Vermont Privacy Law
Vermont has regulated data brokers longer than almost any other state and litigated facial recognition harder than most, and its 2026 comprehensive statute reflects both. Act 145, signed on June 16, 2026 and effective January 1, 2028, adds chapter 61A to Title 9 and carries provisions with no counterpart elsewhere: a privacy notice must state whether the controller collects, uses or sells personal data to train large language models; a geofence may not be drawn within 1,850 feet of a health care facility to gather consumer health data; and the consumer health data provisions apply to any business targeting Vermonters, with no volume threshold at all. The Act also records, in its own text, why the Legislature withheld a private right of action and what would change its mind.
The Vermont Data Privacy and Online Surveillance Act (VDPOSA)
Act No. 145 (S.71), “An act relating to consumer data privacy and online surveillance”, was signed on June 16, 2026 and takes effect January 1, 2028 under section 4. It adds chapter 61A to Title 9, sections 2415a through 2415k. Section 2415j(a) deems a violation a violation of the Vermont Consumer Protection Act and gives the Attorney General the same authority to enforce as under 9 V.S.A. chapter 63, subchapter 1, while providing that the subchapter is not to be construed as providing the basis for, or being subject to, a private right of action for violations of the subchapter or any other law. Section 2415b(c) contains a conflicts rule that resolves against the narrower statute: where this subchapter conflicts with any other law, including the Vermont Age-Appropriate Design Code Act, the provisions affording the greatest protection for the right of privacy control.
Status: Enacted but not yet in force — the law takes effect January 1, 2028.
| Effective date | January 1, 2028 |
|---|---|
| Citation | Act 145 of 2026 (S.71), 9 V.S.A. §§ 2415a–2415k |
| Enforced by | Vermont Attorney General |
| Maximum penalty | Enforced as a violation of the Vermont Consumer Protection Act, 9 V.S.A. chapter 63 |
| Private right of action | No, enforcement by the state only |
| Right to cure | 60 days after a notice of violation, available January 1, 2028 through June 30, 2029 |
Who Must Comply
The VDPOSA reaches a business that conducts business in Vermont or produces products or services targeted to Vermont residents, and during the preceding calendar year controlled or processed the personal data of not fewer than 35,000 consumers, excluding data processed solely to complete a payment transaction, or controlled or processed the sensitive data of not fewer than 3,000 consumers, or offered for sale in trade or commerce the personal data of not fewer than 3,000 consumers.
Section 2415b(b) applies § 2415k and the subchapter’s consumer health data provisions to any person conducting business in Vermont or targeting Vermont residents, with no threshold. Section 2415d(a)(6) gives a consumer subjected to profiling in furtherance of an automated decision with legal or similarly significant effect the right to question the result, be told the reason, review the data processed, and — where the decision concerned housing — correct incorrect data and have the decision reevaluated. Section 2415d(a)(7) adds a right to obtain a list of the third parties to which the controller sold the consumer’s personal data, or, if no such list is kept, a list of all third parties to which it sold personal data
Consumer Rights Under the VDPOSA
Residents of Vermont can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Vermont
Data broker registration and security (9 V.S.A. §§ 2446–2447)
Added by 2017, No. 171 (Adj. Sess.) with effect from January 1, 2019, Vermont’s data broker law was the first of its kind in the country. Section 2446(a) requires annual registration with the Secretary of State on or before January 31 following a year in which a person meets the definition of data broker, with a $100.00 fee and seven categories of disclosure: the broker’s name and physical, email and internet addresses; the method for requesting an opt-out and whether it may be exercised through a third party; a statement specifying the collection, database or sales activities from which a consumer may not opt out; whether the broker implements a purchaser credentialing process; the number of data broker security breaches experienced during the prior year and, if known, the total number of consumers affected; a separate statement of collection practices, databases, sales activities and opt-out policies applicable to minors where the broker has actual knowledge it holds minors’ brokered personal information; and any additional explanation the broker chooses to provide. Subsection (b) makes a failure to register liable to the State for a civil penalty of $50.00 for each day, capped at $10,000.00 for each year, plus the fees due for the unregistered period and other penalties imposed by law, with the Attorney General authorised by subsection (c) to sue in the Civil Division of the Superior Court. Section 2447 layers on a written comprehensive information security program with fourteen minimum features, among them a designated employee to maintain the program, ongoing training including for temporary and contract employees, disciplinary measures for violations, measures preventing terminated employees from accessing records, and contractual security requirements on third-party service providers.
