On June 16, 2026, Vermont Governor Phil Scott signed into law Act No. 145 (S.71), titled “An act relating to consumer data privacy and online surveillance.” The Act creates the new Vermont Data Privacy and Online Surveillance Act (“VDPOSA”), which goes into effect on January 1, 2028 and will be codified in 9 V.S.A., Chapter 61A, §§ 2415a-2415k. Generally speaking, the VDPOSA bears many similarities to various other state privacy laws that have been enacted in the United States to date. There currently are nineteen such laws in effect, with four more (including Vermont) going into effect in 2027 or 2028.
Definitions (9 V.S.A. § 2415a)
The VDPOSA includes definitions for 50 terms that are used throughout its provisions. Many of these terms are defined similarly to how they are defined in other U.S. state privacy laws. A “consumer” is defined as a Vermont resident acting in an individual or household, and not a commercial or employment, capacity. A “controller” is defined as a person who, alone or jointly with others, determines the purpose and means of processing personal data, and a “processor” is defined as a person who processes personal data on behalf of a controller or another processor. (Controllers who deal with consumer health data are further defined as “consumer health data controllers.”) For purposes of these definitions and throughout, the terms “process” or “processing” mean any operation or set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. Also, the VDPOSA does not apply to any person’s processing of personal data in the course of purely personal or household activities.
“Personal data” is defined in the VDPOSA as any information—including derived data and unique identifiers but excluding deidentified data and publicly-available information—that is linked or reasonably linkable to either (a) an identified or identifiable individual or (b) a device that identifies, is linked to, or is reasonably linkable to one or more identified or identifiable individuals. By its inclusion of devices, this definition is broader than in many of the other U.S. privacy laws.
Another key term is “sensitive data,” which is also defined more broadly than in many other states’ laws, and means personal data that:
- reveals a consumer’s racial or ethnic origin, religious beliefs, sex life, sexual orientation, status as transgender or nonbinary, or citizenship or immigration status;
- reveals a consumer’s mental or physical health condition, diagnosis, disability, or treatment;
- is consumer health data;
- is biometric or genetic data, or information derived from such data;
- is collected from an individual whom the controller knows, or willfully disregards, is a child (as defined under COPPA);
- is precise geolocation data;
- is neural data;
- is a financial account number, financial account login information, or credit or debit card number that, in combination with any required security or access code/password/credentials, would allow access to a consumer’s financial account; or
- is a government-issued identification number (such as Social Security number, passport number, State identification card number, or driver’s license number) that applicable law does not require to be publicly displayed.
Applicability and Exemptions (9 V.S.A. §§ 2415b-2415c)
The VDPOSA applies to any person that both (1) either conducts business in Vermont or produces products or services targeted to Vermont residents and (2) during the preceding calendar year either (a) controlled or processed the personal data of 35,000 or more consumers (excluding personal data controlled or processed solely for the purpose of completing a payment transaction), (b) controlled or processed the sensitive data of 3,000 or more consumers (excluding personal data controlled or processed solely for the purpose of completing a payment transaction), or (c) offered for sale in trade or commerce the personal data of 3,000 or more consumers. See 9 V.S.A. § 2415b. Given these relatively low thresholds, the VDPOSA is likely to have wide application both inside and outside Vermont.
In addition to the general applicability thresholds, the VDPOSA’s provisions concerning consumer health data and consumer health data controllers apply to any person that conducts business in Vermont or produces products or services targeted to residents of Vermont.
Similar to other U.S. privacy laws, the VDPOSA contains a fairly long list of entity-level exemptions, data-level exemptions, and activity-level exemptions. See 9 V.S.A. § 2415c. Most of these exemptions are at the specific data/activity level, and include various types of health-related data; emergency contact information; data regulated under or subject to the Fair Credit Reporting Act, the Driver’s Privacy Protection Act, the Family Educational Rights and Privacy Act, the Airline Deregulation Act, the Farm Credit Act, the Controlled Substances Act, or Title V of the Gramm-Leach-Bliley Act; information processed for purposes of compliance, enrollment, degree verification, or related research services on behalf of post-secondary schools; data related to non-commercial activities of certain news and media organizations; data on victims or witnesses of abuse, domestic violence, and other crimes collected or processed by victim services organizations; and employee, job applicant, and independent contractor data processed within the context of those positions.
At the entity level, there are exemptions for federal, state, tribal, and local government entities; covered entities, business associates, and hybrid entities (health care components only) under the Health Insurance Portability and Accountability Act (HIPAA); state- or federally-chartered banks and credit unions, as well as their affiliates and subsidiaries if principally engaged in financial activities; SEC-regulated agents, broker-dealers, investment advisers, and investment-adviser representatives; Vermont-regulated insurance entities; health care providers and facilities that maintain protected health information in accordance with Vermont law and HIPAA; and third-party administrators regulated by the Vermont Department of Financial Regulation.
