Tag Archives: Vermont

Vermont

Who Is Covered?

“Data collector” means a person who, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates, or otherwise deals with personally identifiable information, and includes the state, state agencies, political subdivisions of the state, public and private universities, privately and publicly held corporations, limited liability companies, financial institutions, and retail operators. Vt. Stat. Ann. tit. 9, § 2430(6).

What Information Is Protected?

“Personally identifiable information” means a consumer’s first name or first initial and last name in combination with one or more of the following digital data elements, when the data elements are not encrypted, redacted, or protected by another method that renders them unreadable or unusable by unauthorized persons:

  1. A Social Security number;
  2. A driver license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction;
  3. A financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords;
  4. A password, personal identification number, or other access code for a financial account;
  5. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data;
  6. Genetic information; and
  7. (a) health records or records of a wellness program or similar program of health promotion or disease prevention; (b) a health care professional’s medical diagnosis or treatment of the consumer; or (c) a health insurance policy number. Vt. Stat. Ann. tit. 9, § 2430(10).

“Login credentials” means a consumer’s user name or email address, in combination with a password or an answer to a security question, that together permit access to an online account. Vt. Stat. Ann. tit. 9, § 2430(9).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of electronic data or a reasonable belief of an unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information or login credentials maintained by a data collector. Vt. Stat. Ann. tit. 9, § 2430(13).

In determining whether personally identifiable information or login credentials have been acquired or is reasonably believed to have been acquired by a person without valid authorization, a data collector may consider the following factors, among others:

  1. Indications that the information is in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;
  2. Indications that the information has been downloaded or copied;
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or
  4. That the information has been made public. Vt. Stat. Ann. tit. 9, § 2430(13)(C).

Likelihood of Harm Analysis: Notice of a security breach is not required if the data collector establishes that misuse of personally identifiable information or login credentials is not reasonably possible and the data collector provides notice of the determination that the misuse of the personally identifiable information or login credentials is not reasonably possible pursuant to the requirements of this subsection. If the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible, the data collector shall provide notice of its determination that misuse of the personally identifiable information or login credentials is not reasonably possible and a detailed explanation for said determination to the Vermont Attorney General or to the Department of Financial Regulation in the event that the data collector is a person or entity licensed or registered with the Department under Title 8 or this title. Vt. Stat. Ann. tit. 9, § 2435(d)(1).

What Triggers Notification?

Discovery or notification to the data collector of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

How Is Notice Provided To Individuals?

Timing: Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

Delivery: Delivery may be by direct notice or substitute notice. If by direct notice, it may be by:

  1. Written notice mailed to the consumer’s residence;
  2. Electronic notice, for those consumers for whom the data collector has a valid email address if: a) the data collector’s primary method of communication with the consumer is by electronic means, the electronic notice does not request or contain a hypertext link to a request that the consumer provide personal information, and the electronic notice conspicuously warns consumers not to provide personal information in response to electronic communications regarding security breaches; or b) the notice is consistent with the provisions regarding electronic records and signatures for notices in 15 U.S.C. § 7001; or
  3. Telephonic notice, provided that telephonic contact is made directly with each affected consumer and not through a prerecorded message.

Substitute notice may be made by conspicuously posting the notice on the data collector’s website if the data collector maintains one and notifying major statewide and regional media if:

  1. The data collector demonstrates that the lowest cost of providing notice to affected consumers pursuant to subdivision (6)(A) of this subsection among written, email, or telephonic notice would exceed $10,000; or
  2. The data collector does not have sufficient contact information. Vt. Stat. Ann. tit. 9, § 2435(b)(6).

Content: The notice sent to consumers must be clear and conspicuous and include each of the following, if known:

  1. The incident in general terms;
  2. The type of personally identifiable information that was subject to the security breach;
  3. The general acts of the data collector to protect the personally identifiable information from further security breach;
  4. A telephone number, toll-free if available, that the consumer may call for further information and assistance;
  5. Advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports; and
  6. The approximate date of the security breach. Vt. Stat. Ann. tit. 9, § 2435(b)(5).

