In this article

Sign up for our newsletter

Share this article

Vermont’s added its own patch to the privacy patchwork in the US–and it's certainly contributing to the patchiness. The Vermont Data Privacy and Online Surveillance Act (VDPOSA) mirrors other states’ privacy laws in many ways, but diverges on several significant points.

Governor Phil Scott signed the VDPOSA into law on June 16, 2026, after vetoing a stricter version of the bill in 2024. The version that finally crossed the finish line was negotiated over roughly two years to more closely track the Connecticut Data Privacy Act, a shift business groups pushed for throughout the process.

The VDPOSA doesn't take effect until January 1, 2028, giving businesses a longer runway than most states—but if they may need it to meet Vermont’s unique provisions.

What Is the VDPOSA?

The Vermont Data Privacy and Online Surveillance Act gives Vermont residents rights over their personal data and imposes new obligations on the businesses that collect, use, and sell it.

If you're already compliant with the Connecticut Data Privacy Act, you have a head start—the core framework (controllers, processors, consumer rights, data protection assessments) will look familiar. But Vermont layered on a handful of distinctive requirements that make a copy-paste compliance approach risky. We'll walk through those early, since they're what set this law apart.

But first, let’s take a look at the law’s applicability standards (which are unique in their own right)

Who Must Comply with the VDPOSA (Applicability)

The VDPOSA applies to anybody who conducts business in Vermont, or produces products or services targeted to Vermont residents, and that during the preceding calendar year:

  • Controlled or processed the personal data of 35,000 or more consumers, excluding data processed solely to complete a payment transaction;
  • Controlled or processed the sensitive data of 3,000 or more consumers, with the same payment-transaction carve-out; or
  • Offered the personal data of 3,000 or more consumers for sale.

There's an important wrinkle here: the law's consumer health data provisions and the obligations placed on "consumer health data controllers" apply to any person doing business in or targeting Vermont—full stop, no threshold required. That means even small businesses that never come close to the general applicability thresholds could still be on the hook if they handle Vermonters' health-related data. It's a structure reminiscent of Washington's My Health My Data Act, and it's worth flagging early in any compliance assessment.

And if you’ve looked at applicability thresholds in other state laws, you’ll notice that these thresholds are quite low. Three thousand consumers is not many. Vermont only has a little over half a million residents, so any threshold based on population is going to be correspondingly low.

What Makes Vermont's Law Different

Vermont didn't just copy its neighbors' homework. Here are the provisions that set the VDPOSA apart from the rest of the state privacy patchwork.

Difference #1: Neural Data Is Sensitive Data

Vermont defines "neural data" as any information generated by measuring the activity of an individual's central nervous system. The VDPOPSA classifies neural data as sensitive, requiring consumer consent before it can be processed or sold.

Vermont joins only a small handful of states to explicitly protect neural data this way—a notable move given the growing commercial use of neurotechnology in wellness wearables and brain-computer interfaces.

Difference #2: A Dedicated Consumer Health Data Section—With a Geofencing Ban

Vermont didn't fold consumer health data protections into the general obligations section; it gave them their own section entirely (§2415k if you’d like to read the statute). Under that section, a person may not:

  • Give an employee or contractor access to consumer health data unless that person is bound by a contractual or statutory duty of confidentiality
  • Give a processor access to consumer health data without meeting the processor-contract requirements elsewhere in the law
  • Use a geofence within 1,850 feet of any health care facility—including mental health facilities and reproductive or sexual health facilities—to identify, track, collect data from, or send notifications to a consumer about their consumer health data
  • Sell consumer health data without first obtaining the consumer's consent

"Consumer health data" itself is defined broadly: any personal data a controller uses to identify a consumer's physical or mental health condition, diagnosis, or status, explicitly including gender-affirming health data and reproductive or sexual health data.

Combined with the no-threshold applicability rule above, this section has real teeth for a surprisingly wide range of businesses, not just health tech companies. Don’t mix this up with HIPAA’s “protected health information”—the VDPOSA’s “consumer health data” is a different category with different requirements.

Difference #3: Mandatory AI/LLM Disclosure in Privacy Notices

Vermont is among the first states to require a specific privacy-notice disclosure about AI training. Controllers must state whether they collect, use, or sell personal data for the purpose of training large language models. As AI-related privacy scrutiny intensifies, expect other states to follow Vermont's lead here.

Difference #4: Expanded Rights to Challenge Automated Profiling

Consumers can already opt out of profiling that leads to legally or similarly significant decisions in most state privacy laws. Vermont goes further: if a controller has already used profiling to make such a decision, the consumer can question the result, ask why the profiling led to that outcome, and review the personal data that was used. If the decision concerned housing specifically, the consumer can also correct inaccurate data used in the profiling and have the decision reevaluated based on the correction.