Notably, unlike most other states’ laws, the VDPOSA does not contain an across-the-board exemption for non-profit organizations; instead the Vermont exemption flows only to non-profits that are established to detect and prevent fraudulent acts in connection with insurance. Also unlike most other states’ laws, the VDPOSA does not exempt institutions of higher education from its scope.
Consumer Rights (9 V.S.A. § 2415d)
As with other U.S. privacy laws, the VDPOSA grants consumers a number of rights with respect to their personal data, subject to various exceptions and limitations. Specifically, a consumer has the right to:
- confirm whether or not a controller is processing the consumer’s personal data and access that data, unless such confirmation or access would require the controller to reveal a trade secret or the controller is prohibited from disclosing such personal data (for certain types of personal data enumerated in the VDPOSA—e.g., Social Security numbers—the controller may not disclose the data in response to a request, and instead may only inform the requesting consumer whether the controller has collected such data);
- correct inaccuracies in the consumer’s personal data;
- delete personal data provided by or obtained about the consumer;
- obtain a copy of the consumer’s personal data from the controller in a portable, readily usable, and transmittable format (if the processing of personal data is done by automated means), although the controller is not required to reveal any trade secrets;
- opt out of the processing of personal data for the purposes of targeted advertising, the sale of personal data, or profiling in furtherance of any automated “decision that produces any legal or similarly significant effect” concerning the consumer;
- question the result of any profiling of personal data in furtherance of any automated decision that produced any legal or similarly significant effect concerning the consumer; be informed of why such profiling resulted in such decision; review the consumer’s personal data that was processed for such profiling; and if the profiling decision concerned housing, taking into account the nature of the personal data and the purposes for which such personal data were processed, be allowed to correct any incorrect personal data that was processed for such profiling and have the profiling decision reevaluated based on the corrected personal data; and
- obtain a list of third parties to which the controller has sold the consumer’s personal data (if not available specifically for the consumer, the list can be more general), although the controller is not required to reveal any trade secrets.
Under the VDPOSA, “targeted advertising” is defined—subject to a few exceptions—as the displaying of an advertisement to a consumer based on the consumer’s activity over time and across nonaffiliated websites or online applications to predict the consumer’s preferences or interests.
The VDPOSA defines “sale of personal data”—subject to a few exceptions—as the exchange of a consumer’s personal data by the controller to a third party for monetary or other valuable consideration. There are a variety of exceptions to what constitutes a sale, such as disclosing personal data to a processor that processes the personal data on behalf of the controller, to a third party for purposes of providing a product or service requested by the consumer, or to an affiliate of the controller.
“Profiling” is defined in the VDPOSA as any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects, including an individual’s economic situation, health, personal preferences, interests, reliability, behavior, location, movements, or identifying characteristics. In the context of profiling, a “decision that produces any legal or similarly significant effect” concerning the consumer is defined as “any decision made by the controller, or on behalf of the controller, that results in the provision or denial by the controller of any financial or lending service, any housing, any insurance, any education enrollment or opportunity, any criminal justice, any employment opportunity, or any health care service.”
Consumers may exercise their rights under the VDPOSA by submitting a request using a secure and reliable method specified by the controller in the privacy notice required by the VDPOSA (see below). See 9 V.S.A. § 2415d(b). A parent or legal guardian may exercise rights on behalf of a child, and a guardian or conservator may exercise rights on behalf of a consumer who is subject to a guardianship, conservatorship, or other protective arrangement. Also, a consumer may designate an authorized agent to act on his or her behalf for exercising rights to opt out of processing.
Controllers must respond to consumer rights requests within 45 days (or more if reasonably necessary) and must notify the consumer without undue delay (and within 45 days) if the controller declines to take action on a request. See 9 V.S.A. § 2415d(c). A controller is not required to comply with a request to exercise any of the consumer rights other than the opt-out right if the controller is unable to authenticate the request, provided that the controller informs the consumer that additional authenticating information is needed. A controller is not obligated to authenticate an opt-out request, but may deny any such requests that appear to be fraudulent.
Finally, a controller must establish a process by which a consumer can appeal the controller’s refusal to act upon a rights request. See 9 V.S.A. § 2415d(d). The process must be conspicuously available to consumers, must allow a reasonable time for appeals, must provide for approval or denial of appeals within 60 days of receipt, and must include an online mechanism or other method for consumers to contact the Vermont Attorney General’s Office.
