 6:00 a.m., and protect age assurance data. Violations are unfair and deceptive acts in commerce under 9 V.S.A. section 2453.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.