---------------------------
Title: Vermont Data Privacy and Online Surveillance Act (VDPOSA): An Overview
URL: https://usercentrics.com/us/knowledge-hub/vermont-data-privacy-online-surveillance-act-vdposa/
---------------------------

# Vermont Data Privacy and Online Surveillance Act (VDPOSA): An Overview

The Vermont Data Privacy and Online Surveillance Act (VDPOSA) makes Vermont the 23rd U.S. state with a comprehensive privacy law. This guide covers applicability thresholds, consumer rights, the AI training disclosure requirement, opt-out preference signals, and enforcement, with comparisons to the models in effect in other states.

### At a Glance

- S.71 signed into law on June 16, 2026, enacted as Act 145; Vermont becomes the 23rd U.S. state with a comprehensive consumer privacy law.
- The VDPOSA takes effect January 1, 2028, with a cure period running through June 30, 2029.
- The VDPOSA applies to controllers processing personal data of 35,000 or more Vermont consumers, or sensitive data or data sales involving 3,000 or more consumers.
- Consumer health data provisions apply with no threshold at all.
- The law requires privacy notices to disclose whether personal data is used to train large language models, making Vermont the second state to impose this requirement after Connecticut.
- Enforcement rests exclusively with the Vermont Attorney General; there is no private right of action.

Vermont’s data privacy debate ran for years before landing anywhere. The governor vetoed an earlier, stricter version in 2024, and lawmakers spent the following two sessions negotiating something that could actually clear both chambers and the governor’s desk.

## What Is the Vermont Data Privacy and Online Surveillance Act (VDPOSA)?

The Vermont Data Privacy and Online Surveillance Act is Vermont's comprehensive consumer privacy law. The governor signed it on June 16, 2026, as Act 145, following [S.71](https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf) through both chambers of the General Assembly. It takes effect January 1, 2028.

It’s close in structure to [Connecticut’s data privacy law](https://usercentrics.com/us/us/knowledge-hub/connecticut-data-privacy-act-ctdpa/), but carries a handful of provisions that set it apart, including an AI training disclosure requirement, a broader biometric data definition, and some of the lowest applicability thresholds in the country.

The VDPOSA gives Vermont residents rights over how businesses collect, use, and sell their personal data, and imposes corresponding obligations on the controllers and processors handling that data.

It follows the general structure established by the privacy laws of [Virginia](https://usercentrics.com/us/us/knowledge-hub/virginia-consumer-data-protection-act-vcdpa/) and [Colorado](https://usercentrics.com/us/us/knowledge-hub/colorado-privacy-act/), but adds several provisions of its own, including an AI training disclosure requirement, a mandatory recognition of opt-out preference signals, and some of the lowest applicability thresholds enacted by any state to date. Vermont is the 23rd U.S. state to enact a comprehensive privacy law.

This guide walks through who the law applies to, what it requires, and how it compares to the privacy laws already in effect in other states.

## Key Definitions Under the VDPOSA

A handful of statutory terms come up throughout this guide, and Vermont defines several of them more broadly than comparable state laws, so it's worth reviewing them directly.

### Consumer

A Vermont resident. The definition excludes an individual acting in a commercial or employment context on behalf of an employer.

### Controller

A person who, alone or jointly with others, determines the purpose and means of processing personal data.

### Processor

A person who collects or processes personal data on behalf of a controller or another processor.

### Personal Data

Information linked or reasonably linkable to an identified or identifiable individual or their device. Excludes deidentified data and publicly available information.

### Sensitive Data

Personal data with a greater risk of harm if misused, revealing:

- Racial or ethnic origin
- Religious beliefs
- Sex life
- Sexual orientation
- Transgender or nonbinary status
- Citizenship/immigration status
- Mental or physical health condition, diagnosis, disability, or treatment
- Consumer health data
- Genetic or biometric data
- Personal data of known children
- Precise geolocation data (within a 1,750-foot or 533.4-meter radius)
- Neural data
- Financial account credentials
- Certain government-issued ID numbers

### Consumer Health Data

Personal data a controller uses to identify a consumer's physical or mental health condition, diagnosis, or status, including gender-affirming health data and reproductive or sexual health data.

### Biometric Data

Data from the technological processing of an individual's unique biological, physical, or physiological characteristics, collected on or used to identify a specific consumer via:

- Iris/retina scans
- Fingerprints
- Facial or hand mapping
- Vein patterns
- Voice prints
- Gait

Excludes photographs, audio, or video recordings unless processed to identify a specific individual. Also distinct from neural data, which covers activity measured from the central nervous system rather than physical or behavioral characteristics.

### Sale of Personal Data

The exchange of a consumer's personal data by the controller with a third party for monetary or other valuable consideration. Excludes disclosures to processors, affiliates, or as part of a merger/acquisition, among other carve-outs.

### Targeted Advertising

Displaying ads selected based on personal data obtained or inferred from a consumer's activity over time and across nonaffiliated websites or apps. Excludes contextual advertising on a controller's own site and advertising based on a consumer's current search or direct request.

### Profiling

Automated processing of personal data to evaluate, analyze, or predict aspects such as a consumer's economic situation, health, preferences, reliability, behavior, location, or movements.

### Consent

A clear affirmative act signifying a freely given, specific, informed, and unambiguous agreement to processing. Expressly excludes acceptance of broad terms of use, hovering/muting/pausing/closing content, and agreement obtained through dark patterns.

### Publicly Available Information

Information available through government records or widely distributed media, or that a controller reasonably believes the consumer lawfully made available to the general public.

Notably excludes aggregated consumer profiles built from such information, genetic data, biometric data collected without knowledge, and nonconsensual intimate images.

## Do you know what personal data your site is collecting?

Usercentrics’ free compliance scanner can help identify gaps in your current cookie and consent setup ahead of Vermont’s 2028 deadline, including opt-out signal handling and sensitive data consent flows.

## Who Must Comply With the VDPOSA

The Vermont Data Privacy and Online Surveillance Act applies to any person conducting business in Vermont, or targeting Vermont residents, that during the preceding calendar year did one of the following:

- Controlled or processed personal data of 35,000 or more consumers (excluding data processed solely for payment transactions)
- Controlled or processed sensitive data of 3,000 or more consumers
- Offered for sale the personal data of 3,000 or more consumers

There’s no revenue threshold, which means smaller organizations can’t rely on a turnover exemption the way they might in California. The bill as introduced would have lowered these thresholds progressively each year. However, the enacted version dropped that tiered approach in favor of a single, fixed threshold.

Consumer health data provisions apply more broadly still, reaching any business conducting business in or targeting Vermont residents regardless of scale.

## Consumer Rights Under the VDPOSA

Vermont grants consumers a rights package that broadly matches the Virginia and Colorado model, with two additions that go further than most states.

Right of access: Confirm processing and access personal data, including whether it’s used for profiling in legally significant decisions

Right of correction: For outdated information or other inaccuracies

Right of deletion: Of personal data provided by or obtained about the consumer

Right of portability: Of the personal data in a machine-readable format where processing is automated

Right of opt out: Of targeted advertising, sale of personal data, and profiling for legally significant automated decisions

Right to profiling challenge: Where a legal or significant decision resulted from profiling, consumers may question the result, review the data used, and, in housing decisions specifically, request correction and re-evaluation

Right to the third-party sales list: Obtain a list of third parties to whom their data was sold

Response timelines follow the fairly standard model of 45 days, which is extendable by a further 45 under reasonable circumstances, with notice to the consumer. Appeals of a denied request must be resolved within 60 days, after which the consumer can escalate to the Attorney General.

## Consent Standard and the AI Training Disclosure

The VDPOSA defines consent as a clear affirmative act — freely given, specific, informed, and unambiguous — using language consistent with the Virginia, Colorado, and Connecticut model. It expressly excludes acceptance of broad bundled terms of use, hovering, muting, pausing, or closing content, and any agreement obtained through [dark patterns](https://usercentrics.com/us/knowledge-hub/dark-patterns-and-how-they-affect-consent/).

