VDPOSA § 2415f
Processors’ Duties; Contracts Between Controllers and Processors
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- January 1, 2028
- Last reviewed
- September 2026
- Framework
- VDPOSA
What it requires
Processors must follow controller instructions and assist with consumer-rights responses, security, and breach notification. Controller-processor contracts must require confidentiality, deletion or return of data at the end of services unless the law requires retention, making available on the controller's reasonable request all information needed to demonstrate the processor's compliance, and engaging subcontractors only after the controller has an opportunity to object and under a written flow-down contract. A processor must also provide a report of an assessment to the controller on request. A processor that exceeds its instructions and starts determining the purposes of processing becomes a controller and can face direct Attorney General enforcement.
Statute text
A contract between a controller and a processor shall govern the processor's data processing procedures ... The contract shall require that the processor: (A) ensure that each person processing personal data is subject to a duty of confidentiality ...; (D) after providing the controller an opportunity to object, engage any subcontractor pursuant to a written contract ....
Vermont Data Privacy and Online Surveillance Act, § 2415fRead the full section from Vermont Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.