If a security breach is limited to an unauthorized acquisition of login credentials for an online account other than an email account the data collector shall provide notice of the security breach to the consumer electronically or through one or more of the methods specified above and shall advise the consumer to take steps necessary to protect the online account, including to change his or her login credentials for the account and for any other account for which the consumer uses the same login credentials. Vt. Stat. Ann. tit. 9, § 2435(d)(3).

If a security breach is limited to an unauthorized acquisition of login credentials for an email account: (A) the data collector shall not provide notice of the security breach through the email account; and (B) the data collector shall provide notice of the security breach through one or more of the methods specified above or by clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an Internet protocol address or online location from which the data collector knows the consumer customarily accesses the account. Vt. Stat. Ann. tit. 9, § 2435(d)(4).

Is Notice To The Government Required?

Yes. A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General. The data collector shall notify the Attorney General or the Department, as applicable, of the date of the security breach and the date of discovery of the breach and shall provide a preliminary description of the breach within 14 business days, consistent with the legitimate needs of the law enforcement agency, of the data collector’s discovery of the security breach or when the data collector provides notice to consumers pursuant to this section, whichever is sooner. Vt. Stat. Ann. tit. 9, § 2435(b)(3).

When the data collector provides notice of the breach pursuant to subdivision (1) of this subsection (b), the data collector shall notify the Attorney General or the Department, as applicable, of the number of Vermont consumers affected, if known to the data collector, and shall provide a copy of the notice provided to consumers. The data collector may send to the Attorney General or the Department, as applicable, a second copy of the consumer notice, from which is redacted the type of personally identifiable information or login credentials that was subject to the breach, and which the Attorney General or the Department shall use for any public disclosure of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(3)(C).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a data collector provides notice to more than 1,000 consumers at one time pursuant to this section, the data collector shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. This subsection shall not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation. Vt. Stat. Ann. tit. 9, § 2435(c).

Are There Security Measure Standards?

The Social Security Number Protection Act, Vt. Stat. Ann. tit. 9, § 2440, restricts the use of individuals’ social security numbers, and the Document Safe Destruction Act, Vt. Stat. Ann. tit. 9, § 2445, requires that businesses take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that are no longer to be retained by the business.

What Are The Possible Consequences Of A Violation?

With respect to all data collectors and other entities subject to this subchapter, other than a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Attorney General and State’s Attorney shall have sole and full authority to investigate potential violations of this subchapter and to enforce, prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations made pursuant to this chapter as the Attorney General and State’s Attorney have under chapter 63 of this title. Vt. Stat. Ann. tit. 9, § 2435(h)(1).

With respect to a data collector that is a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Department of Financial Regulation shall have the full authority to investigate potential violations of this subchapter and to prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations adopted pursuant to this subchapter, as the Department has under Title 8 or this title or any other applicable law or regulation. Vt. Stat. Ann. tit. 9, § 2435(h)(2).

Are There Any Exemptions/Exceptions?

A data collector that is subject to the privacy, security, and breach notification rules adopted pursuant to the federal Health Insurance Portability and Accountability Act is deemed to be in compliance with this subchapter if: a) the data collector experiences a security breach that is limited to personally identifiable information specified in 2430(10)(A)(vii); and b) the data collector provides notice to affected consumers pursuant to the requirements of the breach notification rule in 45 C.F.R. Part 164, Subpart D. Vt. Stat. Ann. tit. 9, § 2435(e).

Additionally, a financial institution that is subject to the following guidances, and any revisions, additions, or substitutions relating to an interagency guidance shall be exempt from this section: 

  1. The Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision. 
  2. Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration. 
  3. A financial institution regulated by the Department of Financial Regulation that is subject to subdivision (1) or (2) of this subsection (g) shall notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. Vt. Stat. Ann. tit. 9, § 2435(g).