All Blog Posts

Vermont Data Privacy and Online Surveillance Act (VDPOSA): Requirements, Rights, and Compliance Support

Close
Read time
8 mins
Published
Jul 23, 2026
Share

  • Vermont’s Data Privacy and Online Surveillance Act (VDPOSA) is the 23rd comprehensive privacy law passed by a U.S. state. It takes effect January 1, 2028.
  • Websites and businesses reaching 35,000 or more Vermont consumers each year, or as few as 3,000 for sensitive data or data sales, fall within scope. There’s no revenue exemption.
  • Consumer health data provisions apply without any threshold.
  • Sites must honor browser-level opt-out preference signals, such as the Global Privacy Control.
  • Privacy policies must now disclose whether visitor data is used to train AI models.
  • Only the Vermont Attorney General can enforce the law; there’s no private right of action.

For many website owners, the low compliance thresholds in Vermont’s new data privacy law are of note. However, the threshold of 35,000 visitors covers over 5 percent of the state’s population, making it proportionately quite high.

If your site draws meaningful traffic from New England, Vermont residents are probably already part of your numbers. Here’s what the VDPOSA introduces, changes, and what to do about it before the 2028 deadline.

What Is the Vermont Data Privacy and Online Surveillance Act?

The Vermont Data Privacy and Online Surveillance Act, or VDPOSA, is Vermont's new privacy law for how websites and businesses handle visitor data. Governor Scott signed S.71 into law on June 16, 2026, and it takes effect January 1, 2028. As of mid-2026, it’s the fourth new state privacy law enacted this year, after Oklahoma, Alabama, and Louisiana.

At a basic level, the VDPOSA gives Vermont residents rights over their personal data and puts new obligations on the businesses and websites collecting it. It's built on the same foundation as the laws in Virginia and Colorado, but reaches further in a few ways.

A broader AI disclosure requirement, mandatory recognition of browser-level opt-out preference signals, and lower thresholds than most other states, meaning more small and mid-size sites fall within scope. Vermont is now the 23rd U.S. state with a law like this on the books.

This guide covers whether your site is affected, what changes to make, and how Vermont's approach stacks up against the states you may already be handling compliance for.

Key Terms You'll See in the VDPOSA

A number of terms show up consistently in Vermont's law, and some of them cover more ground than you'd expect from other state privacy laws, so here's what they actually mean.

Consumer

A Vermont resident visiting your site. Doesn't include someone interacting with you in a work or business capacity on behalf of their employer.

Controller

Your business, if you're the one deciding why and how visitor data gets processed.

Processor

A vendor or tool, like a CMP, that processes data on your behalf, under your instructions.

Personal Data

Anything linked or reasonably linkable to an identifiable visitor or their device. Doesn't include deidentified data or information that's genuinely public.

Sensitive Data

A broader category than most site owners expect, covering data with a higher risk of harm if misused, including:

  • Race or ethnicity
  • Religion 
  • Sex life or sexual orientation
  • Transgender or nonbinary status
  • Immigration status
  • Health conditions
  • Genetic or biometric data
  • A known child's data
  • Precise location
  • Neural data
  • Financial credentials
  • Certain government ID numbers

Consumer Health Data

Any data you use to identify a visitor's physical or mental health status, including gender-affirming and reproductive/sexual health data.

Biometric Data

Data drawn from unique physical traits, such as iris scans, fingerprints, face or hand mapping, vein patterns, voice prints, or gait, used to identify someone. Photos and video recordings themselves don't count, unless they're processed specifically to identify a person.

It's a separate category from neural data, which covers activity measured from the nervous system itself rather than physical or behavioral traits.

Sale of Personal Data

Exchanging a visitor's personal data with a third party for money or other value. Sending data to your own processor, affiliate, or as part of a business sale doesn't count as a sale here.

Targeted Advertising

Showing ads chosen based on a visitor's activity across other, unrelated sites over time. Doesn't include ads based on what someone's doing on your own site right now, or ads responding to a direct request.

Profiling

Automated analysis of personal data to evaluate or predict things like a visitor's finances, health, preferences, reliability, behavior, or location.

A clear, freely given, specific, informed, unambiguous yes. Bundling it into broad terms of use, treating a hover, mute, pause, or close as agreement, or using dark patterns to get it doesn't count.

Publicly Available Information

Info from government records or widely distributed media, or something the visitor themselves made public. This does not cover data profiles you've built up and packaged for sale, genetic data, biometric data collected without the person knowing, or nonconsensual intimate images.

Does the VDPOSA Apply to Your Website?

The law applies to any business conducting business in Vermont, or targeting Vermont residents, that during the prior calendar year did any of the following:

  • Controlled or processed personal data of 35,000 or more consumers (payment-only data excluded)
  • Controlled or processed sensitive data of 3,000 or more consumers
  • Sold the personal data of 3,000 or more consumers

Consumer health data provisions apply regardless of size. There’s no revenue threshold, so smaller businesses with meaningful data footprints don’t get a turnover-based pass the way they might under the law in states like California.

What Rights Do Vermont Residents Have?

Vermont’s rights package matches what most site owners are already handling under Virginia, Colorado, and Connecticut privacy law, with two additions:

Compliance

Right of access: Confirm processing and access personal data, including whether it’s used for profiling in legally significant decisions

Right of correction: For outdated information or other inaccuracies

Right of deletion: Of personal data provided by or obtained about the consumer

Right of portability: Of the personal data in a machine-readable format where processing is automated

Right of opt out: Of targeted advertising, sale of personal data, and profiling for legally significant automated decisions

Right to profiling challenge: Where a legal or significant decision resulted from profiling, consumers may question the result, review the data used, and, in housing decisions specifically, request correction and re-evaluation

Right to the third-party sales list: Obtain a list of third parties to whom their data was sold

Businesses have 45 days to respond to a request, with one 45-day extension available if needed. Denied requests can be appealed, and businesses have 60 days to resolve the appeal.

