Skip to Main Content
U.S. Consumer Data Privacy Law Guide: Vermont

This state-specific guide covers data privacy law, rules, and regulations that professionals and clients often encounter or have questions about in Vermont.

Overview


Last updated: August 2026

Please note this is a highlighted overview and not a complete overview of privacy laws for this state. If you would like a complete review of this state's privacy laws or a multi-state privacy compliance cheat sheet on specific topics, please contact Vivien Peaden at vpeaden@bakerdonelson.com.

Disclaimer: These materials do not constitute legal advice and should not be substituted for the advice of legal counsel.

The Vermont Data Privacy and Online Surveillance Act (VDPOSA)

Effective Date: January 1, 2028.

1. Applicability Thresholds:

Subject to certain entity-level and data-level exemptions, the VDPOSA applies to any person doing business in Vermont or producing products or services targeting Vermont residents that, during the preceding calendar year, meets one of the following criteria:

  • Controlled or processed personal data of at least 35,000 Vermont consumers (excluding data processed solely for completing a payment transaction);
  • Controlled or processed sensitive data of at least 3,000 Vermont consumers; or
  • Offered for sale personal data of more than 3,000 consumers.

2. Exemptions and Key Definitions:

  • Entity-level Exemptions: Government entities; certain HIPAA-covered entities and business associates; certain financial institutions; broker-dealers and investment advisers regulated by the SEC; certain insurance companies and licensed professionals; and certain non-profit organizations that detect and prevent insurance fraud, among others.
     
  • Data-level Exemptions: Certain data are also exempt, including data collected in a commercial (B2B), employment, or benefits context; data covered by HIPAA and other health care-related statutes; clinical trial or research-related patient data; and data governed by the Family Educational Rights and Privacy Act (FERPA), the Fair Credit Reporting Act (FCRA), the Driver's Privacy Protection Act (DPPA), the Airline Deregulation Act, the Farm Credit Act, and the Gramm-Leach-Bliley Act (GLBA), among other exemptions.
     
  • Sales of Personal Data: Similar to California, "sales of personal data" is broadly defined in the VDPOSA as "the exchange of personal data by the Controller with a third party for monetary or other valuable consideration."
     
  • Sensitive Data: "Sensitive data" is defined broadly in the VDPOSA, including:
    • Data revealing racial or ethnic origin, religious belief, sex life, sexual orientation, status as nonbinary or transgender, citizenship or immigration status, disability or treatment, and consumer health data, including gender-affirming and reproductive or sexual health data;
    • Genetic or biometric data;
    • Personal data of children under the age of 13;
    • Precise geolocation data (i.e., within a radius of 1,750 feet or less);
    • Neural data;
    • A consumer's financial account number, login credentials, or credit/debit card number that, with required access codes, would allow access to the consumer's financial account; and
    • Government-issued identification numbers, including Social Security number, passport number, state identification card number, or driver's license number.

The VDPOSA requires Controllers to obtain consumer consent before processing or selling sensitive data. In the case of a known child, the data must be processed in accordance with the federal Children's Online Privacy Protection Act (COPPA). If a Vermont consumer revokes consent, a Controller must honor the request within 15 days.

3. Controller Obligations:

In addition to responding to various consumer rights, a Controller must comply with the following responsibilities:

  • Data Processing Agreement (DPA): A written contract, known as the DPA, between a Controller and a supplier (Processor) shall govern the Processor's processing activities. The DPA must include clear instructions for data processing, the nature and duration of processing, and the types of data processed, among other requirements. Each person processing personal data is subject to a duty of confidentiality. Before engaging any subcontractor, a Processor shall provide the Controller with an opportunity to object to the engagement. The Processor shall bind the subcontractor in writing to the same contractual obligations imposed on the Processor with respect to the personal data.
     
  • Data Protection or Impact Assessment: Yes.
    The VDPOSA requires Controllers to conduct and document a data protection assessment for certain "High-Risk Data Processing Activities," i.e., data processing involving: (1) targeted advertising; (2) sale of personal data; (3) profiling presenting a reasonably foreseeable risk of harm; and (4) processing sensitive data.
     
    Further, Vermont also uniquely requires a separate impact assessment if a Controller engages in profiling for making a "decision that produces significant effect concerning a consumer," including detailed disclosures about purpose, use cases, risk analysis, data categories, outputs, performance metrics, transparency measures, and post-deployment monitoring. During any investigation, the Attorney General may require a Controller to provide any Data Protection or Impact Assessment, which will be kept confidential and exempt from disclosure under the Public Records Act.
     
  • Privacy Notice: A Controller must provide consumers with a privacy notice that includes: categories of personal data processed; purposes for processing and a description of the processing; how consumers may exercise their rights, including appeals; categories of data sold to third parties; categories of third parties to which data is sold; disclosure of targeted advertising processing or sales for targeted advertising; and an active email or other online mechanism for Vermont consumers to contact the Controller. Notably, Vermont requires a Controller to expressly disclose, through a statement, whether the Controller collects, uses, or sells data for training large language models (LLMs).
     
  • Data Minimization and Purpose Limitation of Data Processing: The VDPOSA requires Controllers to limit collection of personal data to what is "reasonably necessary and proportionate" to the disclosed purposes. Without consumer consent, Controllers shall not process personal data for any "material new purpose" that is not reasonably necessary to or compatible with the original purposes.

4. Consumer Rights:

Subject to certain exceptions, Vermont consumers have the following rights under the VDPOSA:

  • Confirm whether a Controller (including its agent) is processing their personal data, and access the personal data, unless confirmation or access would require the Controller to reveal a trade secret. Notably, Vermont requires Controllers to:
    • Confirm whether the consumer's personal data has been processed for (i) making inferences about the consumer; or (ii) making a decision that produces any legal or similarly significant effect concerning the consumer's housing, insurance, education, financial or lending services, criminal justice, employment opportunity, or health care services;
    • Allow the consumer to obtain a list of third parties to which the Controller has sold the consumer's personal data;
  • Correct inaccuracies in the consumer's personal data;
  • Delete personal data provided by or obtained about the consumer;
  • Obtain a copy of the personal data previously provided by the consumer to the Controller in a digital format (known as Data Portability), unless providing the data would require the Controller to reveal a trade secret;
  • Opt out of processing of the consumer's personal data for targeted advertising, the sale of personal data, and profiling in furtherance of any automated decision that produces any legal or similarly significant effect concerning the consumer's housing, insurance, education, financial or lending services, criminal justice, employment opportunity, or health care services; and
  • Question and Appeal. A consumer has the right to:
    • Question a profiling decision, understand why it was made, review the data used, and have the decision reconsidered in some instances;
    • Appeal a Controller's refusal to act on a consumer request, with the Controller required to respond within 60 days.

5. Enforcement and Penalties:

Private Right of Action: None

Penalties: Up to $10,000 per violation for deceptive or unfair trade practices.

Cure Period: From January 1, 2028, through June 30, 2029, the Vermont Attorney General may offer a 60-day cure period if a cure is possible. After June 30, 2029, the cure period sunsets.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept