VDPOSA Compliance for Websites in Vermont
The Vermont Data Privacy and Online Surveillance Act (VDPOSA) is one of the broadest state privacy laws in the country — opt-in consent for sensitive data, a low applicability threshold, standalone consumer-health-data rules, and an AI-training disclosure requirement. It takes effect January 1, 2028. ConsentPixel — Privacy · Verified already supports it, so you can be ready ahead of the deadline.
Key facts verified July 2026 against analyses from Mayer Brown, Cooley, Hinshaw & Culbertson, Covington, and the Future of Privacy Forum. This page is educational and is not legal advice.
Vermont became the 24th US state to enact a comprehensive consumer privacy law when Governor Phil Scott signed S.71 into law on June 16, 2026. Codified at 9 V.S.A. Chapter 61A, the VDPOSA closely tracks the Connecticut model but pushes further in several areas — making it one of the more demanding state privacy frameworks enacted to date. The law takes effect January 1, 2028, and is enforced exclusively by the Vermont Attorney General.
Supported in ConsentPixel today — ahead of the 2028 deadline
VDPOSA does not take legal effect until January 1, 2028, but the compliance work — prior consent, opt-in for sensitive data, an AI-training disclosure, and honoring opt-out signals — is infrastructure you can put in place now. ConsentPixel already includes VDPOSA support, so you can switch it on today and be ready well before the deadline rather than scrambling near it.
What is the VDPOSA?
The Vermont Data Privacy and Online Surveillance Act is a comprehensive consumer privacy law that gives Vermont residents rights over how businesses collect, use, and share their personal data — and imposes corresponding duties on the businesses (controllers and processors) that handle it. It follows the "controller/processor" framework now common across US state privacy laws, with definitions generally consistent with the Connecticut Data Privacy Act.
What sets Vermont apart is the reach. The VDPOSA carries one of the lowest applicability thresholds in the country, one of the broadest definitions of sensitive data (including biometric and neural data), standalone consumer-health-data protections that apply with no threshold at all, and — as only the second state after Connecticut — a requirement to disclose AI/LLM training practices in your privacy notice. Governor Scott had vetoed a stricter version, including a private right of action, in 2024; the enacted law removed the private right of action but kept the broad scope.
The low thresholds mean VDPOSA reaches well beyond big companies
Because the sensitive-data and data-sale thresholds trigger at just 3,000 Vermont consumers — and the consumer-health-data rules apply to any business targeting Vermont residents regardless of size — many small and mid-sized businesses that fall outside other state laws will still be in scope here. If you process health-related data about Vermonters, the health-data provisions can apply to you even if the general thresholds don't.
Does the VDPOSA apply to your website?
The VDPOSA applies to any person or business that conducts business in Vermont, or targets products or services to Vermont residents, and in the preceding calendar year met at least one of these thresholds:
- 35,000+ Vermont consumers whose personal data you controlled or processed (excluding data used solely to complete a payment transaction), or
- 3,000+ Vermont consumers whose sensitive data you controlled or processed, or
- 3,000+ Vermont consumers whose personal data you offered for sale in trade or commerce.
Separately — and importantly — the VDPOSA's consumer-health-data provisions apply with no threshold. They reach any business that conducts business in Vermont or targets products or services to Vermont residents, regardless of how many consumers are involved. It is uncommon for a state law to tie a threshold to sensitive-data processing at all, and rarer still to protect health data with no threshold — both are what make Vermont's reach unusually broad.
Consumer rights under VDPOSA
The VDPOSA gives Vermont residents a familiar set of consumer rights, plus a couple that go beyond the standard state model. Businesses must provide a way to exercise each of these and generally respond within 45 days.
Access
Confirm whether you process their data and obtain a copy of it.
Correct
Fix inaccuracies in the personal data you hold about them.
Delete
Request deletion of personal data you have collected or obtained.
Portability
Obtain their data in a portable, readily usable format.
Opt out of sale & targeted ads
Opt out of the sale of their data, targeted advertising, and certain profiling.
List of third parties
Obtain a list of the third parties to whom their personal data was sold — a right that goes beyond the standard state template.
Question profiling
Contest and question certain automated profiling decisions that produce significant effects.
Opt in for sensitive data
Sensitive data cannot be processed at all without the consumer's explicit opt-in consent.
