ConsentPixel – Privacy · Verified

HomeRegulations › VDPOSA
🇺🇸United States · Vermont State Privacy Law

VDPOSA Compliance for Websites in Vermont

The Vermont Data Privacy and Online Surveillance Act (VDPOSA) is one of the broadest state privacy laws in the country — opt-in consent for sensitive data, a low applicability threshold, standalone consumer-health-data rules, and an AI-training disclosure requirement. It takes effect January 1, 2028. ConsentPixel — Privacy · Verified already supports it, so you can be ready ahead of the deadline.

Enacted June 16, 2026Effective Jan 1, 2028Opt-in sensitive dataAI-training disclosureSupported in ConsentPixel now
Enacted
June 16, 2026
Effective
Jan 1, 2028
Enforcer
Vermont AG only
Private suits
None

Key facts verified July 2026 against analyses from Mayer Brown, Cooley, Hinshaw & Culbertson, Covington, and the Future of Privacy Forum. This page is educational and is not legal advice.

Vermont became the 24th US state to enact a comprehensive consumer privacy law when Governor Phil Scott signed S.71 into law on June 16, 2026. Codified at 9 V.S.A. Chapter 61A, the VDPOSA closely tracks the Connecticut model but pushes further in several areas — making it one of the more demanding state privacy frameworks enacted to date. The law takes effect January 1, 2028, and is enforced exclusively by the Vermont Attorney General.

What is the VDPOSA?

The Vermont Data Privacy and Online Surveillance Act is a comprehensive consumer privacy law that gives Vermont residents rights over how businesses collect, use, and share their personal data — and imposes corresponding duties on the businesses (controllers and processors) that handle it. It follows the "controller/processor" framework now common across US state privacy laws, with definitions generally consistent with the Connecticut Data Privacy Act.

What sets Vermont apart is the reach. The VDPOSA carries one of the lowest applicability thresholds in the country, one of the broadest definitions of sensitive data (including biometric and neural data), standalone consumer-health-data protections that apply with no threshold at all, and — as only the second state after Connecticut — a requirement to disclose AI/LLM training practices in your privacy notice. Governor Scott had vetoed a stricter version, including a private right of action, in 2024; the enacted law removed the private right of action but kept the broad scope.

🌿

The low thresholds mean VDPOSA reaches well beyond big companies

Because the sensitive-data and data-sale thresholds trigger at just 3,000 Vermont consumers — and the consumer-health-data rules apply to any business targeting Vermont residents regardless of size — many small and mid-sized businesses that fall outside other state laws will still be in scope here. If you process health-related data about Vermonters, the health-data provisions can apply to you even if the general thresholds don't.

Does the VDPOSA apply to your website?

The VDPOSA applies to any person or business that conducts business in Vermont, or targets products or services to Vermont residents, and in the preceding calendar year met at least one of these thresholds:

  • 35,000+ Vermont consumers whose personal data you controlled or processed (excluding data used solely to complete a payment transaction), or
  • 3,000+ Vermont consumers whose sensitive data you controlled or processed, or
  • 3,000+ Vermont consumers whose personal data you offered for sale in trade or commerce.

Separately — and importantly — the VDPOSA's consumer-health-data provisions apply with no threshold. They reach any business that conducts business in Vermont or targets products or services to Vermont residents, regardless of how many consumers are involved. It is uncommon for a state law to tie a threshold to sensitive-data processing at all, and rarer still to protect health data with no threshold — both are what make Vermont's reach unusually broad.

Consumer rights under VDPOSA

The VDPOSA gives Vermont residents a familiar set of consumer rights, plus a couple that go beyond the standard state model. Businesses must provide a way to exercise each of these and generally respond within 45 days.

1

Access

Confirm whether you process their data and obtain a copy of it.

2

Correct

Fix inaccuracies in the personal data you hold about them.

3

Delete

Request deletion of personal data you have collected or obtained.

4

Portability

Obtain their data in a portable, readily usable format.

5

Opt out of sale & targeted ads

Opt out of the sale of their data, targeted advertising, and certain profiling.

6

List of third parties

Obtain a list of the third parties to whom their personal data was sold — a right that goes beyond the standard state template.

7

Question profiling

Contest and question certain automated profiling decisions that produce significant effects.

8

Opt in for sensitive data

Sensitive data cannot be processed at all without the consumer's explicit opt-in consent.

What VDPOSA requires of your website

On the website side, VDPOSA compliance comes down to consent handling, transparency, and honoring consumer choices. Here are the areas your site needs to address.

Consent

Opt-in for sensitive data

Explicit, affirmative opt-in consent is required before processing any sensitive data — race, ethnicity, religion, sexual orientation, gender identity, health data, biometric or neural data, or precise geolocation.

Signals

Honor universal opt-out

Like the Connecticut model, VDPOSA requires you to recognize a universal opt-out preference signal (such as Global Privacy Control) as a valid opt-out of sale and targeted advertising.

Transparency

AI-training disclosure

Your privacy notice must state whether you collect, use, or sell personal data for the purpose of training large language models — a requirement only Vermont and Connecticut currently impose.

Notice

Clear privacy notice

A reasonably accessible, clear privacy notice covering the categories of data processed, purposes, third parties, consumer rights, and how to exercise them.

Minimization

Data minimization

Collection must be limited to what is adequate, relevant, and reasonably necessary for the specific purpose disclosed to the consumer.

Security

Reasonable safeguards

Appropriate technical, physical, and administrative security measures to protect the personal data you hold.

Profiling

Impact assessments

Data protection impact assessments are required for processing that presents a heightened risk of harm, including certain profiling.

Children & teens

Heightened youth rules

Additional restrictions on processing teenagers' data, working alongside Vermont's Age-Appropriate Design Code Act.

🚫

Trackers still must not fire before consent

Even though Vermont's general model is opt-out for standard data, the practical website exposure is the same one behind every state privacy law and the CIPA wiretapping wave: third-party trackers loading on page load before a visitor has made any choice. Sensitive-data categories require opt-in, and analytics/advertising pixels that fire before consent undercut both your opt-out obligations and your data-minimization duty. The reliable answer is to block non-essential trackers until the visitor consents.

What a compliant setup looks like

✕ Non-compliant

  • Sensitive-data collection with no opt-in consent mechanism
  • Trackers firing on page load before any consent
  • No universal opt-out (GPC) signal recognition
  • Privacy notice silent on AI/LLM training use
  • No way for consumers to exercise access or deletion rights
  • No log or record of consent decisions

✓ Compliant

  • Explicit opt-in captured before any sensitive-data processing
  • Non-essential trackers blocked until the visitor consents
  • Global Privacy Control honored automatically as an opt-out
  • Privacy notice discloses AI-training data use plainly
  • Consumer-rights request process in place, 45-day response
  • Consent decisions logged with timestamp for accountability

See what fires before consent on your site

VDPOSA is about the data you process — but the first thing an investigator checks is what loads before consent. See which trackers fire before consent on your site, in about 10 seconds — no signup, no install.

Scan your site free →

Enforcement and penalties

The VDPOSA is enforced exclusively by the Vermont Attorney General — there is no private right of action, so individual consumers cannot sue directly. Before bringing an enforcement action, the Attorney General must issue notice of the alleged violation and provide a mandatory cure period.

Enforcement authority
Vermont AG
Exclusive enforcement by the Office of the Attorney General. No private right of action for consumers.
Cure period
60 days
A mandatory 60-day right to cure applies through June 30, 2029. After that date, the cure period becomes discretionary.

Violations of the VDPOSA are treated as unfair and deceptive acts under Vermont's Consumer Protection Act, which is the mechanism through which penalties are assessed. The absence of a private right of action does not lessen the compliance obligation — it channels enforcement through the Attorney General rather than the courts.

Live compliance check — fresh session
Meta Pixel (connect.facebook.net)BLOCKED
Google Analytics / GA4 (gtag)BLOCKED
Precise-geolocation SDKBLOCKED
Health-data analytics tagBLOCKED
Consent banner✓ DISPLAYED
AI-training disclosure✓ IN NOTICE
Consent log entry✓ PENDING CHOICE
With ConsentPixel, non-essential and sensitive-data trackers stay blocked until the visitor makes a choice — and every decision is logged. Sensitive categories require an explicit opt-in before they release at all.

How to comply with VDPOSA

VDPOSA readiness is operational infrastructure, not a one-time task — and because the effective date is January 1, 2028, you have room to get it right now rather than under deadline pressure. These are the steps, ordered by impact.

01

Install a consent platform that blocks before consent

The foundation. A CMP technically blocks non-essential trackers until consent is given, captures opt-in for sensitive categories, honors universal opt-out signals, and logs every decision. ConsentPixel — Privacy · Verified does all of this from one script tag, with VDPOSA support already built in.

02

Turn on sensitive-data opt-in

Identify any sensitive-data processing — health, biometric, precise location, and the other listed categories — and gate it behind explicit opt-in consent rather than opt-out. This is the single biggest difference from the standard state model.

03

Add the AI-training disclosure to your privacy notice

State plainly whether you collect, use, or sell personal data to train large language models. ConsentPixel's privacy policy generator can include this disclosure so your notice meets the Vermont (and Connecticut) requirement.

04

Recognize the Global Privacy Control signal

Configure your site to treat a universal opt-out signal as a valid opt-out of sale and targeted advertising, automatically — no extra step required from the visitor.

05

Set up a consumer-rights request process

Provide a way for Vermont residents to submit access, correction, deletion, portability, and opt-out requests, and to obtain a list of third parties their data was sold to. ConsentPixel includes a DSAR request flow with deadline tracking.