[Sensitive data](https://usercentrics.com/us/knowledge-hub/sensitive-information-guide/) requires affirmative consent before processing or sale, aligning with the Virginia, Colorado, and Connecticut model.

The provision drawing the most attention outside Vermont is the privacy notice requirement to disclose whether the controller collects, uses, or sells personal data to train large language models. This makes Vermont the second state to require an AI training disclosure, following Connecticut’s amended CTDPA, which took effect July 1, 2026.

## Opt-Out Preference Signals

Vermont requires controllers to honor opt-out preference signals, the browser- or platform-level signals sent with the consumer’s consent, indicating an intent to opt out of targeted advertising or the sale of personal data.

The signal must require an affirmative consumer choice with no defaults enabled, be consumer-friendly, align as closely as possible with other applicable state or federal mechanisms, and allow the controller to verify Vermont residency.

This places Vermont alongside California and Colorado as one of the few states that mandate technical signal compliance rather than treating it as optional best practice. Many other states, including Virginia, do not require controllers to honor browser-level signals at all.

> Learn more: [What companies need to know about Global Privacy Control and GPC compliance requirements](https://usercentrics.com/us/knowledge-hub/what-is-global-privacy-control/)

## VDPOSA Obligations for Businesses

Controllers’ obligations under the VDPOSA follow a similar pattern to prior U.S. state laws, focused largely around judicious management of data collection and use, providing adequate notice about data processing, security, and honoring opt-outs.

- **Minimize data collection** to what is reasonably necessary and proportionate to the disclosed purpose.
- **Limit new processing purposes**, so no material new use of previously collected data without obtaining consent.
- **Maintain reasonable security**, including administrative, technical, and physical safeguards.
- **Obtain prior consent for sensitive data** before processing or selling it.
- **Restrict targeted advertising and sale involving minors** aged 13 to 17 where the controller has actual knowledge or willfully disregards the consumer’s age.
    - The [Vermont Age-Appropriate Design Code](https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT063/ACT063%20As%20Enacted.pdf) applies to this age group, and [COPPA](https://usercentrics.com/us/knowledge-hub/childrens-online-privacy-protection-act-coppa/) governs consumers under 13.
- **Provide a clear privacy notice** (that’s kept up to date), covering:
    - Data categories processed
    - Processing purposes
    - Third-party sale categories
    - Targeted advertising disclosures
    - LLM training disclosure
    - Contact mechanism
    - Date of last update
- **Honor consent revocation** as easily as consent was granted, ceasing processing within 15 days.
- **Conduct data protection assessments** for targeted advertising, data sales, higher-risk profiling, and sensitive data processing.
- **Conduct profiling impact assessments** for decisions producing legal or similarly significant effects, covering:
    - Purpose
    - Risk analysis
    - Mitigation
    - Data categories
    - Post-deployment monitoring
- **Notify consumers of material privacy notice changes** and give them the opportunity to withdraw consent before further, materially different processing of previously collected data.

## Sensitive Data, Children’s Data, and Consumer Health Data Protections

Vermont's sensitive data definition is among the broadest enacted to date, covering data types from race and ethnicity to financial account credentials to neural data, a category so far only otherwise found in Colorado's 2024 amendments.

Children's data is also named as its own sensitive category. Personal data collected from an individual the controller has actual knowledge of, or willfully disregards, that an individual is a child requires the same heightened protections as any other sensitive data, including consent before processing or sale.

Vermont's biometric data definition is also broader than most states'. It doesn't require that the data be processed for identification purposes, so voice prints collected for AI quality-assurance training, or gait data collected to analyze mobility patterns, fall within scope even where identifying the consumer isn't the intent.

Consumer health data gets its own subchapter, applying to any business regardless of the general thresholds. Controllers must obtain consent before selling consumer health data, hold employees who access it to a duty of confidentiality, and cannot deploy a geofence within 1,850 feet of any health care, mental health, or reproductive or sexual health facility.