What VDPOSA requires of your website
On the website side, VDPOSA compliance comes down to consent handling, transparency, and honoring consumer choices. Here are the areas your site needs to address.
Opt-in for sensitive data
Explicit, affirmative opt-in consent is required before processing any sensitive data — race, ethnicity, religion, sexual orientation, gender identity, health data, biometric or neural data, or precise geolocation.
Honor universal opt-out
Like the Connecticut model, VDPOSA requires you to recognize a universal opt-out preference signal (such as Global Privacy Control) as a valid opt-out of sale and targeted advertising.
AI-training disclosure
Your privacy notice must state whether you collect, use, or sell personal data for the purpose of training large language models — a requirement only Vermont and Connecticut currently impose.
Clear privacy notice
A reasonably accessible, clear privacy notice covering the categories of data processed, purposes, third parties, consumer rights, and how to exercise them.
Data minimization
Collection must be limited to what is adequate, relevant, and reasonably necessary for the specific purpose disclosed to the consumer.
Reasonable safeguards
Appropriate technical, physical, and administrative security measures to protect the personal data you hold.
Impact assessments
Data protection impact assessments are required for processing that presents a heightened risk of harm, including certain profiling.
Heightened youth rules
Additional restrictions on processing teenagers' data, working alongside Vermont's Age-Appropriate Design Code Act.
Trackers still must not fire before consent
Even though Vermont's general model is opt-out for standard data, the practical website exposure is the same one behind every state privacy law and the CIPA wiretapping wave: third-party trackers loading on page load before a visitor has made any choice. Sensitive-data categories require opt-in, and analytics/advertising pixels that fire before consent undercut both your opt-out obligations and your data-minimization duty. The reliable answer is to block non-essential trackers until the visitor consents.
What a compliant setup looks like
✕ Non-compliant
- Sensitive-data collection with no opt-in consent mechanism
- Trackers firing on page load before any consent
- No universal opt-out (GPC) signal recognition
- Privacy notice silent on AI/LLM training use
- No way for consumers to exercise access or deletion rights
- No log or record of consent decisions
✓ Compliant
- Explicit opt-in captured before any sensitive-data processing
- Non-essential trackers blocked until the visitor consents
- Global Privacy Control honored automatically as an opt-out
- Privacy notice discloses AI-training data use plainly
- Consumer-rights request process in place, 45-day response
- Consent decisions logged with timestamp for accountability
See what fires before consent on your site
VDPOSA is about the data you process — but the first thing an investigator checks is what loads before consent. See which trackers fire before consent on your site, in about 10 seconds — no signup, no install.
Scan your site free →Enforcement and penalties
The VDPOSA is enforced exclusively by the Vermont Attorney General — there is no private right of action, so individual consumers cannot sue directly. Before bringing an enforcement action, the Attorney General must issue notice of the alleged violation and provide a mandatory cure period.
Violations of the VDPOSA are treated as unfair and deceptive acts under Vermont's Consumer Protection Act, which is the mechanism through which penalties are assessed. The absence of a private right of action does not lessen the compliance obligation — it channels enforcement through the Attorney General rather than the courts.
How to comply with VDPOSA
VDPOSA readiness is operational infrastructure, not a one-time task — and because the effective date is January 1, 2028, you have room to get it right now rather than under deadline pressure. These are the steps, ordered by impact.
Install a consent platform that blocks before consent
The foundation. A CMP technically blocks non-essential trackers until consent is given, captures opt-in for sensitive categories, honors universal opt-out signals, and logs every decision. ConsentPixel — Privacy · Verified does all of this from one script tag, with VDPOSA support already built in.
Turn on sensitive-data opt-in
Identify any sensitive-data processing — health, biometric, precise location, and the other listed categories — and gate it behind explicit opt-in consent rather than opt-out. This is the single biggest difference from the standard state model.
Add the AI-training disclosure to your privacy notice
State plainly whether you collect, use, or sell personal data to train large language models. ConsentPixel's privacy policy generator can include this disclosure so your notice meets the Vermont (and Connecticut) requirement.
Recognize the Global Privacy Control signal
Configure your site to treat a universal opt-out signal as a valid opt-out of sale and targeted advertising, automatically — no extra step required from the visitor.