Vermont’s consent standard rules out several practices some sites still lean on, including:

  • Bundling consent into broad terms of use
  • Treating a hover, mute, pause, or close action as agreement
  • Any consent obtained through dark patterns

Sensitive data needs affirmative opt-in consent before you process or sell it, and children’s data is included in that category.

Two additional changes are worth building into your cookie banner and privacy policy specifically.

Opt-Out Preference Signals

Vermont requires sites to honor browser-level opt-out preference signals, such as the Global Privacy Control (GPC), provided the signal reflects an affirmative choice, works without defaults turned on, and lets you verify the visitor is a Vermont resident.

AI Training Disclosure

Your privacy notice now needs to state whether visitor data is collected, used, or sold to train large language models (LLMs). Vermont is the second state to require this, after Connecticut’s amended law.

Obligations for Websites from the VDPOSA

Checklist icon

Limit data collection to what you actually need for the purpose you’ve disclosed

Avoid repurposing existing data for a new, unrelated use without fresh consent

Maintain reasonable security measures across data you hold on Vermont residents

Get consent before processing or selling sensitive data, including that of children

Restrict targeted ads and data sales for known 13-to-17-year-olds, and apply Vermont’s Age-Appropriate Design Code to that age group; COPPA still governs under-13s

Update your privacy notice to cover data categories, purposes, third-party sale categories, targeted advertising disclosures, the LLM disclosure, and a contact method

Make opting out as easy as opting in, and stop processing within 15 days of a revoked consent

Document data protection assessments for targeted advertising, data sales, higher-risk profiling, and sensitive data processing

Notify visitors of material privacy notice changes and give them a chance to withdraw consent before you process previously collected data differently

What Counts as Sensitive on Your Site: Kids, Health Data, and More

Vermont's sensitive data list is one of the longest of any state. Neural data, for example, is a category so far only otherwise found in Colorado’s privacy law.

Children's data counts as sensitive too, which is fairly standard. If you have actual knowledge, or willfully disregard, that a visitor is a child, their data gets the same heightened protections as any other sensitive data, including consent before you process or sell it.

If your site collects voice recordings, gait data, or similar signals for any purpose, even quality assurance rather than identification, it's worth double-checking against Vermont's biometric data definition, which is broader than most states' and doesn't require an identification purpose to trigger protection.

Sites operating near health care facilities should also note the geofencing rule: no geofence within 1,850 feet of a health care, mental health, or reproductive or sexual health facility, and consent is required before selling consumer health data at all, regardless of your general size thresholds.

VDPOSA Exemptions

While the VDPOSA applies broadly, it does not cover every organization or type of information. The following exemptions clarify which entities and data categories fall outside the law's scope.

Exempt entities include:

  • Government entities
  • HIPAA-covered entities
  • Air carriers

Data-level carve-outs include:

  • GLBA
  • HIPAA
  • FCRA
  • FERPA
  • Driver’s Privacy Protection Act
  • Farm Credit Act
  • Employment-context data
  • Emergency contact information

Two things not to assume: Vermont doesn’t give nonprofits a blanket pass. Only fraud-detection, postsecondary enrollment-verification, and certain media nonprofits qualify. 

And the financial-institution exemption only covers chartered banks and credit unions, not financial services businesses generally.

VDPOSA Enforcement, Penalties, and Cure Period

Only the Vermont Attorney General can bring an enforcement action. California is the only comprehensive state privacy law with any private right of action, and even there it's limited to data breaches. Vermont, like every other state so far, has no private right of action at all.

Penalties can reach USD 10,000 per violation. Between January 1, 2028, and June 30, 2029, the Attorney General must give 60 days’ notice to fix a violation before taking action, where a fix is possible. After that window, a cure period is no longer guaranteed and is at the AG’s discretion.

Prepare for the VDPOSA with Cookiebot™

Preparing for the VDPOSA means updating your cookie banner, privacy policy, and opt-out handling ahead of the January 1, 2028 deadline. Cookiebot CMP is built to support privacy requirements, whether state-by-state, coast-to-coast, or globally. That includes recognition of opt-out preference signals, granular consent for sensitive data categories, and consent logs that support documenting compliance in the event of a regulatory inquiry.

As more states adopt AI training disclosure requirements and lower thresholds like Vermont's, keeping your cookie banner and privacy settings current across every state your visitors come from gets harder to manage by hand. Cookiebot™ helps centralize and automate that work, so you can focus on running your site rather than tracking every statutory deadline yourself.

Frequently asked questions

January 1, 2028. There’s a cure period for violations through June 30, 2029.

No. Only the Vermont Attorney General can enforce the VDPOSA.

Only the Vermont Attorney General can bring an enforcement action, and penalties can reach USD 10,000 per violation. Between January 1, 2028, and June 30, 2029, you'll get 60 days' notice to fix a violation before the AG takes action, where a fix is possible. After that window, that cure period is no longer guaranteed and is at the AG’s discretion.

You're covered if you process personal data on 35,000 or more Vermont visitors a year, or as few as 3,000 for sensitive data or data sales. There's no revenue exemption, so smaller sites with meaningful traffic can't rely on a turnover-based pass the way they might under California's law. Consumer health data provisions apply regardless of size.