惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
SecWiki News
SecWiki News
WordPress大学
WordPress大学
小众软件
小众软件
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
Y
Y Combinator Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
云风的 BLOG
云风的 BLOG
MyScale Blog
MyScale Blog
K
Kaspersky official blog
T
The Exploit Database - CXSecurity.com
腾讯CDC
Scott Helme
Scott Helme
I
InfoQ
Cyberwarzone
Cyberwarzone
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Security Latest
Security Latest
The Register - Security
The Register - Security
Project Zero
Project Zero
F
Fortinet All Blogs
C
CERT Recently Published Vulnerability Notes
A
Arctic Wolf
C
Cisco Blogs
L
LINUX DO - 热门话题
P
Privacy International News Feed
IT之家
IT之家
U
Unit 42
P
Privacy & Cybersecurity Law Blog
H
Help Net Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
Cyber Attacks, Cyber Crime and Cyber Security
P
Palo Alto Networks Blog
F
Full Disclosure
宝玉的分享
宝玉的分享
Simon Willison's Weblog
Simon Willison's Weblog
L
Lohrmann on Cybersecurity
Google DeepMind News
Google DeepMind News
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
H
Hacker News: Front Page
Know Your Adversary
Know Your Adversary
PCI Perspectives
PCI Perspectives
Hugging Face - Blog
Hugging Face - Blog
AWS News Blog
AWS News Blog
MongoDB | Blog
MongoDB | Blog
S
Schneier on Security
Recent Announcements
Recent Announcements
Forbes - Security
Forbes - Security
Cisco Talos Blog
Cisco Talos Blog

Privacy & Cybersecurity Law Blog

UK Data Protection Complaints Obligations Take Effect Vermont Enacts Significant Amendments to Data Broker Legislation Louisiana Enacts Comprehensive Consumer Privacy Law Connecticut Signs Comprehensive AI Bill into Law China CAC Issues Guidance on Conducting Audits Technology Companies Should Prepare for FTC Enforcement of Take It Down Act HHS Reorganizes Office for Civil Rights Oregon Prohibition on Public Body Disclosures to Data Brokers for Federal Immigration Purposes Now In Effect Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations NYDFS Warns of Cybersecurity Risks from Frontier AI Models UK and Australia Announce Memorandum of Understanding on AI Security FTC Announces Settlements With Three Marketing Firms Over Allegations of Deceptive Statements About Active Listening AI-Powered Services Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems Colorado AI Act Amended and Effective Date Delayed European Commission Releases Draft Guidelines on High-Risk AI Under the EU AI Act Texas AG Announces Lawsuit Against Netflix for Alleged Misrepresentations Regarding User Data UK ICO Recommends Targeted Changes to PECR Rules for Online Advertising California AG Announces Record $12.75M Settlement with GM over CCPA Data Minimization and Purpose Limitation Violations Illinois Department of Human Rights Issues Regulations Governing the Use of AI in Employment Decisions Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response Maryland Enacts First-of-its-Kind Ban on Surveillance Pricing for Grocery Sales UK ICO Publishes Guidance on Storage and Access Technologies CIPL Report Discusses Significant Alignment between GDPR and Global CBPR CalPrivacy Announces the Agenda for its April 30–May 1 Board Meeting CalPrivacy Requests Preliminary Comments on Notices & Disclosures, Employee Data COPPA Rule Amendment Compliance Deadline Approaches House Republicans Introduce Comprehensive Federal Privacy Bill: “SECURE Data Act” Kentucky Classifies Smart TV Data as Sensitive Alabama Becomes 21st State With Comprehensive Consumer Privacy Law CalPrivacy Director Expects CCPA Compliance Audits in 2026 Virginia Bans Sale of Geolocation Data HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data Washington State Enacts Law Regulating AI Companion Chatbots with Private Right of Action Guardrails for Legal AI: What California’s SB 574 Would Require of Attorneys and Arbitrators
Vermont Becomes 23rd State with Comprehensive Consumer Privacy Law
2026-06-17 · via Privacy & Cybersecurity Law Blog

On June 16, 2026, Vermont Governor Phil Scott signed into law Senate Bill S.71, the Vermont Data Privacy and Online Surveillance Act (“VDPOSA” or the “Act”), making Vermont the 23rd state with a comprehensive consumer privacy law.

The VDPOSA follows the now-familiar controller/processor and consumer rights framework seen in many state comprehensive consumer data privacy laws, with certain distinctions.

Effective Date

The Act takes effect on January 1, 2028.

Scope

The Act’s applicability thresholds are unique in comparison to other state comprehensive consumer privacy laws.

The majority of the VDPOSA’s provisions apply to any person or entity that does business in Vermont or produces products or services targeted to Vermont residents and in the preceding calendar year met one or more of the following thresholds:

  • controlled or processed the personal data of at least 35,000 Vermont consumers (excluding personal data processed solely to complete a transaction);
  • controlled or processed the sensitive data of at least 3,000 Vermont consumers (excluding personal data processed solely to complete a transaction); or
  • offered for sale (for monetary or other valuable consideration) the personal data of at least 3,000 Vermont consumers.

The VDPOSA’s consumer health data provisions apply to any person or entity that conducts business in Vermont or that produces products or services targeted to Vermont residents, with no other required criteria.

Notably, the Act provides that in the event of a conflict between the VDPOSA and any other law, including the Vermont Age-Appropriate Design Code, the provisions of the law that provide the greatest privacy protections control.

Like other state comprehensive privacy laws, the VDPOSA exempts certain entities and data from its scope. Exempt entities include state agencies, GLB-regulated financial institutions, HIPAA-covered entities and business associates, nonprofits and institutions of higher education. Notably, the Act also exempts health care providers and facilities that maintain PHI according to HIPAA and Vermont law even if they are not HIPAA covered entities. Data-level exemptions include HR-related data, PHI subject to HIPAA, GLBA-covered data, substance use disorder and patient safety records, and FCRA-covered data.

Key Obligations

The VDPOSA imposes several obligations on controllers, including:

  • Privacy Notice: Controllers must provide a reasonably accessible and clear privacy notice that discloses the categories of personal data processed; the purposes of processing; the categories of personal data sold to third parties; the categories of third parties to whom personal data is sold; whether the controller engages in targeted advertising (including the sale of personal data in connection with targeted advertising); whether the controller processes personal data for the purpose of training large language models (“LLMs”); and the methods for submitting consumer rights requests.
    • The requirement to disclose information about the processing of personal data to train LLMs is novel.
    • Notably, the VDPOSA also requires controllers to notify consumers of material changes to a privacy notice and provide a reasonable opportunity for consumers to withdraw consent to any further and materially different processing of previously collected personal data.
  • Data Minimization: Controllers must limit the collection of personal data to what is reasonably necessary and proportionate for the disclosed purposes, and not process a consumer’s personal data for any materially new purpose that is neither reasonably necessary to nor compatible with the disclosed purposes, unless the controller obtains consent.
  • Security Safeguards: Controllers must implement and maintain reasonable administrative, technical and physical safeguards appropriate to the volume and nature of the personal data.
  • Vendor Contracts: Contracts between controllers and processors must describe the nature and purpose(s) of processing; the types of personal data subject to processing; the duration of processing; the rights and obligations of both parties; and requirements for confidentiality, data return/deletion, audit cooperation and sub-processor obligations.
  • Data Protection Assessments and Impact Assessments: Controllers must conduct and document data protection assessments for higher-risk processing activities, including targeted advertising, the sale of personal data, profiling that presents a foreseeable risk of harm and the processing of sensitive data. Controllers must separately conduct impact assessments for profiling that produces a legal or similarly significant effect. Controllers must disclose data protection or impact assessments to the Vermont Attorney General upon request.
  • Sensitive Data: Controllers must obtain prior consent to process sensitive data, and only process such data if it is reasonably necessary in relation to the purposes for which the sensitive data was collected.
  • Children’s and Minors’ Data: Controllers are prohibited from selling or processing for targeted advertising the personal data of minor consumers age 13 to 17, and must comply with the Vermont Age-Appropriate Design Code with respect to such consumers’ personal data, if applicable. Additionally, controllers must process the personal data of child consumers under the age of 13 in accordance with COPPA and, if applicable, the Vermont Age-Appropriate Design Code.
  • Consumer Health Data: The Act requires entities to (1) restrict access to consumer health data to employees and contractors who are subject to confidentiality obligations; (2) ensure that any processor with access to consumer health data is contractually bound in accordance with the Act’s processor requirements; (3) refrain from using a geofence within 1,850 feet of a health care facility to identify, track, collect data from, or send notifications to consumers based on their consumer health data; and (4) obtain consumer consent before selling consumer health data.

Consumer Rights

The VDPOSA provides Vermont consumers the right to:

  • confirm whether the controller is processing their personal data;
  • access their personal data, in a portable copy if feasible (including any inferences drawn about the consumer and whether a controller or processor processes the consumer’s personal data for the purpose of profiling to make a decision that produces any legal or similarly significant effect);
  • correct inaccuracies in the consumer’s personal data;
  • delete the consumer’s personal data;
  • opt out of (1) targeted advertising, (1) the sale of personal data, and (3) profiling that produces a legal or similarly significant effect; and
  • obtain certain information about the use of profiling that produces a legal or similarly significant effect (including the reason that such profiling resulted in a decision and the personal data used for the profiling), and correct personal data used in a profiling decision concerning housing and have the decision be reevaluated based on the corrected personal data;
  • obtain a list of third parties to whom the controller has sold their personal data; and
  • appeal the denial of a privacy request.

Enforcement

The Vermont Attorney General has exclusive enforcement authority. A violation of the Act constitutes a violation of the Vermont Consumer Protection Act. A 60-day cure period applies from January 1, 2028 through June 30, 2029, after which the cure period expires.