Skip to main content

Vermont’s Privacy Law Reaches Far Beyond Its Borders: What Companies Everywhere Need to Know

What You Need To Know

  • Vermont’s new data privacy and online surveillance law takes effect January 1, 2028, and applies to any company annually processing personal data of at least 35,000 Vermont residents, regardless of physical presence in the state, capturing many national and global tech and life sciences firms.
  • The law includes strong consumer health protections, prohibiting the sale of consumer health data without consent and banning geofencing near healthcare facilities for health-related targeting. A companion Genetic Information Privacy Act requires explicit opt-in consent before direct-to-consumer genetic testing companies may sell genetic data.
  • Privacy notices must disclose whether personal data is collected or sold to train large language models, a unique requirement pushing companies to document AI training data sources and update governance controls.
  • Consumer rights expand to include questioning profiling outcomes and requesting reevaluation of automated decisions that produce legal or similarly significant effects. Companies must also maintain third-party sale logs and honor universal opt-out signals from privacy browser settings. 
  • Enforcement rests with the Vermont Attorney General, with a 60-day cure period through June 30, 2029. Companies should begin compliance planning now, including data protection assessments and updated consent workflows for sensitive and health data.

Vermont’s new comprehensive privacy law, the Vermont Data Privacy and Online Surveillance Act (VDPOSA), takes effect January 1, 2028, and will reverberate well beyond state lines. It applies to any company doing business in Vermont or targeting Vermont residents, even if it has no physical footprint in the state, an important consideration for tech and life sciences companies with digital products, remote services, or data-driven operations touching Vermonters. 

Coverage thresholds are low by U.S. standards, making it easier for out-of-state companies to be pulled in. The law applies if, in the prior year, a company processed personal data of at least 35,000 Vermont residents (excluding data used solely to complete a payment), processed sensitive data for at least 3,000 residents, or sold the personal data of at least 3,000 residents. That 35,000-consumer threshold is low in absolute terms; a bar that large national and global companies easily clear. 

Business Impacts from the Vermont Data Privacy and Online Surveillance Act 

Tech companies face a familiar but expanding slate of consumer rights, along with some novel twists. Vermont residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, sale of personal data, and certain automated profiling decisions that produce legal or similarly significant effects. The law adds a right to question profiling outcomes, be informed of the reasoning behind such decisions, and, in housing contexts, correct inaccurate data and have the decision reevaluated. Companies must also provide a list of third parties to whom they sold the consumer’s personal data, or, if they do not maintain a consumer-specific list, a list of all third parties to whom they have sold personal data. These obligations will require robust data inventories, sale logs, and explainability mechanisms for algorithmic decision-making. 

For life sciences and digital health companies, the VDPOSA’s consumer health protections demand special attention. The law broadly defines consumer health data and prohibits selling such data without consent. It also bans geofencing within 1,850 feet of healthcare facilities when used to track or target individuals for certain health-related purposes, an adtech and analytics practice that has drawn regulatory scrutiny nationwide. 

Operationally, the VDPOSA reinforces modern privacy-by-design expectations. Controllers must implement clear privacy notices, practice data minimization and purpose limitation, maintain reasonable security, and obtain consent before processing sensitive data, which Vermont defines broadly to include health and genetic data, biometrics, precise geolocation, and more. Notably for AI builders and enterprise adopters, privacy notices must disclose whether personal data is collected, used, or sold to train large language models (LLMs). This unique disclosure requirement will push companies to document AI training data sources and update notices and governance controls accordingly, particularly for product teams fine-tuning or retraining models with consumer data. 

Vermont also requires companies to respect universal opt-out preference signals and opt-outs submitted by authorized agents. Practically, that means engineering teams should prepare to recognize and honor signals (for example, from browser privacy settings) consistent with other states’ opt-out frameworks, and to manage agent-submitted requests at scale. Failing to do so could invite enforcement risk once the cure period sunsets. 

Risk assessment duties rise as well. Controllers must conduct data protection assessments for targeted advertising, sale of personal data, sensitive data processing, and profiling that creates foreseeable risk of harm or produces legal or similarly significant effects. These assessments apply to processing created or generated after January 1, 2028, giving product, privacy, and security leaders a window to build or enhance assessment programs that can withstand regulator scrutiny across jurisdictions. 

Enforcement is centralized with the Vermont Attorney General; there is no private right of action. A 60-day cure period applies through June 30, 2029, after which the attorney general may, but doesn’t have to, offer an opportunity to cure. For global companies navigating a patchwork of state privacy laws, this model aligns with several non-California regimes, but Vermont’s relatively strong health/genetic data protections raise the stakes for compliance planning in 2026–2027. 

The Wider Legal Landscape 

Adjacent laws amplify the compliance picture. In parallel, Vermont enacted a Genetic Information Privacy Act that restricts direct-to-consumer (DTC) genetic testing companies from selling genetic data without explicit, opt-in consent, prohibits the use of dark patterns to obtain consent, and requires destruction of DNA samples and deletion of related data upon request — requirements that will materially affect genomics platforms and DTC testing providers operating across borders if they serve Vermont residents. 

Vermont’s new data broker registration law also imposes annual registration and fees on data brokers and establishes a public registry, pressuring advertising technology, analytics, and data enrichment providers to evaluate their status and disclosures. It also directs studies on state-wide deletion mechanisms and creates a cybersecurity advisory council, signaling continued legislative attention to data governance and security resilience. 

Key Action Items: 

  • Map data flows comprehensively, including health, genetic, biometric, precise location, and children’s data; update lawful basis and consent records for sensitive data and health data sales. 
  • Build or refine mechanisms to honor opt-out signals and authorized-agent requests; ensure targeted advertising, sale, and profiling flags are propagated across systems. 
  • Stand up explainability and contestation workflows for high-impact automated decisions, with special protocols for housing-related outcomes. 
  • Enhance privacy notices to disclose any use of personal data for LLM training and maintain auditable records to substantiate those disclosures. 
  • Prepare third-party sale lists and implement sale logs to respond to new consumer rights efficiently. 
  • Rework consent user experience for DTC genomics and digital health businesses to avoid dark patterns and implement verifiable destruction/deletion workflows for genetic materials and data upon request. 
  • Establish scalable data protection assessment practices for new or materially changed processing after January 1, 2028. 

With thoughtful preparation in 2026–2027, companies can meet Vermont’s requirements while advancing trustworthy AI, analytics, and health innovation across their national and global footprints.