Duties of Controllers and Processors (9 V.S.A. §§ 2415e–2415f, § 2415i)
The VDPOSA enumerates a wide range of requirements and prohibitions on controllers and processors. See 9 V.S.A. §§ 2415e-2415f. Specifically, controllers must:
- limit the collection of a consumer’s personal data to what is reasonably necessary and proportionate in relation to the purposes for which the data are processed, as disclosed to the consumer;
- establish, implement, and maintain reasonable (i.e., appropriate to the volume and nature of the personal data processed) administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data;
- provide an easy and effective mechanism for consumers to revoke consent to processing of their personal data, and upon revocation, cease processing the data within 15 days of the request to revoke;
- comply with the Vermont Age-Appropriate Design Code Act (9 V.S.A. § 2449f), if applicable; and
- provide a reasonably accessible, clear, and meaningful privacy notice (see below).
On the other hand, controllers must not:
- process personal data for any material new purpose that is neither reasonably necessary to nor compatible with an already-disclosed purpose, unless the consumer consents;
- process sensitive data unless the consumer consents and the processing is reasonably necessary to the purposes for which the data was collected;
- sell sensitive data, unless the consumer consents;
- process sensitive data of children, unless in accordance with COPPA and, if applicable, the Vermont Age-Appropriate Design Code Act (9 V.S.A. § 2449f);
- process personal data in violation of state and federal laws that prohibit unlawful discrimination;
- sell or process for purposes of targeted advertising the personal data of consumers known to be between 13-17 years of age; or
- discriminate against consumers who exercise their privacy rights under the VDPOSA.
As for processors, the VDPOSA requires them to (1) follow the instructions of controllers; (2) assist controllers in meeting their various obligations under the VDPOSA (including with responding to consumer requests, maintaining security in processing, notifying affected parties of data breaches, and preparing data protection and impact assessments); (3) only process personal data pursuant to a written contract with the controller (see below); and (4) provide to controllers upon request any reports of assessments of the processor’s policies and security measures.
In addition to stating various duties and restrictions on controllers and processors, the VDPOSA outlines a variety of limitations on these duties and restrictions. See 9 V.S.A. § 2415i. For example, the provisions in the VDPOSA do not restrict controllers’ and processors’ ability to comply with laws, regulations, government investigations, evidentiary privileges, subpoenas, etc.; cooperate with law enforcement agencies; provide products and services specifically requested by consumers; perform under contracts to which a consumer is a party; take steps at the request of a consumer prior to entering into a contract; take steps to protect interests essential for the life or safety of the consumer; establish, exercise, or defend legal claims; prevent, detect, or respond to network security incidents and related criminal activity; engage in public or peer-reviewed research in the public interest; assist other controllers, processors, or third parties with any obligations under the VDPOSA; process data for reasons of public interest; or make internal use of data for various enumerated purposes. Additionally, the VDPOSA may not be construed so as to impose obligations on controllers or processors that adversely affect any person’s rights or freedoms, such as those under the First Amendment, or to apply to a person’s processing of personal data in the course of purely personal or household activities.
The VDPOSA also permits controllers to offer a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee if the offering is in connection with a consumer’s voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program.
Finally, all processing of personal data must be reasonably necessary and proportionate to the purposes of the processing, and must be adequate, relevant, and limited to what is necessary in relation to those purposes. The collection, use, or retention of personal data must also take into account the nature and purposes of those activities, and reasonable administrative, technical, and physical measures must be employed to protect the confidentiality, integrity, and accessibility of personal data and to reduce reasonably foreseeable risks of harm to consumers.
Privacy Notice (9 V.S.A. § 2415e)
As noted above, the VDPOSA requires controllers to provide consumers with a reasonably accessible, clear, and meaningful privacy notice. See 9 V.S.A. § 2415e(c). The notice must be publicly available (1) through a conspicuous hyperlink that includes the word “privacy” and appears on the controller’s website home page, the application store page or download page of a mobile device, and the application settings menu; (2) through a medium in which the controller regularly interacts with consumers; (3) in each language in which the controller provides its products or services or carries out any related activity; and (4) in a manner that is reasonably accessible to and usable by individuals with disabilities.
As for content, the privacy notice must:
- list the categories of personal data that the controller processes;
- describe how the controller processes personal data and the purposes for processing;
- describe how consumers may exercise their consumer rights under the VDPOSA and appeal a decision by the controller with regard to requests to exercise such rights;
- list the categories of personal data that the controller sells to third parties, if any;
- list the categories of third parties, if any, to which the controller sells personal data;
- provide a clear and conspicuous description of (1) any processing of personal data for the purpose of targeted advertising or (2) any sale of personal data to third parties for the purpose of targeted advertising;
- provide an active email address or online mechanism for contacting the controller;
- include a statement disclosing whether the controller collects, uses, or sells personal data for the purpose of training large language models; and
- identify the most recent month and year when the privacy notice was updated.
