Vermont's private-sector security posture rests on one enacted general-application statute, the Document Safe Destruction Act's disposal duty at 9 V.S.A. section 2445, plus two enacted but role-gated security-program duties, on data brokers and on insurance licensees, whose bound party the LexLint activity vocabulary cannot yet express and which are therefore deferred rather than flagged on a guess; Vermont has enacted no connected-device or product-security statute and no general private-sector duty to report an exploited vulnerability or a security incident to an authority.
9 V.S.A. section 2445, added by 2005, No. 162 (Adj.
Sess.), section 1, effective January 1, 2007, requires a business, defined broadly as any sole proprietorship, partnership, corporation, association, limited liability company or other group however organized, including a financial institution, but never the State, a State agency or a political subdivision of the State, to take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information (a signature, Social Security number, physical description, passport number, driver's license or State ID number, insurance policy number, or bank, credit or debit card number) once no longer retained, by shredding, erasing or otherwise rendering it unreadable, for the purpose of ensuring the security and confidentiality of the information, protecting against threats or hazards to its security or integrity, and protecting against unauthorized access; a business that itself disposes of personal financial information for others carries the same duty as to the personal information it handles on their behalf.
The duty does not reach a bank, credit union or other financial institution already subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a Health Insurance Portability and Accountability Act (HIPAA)-compliant health insurer or facility, or an FCRA-compliant consumer reporting agency, and it is a disposal duty only: the section imposes no ongoing obligation to safeguard personal information that remains in active use, so it is narrower than a full information-security-program mandate such as New York's SHIELD Act 899-bb or Massachusetts's 201 CMR 17.00.
No source read (9 V.S.A. section 2435, the Security Breach Notice Act, searched directly for "safeguard" and "reasonable security" and read in full) states any such ongoing safeguards duty on Vermont businesses generally; section 2435 is a pure breach-notification statute (already this jurisdiction's privacy row, the standing seam rule) and contains no affirmative security-program requirement of its own.
Separately, 9 V.S.A. section 2447, the Data Broker Duty to Protect Information, added by 2017, No. 171 (Adj.
Sess.), section 2, effective January 1, 2019, requires a data broker, defined at 9 V.S.A. section 2430(4)(A) as a business that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom it has no direct relationship, to develop, implement and maintain a comprehensive written information security program with administrative, technical and physical safeguards, and prescribes minimum program features (a designated responsible employee, a documented risk assessment, employee training, vendor oversight, physical access restrictions, annual review, and post-incident review) and minimum computer-system controls (secure authentication, access controls, encryption of transmitted and portable-device data, firewalls, patching, malware protection); a violation is deemed an unfair and deceptive act in commerce under 9 V.S.A. section 2453, enforced by the Attorney General.
Because a Vermont consumer who "sustains damages or injury as a result of any ... practices prohibited by section 2453" may sue under 9 V.S.A. section 2461(b), a violation of the data-broker security duty appears to carry a private remedy that the narrower section 2445 disposal duty, whose own enforcement clause borrows chapter 63's remedies without the same deeming language, does not.
The bound party, "data broker," is a defined business model (collecting and selling data about people with whom the business has no direct relationship) that no value in the LexLint activity vocabulary currently expresses, so no instrument is filed for section 2447 here, per the profile's standing rule for a regime whose bound party no declared activity can express; a data-broker document should add it once a profile fact for that role exists.
Act 138 (H.211), enacted in 2026 with multiple effective dates beginning July 1, 2026, revises this chapter's data-broker definitions, adds a duty to verify a recipient and its purposes before disclosing brokered personal information, adds a separate Data Broker Security Breach Notice Act (a breach-notification duty, already privacy-shaped under this topic's own seam rule), and substantially raises data-broker registration fees and registration-violation penalties; nothing in the Act's official summary indicates it rewrites the information-security-program duty in section 2447 itself, so that duty's content as described here is read from the current statute text rather than from the amending act.
Vermont also binds a defined sector through 8 V.S.A. section 4728, the Vermont Insurance Data Security Law, added by 2021, No. 139 (Adj.
Sess.), section 20, and operative January 1, 2023 (with a one- or two-year phase-in for particular subsections): a licensee, any person licensed, authorized or registered under Vermont's insurance laws, must develop, implement and maintain a comprehensive written information security program based on a documented risk assessment, with named administrative, technical and physical safeguards, board oversight, vendor due diligence, and a written incident response plan for a "cybersecurity event" (unauthorized access to, or disruption or misuse of, an information system or nonpublic information); the licensee must investigate a cybersecurity event, keep records of it for five years, and certify compliance to the Commissioner of Financial Regulation annually by April 15, but the section as read here contains no separate clock-bound duty to notify the Commissioner of an individual cybersecurity event the way many other states' adoptions of the NAIC Insurance Data Security Model Law do; a licensee with fewer than twenty employees is exempt, and the section "may not be construed to create or imply a private cause of action for violation of its provisions," enforced instead by the Commissioner under 8 V.S.A. sections 3661 and 4726.
Because "licensee" (an insurance-regulated entity) is, like "data broker," a role no current LexLint activity value expresses, no instrument is filed for section 4728 either, and it is recorded here only so a reader knows the duty exists; this mirrors how New York's DFS Part 500 is handled in this jurisdiction's own sibling document.
On product requirements, Vermont has enacted no connected-device or IoT security statute: H.630 (2026), "An act relating to adopting minimum security standards for connected devices," sponsored by Rep. Barbara Rachelson, was read a first time and referred to the House Committee on Commerce and Economic Development on January 9, 2026, had one recorded committee hearing (introduction only) on January 21, 2026, and shows no further recorded action or enactment as of this reading, so this is a researched absence rather than a gap in coverage, the same shape as New York's still-pending General Business Law 390-d. On vulnerability and incident reporting, Vermont has no general private-sector duty to report an exploited vulnerability or a security incident to an authority.
The Cybersecurity Advisory Council, established under 20 V.S.A. chapter 208 (Act 71) and continued and expanded by Act 138 through 2033, is charged to develop a statewide cybersecurity strategic plan, evaluate readiness, share best practices "as a resource for State government, Vermont businesses, and the public," and "provide technical capabilities, training, and advice to local government and the private sector," but it imposes no compliance duty, reporting obligation or penalty on a private business and belongs with government-accountability material rather than as a row in this profile's private-sector scope.
On enforcement generally, the Attorney General and State's Attorneys enforce most of this chapter under the Vermont Consumer Protection Act, chapter 63 of Title 9, which carries a civil penalty of up to $10,000.00 for each unfair or deceptive act or practice in commerce (9 V.S.A. section 2458(b)(1)); no published enforcement record specific to a security-shaped duty in this chapter was located in the sources checked.