Vermont will enforce a new data privacy and online surveillance law starting January 1, 2028, and the law will apply to companies outside the state's borders.
What happened
Vermont enacted the Vermont Data Privacy and Online Surveillance Act (VDPOSA), which takes effect January 1, 2028. The law applies to any company doing business in Vermont or targeting Vermont residents, even without a physical presence in the state. It covers companies that, in the prior year, processed personal data of at least 35,000 Vermont residents, processed sensitive data for at least 3,000 residents, or sold personal data of at least 3,000 residents. The law grants Vermont residents rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, data sales, and certain automated profiling decisions. It also requires companies to disclose whether they collect, use, or sell personal data to train large language models.
The backstory
Vermont signed VDPOSA into law in June 2026. On August 4, 2026, Attorney General Charity Clark announced Vermont had joined the Consortium of Privacy Regulators, a coalition of state privacy regulators and attorneys general, following the law's passage and ahead of its 2028 effective date.
Going deeper
The law sets specific protections for health and genetic data. It prohibits companies from selling consumer health data without consent and bans geofencing within 1,850 feet of healthcare facilities when used to track or target people for health-related purposes. A companion law, the Genetic Information Privacy Act, requires direct-to-consumer genetic testing companies to obtain explicit opt-in consent before selling genetic data, bars dark patterns in obtaining that consent, and requires companies to destroy DNA samples and delete related data upon request.
Companies must recognize and honor universal opt-out signals, including those sent through browser privacy settings, and must process opt-out requests submitted by authorized agents. They must also maintain lists of third parties that received a consumer's personal data through a sale, or a general list of such third parties if they don't track sales by individual. The law requires companies to conduct data protection assessments for targeted advertising, data sales, sensitive data processing, and profiling that creates a foreseeable risk of harm, for any processing created or generated after January 1, 2028.
On August 4, 2026, Vermont Attorney General Charity Clark announced that Vermont has joined the Consortium of Privacy Regulators, a coalition of state privacy regulators and attorneys general that share expertise, resources, and enforcement strategies for state privacy laws. Vermont's participation follows directly from the passage of VDPOSA. With Vermont's addition, the consortium now includes the California Privacy Protection Agency and attorneys general from California, Colorado, Connecticut, Delaware, Indiana, New Hampshire, New Jersey, Maryland, Minnesota, Oregon, and Vermont. Attorney General Clark's office has worked with other states on privacy and consumer protection matters before, those multistate efforts have secured more than $8 million in settlements for Vermont over the last five years, according to the announcement.
What was said
Announcing Vermont's move to join the consortium, Attorney General Charity Clark said, “Vermonters should not have to give up their privacy to participate in modern life.” She added that Vermont's new law "gives each of us greater control over corporate use of our data, and joining this consortium will help my office work with other states to enforce those protections effectively and hold companies accountable when they violate the law."
In the know
Consumer health data, under Vermont's law, is defined broadly and receives its own set of protections, including a ban on selling it without consent. Universal opt-out signals let a person set their privacy preferences once, often through browser settings, so that websites automatically honor those preferences instead of requiring the person to opt out on every site individually. Geofencing uses a device's location to trigger targeted actions, such as advertising, when someone enters a defined area; Vermont's law restricts this practice near healthcare facilities.
Why it matters
This law reaches companies outside of Vermont. Since the law applies based on how many Vermont residents a company's data touches, national and global tech and life sciences companies can fall under it without operating locally, simply by having enough users or customers who happen to live in the state. The law's LLM training disclosure requirement stands out because it addresses telling consumers whether their data trains AI models. Any company building or fine-tuning language models with consumer data will need to trace and document where that data came from, not just how it's stored or shared.
For life sciences and digital health companies, the health data and geofencing restrictions add a compliance layer on top of existing HIPAA obligations, since VDPOSA's consumer health data protections apply regardless of whether HIPAA already covers the data.
The bottom line
Companies don't need a Vermont office to fall under this law, only enough Vermont users or customers. With the law taking effect January 1, 2028, and data protection assessment duties starting the same day, companies should use 2026 and 2027 to map their data flows, update consent and disclosure practices, and confirm whether they meet the law's requirements before enforcement begins.
FAQs
What happens if a company violates a state privacy law?
A state attorney general or dedicated privacy agency investigates and can pursue enforcement action, which may include fines.
Do small businesses have to comply with state privacy laws?
Usually not, since most state privacy laws exempt companies that fall below certain data-processing thresholds.
What is a "cure period" in privacy law enforcement?
A cure period is a set window of time during which a company can fix a violation before facing formal penalties.
Do state privacy laws apply to nonprofit organizations?
It differs by state, some laws exempt nonprofits, while others apply the same thresholds regardless of an organization's tax status.
