VDPOSA § 2415g
Data Protection and Impact Assessments; Disclosure to Attorney General
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- January 1, 2028
- Last reviewed
- September 2026
- Framework
- VDPOSA
What it requires
Controllers must conduct data protection assessments for high-risk processing (targeted advertising, sale of data, risky profiling, sensitive data). New in the enacted version: profiling used for legally or similarly significant decisions requires a separate, more detailed impact assessment covering intended use, foreseeable harms, input/output data categories, and post-deployment monitoring. Assessments are confidential but discoverable by the Attorney General; the duty applies only to activity created after January 1, 2028.
Statute text
Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer shall conduct an impact assessment for the profiling. ... Data protection and impact assessment requirements shall apply to processing activities created or generated after January 1, 2028, and are not retroactive.
Vermont Data Privacy and Online Surveillance Act, § 2415gRead the full section from Vermont Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.