US-VTschema gdpri-v2trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC
Last updated · 10 categories · 37
claims · 29 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 28 September 2026.
Lead Signal
Vermont enacted its first comprehensive consumer privacy statute this cycle. The Vermont Data Privacy and Online Surveillance Act, passed as S.71 and codified as Act 145, was signed into law on 16 June 2026 and is codified at 9 V.S.A. Chapter 61A, Sections 2415a through 2415k. It takes effect 1 January 2028. The statute applies to persons conducting business in Vermont or targeting Vermont residents that, in the preceding calendar year, controlled or processed personal data of at least 35,000 consumers, controlled or processed sensitive data of at least 3,000 consumers, or offered personal data for sale involving at least 3,000 consumers; its health-data provisions apply without these numerical thresholds. The legislative path to enactment was notable: Governor Phil Scott vetoed an earlier version of S.71 on 8 June 2026 over concerns about a private-right-of-action design, and the version he signed eight days later, on 16 June 2026, removed that private right of action, leaving the Attorney General as the sole enforcement authority.
Among the statute's substantive provisions is a consumer-health-data protection that bars the use of geofencing to establish a virtual boundary within 1,850 feet of a health care facility for identifying, tracking, collecting data from, or notifying a consumer regarding reproductive or sexual health services. This is understood to be a deliberately specific and location-based restriction targeting a particular tracking modality rather than a general prohibition on health-data processing.
Other Developments
Vermont's Age-Appropriate Design Code Act, enacted as S.69/Act 63 in 2025 and signed 12 June 2025, takes effect 1 January 2027 and requires covered businesses to use Attorney-General-specified age-assurance methods while restricting privacy-invasive design features directed at minors. This predates and is legally distinct from the newly enacted comprehensive privacy statute, though both fall under the same Attorney General enforcement authority once each takes effect.
H.814 establishes neurological-rights protections in Vermont law and extends the state's AI and Data Privacy Advisory Council through 2030, with its mandate expanded to studying AI applications in healthcare, education, insurance, and government operations. This is understood to be in force as of 1 July 2026.
Act 142, the same instrument driving this cycle's financial-sector and payments developments, also broadens Vermont's financial-privacy protections to cover non-bank regulated entities, alongside its virtual-currency-kiosk ban and new commercial-financing licensing regime, effective 1 July 2026.
A genuine dispute exists regarding the status of H.812, the proposed Duty of Data Loyalty Act. The official Vermont legislature bill-status record indicates the bill remains pending before the House Committee on Commerce and Economic Development, while some secondary legislative trackers report it as passed with a 1 January 2027 effective date. This conflict between a Tier-1 primary source and Tier-3 secondary trackers has not been resolved as of this cycle, and readers should treat H.812's enactment status as unconfirmed pending clarification.
Cross-Monitor Connections
Act 142's financial-privacy broadening provisions connect directly to the financial-integrity monitor's coverage of the same instrument's virtual-currency-kiosk ban and commercial-financing licensing regime, though this brief addresses only the data-protection dimension of that overlap. The world-payments monitor separately covers the licensing and market-structure dimensions of Act 142's kiosk and commercial-financing provisions.
Outlook
The Vermont Data Privacy and Online Surveillance Act is not scheduled to take effect until 1 January 2028, as adopted; whether the Attorney General has begun implementing rulemaking ahead of that date has not been established in the evidence available this cycle. The Age-Appropriate Design Code Act is scheduled to take effect 1 January 2027, as adopted, with Attorney-General rulemaking on age-assurance methods understood to be underway. The disputed status of H.812 remains the principal unresolved item and should be revisited once the official bill-status record and secondary trackers converge or the discrepancy is otherwise clarified.
trust tier: ai_unverified
Standing brief, as of 28 September 2026.