The privacy notice must also describe one or more secure and reliable means by which consumer rights requests may be submitted. These means must take into account (1) the ways in which consumers normally interact with the controller, (2) the need for security and reliability in communications related to the request, and (3) the controller’s ability to verify the identity of consumers who make requests. The means must also provide a clear and conspicuous link on the controller’s website to a web page where consumers or their authorized agents may exercise opt-out rights. In addition, the means must allow consumers to opt-out through an opt-out preference signal sent via a platform, technology, or mechanism that meets various criteria enumerated in the VDPOSA.
Notably, in the event a controller makes any “retroactive material change” to its privacy notice or practices, the controller must notify consumers affected by the change with respect to any personal data to be collected after the effective date of the change. (The term “retroactive material change” is not defined in the VDPOSA.) To provide this notice, the controller must take all reasonable electronic measures, taking into account available technology and the nature of the controller’s relationship with the affected consumers. In addition, the controller must provide a reasonable opportunity for affected consumers to withdraw consent to any further and materially different collection, processing, or transfer of previously-collected personal data following the change.
Data Processing Contracts (9 V.S.A. § 2415f)
A contract between a controller and a processor must be valid and binding on both parties and must:
- set forth clear instructions for processing data;
- identify the nature and purpose of the processing;
- identify the type of data that is subject to processing;
- indicate the duration of the processing;
- specify the rights and obligations of both parties under the contract;
- ensure that each person that processes personal data is subject to a duty of confidentiality regarding such data;
- require the processor, at the controller’s direction, to delete the personal data or return the personal data to the controller at the end of the provision of services, unless a law requires the processor to retain the personal data;
- require the processor to make available to the controller upon reasonable request all information the controller needs to verify that the processor has complied with all of its obligations under the VDPOSA; and
- require the processor, in the event it engages another person to assist with processing personal data on the controller’s behalf, to enter into a subcontract with such person, after providing the controller an opportunity to object.
Data Protection and Impact Assessments (9 V.S.A. § 2415g)
The VDPOSA requires controllers to conduct and document a data protection assessment for each of the following processing activities (if performed), as such activities are deemed under the VDPOSA to present a “heightened risk of harm” to a consumer:
- the processing of personal data for the purpose of targeted advertising;
- the sale of personal data;
- the processing of personal data for the purpose of profiling, where the profiling presents a reasonably foreseeable risk of (a) unfair or deceptive treatment or unlawful disparate impact, (b) financial, physical, or reputational injury to a consumer, (c) unreasonably offensive physical or other intrusion upon solitude, seclusion, or private affairs or concerns, or (d) other substantial injury to consumers; and
- the processing of sensitive data.
Data protection assessments must identify and weigh any potential benefits from the processing to the controller, the consumer, other stakeholders, and the public against the potential risks to the consumer from the processing, as mitigated by risk reduction safeguards that can be employed by the controller. In addition, assessments must factor in the use of deidentified data, the reasonable expectations of consumers, the context of the processing, and the relationship between the controller and consumers.
In the case of profiling for the purpose of making a decision that produces any legal or similarly significant effect concerning a consumer, a controller must conduct an impact assessment that includes the following (to the extent reasonably known by or available to the controller):
- a statement disclosing the purpose, intended use cases, deployment context of, and benefits afforded by the profiling;
- an analysis of any known or reasonably foreseeable heightened risk of harm to a consumer due to the profiling, including the nature of such heightened risk and the steps taken to mitigate such risk;
- a description of the main categories of personal data used for the profiling and the outputs produced by the profiling;
- an overview of the main categories of personal data, if any, used to customize the profiling;
- any metrics used to evaluate the performance and known limitations of the profiling;
- a description of any transparency measures taken concerning the profiling, including disclosure to consumers that profiling is occurring; and
- a description of the post-deployment monitoring and user safeguards provided concerning the profiling.
The Vermont Attorney General may require a controller to disclose any data protection or impact assessment if relevant to an investigation conducted by the Attorney General. Any assessments provided to the Attorney General are kept confidential and are exempt from public records requests.