Set up a consumer-rights request process
Provide a way for Vermont residents to submit access, correction, deletion, portability, and opt-out requests, and to obtain a list of third parties their data was sold to. ConsentPixel includes a DSAR request flow with deadline tracking.
Keep a consent and processing record
Log consent decisions with timestamps and maintain records of your processing activities and any required impact assessments — the documentation that demonstrates accountability if the Attorney General asks.
VDPOSA compliance checklist
Use this to assess where your website stands today, ahead of the January 1, 2028 effective date.
Being ready before 2028 is the easy win
The VDPOSA doesn't take effect until January 1, 2028 — which is exactly why now is the time to handle it. The compliance infrastructure it requires (prior blocking, sensitive-data opt-in, the AI-training disclosure, opt-out signal handling) is the same infrastructure that protects you under every other state privacy law and the CIPA wiretapping wave already in motion.
ConsentPixel already supports VDPOSA today. You can switch it on now, be verifiably ready well ahead of the deadline, and cover Vermont alongside the rest of your US state-law exposure from a single script tag — rather than treating each new state law as a fresh fire drill.
VDPOSA frequently asked questions
When does the VDPOSA take effect?
The Vermont Data Privacy and Online Surveillance Act was signed into law on June 16, 2026, and takes legal effect on January 1, 2028. The two-year runway is deliberate, giving businesses time to prepare — but because the required infrastructure (prior tracker blocking, sensitive-data opt-in, AI-training disclosure, opt-out signal handling) overlaps heavily with other state laws already in force, there is little reason to wait. ConsentPixel already includes VDPOSA support, so you can be compliant-ready well ahead of the effective date.
Does the VDPOSA apply to my business?
It applies if you conduct business in Vermont or target products or services to Vermont residents and, in the prior year, met one of three thresholds: controlling or processing the personal data of 35,000+ Vermont consumers; controlling or processing the sensitive data of 3,000+ consumers; or offering for sale the personal data of 3,000+ consumers. Separately, the consumer-health-data provisions apply with no threshold to any business targeting Vermont residents. These thresholds are among the lowest in the country, so many small and mid-sized businesses that escape other state laws are still in scope.
How is the VDPOSA different from other state privacy laws?
While it follows the Connecticut controller/processor model, the VDPOSA is broader in several ways: one of the lowest applicability thresholds in the country, a very broad definition of sensitive data (including biometric and neural data), standalone consumer-health-data protections that apply with no threshold, a consumer right to obtain the list of third parties their data was sold to, and — as only the second state after Connecticut — a requirement to disclose AI/LLM training practices in the privacy notice. It requires opt-in consent for sensitive data, unlike the opt-out default for standard data.
Does the VDPOSA require opt-in consent?
For sensitive data, yes. The VDPOSA requires explicit, affirmative opt-in consent before processing sensitive data — which it defines broadly to include race, ethnicity, religious beliefs, sexual orientation, gender identity, health data, biometric and neural data, and precise geolocation. For standard personal data, Vermont follows the opt-out model common to most state laws, meaning consumers can opt out of sale, targeted advertising, and certain profiling. In practice this means your consent setup must handle both an opt-in path for sensitive categories and opt-out signal recognition for the rest.
Is there a private right of action under the VDPOSA?
No. The VDPOSA is enforced exclusively by the Vermont Attorney General, and there is no private right of action — individual consumers cannot sue businesses directly for violations. An earlier, stricter version of the bill that included a private right of action was vetoed in 2024; the enacted law removed it. Before bringing an action, the Attorney General must give notice and a mandatory 60-day cure period, which applies through June 30, 2029, after which the cure period becomes discretionary.
What does the AI-training disclosure requirement mean for my website?
The VDPOSA requires your privacy notice to state whether you collect, use, or sell personal data for the purpose of training large language models. Vermont is only the second state, after Connecticut, to impose this. If you use customer or visitor data to train or fine-tune AI models — or share it with parties who do — that has to be disclosed plainly in your privacy notice. ConsentPixel's privacy policy generator can include this disclosure so your notice meets the requirement without you having to draft the language yourself.
Be VDPOSA-ready before Vermont's 2028 deadline
ConsentPixel — Privacy · Verified handles prior tracker blocking, sensitive-data opt-in, the AI-training disclosure, opt-out signal recognition, consumer-rights requests, and consent logging — for Vermont and every other US state law, from one script tag.