News

Vermont Enacts Data Privacy and Online Surveillance Act: What Businesses Need to Know

By  |  

On June 16, 2026, Vermont became the 23rd state to enact a comprehensive consumer data privacy law when Governor Phil Scott signed Senate Bill 71, the Vermont Data Privacy and Online Surveillance Act (the “Data Privacy Act”), into law.  The Data Privacy Act goes into effect on January 1, 2028.  While the Data Privacy Act largely tracks the framework adopted by other states, it includes notable departures that businesses should understand well before its effective date.

To whom will the new Data Privacy Act apply?

Notably, the Data Privacy Act’s applicability thresholds are lower than those adopted in many states, meaning more businesses will be subject to its requirements.  The Data Privacy Act applies to any person or business that conducts business in Vermont or produces products or services targeted to Vermont residents, and that meets one of the following thresholds during the prior calendar year: (1) controls or processes the personal data of at least 35,000 consumers; (2) controls or processes the sensitive data of at least 3,000 consumers; or (3) offers the personal data of at least 3,000 consumers for sale.  9 V.S.A. § 2415b.  Notably, those that would be regulated under items (1) or (2) above are exempt if the data is used solely for purposes of payment processing.

However, these applicability thresholds do not apply to the Data Privacy Act’s provisions regarding consumer health data.  In other words, every business that conducts business in Vermont, or produces products or services targeted towards Vermont residents, must comply with the consumer health data provisions regardless of the number of people whose data is involved.  Id.

Key Definitions

Under the Data Privacy Act, to “process” data means to conduct any operation on personal data, including to collect, use, store, disclose, or analyze such data.  9 V.S.A. § 2415a.

“Consumer” means an individual who resides in Vermont, acting only in an individual or household context.  For purposes of determining whether the Data Privacy Act applies, the term “consumer” does not include individuals acting in a commercial or employment context.  Id..  For example, the Data Privacy Act wouldn’t apply to the exchange of information between a sales representative and a prospective client during contract negotiations, or to an employer’s collection of an employee’s information for payroll purposes.

The Data Privacy Act covers businesses’ use of “personal data,” meaning any information that is linked, or could be reasonably linked, to an individual, such as an individual’s name, email address, and date of birth.  The definition even includes data that has been de-identified but can still be re-linked to an individual.  The Data Privacy Act imposes heightened protections on a subset of personal data known as “sensitive data.”  The Data Privacy Act has a broader definition of sensitive data than some other state privacy laws.  Sensitive data includes data revealing racial or ethnic origin, religious beliefs, sexual orientation, or immigration status, along with other protected categories such as consumer health data, genetic and biometric data, children’s data, precise geolocation, and financial information.  Id.

“Consumer health data” is defined as any personal information that is used to identify a consumer’s physical or mental health condition, diagnosis, or status.  Id.

What rights does the Data Privacy Act grant consumers?

Consistent with other state privacy laws, the Data Privacy Act grants consumers a standard set of rights with respect to their personal data.  Under the Data Privacy Act, consumers have the right to:

  • access copies of information about their own personal data;
  • require data holders to correct inaccuracies;
  • require data holders to delete certain personal data;
  • obtain personal data in a format that is portable and readily usable;
  • opt-out of certain processing activities, such as targeted advertising or the sale of personal data; and
  • request a list of the third parties to which the controller has sold the consumer’s personal data.  Id. at § 2415d.

What obligations does the Data Privacy Act impose on businesses?

The Data Privacy Act imposes several obligations on businesses that control or process data.  Businesses must maintain a written privacy policy that notifies consumers of the business’s data processing practices and informs consumers about how to exercise their privacy rights.  The privacy policy must be reasonably accessible to the consumer at the point of data collection, which means on the homepage of the business’s website or on the download page of the business’s mobile app, if applicable.  9 V.S.A. § 2415e(c).  Additionally, businesses must:

  • be transparent about the types of personal information they collect and how they use that information. 
  • limit the collection of personal data to what is reasonably necessary and proportionate to accomplish the purpose for which the data was provided.
  • obtain consumers’ consent before processing sensitive data, including consumer health data.
  • ensure reasonable data security practices. 

What’s next?

In order to come into compliance with the Data Privacy Act by January 1, 2028, businesses that operate in Vermont need to closely evaluate the types of data they collect, process, and sell, determine whether they should cease collecting certain types of data due to the requirements and limits that will apply to such data, and start discussing how to implement internal processes for handling consumer rights requests.

Please contact Catherine A. Burke (cburke@gravelshea.com) or Eleanor Moody (emoody@gravelshea.com) at Gravel & Shea PC if you have questions or would like assistance.