Vermont Data Privacy and Online Surveillance Act (VDPOSA)

UniConsent helps businesses comply with the Vermont Data Privacy and Online Surveillance Act (VDPOSA). Manage sensitive data opt-in consent, consumer rights requests, AI training disclosures, and opt-out mechanisms for targeted advertising and data sales.

Fait confiance à plus de 5000 éditeurs et marketeurs du monde entier
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Vermont Data Privacy and Online Surveillance Act (VDPOSA)

The Vermont Data Privacy and Online Surveillance Act (VDPOSA), enacted as Act 145, was signed into law on June 16, 2026, and takes effect on January 1, 2028. Vermont's law is among the most comprehensive and consumer-protective state privacy laws in the United States, with notable provisions covering neural data, AI training disclosure, and health data geofencing.

What Is the VDPOSA?

The VDPOSA grants Vermont residents rights over their personal data and imposes obligations on businesses that collect or process that data. It requires opt-in consent for sensitive data, mandates disclosure when personal data is used to train AI models, and prohibits geofencing around healthcare facilities. A 60-day cure period applies from January 1, 2028 through June 30, 2029, after which the Attorney General may bring enforcement actions without prior notice.

Who Does the VDPOSA Apply To?

The VDPOSA applies to entities conducting business in Vermont or targeting Vermont residents that, in the preceding calendar year, met at least one of the following thresholds:

  • Controlled or processed personal data of 35,000 or more consumers; or
  • Controlled or processed sensitive data of 3,000 or more consumers; or
  • Offered to sell personal data of 3,000 or more consumers.

Any business handling consumer health data is covered regardless of size or volume.

Exempted entities include federal, state, tribal, and local government; HIPAA-covered entities (non-hybrid) and their business associates; state and federally chartered banks, credit unions, and affiliates primarily engaged in financial activities; and limited nonprofit categories (fraud detection organizations, enrollment verification providers, and certain noncommercial media).

Consumer Rights Under the VDPOSA

Vermont residents are entitled to:

  • Right to access: request a copy of their personal data and any inferences drawn from it
  • Right to correction: request correction of inaccurate personal data
  • Right to deletion: request deletion of personal data
  • Right to portability: obtain a portable copy in a usable format
  • Right to opt out: opt out of targeted advertising, the sale of personal data, and certain profiling

Consumers may designate authorized agents to exercise these rights on their behalf. Businesses must respond to verified consumer requests within 45 days of receipt, with a 45-day extension permitted where reasonably necessary.

Sensitive Data

The VDPOSA requires explicit opt-in consent before processing sensitive data. Sensitive data includes:

  • Consumer health data, including gender-affirming and reproductive health information
  • Genetic and biometric data (including biometric data not used for unique identification)
  • Precise geolocation data
  • Mental health data
  • Financial account data
  • Personal data of known children
  • Immigration status
  • Neural data (information generated by measuring the activity of an individual's central nervous system)

Vermont's inclusion of neural data and its expanded biometric definition set it apart from most other state privacy laws.

Key Obligations

Beyond consumer rights, controllers must:

  • Limit data collection to what is reasonably necessary for the stated purpose
  • Publish an accessible privacy notice with required disclosures
  • Conduct data protection assessments for high-risk processing activities
  • Enter into written processor contracts with specified terms
  • Disclose in their privacy policy whether personal data will be used to train large language models or AI systems, including the exact date and month of the last policy update; for mobile apps, this disclosure must be accessible directly within app settings
  • Refrain from deploying a geofence within 1,850 feet of any healthcare facility to identify, track, or collect data from consumers

Enforcement

The VDPOSA is enforced exclusively by the Vermont Attorney General. There is no private right of action. Civil penalties of up to $10,000 per violation apply under the Vermont Consumer Protection Act, with each affected consumer counting as a separate violation. A 60-day cure period is available from January 1, 2028 through June 30, 2029; after that date, enforcement proceeds without prior notice.

How UniConsent Supports VDPOSA Compliance

UniConsent provides the tools businesses need to meet VDPOSA requirements:

  • Opt-in consent banners for sensitive and health data, configurable by state
  • Opt-out mechanisms for targeted advertising, data sales, and profiling
  • Consumer rights request management, including support for authorized agents
  • AI training disclosure support in privacy notice workflows
  • Integration with websites, mobile apps, and tag managers

Get started with UniConsent or explore our features.

Other US State Privacy Laws

  • CCPA: California Consumer Privacy Act, learn more at CCPA
  • CPRA: California Privacy Rights Act, learn more at CPRA
  • CPA: Colorado Privacy Act, learn more at CPA
  • VCDPA: Virginia Consumer Data Protection Act, learn more at VCDPA
  • UCPA: Utah Consumer Privacy Act, learn more at UCPA
  • CTDPA: Connecticut Data Protection Act, learn more at CTDPA
  • TDPSA: Texas Data Privacy and Security Act, learn more at TDPSA
  • DPDPA: Delaware Personal Data Privacy Act, learn more at DPDPA
  • NHPA: New Hampshire Privacy Act, learn more at NHPA
  • MTCDPA: Montana Consumer Data Privacy Act, learn more at MTCDPA
  • FDBR: Florida Digital Bill of Rights, learn more at FDBR
  • NJDPA: New Jersey Data Protection Act, learn more at NJDPA
  • INCDPA: Indiana Consumer Data Protection Act, learn more at INCDPA
  • ICDPA: Iowa Consumer Data Protection Act, learn more at ICDPA
  • LDPA: Louisiana Data Privacy Act, learn more at LDPA

Compare different US State Privacy Laws

VDPOSA Compliance by UniConsent

  • CMP certifié IAB
  • Prise en charge de Google Consent Mode v2
  • Prise en charge du Global Privacy Control (GPC)
  • Prise en charge du signal universel de désinscription
  • Plusieurs étapes entièrement personnalisables
  • Implémentation en une seule balise
  • Prise en charge de Google Tag Manager
  • Suivi et analyse
  • Prise en charge de plusieurs langues
  • Blocage des balises JavaScript et des cookies
  • Analyse et divulgation des cookies
  • Solution facile en libre-service

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Conformez-vous aux réglementations mondiales sur la confidentialité

Commencez à rendre votre site web et votre application conformes au RGPD de l'UE, au CPRA des États-Unis, au PIPEDA de la CA, etc.

S'inscrire