06

Keep a consent and processing record

Log consent decisions with timestamps and maintain records of your processing activities and any required impact assessments — the documentation that demonstrates accountability if the Attorney General asks.

VDPOSA compliance checklist

Use this to assess where your website stands today, ahead of the January 1, 2028 effective date.

Consent platform installed — non-essential trackers blocked until consent
Sensitive-data processing gated behind explicit opt-in consent
Consumer-health-data handling reviewed (applies with no threshold)
Global Privacy Control recognized automatically as an opt-out
Privacy notice discloses AI/LLM training data use
Privacy notice covers data categories, purposes, third parties, and rights
Consumer-rights request process in place — 45-day response window
Mechanism to provide a list of third parties data was sold to
Data protection impact assessments completed for higher-risk profiling
Consent decisions logged with timestamp for accountability
Teen-data handling aligned with the Age-Appropriate Design Code Act

Being ready before 2028 is the easy win

The VDPOSA doesn't take effect until January 1, 2028 — which is exactly why now is the time to handle it. The compliance infrastructure it requires (prior blocking, sensitive-data opt-in, the AI-training disclosure, opt-out signal handling) is the same infrastructure that protects you under every other state privacy law and the CIPA wiretapping wave already in motion.

ConsentPixel already supports VDPOSA today. You can switch it on now, be verifiably ready well ahead of the deadline, and cover Vermont alongside the rest of your US state-law exposure from a single script tag — rather than treating each new state law as a fresh fire drill.

VDPOSA frequently asked questions

When does the VDPOSA take effect?

The Vermont Data Privacy and Online Surveillance Act was signed into law on June 16, 2026, and takes legal effect on January 1, 2028. The two-year runway is deliberate, giving businesses time to prepare — but because the required infrastructure (prior tracker blocking, sensitive-data opt-in, AI-training disclosure, opt-out signal handling) overlaps heavily with other state laws already in force, there is little reason to wait. ConsentPixel already includes VDPOSA support, so you can be compliant-ready well ahead of the effective date.

Does the VDPOSA apply to my business?

It applies if you conduct business in Vermont or target products or services to Vermont residents and, in the prior year, met one of three thresholds: controlling or processing the personal data of 35,000+ Vermont consumers; controlling or processing the sensitive data of 3,000+ consumers; or offering for sale the personal data of 3,000+ consumers. Separately, the consumer-health-data provisions apply with no threshold to any business targeting Vermont residents. These thresholds are among the lowest in the country, so many small and mid-sized businesses that escape other state laws are still in scope.

How is the VDPOSA different from other state privacy laws?

While it follows the Connecticut controller/processor model, the VDPOSA is broader in several ways: one of the lowest applicability thresholds in the country, a very broad definition of sensitive data (including biometric and neural data), standalone consumer-health-data protections that apply with no threshold, a consumer right to obtain the list of third parties their data was sold to, and — as only the second state after Connecticut — a requirement to disclose AI/LLM training practices in the privacy notice. It requires opt-in consent for sensitive data, unlike the opt-out default for standard data.

Does the VDPOSA require opt-in consent?

For sensitive data, yes. The VDPOSA requires explicit, affirmative opt-in consent before processing sensitive data — which it defines broadly to include race, ethnicity, religious beliefs, sexual orientation, gender identity, health data, biometric and neural data, and precise geolocation. For standard personal data, Vermont follows the opt-out model common to most state laws, meaning consumers can opt out of sale, targeted advertising, and certain profiling. In practice this means your consent setup must handle both an opt-in path for sensitive categories and opt-out signal recognition for the rest.

Is there a private right of action under the VDPOSA?

No. The VDPOSA is enforced exclusively by the Vermont Attorney General, and there is no private right of action — individual consumers cannot sue businesses directly for violations. An earlier, stricter version of the bill that included a private right of action was vetoed in 2024; the enacted law removed it. Before bringing an action, the Attorney General must give notice and a mandatory 60-day cure period, which applies through June 30, 2029, after which the cure period becomes discretionary.

What does the AI-training disclosure requirement mean for my website?

The VDPOSA requires your privacy notice to state whether you collect, use, or sell personal data for the purpose of training large language models. Vermont is only the second state, after Connecticut, to impose this. If you use customer or visitor data to train or fine-tune AI models — or share it with parties who do — that has to be disclosed plainly in your privacy notice. ConsentPixel's privacy policy generator can include this disclosure so your notice meets the requirement without you having to draft the language yourself.

Be VDPOSA-ready before Vermont's 2028 deadline

ConsentPixel — Privacy · Verified handles prior tracker blocking, sensitive-data opt-in, the AI-training disclosure, opt-out signal recognition, consumer-rights requests, and consent logging — for Vermont and every other US state law, from one script tag.

No credit card required · from $8.99/domain/mo · cancel any time
Scroll to Top