Loading chat...
VT H0630
Bill
Status
1/9/2026
Primary Sponsor
Barbara Rachelson
Click for details
AI Summary
-
Prohibits businesses from selling internet-connected consumer electronic devices in Vermont unless they meet minimum security standards, effective July 1, 2026
-
Requires connected devices to use encryption for network communications and support automatic security updates enabled by default for a reasonable period after sale
-
Mandates strong password requirements for devices using remote authentication, with nonunique default passwords required to be reset during initial setup
-
Businesses must maintain vulnerability management systems with a public point of contact for reporting security issues throughout the product's lifecycle
-
Requires accessible privacy policies, consumer notification of policy changes, disclosure of marketing data practices with opt-out rights, and the ability for consumers to delete their data; violations constitute unfair and deceptive trade practices
Legislative Description
An act relating to adopting minimum security standards for connected devices
Last Action
Read first time and referred to the Committee on Commerce and Economic Development
1/9/2026