VDPOSA § 2415f

Processors’ Duties; Contracts Between Controllers and Processors

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
January 1, 2028
Last reviewed
September 2026
Framework
VDPOSA

What it requires

Processors must follow controller instructions and assist with consumer-rights responses, security, and breach notification. Controller-processor contracts must require confidentiality, deletion or return of data at the end of services unless the law requires retention, making available on the controller's reasonable request all information needed to demonstrate the processor's compliance, and engaging subcontractors only after the controller has an opportunity to object and under a written flow-down contract. A processor must also provide a report of an assessment to the controller on request. A processor that exceeds its instructions and starts determining the purposes of processing becomes a controller and can face direct Attorney General enforcement.

Statute text

A contract between a controller and a processor shall govern the processor's data processing procedures ... The contract shall require that the processor: (A) ensure that each person processing personal data is subject to a duty of confidentiality ...; (D) after providing the controller an opportunity to object, engage any subcontractor pursuant to a written contract ....

Vermont Data Privacy and Online Surveillance Act, § 2415fRead the full section from Vermont Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit