More

    Vermont Enacts Comprehensive Consumer Privacy Law, Now 23rd State to Do So

    Vermont Data Privacy and Online Surveillance Act: A New Era of Consumer Protection

    On June 16, 2026, Vermont marked a significant milestone in the realm of digital privacy when Governor Phil Scott signed Senate Bill S.71 into law. The Vermont Data Privacy and Online Surveillance Act (VDPOSA) positions Vermont as the 23rd state to enact a comprehensive consumer privacy law. Departing from traditional frameworks, the VDPOSA sets a distinctive standard that blends consumer rights with enhanced protections against digital surveillance.

    Effective Date and Scope of the Act

    The VDPOSA is set to take effect on January 1, 2028. This date serves as a launchpad for a myriad of obligations that businesses operating in Vermont will need to adhere to. The Act’s applicability is noteworthy—any entity either doing business in Vermont or targeting Vermont residents will find themselves under its jurisdiction if they meet certain thresholds in relation to personal data.

    To be specific, the Act applies to businesses that, in the preceding calendar year:

    • Controlled or processed the personal data of at least 35,000 Vermont consumers (excluding data solely for completing transactions).
    • Handled sensitive data for at least 3,000 Vermont consumers.
    • Sold personal data of at least 3,000 Vermont consumers in exchange for monetary or other valuable considerations.

    Additionally, provisions related to consumer health data cover virtually any entity operating in Vermont, accentuating the critical nature of health information privacy.

    A standout feature of the VDPOSA is its provision to prioritize the law offering the greatest privacy protections in the event of conflicts with other laws, including the Vermont Age-Appropriate Design Code.

    Exemptions from the VDPOSA

    Like many privacy laws, the VDPOSA includes a range of exemptions. Certain entities are entirely exempt, such as:

    • State agencies
    • GLB-regulated financial institutions
    • HIPAA-covered entities and their business associates
    • Nonprofits and institutions of higher education

    Additionally, various types of data are exempted, including:

    • Human Resources-related data
    • Protected Health Information (PHI) governed by HIPAA
    • Data covered by the Gramm-Leach-Bliley Act (GLBA)
    • Records associated with substance use disorders and patient safety

    This framework reflects an effort to strike a balance between consumer protection and the realities of data management across varied sectors.

    Key Obligations Imposed on Controllers

    The VDPOSA introduces a range of responsibilities for data controllers, which can be understood through several key obligations:

    Privacy Notice

    Controllers must provide a comprehensive privacy notice that is both clear and accessible. This notice should detail categories of personal data processed, purposes for processing, third parties involved in selling personal data, and any engagement in targeted advertising. Notably, it also calls for disclosure regarding the use of personal data for training large language models (LLMs), highlighting the evolving landscape of AI technologies.

    Data Minimization

    The Act mandates that data collected is strictly limited to what is necessary for the stated purposes. Any processing of personal data for different purposes requires explicit consumer consent.

    Security Safeguards

    On the technical side, entities are required to implement robust administrative, technical, and physical safeguards in alignment with the nature and volume of the data processed. This is a proactive measure designed to anticipate potential data breaches and rapid technological advancements.

    Vendor Contracts

    Contracts with data processors must articulate specific conditions regarding processing, data types, duration, and confidentiality obligations. This requirement ensures that liability and accountability are well-defined in business operations.

    Data Protection Assessments

    Controllers of higher-risk data processing activities must conduct and document data protection assessments. This includes areas like targeted advertising and sensitive data processing, making it clear that accountability doesn’t stop at data collection but extends into responsible processing practices.

    Children’s and Minors’ Data

    The VDPOSA places special emphasis on the personal data of minors. Controllers are restricted from processing or selling data related to consumers aged 13 to 17 for targeted advertising. For children under 13, compliance with the Children’s Online Privacy Protection Act (COPPA) is mandatory.

    Consumer Health Data

    The Act sets forth specific guidelines surrounding consumer health data. Entities must restrict access to this sensitive information to employees with confidentiality obligations, ensure processors are bound by contractual requirements, and obtain consent before selling such data.

    Empowering Consumer Rights

    One of the hallmark features of the VDPOSA is its focus on empowering consumers. Among the rights guaranteed are:

    • The right to confirm if a controller is processing their data.
    • The right to access their data, including insights into profiling.
    • The right to correct inaccuracies.
    • The right to request deletion of personal data.
    • The right to opt out of targeted advertising and the sale of personal data.
    • The right to know which third parties have received their data.

    These rights serve as a robust framework to enhance individual privacy and control in the digital domain.

    Enforcement Mechanism

    The enforcement of the VDPOSA is designated to the Vermont Attorney General, who possesses exclusive authority to initiate actions against violators. Importantly, any violation of the Act also represents a breach of the Vermont Consumer Protection Act. A 60-day cure period will be in place from January 1, 2028, through June 30, 2029, allowing businesses an opportunity to rectify any non-compliance before facing potential penalties.

    The establishment of the VDPOSA signals Vermont’s commitment to consumer privacy and protection in the increasingly complex digital landscape. As we approach the effective date, it will undoubtedly set a precedent for how states govern data privacy and online surveillance in the years to come.

    Latest articles

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    Popular