Regulatory Status
Vermont enacted its first comprehensive consumer data-privacy statute this cycle, the Vermont Data Privacy and Online Surveillance Act (S.71/Act 145), signed 16 June 2026 and codified at 9 V.S.A. Chapter 61A, Sections 2415a through 2415k, effective 1 January 2028. Governor Phil Scott vetoed an earlier version on 8 June 2026 over a private-right-of-action provision; the version he signed eight days later removed that provision, leaving the Attorney General as sole enforcer. The statute applies to entities meeting activity-based thresholds and includes a consumer-health-data geofencing restriction barring tracking within 1,850 feet of health care facilities for reproductive or sexual health purposes.
Vermont's Age-Appropriate Design Code Act (S.69/Act 63 of 2025), effective 1 January 2027, requires age-assurance methods and restricts privacy-invasive design features for minors. H.814 establishes neurological-rights protections and extends the AI and Data Privacy Advisory Council through 2030 with an expanded remit. Act 142 separately broadens financial-privacy protections to cover non-bank regulated entities, effective 1 July 2026. The status of a further proposed statute, H.812 (Duty of Data Loyalty Act), is disputed between the official bill-status record, which shows it pending in committee, and secondary trackers reporting enactment.
Outlook
The Data Privacy and Online Surveillance Act takes effect 1 January 2028 and the Age-Appropriate Design Code Act takes effect 1 January 2027, both as adopted. The disputed status of H.812 remains the principal open item for this jurisdiction and should be revisited once the discrepancy between the official bill-status record and secondary trackers is resolved.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Traffic-light rationale — AmberComprehensive statute enacted but not yet operative (effective 2028-01-01); current regime remains sectoral/breach-notification only.
Sub-modules (5)
Regulator And AuthorityGreen
AG holds exclusive enforcement power over S.71 and existing breach/broker statutes; no separate DPA exists.
Claims (1):
Enforcement power under the Data Privacy and Online Surveillance Act is granted exclusively to the Vermont Attorney General, with no private right of action.
Act And InstrumentsAmber
Instruments span the enacted-not-yet-effective S.71 and the currently in-force breach/broker/sector statutes.
Claims (2):
Vermont's Data Privacy and Online Surveillance Act (S.71) was signed into law on 16 June 2026 and enters into force on 1 January 2028.
Pending S.71's effective date, personal data protection in Vermont is governed by a combination of the Security Breach Notice Act and sector-specific statutes for health information (18 V.S.A. §§1881-1882) and financial privacy (8 V.S.A. §§10201-10206).
Material ScopeAmber
S.71 thresholds are population-based (35,000/3,000 consumers), not a GDPR-style processing-purpose scope test.
Claims (1):
S.71 applies to controllers/processors handling the personal data of at least 35,000 Vermont consumers, or the sensitive data of at least 3,000 consumers, or selling the personal data of at least 3,000 consumers.
Territorial ScopeAmber
S.71 applies extraterritorially to any entity targeting Vermont residents meeting thresholds, regardless of establishment location.
Claims (1):
S.71 applies to persons conducting business in Vermont or targeting Vermont residents that meet the applicable processing thresholds.
Regulator Registration And FilingAmber
Data-broker registration is transitioning from AG-office registration (Act 171, 2018) to Secretary-of-State registration under H.211 (phased 2026-2027).
Claims (2):
House Bill 211 requires data brokers to annually register with the Vermont Secretary of State and pay a USD900 fee, superseding the prior Attorney-General registry.
Under the original Data Broker Regulation Act (Act 171, 2018), data brokers were required to register annually with the Attorney General's office, a regime that remains operative until H.211's registration provisions commence.