Deidentified and Pseudonymous Data (9 V.S.A. § 2415h)
Like most of the other state privacy laws, the VDPOSA contains various provisions directed specifically toward deidentified and pseudonymous data. “Deidentified data” is data that does not identify and cannot be reasonably used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to the individual. Regarding deidentified data (which does not qualify as “personal data” in any instance), the VDPOSA requires controllers to take reasonable measures to prevent the data from being associated with an individual. Controllers must also publicly commit to maintaining and using deidentified data without attempting to reidentify it and must contractually obligate any recipients of the data to comply with the VDPOSA. “Pseudonymous data” is defined as data that cannot be attributed to a specific individual without the use of additional information, provided the additional information is kept separately and is subject to appropriate technical and organizational measures to ensure personal data is not attributed to an identified or identifiable individual. Regarding pseudonymous data (which does qualify as “personal data”), consumers do not have many of the rights that are available for other forms of personal data—with the exception of the rights to opt-out of targeted advertising, sale, or profiling; to question and obtain additional information about profiling; and to obtain a list of third parties to which the controller has sold the consumer’s personal data—if the controller can demonstrate that information necessary to identify the consumer is separately kept and inaccessible to the controller. Finally, controllers that disclose or transfer deidentified or pseudonymous data must reasonably monitor compliance with any contractual obligations governing the data and must take appropriate steps to address any breaches of such obligations.
Consumer Health Data Privacy (9 V.S.A. § 2415k)
The VDPOSA contains a few provisions specifically addressing the confidentiality of “consumer health data,” which is defined as “any personal data that a controller uses to identify a consumer’s physical or mental health condition, diagnosis, or status, including gender-affirming health data and reproductive or sexual health data.” These provisions prevent any person from (1) providing employees or contractors with access to consumer health data unless the recipient is subject to a contractual or statutory duty of confidentiality; (2) providing processors with access to consumer health data unless both parties comply with the VDPOSA’s provisions governing duties of processors (see above); (3) using a geofence to establish a virtual boundary that is within 1,850 feet of any health care facility (including any mental health facility or reproductive or sexual health facility) for the purpose of identifying, tracking, collecting data from, or sending any notification to a consumer regarding the consumer’s consumer health data; or (4) selling or offering to sell consumer health data without first obtaining consumer consent.
Enforcement (9 V.S.A. § 2415j)
Violations of the VDPOSA are expressly deemed to be violations of the Vermont Consumer Protection Act (9 V.S.A. § 2451 et seq.). However, there is no private right of action for consumers. The Vermont Attorney General is given the exclusive authority to enforce violations. In addition, during the period from January 1, 2028 through June 30, 2029, the Attorney General must issue a notice of violation to an alleged violator—prior to initiating any enforcement action—if the Attorney General determines that a cure is possible. If the violation is not cured within 60 days of the notice, an enforcement action may be brought.
What Can Your Business Do to Prepare?
Although the VDPOSA does not go into effect until January 1, 2028, it is never too early to begin preparing for compliance. The good news is that, if your business is already subject to and in compliance with existing privacy laws in other states (California, Connecticut, etc.), then achieving compliance with the VDPOSA may be a relatively seamless process. For smaller or more localized businesses that have not yet had to comply with any comprehensive privacy laws, the process likely will be more complicated.
A critical first step is to determine what types of personal data regarding Vermont residents are processed by your business and, in a given year, for how many Vermont residents your business processes the data. (And remember: “personal data” is very broadly defined to include any information that can be reasonably linked to an identified or identifiable Vermont resident, and “processing” is very broadly defined to include collection, use, storage, disclosure, analysis, deletion, modification, and more.) This step will involve understanding how and where you collect or receive data—which might not be obvious at first glance.
It is also important to determine the purposes for which your business processes personal data of Vermont residents and, even more importantly, whether this processing is necessary and is limited as much as reasonably possible. You will also need to consider with what third parties your business shares personal data, how it is shared, for what purposes it is shared, and whether there is an adequate contract in place to govern the data.
Another key item is whether your business’s current privacy policy or privacy notice (if you have one) adequately describes and discloses the organization’s data practices. Along the same lines, your business will need to put in place secure and reliable mechanisms for consumers to exercise the various rights afforded to them by the VDPOSA.
How DRM Can Help
Working through these and other challenges presented by the VDPOSA can be a daunting task. DRM’s Data Privacy team can help, including assessing whether the law applies to your organization, advising on compliance matters, drafting or updating privacy notices, drafting or reviewing data processing agreements with vendors, and guiding data protection and impact assessments.
Please reach out to Matt Borick or Jenny Drake with any questions about the VDPOSA or your organization’s compliance efforts.
This article is for informational purposes only and does not constitute legal advice. Legal advice tailored to your organization’s specific circumstances requires a new engagement with DRM.