Age-Appropriate Design Code (Act 63 of 2025, 9 V.S.A. § 2449a et seq.)
Act 63, passed in May 2025, requires covered businesses to protect minors using their products from harms arising from the processing of their data, and takes effect January 1, 2027. As the Attorney General’s office describes it, the act requires the default privacy setting of a covered digital product to be set to the highest level of privacy when used by a minor, prohibits the collection or sharing of a minor’s personal data unless necessary to provide a service to that minor, and restricts a covered business from permitting an individual to monitor a minor’s activity or location on its product without giving the minor a conspicuous signal. The Legislature assigned the rulemaking to the Attorney General rather than to a consumer agency. Section 2449f(b) directs rules prohibiting data processing or design practices that, in the Attorney General’s opinion, lead to compulsive use or subvert or impair user autonomy, decision making or choice. Section 2449g(b) directs rules identifying commercially reasonable and technically feasible methods for determining whether a user is a covered minor, describing review processes for users appealing their age designations, and providing additional privacy protections for age assurance data — and instructs the office to prioritise user privacy and accessibility over the accuracy of age assurance methods.
Vermont Consumer Protection Act (9 V.S.A. ch. 63)
Chapter 63 is the enforcement chassis for Vermont’s privacy statutes, and its private remedy is stronger than most — which makes the exclusions drawn around it significant. Section 2461(b) allows a consumer who contracts for goods or services in reliance on false or fraudulent representations or practices prohibited by § 2453, or who sustains damages or injury as a result of them, to sue for equitable relief and to recover damages or the consideration given, reasonable attorney’s fees, and exemplary damages not exceeding three times the value of the consideration given. The same subsection makes unenforceable any written or oral language by which a seller or solicitor attempts to exclude or modify recovery of the penalty or the attorney’s fees, and subsection (c) preserves a jury trial. On the public side, § 2461(a) sets a civil penalty of not more than $10,000.00 for each violation of an injunction issued under § 2458, recoverable on petition by the Attorney General or a State’s Attorney in the court that retains jurisdiction. Section 2415j(a) of the new privacy subchapter borrows the Attorney General’s chapter 63 authority while closing off the § 2461(b) route for privacy claims.
Data Breach Notification in Vermont
The Security Breach Notice Act at 9 V.S.A. § 2435 splits its clock in two and splits its regulator in two as well. Consumer notice under subsection (b)(1) runs in the most expedient time possible and without unreasonable delay but not later than 45 days after discovery or notification. Regulator notice under subsection (b)(3)(A) goes to the Department of Financial Regulation where the data collector is regulated by that department under Title 8 or Title 9, and to the Attorney General in every other case. Subsection (b)(3)(B)(i) requires the date of the breach, the date of discovery and a preliminary description within 14 business days of discovery or of consumer notice, whichever is sooner; subsection (b)(3)(B)(ii) then supplies a way out of that preliminary notice for a data collector that, before the breach, swore in writing to the Attorney General on a prescribed form that it maintains written policies and procedures to secure personally identifiable information and respond to a breach consistent with Vermont law. Subsection (b)(3)(B)(iv) keeps the preliminary notice confidential from anyone but the Department, the Attorney General’s representatives, a State’s Attorney or a law enforcement officer, absent a court order for good cause. The statute also reaches login credentials as a protected category in their own right, with subsection (b)(3)(D) requiring regulator notice for a credentials-only breach only where the credentials were acquired directly from the data collector or its agent. Subsection (b)(1) applies to a data collector that owns or licenses the data; subsection (b)(2) puts one that merely maintains or possesses it on an immediate duty to tell the owner or licensee.
Residents must be notified in the most expedient time possible and without unreasonable delay, but not later than 45 days after discovery or notification. A preliminary description of the breach goes to the Attorney General, or to the Department of Financial Regulation for entities it regulates, within 14 business days of discovery or of consumer notice, whichever is sooner. Complaints are taken by the Vermont Attorney General, which enforces the statute.