Difference #5: The Right to Name Names on Data Sales

Most state laws let consumers request the categories of third parties their data was sold to. Vermont lets consumers request the specific list of third parties a controller sold their personal data to—or, if the controller doesn't maintain a consumer-specific list, a list of every third party the controller sold any personal data to. The exception here is when doing so would reveal a trade secret.

Difference #6: No Private Right of Action—But Watch This Space

Enforcement rests exclusively with the Vermont Attorney General. There's no private right of action, and the law is explicit that violations aren't grounds for one. But Vermont attached unusual legislative "intent" language to that decision. Section 2(a) of the act reads:

In prohibiting a private right of action, it is the intent of the General Assembly that additional appropriations and resources will be provided in the following years to support the Office of the Attorney General’s enforcement of this Act, which may require the creation of a data privacy unit. If such appropriations or resources are not provided, the General Assembly may consider adding a private right of action for consumers.

So, if no additional resources are made available to the AG for dedicated data privacy enforcement, legislators may reconsider adding a private right of action. It’s not binding, but it does signal a level of seriousness about the enforcement of the VDPOSA–if the legislature feels the AG isn’t able to enforce the law, they’ll make sure somebody will. Consequently, keep an eye on Vermont for data privacy enforcement.

Consumer Rights Under the VDPOSA

Beyond the profiling and third-party-list rights covered above, Vermont consumers have the rights to:

  • Confirm whether a controller is processing their personal data, and access that data—including inferences drawn from it
  • Correct inaccuracies in their personal data
  • Delete personal data provided by, or obtained about, them
  • Obtain a portable copy of their data in a format that can be transmitted to another controller
  • Opt out of the processing of their data for targeted advertising, the sale of personal data, or profiling used in legally or similarly significant decisions
  • Challenge the results of automated profiling (see above for details)
  • Receive a list of the third parties that have purchased their data or all third parties that the controller sells data to (see above for details)

Consumers can also designate an authorized agent to submit opt-out requests on their behalf, including through browser or device-level signals. Note that this is effectively a requirement to honor universal opt-out signals like the Global Privacy Control (GPC), which is also a named requirement in another section of the statute.

Controllers generally must respond to rights requests within 45 days, with a possible 45-day extension for complex or numerous requests. If a controller denies a request, consumers can appeal, and the controller has 60 days to respond in writing.

Exemptions

Like most state privacy laws, the VDPOSA carves out a long list of entities and data types, including:

  • Government entities acting in the ordinary course of business
  • HIPAA-covered entities (that aren't hybrid entities) and business associates and uses of data covered by HIPAA
  • Information that could identify patients being treated for substance use disorder
  • Health care providers and facilities that maintain protected health information consistent with Vermont's health records law and HIPAA—regardless of whether they're technically "covered entities"
  • Information that identifies individuals in connection with human subjects research
  • Information created for the purpose of the Healthcare Quality Improvement Act
  • Information used to notify individuals of an emergency
  • Financial institutions subject to the Gramm-Leach-Bliley Act, and state- or federally chartered banks and credit unions
  • Entities and activity governed by the Fair Credit Reporting Act
  • Information subject to the Driver’s Privacy Protection Act, Family Educational Rights and Privacy Act, Airline Deregulation Act, Farm Credit Act
  • Entities subject to the banking and insurance statutes of the Vermont Statutes
  • A narrow set of nonprofits—specifically those established to detect insurance fraud, and those providing enrollment-verification services for postsecondary schools
  • Employment-context data, emergency contact information, and data necessary to administer benefits
  • Noncommercial journalism, broadcast, and press-association activity
  • Data collected by victim services organizations about victims or witnesses of abuse, trafficking, or violent crime

Note that unlike several other state laws, Vermont doesn't exempt nonprofits or higher-education institutions broadly—only the specific, narrow categories listed above. Additionally, this list above is not exhaustive

Controller Duties & Obligations

Controllers must:

  • Limit data collection to what's reasonably necessary for the disclosed purpose, and avoid using data for new, incompatible purposes without consent
  • Maintain reasonable administrative, technical, and physical data security practices
  • Get consent before processing or selling sensitive data, and follow COPPA (and Vermont's own children's-data provisions) for data from known children
  • Avoid unlawfully discriminatory processing and avoid discriminating against consumers who exercise their rights
  • Offer a consent-revocation mechanism at least as easy as the original consent flow, honoring revocations within 15 days
  • Refrain from processing the data of known 13-to-17-year-olds for targeted advertising or selling it, regardless of whether that data otherwise qualifies as "sensitive"

Controllers must also support a recognized universal opt-out signal that lets consumers opt out of targeted advertising and data sales without visiting every site individually—with specific requirements to keep it consumer-friendly and non-discriminatory toward other controllers. Oddly, this must not make use of a default setting–making universal opt-out signals from browsers that enable them by default (like DuckDuckGo or Brave) ineligible under this requirement. It’s unclear how a business might determine whether a universal opt-out signal was enabled by default or not.

