Skip to main content

Vermont's H.211 Data Broker Law: Is Your Small Business a 'Data Broker' Now?

8 min readMike ThriftMike Thrift
Vermont's H.211 Data Broker Law: Is Your Small Business a 'Data Broker' Now?

If your business has ever rented out an email list, sold aggregated customer analytics to a marketing partner, or run a loyalty program that shares purchase data with a retail chain, you might already be a "data broker" under Vermont law — and as of this summer, that label just got a lot more expensive to earn.

On June 16, 2026, Governor Phil Scott signed H.211 (now Act 138), a sweeping overhaul of Vermont's data broker registration law — the first of its kind in the country when it originally passed in 2018. The amendments don't take effect until January 1, 2027, but the compliance runway is shorter than it looks once you understand how much broader the new definitions are. A lot of small businesses that never thought of themselves as "data brokers" are about to find out otherwise.

What Vermont's Data Broker Law Actually Is

Vermont was the first state to require businesses that trade in consumer data to register with the government, well before California, Texas, Oregon, and a handful of other states followed with their own versions. The core idea has always been simple: if you knowingly collect and then sell or license personal information about people you have no direct relationship with, the state wants to know who you are, what you're selling, and how much data changes hands.

Since 2018, that's meant an annual registration with the Vermont Secretary of State, a $100 fee, and some baseline disclosure requirements. For nearly eight years, that registration has mostly been a compliance afterthought for the handful of companies large enough to clearly fit the "data broker" label — think background-check firms, marketing-data aggregators, and people-search sites.

H.211 changes that calculus for a much wider set of businesses.

What Actually Changed

The definition of "direct relationship" got narrower — and that's the part that catches people off guard. Under the old law, simply collecting information directly from a consumer was generally enough to establish a "direct relationship" and stay outside the data-broker definition. The amended law requires that the consumer intentionally interact with your business. That distinction specifically pulls in businesses that operate behind the scenes of a transaction — payment processors, loyalty-program vendors, and white-label platform providers are named examples in the legislative commentary. If a consumer's relationship is really with the retailer, restaurant, or app they think they're using — and your business is the infrastructure quietly capturing their data in the background — you may no longer qualify for the direct-relationship carve-out just because you technically collected the data yourself.

"Brokered personal information" got a lot broader too. The old law listed specific categories of data that counted. The new law replaces that list with a general standard: any information that's linked or reasonably linkable to an identified or identifiable individual — or to a household device — including derived data and unique identifiers. That's a deliberate alignment with the kind of broad definitions used in comprehensive state privacy laws, and it sweeps in things like device IDs, behavioral profiles, and inferred attributes that the original enumerated list didn't clearly reach.

New due-diligence obligations kick in before you can sell or license data. Data brokers now have to identify who's receiving brokered personal information, understand what they intend to do with it, and get certification that they won't use it for anything else. If a broker has reasonable grounds to believe the data will be misused — or used unlawfully — they're required to decline the transaction. This is a real operational obligation, not just a paperwork exercise: it means a documented intake and vetting process for every data-sharing partner, not a one-time registration filing.

One helpful carve-out: the affiliate exception. Sharing data with corporate affiliates is now explicitly excluded from the definition of a "sale," which brings Vermont in line with how Texas treats intra-company data sharing. If your data movement is confined to entities under common ownership, this amendment likely keeps you out of scope for that specific activity — though it's worth confirming your corporate structure actually qualifies before you rely on it.

The Money Side Got Serious

The fee and penalty structure is where H.211 stops being a compliance nuisance and starts being a real budget line:

RequirementOldNew
Annual registration fee$100$900
Surety bondNone specified$20,000
Failure to register$200/day
Incomplete registration (after 30 days)$1,000/day
Materially incorrect information$25,000 flat, plus $1,000/day after the correction deadline

A $900 annual fee and a $20,000 surety bond are not the kind of numbers a small business absorbs without noticing. And the daily penalty structure means that a registration mistake left uncorrected doesn't just sit there quietly — it accrues, the same way an unpaid tax liability accrues interest, for as long as it goes unaddressed.

The Vermont Secretary of State is also required to study the feasibility of a centralized consumer deletion-request platform, with a report due in December 2028 — a signal that this is very likely the first of several rounds of tightening, not the last.

Who Should Actually Be Worried

Big people-search and marketing-data firms already know they're data brokers. The businesses that should be paying closer attention are the ones that never thought the label applied to them:

  • E-commerce and subscription businesses that share customer purchase history or engagement data with an ad network, influencer platform, or co-marketing partner in exchange for money or reciprocal data.
  • SaaS platforms and app developers that monetize aggregated or "anonymized" usage data — remember, the new standard covers anything "reasonably linkable" to a person or household device, which is a much lower bar than most engineering teams assume when they call data "anonymized."
  • Loyalty program operators and payment facilitators who sit between a consumer and the retailer they think they're dealing with — exactly the scenario the narrowed "direct relationship" definition targets.
  • Affiliate marketers and lead-generation businesses whose entire model is capturing a consumer's information and selling or licensing access to it to other companies.
  • Referral and rewards programs that share member data with retail or hospitality partners as part of a cross-promotional deal.

None of these businesses would describe themselves as a "data broker" in casual conversation. Under the amended Vermont law, several of them might legally be one anyway — and ignorance of the classification doesn't make the $200-a-day penalty go away.

What to Do Before January 1, 2027

  1. Map every place customer data leaves your business. Not just obvious data sales — vendor integrations, co-marketing arrangements, ad-network pixels, and "data-sharing" partnerships that don't involve cash changing hands but do involve reciprocal access to consumer information.
  2. Test each data flow against the new "direct relationship" standard. Ask honestly: did the consumer intentionally interact with your business, or are you the infrastructure behind someone else's storefront?
  3. Check whether the affiliate exception actually covers your structure. It only applies to data shared within a genuine corporate affiliate relationship — not to arms-length partners you happen to work with regularly.
  4. Build a due-diligence process for data recipients, including a way to document what they told you the data would be used for, before the January 2027 deadline makes that a legal requirement rather than a best practice.
  5. Budget for the new fee structure now. A $900 annual registration fee and a $20,000 surety bond are real costs that belong in next year's operating budget, not a surprise you discover when a compliance deadline is already on top of you.

Compliance costs like these have a way of getting lost between departments — legal owns the registration, but finance ends up absorbing the fee, the bond premium, and any penalty exposure without a clear line item tracking it. Treating the Vermont registration fee, the surety bond cost, and any potential daily-penalty exposure as their own tracked accounts — rather than burying them in a generic "legal and professional fees" bucket — makes it much easier to see the real cost of a compliance misstep and to budget accurately for it year over year. If your business does end up registering as a data broker, that $900 fee and bond premium are recurring costs worth tracking with the same discipline you'd apply to a software subscription or an insurance premium — not treated as a one-time filing you forget about until next January.

Keep Your Compliance Costs Visible

As new state laws like Vermont's H.211 turn ordinary data-sharing partnerships into regulated activity, clear financial records make it much easier to track compliance costs, penalty exposure, and vendor obligations without losing sight of what they're actually costing you. Beancount.io offers plain-text accounting that's transparent, version-controlled, and easy to audit — no black boxes, no vendor lock-in. Get started for free and see why developers and finance-savvy business owners are switching to plain-text accounting.

Share this article