## VDPOSA Exemptions

The VDPOSA provides specific exemptions to ensure the law focuses on relevant commercial entities and data processing activities, balancing consumer protection with existing regulatory frameworks.

Exempt entities include:

- Government entities
- HIPAA-covered entities (excluding hybrid entities’ non-health-care components)
- Air carriers regulated under the Airline Deregulation Act

Data-level exemptions cover:

- [GLBA](https://usercentrics.com/us/us/knowledge-hub/glba-compliance/)-regulated data
- [HIPAA](https://usercentrics.com/us/us/knowledge-hub/health-insurance-portability-and-accountability-act-hipaa/) protected health information
- [FCRA](https://usercentrics.com/us/knowledge-hub/fair-credit-reporting-act-fcra/) data
- FERPA data
- Driver’s Privacy Protection Act data
- Farm Credit Act data
- Employee and job applicant data processed in an employment context
- Emergency contact information

Two points are worth flagging because they depart from the standard state-law template. First, Vermont does not provide a blanket nonprofit exemption. The carve-out is limited to organizations detecting insurance fraud, organizations providing enrollment-verification data reporting for postsecondary schools, and the noncommercial activity of certain media entities.

Second, the GLBA-related entity-level exemption is narrower than in many states. It covers state- or federally chartered banks and credit unions and their affiliates, not financial institutions generally.

## Enforcement and Penalties

Violations of the VDPOSA are treated as violations of the [Vermont Consumer Protection Act](https://legislature.vermont.gov/statutes/section/09/063/02453), with civil penalties reaching USD 10,000 per violation. Enforcement rests exclusively with the Attorney General. California is the only comprehensive state privacy law with any private right of action, and even there it's limited to data breaches.

Interestingly, the General Assembly may revisit the question of private right of action if adequate enforcement resources aren’t appropriated.

From January 1, 2028, through June 30, 2029, the Attorney General must issue a notice of violation and allow 60 days to cure before initiating an enforcement action, where a cure is possible. After that date, granting a cure period becomes discretionary. The Attorney General must also report annually to the General Assembly on enforcement activity.

## How Usercentrics Supports VDPOSA Compliance Preparedness

Preparing for the VDPOSA means updating consent flows, privacy notices, and opt-out mechanisms ahead of the January 1, 2028 deadline. [Usercentrics consent management platform](https://usercentrics.com/us/us/website-consent-management/) is built to help support these kinds of state-by-state requirements, including recognition of opt-out preference signals, granular consent for sensitive data categories, and consent logs that can help document compliance efforts across your organization's data footprint.

As more states adopt AI training disclosure requirements and lower applicability thresholds like Vermont's, keeping privacy notices and consent settings current across every jurisdiction gets harder to manage manually. Usercentrics can help centralize that work, so your team can focus on the decisions that matter rather than tracking every statutory deadline and updating manually.

---

## Footer

### Products
- [Usercentrics Web CMP](https://usercentrics.com/us/website-consent-management/)
- [Usercentrics App CMP](https://usercentrics.com/us/in-app-sdk/)
- [Usercentrics CTV CMP](https://usercentrics.com/us/usercentrics-ctv-cmp/)
- [Usercentrics Privacy Policy Generator](https://usercentrics.com/us/privacy-policy-generator/)
- [Server-side Tagging Solution](https://usercentrics.com/us/server-side-tracking-solution/)
- [Usercentrics Preference Manager](https://usercentrics.com/us/preference-management/)
- [Audience Unlocker](https://usercentrics.com/us/audience-unlocker/)
- [Integrations](https://usercentrics.com/us/integrations/)
- [Web compliance scan](https://usercentrics.com/us/privacy-compliance-scanner/)
- [App compliance scan](https://usercentrics.com/us/app-data-privacy-audit/)
- [ROAS calculator](https://usercentrics.com/roas-calculator/)