Where the controller is a "covered business" under Vermont's Age-Appropriate Design Code Act processing data for a "covered minor," the AADC's requirements apply on top of the VDPOSA's.

Privacy notices need to cover the standard categories (data collected, purposes, consumer rights, contact information) plus Vermont's own additions: the LLM-training disclosure noted above and the most recent month and year the notice was updated.

Processor relationships must be governed by a contract spelling out processing instructions, purpose, data types, duration, and each party's obligations—including confidentiality, data deletion/return, subcontractor flow-down requirements, and audit cooperation.

Data Protection & Impact Assessments

Controllers must conduct and document data protection assessments for processing that presents a heightened risk of harm, specifically:

  • Targeted advertising
  • Sale of personal data
  • Higher-risk profiling
  • Sensitive data processing
  • Profiling for legally or similarly significant decisions.

Profiling requires an even more detailed impact assessment covering the profiling's purpose, risks, inputs, outputs, and post-deployment monitoring.

These assessments are confidential and exempt from Vermont's Public Records Act; the Attorney General can request them only in connection with an investigation. And the requirement is prospective only—it applies to processing activities created or generated after January 1, 2028, not retroactively.

Enforcement & Penalties

A VDPOSA violation is treated as a violation of the Vermont Consumer Protection Act, which carry a whopping $10,000 penalty per violation.

As covered above, there's no private right of action, a temporary 60-day cure period runs until June 30, 2029, and lawmakers have signaled a private right of action could return to the table if AG enforcement isn't adequately resourced.

Additionally, the Attorney General must submit an annual report disclosing the number of violation notices issued, the nature of each violation, how many led to enforcement actions or trials, how often cure opportunities were offered, and other relevant details. Few other state privacy laws require this level of public enforcement reporting.

How Businesses Can Prepare

January 2028 may feel like a ways off, but Vermont's distinctive provisions call for some early groundwork:

  • Map your data flows now—especially anything touching consumer health data, neural data, or personal data used to train AI models.
  • Update privacy notice templates ahead of 2028 to cover the LLM-training disclosure, third-party sale details, and required update-date stamp.
  • Audit location-based marketing and analytics for any geofencing near health care facilities, mental health facilities, or reproductive/sexual health facilities.
  • Confirm your universal opt-out signal handling meets Vermont's specific requirements.
  • Build a profiling-appeal workflow, particularly for any housing-related automated decisions.

If your team is already tracking Connecticut, Colorado, or similar comprehensive privacy laws, use this as a gap-assessment exercise rather than a build-from-scratch project—but don't assume full overlap.

Frequently Asked Questions

What is the effective date of the Vermont Data Privacy and Online Surveillance Act? January 1, 2028.

Who must comply with the VDPOSA? Businesses that conduct business in or target products/services to Vermont residents and meet one of three thresholds: processing 35,000+ consumers' personal data, processing 3,000+ consumers' sensitive data, or selling 3,000+ consumers' personal data. Consumer health data obligations apply regardless of these thresholds.

Does the VDPOSA have a private right of action? No. The Attorney General has exclusive enforcement authority. However, the legislature has signaled it may reconsider adding one if AG enforcement isn't sufficiently resourced.

Does Vermont's law have a cure period? Yes, but only temporarily. A mandatory 60-day cure period applies until June 30, 2029. After that, the AG isn't required to offer one.

Is neural data protected under Vermont's law? Yes. Neural data is defined as information generated by measuring central nervous system activity and is classified as sensitive data requiring consent to process or sell.

How does the VDPOSA treat consumer health data differently? It has its own dedicated section with obligations that apply regardless of a business's size or data volume, including a ban on geofencing within 1,850 feet of health care facilities for health data-related purposes and a consent requirement before selling consumer health data.

Get a demo of Osano today

U.S. Data Privacy Checklist

Stay up to date with U.S. data privacy laws and requirements.

Download Your Copy
2025 Law Checklist Resource Listing
Share this article