Law / United States / Vermont

Document Safe Destruction Act, safe destruction of records containing personal information

9 V.S.A. § 2445 (Added 2005, No. 162 (Adj. Sess.), § 1, eff. Jan. 1, 2007)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 January 2007.

A security baseline statutes rule binding private bodies.

As of 15 September 2026.

What it requires

  • This binds a business, any sole proprietorship, partnership, corporation, association, limited liability company or other group however organized and whether or not organized to operate at a profit, including a financial institution, but never the State, a State agency or a political subdivision of the State; a customer's personal information covered is a signature, Social Security number, physical description, passport number, driver's license or State identification card number, insurance policy number, bank account number, credit card number, debit card number, or other financial information.
  • Take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information once the business no longer retains them, by shredding, erasing or otherwise modifying the information to make it unreadable or indecipherable through any means.
  • An entity in the business of disposing of personal financial information on another business's behalf must implement and monitor policies and procedures that protect against unauthorized access to or use of the information during and after its collection, transportation and disposal.
  • This duty applies to disposal only; it does not itself require safeguarding personal information that remains in active use, and it exempts a Gramm-Leach-Bliley-compliant financial institution, a HIPAA-compliant health insurer or facility, and an FCRA-compliant consumer reporting agency.
  • A violation is investigated and prosecuted by the Attorney General or a State's Attorney, or by the Department of Financial Regulation for a business it licenses or registers, with remedies including a civil penalty of up to $10,000.00 for each violation under the Consumer Protection Act; the section does not itself state whether a violation carries a private right of action.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

The $10,000-per-violation civil penalty is 9 V.S.A. section 2458(b)(1), the Consumer Protection Act's general civil-penalty provision for an unfair or deceptive act or practice in commerce, made available for a section 2445 violation by section 2445(e)'s cross-reference to chapter 63 remedies rather than stated as an amount within section 2445 itself, and recoverable only by the Attorney General or a State's Attorney (or the Department of Financial Regulation for a licensed or registered business).

Rule
Per violation only
As of
15 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
10,000

Who enforces it

Enforcement body

The Attorney General or a State's Attorney for a business not licensed or registered with the Department of Financial Regulation; the Department of Financial Regulation for a business that is licensed or registered with it.

Settledness

No case law or Attorney General guidance construing section 2445's enforcement mechanism was located in the sources checked.

As of
15 September 2026
Open questions
Does the Consumer Protection Act's private right of action at 9 V.S.A. section 2461(b), which reaches a consumer who sustains damages from a practice prohibited by section 2453, extend to a violation of the Document Safe Destruction Act at section 2445, given that section 2445(e) borrows chapter 63's enforcement remedies without the express clause deeming a violation an unfair and deceptive act under section 2453 that the data-broker security duty at section 2447(d)(1) uses for the same purpose?

What it reaches

Obligation class

Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A business must take all reasonable steps to destroy or arrange for the destruction of a customer's records within its custody or control that contain personal information no longer to be retained, by shredding, erasing or otherwise modifying the personal information to make it unreadable or indecipherable, for the purpose of ensuring the security and confidentiality of the information, protecting against anticipated threats or hazards to its security or integrity, and protecting against unauthorized access to or use of it that could cause substantial harm or inconvenience to a customer.

A business is defined to include any sole proprietorship, partnership, corporation, association, limited liability company or other group however organized and whether or not operated for profit, including a financial institution, but never the State, a State agency or a political subdivision of the State.

An entity in the business of disposing of personal financial information that conducts business in Vermont, or that disposes of Vermont residents' personal information, carries the same duty as to the information it handles on another business's behalf, by implementing and monitoring policies and procedures that protect against unauthorized access during and after collection, transportation and disposal.

The duty is limited to disposal, imposing no ongoing obligation to safeguard personal information that remains in active use, and it does not apply to a bank, credit union or other financial institution already subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a health insurer or facility already compliant with HIPAA's privacy and security standards, or a consumer reporting agency already compliant with the Fair Credit Reporting Act.

The Attorney General and State's Attorneys have sole enforcement authority over a business not licensed or registered with the Department of Financial Regulation, and the Department of Financial Regulation has authority over one that is; both prosecute a violation and obtain remedies as the Attorney General and State's Attorneys have under Vermont's Consumer Protection Act, chapter 63 of this title, which sets a civil penalty of up to $10,000.00 for each unfair or deceptive act or practice in commerce.

The section does not itself declare a violation an unfair and deceptive act under 9 V.S.A. section 2453 the way the data-broker security duty at section 2447 does, so whether the Consumer Protection Act's private right of action, 9 V.S.A. section 2461(b), reaching damages caused by practices prohibited by section 2453, extends to a violation of this section is not settled by the text read here.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Vermont Statutes Online, Title 9 chapter 62

Back to the example  ·  Lint your app