Business Compliance Guidance for the New Vermont Data Privacy and Online Surveillance Act (VDPOSA)
Vermont Becomes the 23rd US State to Enact a Consumer Privacy Law
On June 16, 2026, Governor Scott signed S.71, the Vermont Data Privacy and Online Surveillance Act (VDPOSA), making Vermont the 23rd state to enact a comprehensive consumer privacy law.
While the final bill is more business-friendly than its predecessor—most notably, the controversial private right of action was stripped out—the VDPOSA imposes several obligations that go beyond the typical Connecticut-style framework, and companies should not mistake the January 1, 2028, effective date for breathing room.
Our following alert summarizes the scope of the new law, the provisions that materially differ the most from the multi-state baseline, and the compliance planning steps businesses should begin taking now.
Scope and Applicability
Consumer Rights
Sensitive Data and Consumer Health Data
Data Protection and Profiling Assessments
AI Training Disclosure
Protections for Minors
Companion Legislation: Data Broker Reforms (H.211)
Governor Scott signed House Bill 211 on the same day as the VDPOSA. Its data broker and edtech provisions take effect January 1, 2027, and require, among other things:
-
- annual data broker registration with the Vermont Secretary of State and payment of a $900 registration fee;
-
- accelerated 30-day registration once a data broker first meets the statutory definition;
-
- expanded mandatory disclosures, including whether the broker collects precise geolocation data or immigration status; whether it has sold or shared consumer data with foreign actors, government entities, or “developer[s] of a GenAI system or model;” and the URL of a page addressing consumer rights;
-
- a new $20,000 bond requirement; and
-
- data broker-specific security breach notice requirements.
Data brokers and companies whose vendor arrangements may implicate the definition should reassess their Vermont posture well before the 2027 effective date.
Compliance Planning Steps
The January 1, 2028, effective date is deceptive. Because the VDPOSA layers Connecticut-style obligations onto several Vermont-specific enhancements—and since the data broker and Age Appropriate Design Code obligations arrive sooner—businesses subject to the VDPOSA should begin the following compliance activities now:
-
- Reassess applicability against the 35,000/3,000/3,000 thresholds and inventory Vermont resident data flows.
- Update sensitive data inventories to capture neural data, gender affirming health data, and reproductive or sexual health data, and confirm opt-in consent workflows.
- Evaluate consumer health data practices, including employee confidentiality obligations, geofencing controls near healthcare facilities, and any sale of consumer health data, regardless of whether the general law applies.
- Refresh privacy notices to include AI training disclosures and to align with Connecticut’s amended notice standard.
- Design a profiling impact assessment framework distinct from your existing data protection assessment template, and confirm assessments will be preserved as confidential and producible upon Attorney General request.
- Refine data subject rights processes to accommodate the third-party disclosure list, human review, and appeal of profiling (including housing-specific correction and reevaluation), and the restricted response categories that must not be disclosed in access responses.
- Configure teen data controls for consumers between 13 and 17 years old where the controller has actual knowledge of age.
- For data brokers, prepare for the January 1, 2027, registration, bond, disclosure, and breach notice obligations under H.211.
We Are Here to Help
Companies with mature Connecticut Data Privacy Act programs will find the VDPOSA less burdensome to comply with. However, the Vermont-specific overlays—particularly around consumer health data, profiling assessments, restricted access responses, and AI training disclosures—will require targeted work.
Hinshaw’s Data Privacy, AI & Cybersecurity team is available to help clients scope Vermont’s requirements against their existing multi-state compliance frameworks.
Related People
Related Capabilities
Featured Insights

Healthcare Alert
Jul 24, 2026
Q&A: Right to Electronic Monitoring Extended to Illinois Assisted and Shared Living Facilities

Press Release
Jul 23, 2026
Insurance Partner Christophe Burusco Joins Hinshaw in Los Angeles

In The News
Jul 16, 2026
Jennifer Driscoll Anticipates Epic Battle Between “Titans of the Antitrust Bar”

Press Release
Jul 15, 2026
Two Hinshaw Partners Recognized in Minnesota Monthly's 2026 Top Lawyers in Minnesota

Event
July 13-15, 2026
Hinshaw Proudly Sponsors 2026 Lavender Law Conference and Career Fair

Webinar
Jul 14, 2026
Scott Seaman Presents on Horizontal vs. Vertical Exhaustion of Insurance

Healthcare Alert
Jul 8, 2026
A New Era of Compliance Standards for California DSOs and MSOs After the Aspen Dental Settlement

Insights for Insurers Alert
Jul 7, 2026
What Insurers Need to Know About California’s FAIR Plan Assessment Recoupment Guidance

In The News
Jul 6, 2026
Francesco Palanda’s Practical Guide for Mitigating AI-Related Business Interruption Risk