### Solutions
- [Data Privacy Regulatory Compliance](https://usercentrics.com/us/data-privacy-regulatory-compliance/)
- [Marketing Performance Optimization](https://usercentrics.com/us/marketing-performance-optimization/)
- [Migration](https://usercentrics.com/us/migration/)
- [Media & Publishing](https://usercentrics.com/us/media-publishing/)
- [Retail &amp; Ecommerce](https://usercentrics.com/us/retail-ecommerce/)
- [Banking, Finance &amp; Insurance](https://usercentrics.com/us/banking-finance-insurance/)
- [Healthcare & Pharmaceuticals](https://usercentrics.com/us/healthcare-pharmaceuticals/)
- [Gaming](https://usercentrics.com/us/gaming/)
- [Education](https://usercentrics.com/us/education/)
- [Automotive](https://usercentrics.com/us/automotive/)
- [Travel & Hospitality](https://usercentrics.com/us/travel/)

### Regulations
- [CCPA (California)](https://usercentrics.com/us/ccpa/)
- [GDPR (EU)](https://usercentrics.com/us/gdpr/)
- [CPRA (California)](https://usercentrics.com/us/cpra)
- [CPA (Colorado)](https://usercentrics.com/us/cpa/)
- [DMA (EU)](https://usercentrics.com/us/digital-markets-act-dma/)
- [FADP (Switzerland)](https://usercentrics.com/us/fadp/)
- [PIPEDA (Canada)](https://usercentrics.com/us/pipeda/)
- [TCF v2.3 (IAB)](https://usercentrics.com/us/cmp-for-publishers/)
- [Google Consent Mode (EU)](https://usercentrics.com/us/usercentrics-cmp-and-google-consent-mode-v2/)
- [Microsoft UET Consent Mode (EU)](https://usercentrics.com/us/usercentrics-cmp-and-microsoft-consent-mode/)
- [View all regulations](https://usercentrics.com/us/regulations-and-frameworks/)

### Resources
- [Blog](https://usercentrics.com/us/knowledge-hub/)
- [Whitepapers](https://usercentrics.com/us/whitepapers/)
- [Checklists](https://usercentrics.com/us/checklists/)
- [Courses](https://courses.usercentrics.com)
- [Customer stories](https://usercentrics.com/us/customer-stories/)
- [Privacy-Led Marketing](https://usercentrics.com/us/privacy-led-marketing/)
- [Events](https://usercentrics.com/us/webinar/)
- [CONSENTED podcast](https://usercentrics.com/us/consented/)
- [Guides](https://usercentrics.com/us/guides/)
- [Release notes](https://releases.usercentrics.com/en)
- [Developer documentation](https://usercentrics.com/docs/)
- [RFI template](https://usercentrics.com/us/resources/usercentrics-rfi-template/)
- [Customer directory](https://usercentrics.com/us/usercentrics-customer-directory/)

### Company
- [About us](https://usercentrics.com/us/about-us/)
- [Press](https://usercentrics.com/us/press/)
- [Our offices](https://usercentrics.com/us/contact/)
- [Trust center](https://trust.usercentrics.com/)
- [Careers](https://usercentrics.com/us/career/)
- [Open positions](https://apply.workable.com/usercentrics/)
- [Diversity and inclusion](https://usercentrics.com/us/dei/)

### Support
- [General support](https://support.usercentrics.com/hc/en-us)
- [Contact sales](https://usercentrics.com/us/book-a-consultation/)
- [Technical support](https://support.usercentrics.com/hc/en-us/requests/new)
- [Billing and account](https://support.usercentrics.com/hc/en-us/categories/12253804608156-Account-and-billing)
- [Suggest a feature](https://support.usercentrics.com/hc/en-us/requests/new?ticket_form_id=10610312381340)
- [Partner login](https://partnerportal.usercentrics.com/)
- [Partner program](https://usercentrics.com/us/partner-program-overview/)
- [Affiliate program](https://usercentrics.com/us/affiliates/)