How the VDPOSA Is Enforced
Consumer Protection Act authority, with the private route closed. Section 2415j(a) does not create a new penalty schedule. It deems a violation of the privacy subchapter a violation of the Vermont Consumer Protection Act under chapter 63 of Title 9 and gives the Attorney General the same authority to enforce as chapter 63, subchapter 1 provides — which reaches the civil investigative demands, injunctions and the $10,000.00-per-violation penalty for disobeying an injunction under § 2461(a). The same sentence forecloses the private action that § 2461(b) would otherwise supply. Section 2415j(c) adds a guidance duty: the Attorney General provides, and updates as necessary, guidance to controllers and processors on compliance.
A published breach-notice practice, and a way to waive the preliminary notice. The Attorney General’s office publishes the mechanics of § 2435 rather than leaving them to the statute. It states that businesses notify the office within 14 days of discovering or being notified of a breach, that the notification may be preliminary and is kept confidential by statute, and it supplies a Preliminary Notice form, a Security Breach Reporting Form, and a form of affirmation required to waive the 14-day preliminary notice under § 2435(b)(3)(B)(ii). The office also maintains a public table of the notice letters it receives concerning incidents that may have compromised the personal information of Vermont residents.
Recent Enforcement in Vermont
State of Vermont v. Clearview AI — Consumer Protection Act suit refiled April 2025. The Attorney General’s office announced on April 25, 2025 that Attorney General Charity Clark had refiled a lawsuit against Clearview AI in Vermont Superior Court, Washington Civil Division, alleging violations of the Vermont Consumer Protection Act. The office states that the complaint alleges the company collects Vermonters’ photographs from the internet and stores the unique facial biometric identifiers of Vermonters, including children, in its database without their knowledge or consent, and that while Vermont law sets strict limits on the use of biometric information by state or local law enforcement agencies, the company sells access to other state and federal law enforcement, including the federal government and its contractors. The office notes that a prior action it filed against the same defendant was dismissed on venue grounds, and that the 2025 action was filed in Washington County, where the Attorney General resides by statute. The original 2020 action, filed in Chittenden Superior Court, alleged violations of both the Consumer Protection Act and the then-new data broker law.
Pending Privacy Legislation
The live Vermont proceeding is administrative rather than legislative. The Attorney General’s office is conducting rulemaking under Act 63 of 2025, the Age-Appropriate Design Code, and has published proposed rules for §§ 2449f and 2449g while soliciting comments, data and other information; comments are due on or before October 2, 2026, and the law and any adopted rules take effect January 1, 2027. Two dates already fixed by statute follow it. Act 145’s substantive obligations begin January 1, 2028, and its notice-and-cure requirement in section 3 — under which the Attorney General issues a notice of violation before initiating any action where a cure is possible, and may sue only if the person fails to cure within 60 days — runs from that date until June 30, 2029. Section 2415j(b) then adds a standing reporting duty: annually on or before December 1 the Attorney General reports to the General Assembly the number of notices of violation issued, the nature of each violation, the number resulting in enforcement action, the number that proceeded to trial, and whether and to what extent an opportunity to cure was offered.
Federal Privacy Laws That Apply in Vermont
Federal privacy law applies in Vermont by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The VDPOSA sits alongside those rules rather than displacing them: the Vermont Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Vermont Consumer Protection Act (9 V.S.A. ch. 63), which the Vermont Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Vermont Privacy Law FAQ
How quickly must a Vermont breach be reported to a regulator?
Does Vermont’s breach law cover stolen login credentials?
Will Vermonters be able to sue under the new privacy act?
What does the Vermont act require a privacy notice to say about AI training?
Does the Vermont act restrict geofencing near health facilities?
Do the Vermont act’s consumer health data rules have a size threshold?
Who has to register as a data broker in Vermont, and what does a failure cost?
Can a Vermont consumer recover exemplary damages for a privacy violation?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Vermont Act 145 of 2026 (S.71) — as enacted legislation
- Vermont Act 145 of 2026 — Office of Legislative Counsel act summary legislation
- 9 V.S.A. § 2435 — Security Breach Notice Act statute
- 9 V.S.A. § 2446 — Data broker annual registration statute
- 9 V.S.A. § 2447 — Data broker duty to protect information statute
- 9 V.S.A. § 2461 — Consumer Protection Act civil penalty and private remedy statute
- Vermont Attorney General — Privacy and Data Security agency
- Vermont Attorney General — Age-Appropriate Design Code rulemaking agency
- Vermont Attorney General — Clearview AI lawsuit refiled, April 25, 2025 agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.