On June 16, 2026, Vermont Governor Phil Scott signed into law Senate Bill S.71, the Vermont Data Privacy and Online Surveillance Act (“VDPOSA” or the “Act”), making Vermont the 23rd state with a comprehensive consumer privacy law.
The VDPOSA follows the now-familiar controller/processor and consumer rights framework seen in many state comprehensive consumer data privacy laws, with certain distinctions.
Effective Date
The Act takes effect on January 1, 2028.
Scope
The Act’s applicability thresholds are unique in comparison to other state comprehensive consumer privacy laws.
The majority of the VDPOSA’s provisions apply to any person or entity that does business in Vermont or produces products or services targeted to Vermont residents and in the preceding calendar year met one or more of the following thresholds:
- controlled or processed the personal data of at least 35,000 Vermont consumers (excluding personal data processed solely to complete a transaction);
- controlled or processed the sensitive data of at least 3,000 Vermont consumers (excluding personal data processed solely to complete a transaction); or
- offered for sale (for monetary or other valuable consideration) the personal data of at least 3,000 Vermont consumers.
The VDPOSA’s consumer health data provisions apply to any person or entity that conducts business in Vermont or that produces products or services targeted to Vermont residents, with no other required criteria.
Notably, the Act provides that in the event of a conflict between the VDPOSA and any other law, including the Vermont Age-Appropriate Design Code, the provisions of the law that provide the greatest privacy protections control.
Like other state comprehensive privacy laws, the VDPOSA exempts certain entities and data from its scope. Exempt entities include state agencies, GLB-regulated financial institutions, HIPAA-covered entities and business associates, nonprofits and institutions of higher education. Notably, the Act also exempts health care providers and facilities that maintain PHI according to HIPAA and Vermont law even if they are not HIPAA covered entities. Data-level exemptions include HR-related data, PHI subject to HIPAA, GLBA-covered data, substance use disorder and patient safety records, and FCRA-covered data.
Key Obligations
The VDPOSA imposes several obligations on controllers, including:
- Privacy Notice: Controllers must provide a reasonably accessible and clear privacy notice that discloses the categories of personal data processed; the purposes of processing; the categories of personal data sold to third parties; the categories of third parties to whom personal data is sold; whether the controller engages in targeted advertising (including the sale of personal data in connection with targeted advertising); whether the controller processes personal data for the purpose of training large language models (“LLMs”); and the methods for submitting consumer rights requests.
- The requirement to disclose information about the processing of personal data to train LLMs is novel.
- Notably, the VDPOSA also requires controllers to notify consumers of material changes to a privacy notice and provide a reasonable opportunity for consumers to withdraw consent to any further and materially different processing of previously collected personal data.
- Data Minimization: Controllers must limit the collection of personal data to what is reasonably necessary and proportionate for the disclosed purposes, and not process a consumer’s personal data for any materially new purpose that is neither reasonably necessary to nor compatible with the disclosed purposes, unless the controller obtains consent.
- Security Safeguards: Controllers must implement and maintain reasonable administrative, technical and physical safeguards appropriate to the volume and nature of the personal data.
- Vendor Contracts: Contracts between controllers and processors must describe the nature and purpose(s) of processing; the types of personal data subject to processing; the duration of processing; the rights and obligations of both parties; and requirements for confidentiality, data return/deletion, audit cooperation and sub-processor obligations.
- Data Protection Assessments and Impact Assessments: Controllers must conduct and document data protection assessments for higher-risk processing activities, including targeted advertising, the sale of personal data, profiling that presents a foreseeable risk of harm and the processing of sensitive data. Controllers must separately conduct impact assessments for profiling that produces a legal or similarly significant effect. Controllers must disclose data protection or impact assessments to the Vermont Attorney General upon request.
- Sensitive Data: Controllers must obtain prior consent to process sensitive data, and only process such data if it is reasonably necessary in relation to the purposes for which the sensitive data was collected.
- Children’s and Minors’ Data: Controllers are prohibited from selling or processing for targeted advertising the personal data of minor consumers age 13 to 17, and must comply with the Vermont Age-Appropriate Design Code with respect to such consumers’ personal data, if applicable. Additionally, controllers must process the personal data of child consumers under the age of 13 in accordance with COPPA and, if applicable, the Vermont Age-Appropriate Design Code.
- Consumer Health Data: The Act requires entities to (1) restrict access to consumer health data to employees and contractors who are subject to confidentiality obligations; (2) ensure that any processor with access to consumer health data is contractually bound in accordance with the Act’s processor requirements; (3) refrain from using a geofence within 1,850 feet of a health care facility to identify, track, collect data from, or send notifications to consumers based on their consumer health data; and (4) obtain consumer consent before selling consumer health data.
Consumer Rights
The VDPOSA provides Vermont consumers the right to:
- confirm whether the controller is processing their personal data;
- access their personal data, in a portable copy if feasible (including any inferences drawn about the consumer and whether a controller or processor processes the consumer’s personal data for the purpose of profiling to make a decision that produces any legal or similarly significant effect);
- correct inaccuracies in the consumer’s personal data;
- delete the consumer’s personal data;
- opt out of (1) targeted advertising, (1) the sale of personal data, and (3) profiling that produces a legal or similarly significant effect; and
- obtain certain information about the use of profiling that produces a legal or similarly significant effect (including the reason that such profiling resulted in a decision and the personal data used for the profiling), and correct personal data used in a profiling decision concerning housing and have the decision be reevaluated based on the corrected personal data;
- obtain a list of third parties to whom the controller has sold their personal data; and
- appeal the denial of a privacy request.
Enforcement
The Vermont Attorney General has exclusive enforcement authority. A violation of the Act constitutes a violation of the Vermont Consumer Protection Act. A 60-day cure period applies from January 1, 2028 through June 30, 2029, after which the cure period expires.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code