VDPOSA § 2415h
Deidentified Data
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- January 1, 2028
- Last reviewed
- September 2026
- Framework
- VDPOSA
What it requires
A controller holding deidentified data must take reasonable measures against re-identification, publicly commit not to re-identify it, and bind recipients to the same obligations by contract. The Act does not require re-identification to fulfill a request, and the rights to confirm, access, correct, or delete data do not apply to properly safeguarded pseudonymous data.
Statute text
A controller in possession of deidentified data shall: (1) take reasonable measures to ensure that the data cannot be associated with an individual; (2) publicly commit to maintaining and using deidentified data without attempting to reidentify the data; and (3) contractually obligate any recipients of the deidentified data to comply with the provisions of this subchapter.
Vermont Data Privacy and Online Surveillance Act, § 2415hRead the full section from Vermont Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.