VDPOSA § 2415g

Data Protection and Impact Assessments; Disclosure to Attorney General

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
January 1, 2028
Last reviewed
September 2026
Framework
VDPOSA

What it requires

Controllers must conduct data protection assessments for high-risk processing (targeted advertising, sale of data, risky profiling, sensitive data). New in the enacted version: profiling used for legally or similarly significant decisions requires a separate, more detailed impact assessment covering intended use, foreseeable harms, input/output data categories, and post-deployment monitoring. Assessments are confidential but discoverable by the Attorney General; the duty applies only to activity created after January 1, 2028.

Statute text

Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer shall conduct an impact assessment for the profiling. ... Data protection and impact assessment requirements shall apply to processing activities created or generated after January 1, 2028, and are not retroactive.

Vermont Data Privacy and Online Surveillance Act, § 2415gRead the full section from Vermont Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit