VDPOSA: Vermont Data Privacy and Online Surveillance Act
Comprehensive Vermont privacy law granting consumer data rights with heightened health-data protections.
VDPOSA citations (11)
Short Title and Definitions
Establishes the short title, "Vermont Data Privacy and Online Surveillance Act," and defines key terms. "Sensitive data" covers data revealing racial or ethnic origin, religious beliefs, sex life, sexual orientation, status as nonbinary or transgender, citizenship or immigration status, or a mental or physical health condition, diagnosis, disability, or treatment; consumer health data; genetic or biometric data and information derived from it; personal data collected from someone the controller actually knows, or willfully disregards, is a child (as defined in COPPA); precise geolocation data; neural data; financial account or card numbers or logins that would allow account access; and government-issued ID numbers the law does not require to be publicly displayed. Compared with the Senate-passed version, which already covered consumer health data, the enacted list adds nonbinary or transgender status, disability and treatment, neural data, financial credentials, and government ID numbers, reaches genetic and biometric data generally rather than only when processed to identify someone, and drops crime-victim status. The bill as introduced reached further: it also covered data from any consumer the controller knew or should have known was a minor (under 18), keystrokes, driving behavior, cross-context online activity, income or indebtedness, union membership, and crime-victim status.
Applicability
Applies to a person that conducts business in Vermont, or produces products or services targeted to Vermont residents, and that during the preceding calendar year controlled or processed the personal data of at least 35,000 consumers, controlled or processed the sensitive data of at least 3,000 consumers (both tests exclude data processed solely to complete a payment transaction), or offered for sale the personal data of at least 3,000 consumers. Section 2415k and the other consumer health data provisions apply regardless of these thresholds. The Senate-passed version used a 100,000-consumer test, or 25,000 consumers plus more than 25% of gross revenue from selling personal data. The bill as introduced used 25,000 consumers, or 12,500 plus more than 25% of revenue, stepping down to 12,500 and 6,250 (with a 20% revenue share) on July 1, 2027 and to 6,250 and 3,125 on July 1, 2028.
Exemptions
Replaces the Senate-passed version's blanket carve-outs for all nonprofits and institutions of higher education with a granular list that largely restores, and adds to, the introduced bill's: government entities; HIPAA covered entities that are not hybrid entities, health care components of hybrid entities, and business associates; protected health information; specific federal human-subjects research regimes; Fair Credit Reporting Act activity; data subject to GLBA Title V; state- or federally chartered banks and credit unions; regulated securities professionals; persons regulated under Vermont's insurance code (8 V.S.A. part 3, other than self-insurers not otherwise in the insurance business); health care providers and facilities; victim-services data; employment-context data; and narrow nonprofit and noncommercial-media carve-outs.
Consumer Personal Data Rights
Grants rights to confirm and access personal data (including inferences derived from it, and whether it is processed for profiling behind decisions with legal or similarly significant effects), correct inaccuracies, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling in furtherance of such automated decisions. Where that profiling occurred, a consumer may, if feasible, question the result, be told the reason, and review the personal data used; only for housing decisions may the consumer also correct the data and have the decision reevaluated. Consumers may also obtain a list of the third parties to which the controller sold their personal data. Compared with the Senate-passed version, the rights to access inferences and profiling use, to question profiling results, and to obtain the sold-to list are new, and authorized-agent opt-out designation moves from a standalone section into § 2415d(b)(2). The bill as introduced had a broader list right (every third party the data was disclosed to) and a right to know whether data is used in an AI system; the Act narrowed the first and dropped the second.
Duties of Controllers
Requires data minimization, consent for sensitive-data processing and sale, non-discrimination, and a detailed privacy notice, including a statement of whether the controller collects, uses, or sells personal data to train large language models. Bars targeted advertising to, and sale of the personal data of, a consumer the controller has actual knowledge, and willfully disregards, is at least 13 but younger than 18, with no consent exception. The Senate-passed version covered only ages 13 to 15 and allowed both with consent; the bill as introduced barred a controller offering an online service, product, or feature from doing either for any minor under 18 it knew or should have known was a minor. A known child's data is sensitive data, which may be processed or sold only with consent and must be processed in accordance with COPPA. Covered businesses must also follow the Vermont Age-Appropriate Design Code Act for covered minors, and controllers must accept opt-outs sent by an opt-out preference signal whose mechanism does not rely on a default setting.
Processors’ Duties; Contracts Between Controllers and Processors
Processors must follow controller instructions and assist with consumer-rights responses, security, and breach notification. Controller-processor contracts must require confidentiality, deletion or return of data at the end of services unless the law requires retention, making available on the controller's reasonable request all information needed to demonstrate the processor's compliance, and engaging subcontractors only after the controller has an opportunity to object and under a written flow-down contract. A processor must also provide a report of an assessment to the controller on request. A processor that exceeds its instructions and starts determining the purposes of processing becomes a controller and can face direct Attorney General enforcement.
Data Protection and Impact Assessments; Disclosure to Attorney General
Controllers must conduct data protection assessments for high-risk processing (targeted advertising, sale of data, risky profiling, sensitive data). New in the enacted version: profiling used for legally or similarly significant decisions requires a separate, more detailed impact assessment covering intended use, foreseeable harms, input/output data categories, and post-deployment monitoring. Assessments are confidential but discoverable by the Attorney General; the duty applies only to activity created after January 1, 2028.
Deidentified Data
A controller holding deidentified data must take reasonable measures against re-identification, publicly commit not to re-identify it, and bind recipients to the same obligations by contract. The Act does not require re-identification to fulfill a request, and the rights to confirm, access, correct, or delete data do not apply to properly safeguarded pseudonymous data.
Construction of Duties
Clarifies that the Act does not restrict compliance with law, law-enforcement cooperation, fraud/security response, contract performance, or approved scientific research, and adds a new exception (not in the introduced bill) allowing limited internal use of personal data to detect or correct bias in automated decision-making. Also confirms the Act does not authorize facial recognition use by law enforcement.
Attorney General Enforcement; Reporting
A violation is deemed a violation of the Vermont Consumer Protection Act (9 V.S.A. chapter 63), and the Attorney General enforces it with the same chapter 63, subchapter 1 authority. The Act bars any private right of action; the bill as introduced had also given consumers a limited private right of action against data brokers and large data holders for certain violations. A separate transitional provision in the Act (Sec. 3, not part of § 2415j) provides that from January 1, 2028 through June 30, 2029, before initiating any action, the Attorney General must issue a notice of violation if the Attorney General determines a cure is possible, and may sue under § 2415j(a) if the violation is not cured within 60 days after the notice is received. The Attorney General must report to the General Assembly annually, by December 1, on enforcement activity.
Consumer Health Data Privacy
Applies regardless of the Act's general size thresholds. Bars sale of consumer health data without consent, requires confidentiality obligations for employees/contractors and processors with health-data access, and prohibits geofencing within 1,850 feet (the distance in the bill as introduced; the Senate-passed version had narrowed it to 1,750 feet, and the House restored 1,850) of any health care, mental health, or reproductive/sexual health facility for tracking or notification purposes.
Legal notice: This reference library is for informational purposes only and does not constitute legal advice. Excerpts are reproduced from official public sources and are current as of June 2026. Laws and regulations change: always verify against the authoritative source and consult a qualified attorney.