Category narrative91 words
The injected seed's disambiguation (no comprehensive VT statute) is now materially STALE: on 16 June 2026 Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (S.71), making <cite index="11-4">Vermont becomes the 23rd state to feature a comprehensive state privacy law</cite>, but <cite index="11-9">The law will enter into force 1 Jan. 2028</cite>. Until that date, Vermont has no comprehensive statute in force; personal data is governed by the Security Breach Notice Act, the Data Broker Regulation Act, and sector overlays. Enforcement authority sits with the Vermont Attorney General throughout.
no periodic updates on record for this sub-brief
Sources and claims (7)
ConfirmedIAPP — Enforcement power under the Data Privacy and Online Surveillance Act is granted exclusively to the Vermont Attorney General, with no private right of action.observed
ConfirmedDataGuidance — Vermont's Data Privacy and Online Surveillance Act (S.71) was signed into law on 16 June 2026 and enters into force on 1 January 2028.observed
ConfirmedDataGuidance — Pending S.71's effective date, personal data protection in Vermont is governed by a combination of the Security Breach Notice Act and sector-specific statutes for health information (18 V.S.A. §§1881-1882) and financial privacy (8 V.S.A. §§10201-10206).observed
ConfirmedIAPP — S.71 applies to controllers/processors handling the personal data of at least 35,000 Vermont consumers, or the sensitive data of at least 3,000 consumers, or selling the personal data of at least 3,000 consumers.observed
ProbableDataGuidance — S.71 applies to persons conducting business in Vermont or targeting Vermont residents that meet the applicable processing thresholds.observed
ConfirmedIAPP — House Bill 211 requires data brokers to annually register with the Vermont Secretary of State and pay a USD900 fee, superseding the prior Attorney-General registry.observed
ConfirmedIAPP — Under the original Data Broker Regulation Act (Act 171, 2018), data brokers were required to register annually with the Attorney General's office, a regime that remains operative until H.211's registration provisions commence.observed
Traffic-light rationale — AmberConsent/threshold model confirmed; formal lawful-basis taxonomy and anonymisation safe-harbours not confirmed in research.
Sub-modules (4)
Lawful BasesRed
No enumerated Art.6-equivalent basis list identified; gap noted explicitly rather than assumed.
Claims (1):
No GDPR Article-6-equivalent enumerated list of lawful processing bases was identified for Vermont; S.71 relies on a consent-and-threshold model rather than an enumerated basis taxonomy.
Consent ThresholdsAmber
Consent required for sensitive-data processing above the 3,000-consumer threshold.
Claims (1):
S.71 requires consumer consent for processing sensitive data, with the sensitive-data threshold (3,000 consumers) triggering these obligations, departing from Connecticut's law which contains no comparable trigger.
Special CategoriesAmber
Genetic data is treated as a discrete special category under H.639.
Claims (1):
Vermont's Genetic Information Privacy Act (H.639), signed 15 June 2026 and effective 1 July 2026, restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent to share the data with third parties.
Pseudonymisation And AnonymisationRed
No Vermont-specific pseudonymisation/anonymisation safe-harbour definitions were located.
S.71 does not adopt a GDPR Article-6-style enumerated lawful-basis list; it instead gates obligations on consumer consent plus quantitative thresholds. Vermont's Genetic Information Privacy Act (H.639) creates a discrete special-category regime for genetic data effective 1 July 2026.
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainIAPP — No GDPR Article-6-equivalent enumerated list of lawful processing bases was identified for Vermont; S.71 relies on a consent-and-threshold model rather than an enumerated basis taxonomy.observed
ConfirmedIAPP — S.71 requires consumer consent for processing sensitive data, with the sensitive-data threshold (3,000 consumers) triggering these obligations, departing from Connecticut's law which contains no comparable trigger.observed
ConfirmedIAPP — Vermont's Genetic Information Privacy Act (H.639), signed 15 June 2026 and effective 1 July 2026, restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent to share the data with third parties.observed
Traffic-light rationale — AmberRights are enacted but not yet exercisable; statutory response-window details not confirmed.
Sub-modules (5)
Access RightAmber
Access right confirmed for 2028 effective date.
Claims (1):
S.71 grants consumers rights to access, correct, and delete their personal data held by controllers, effective 1 January 2028.
Rectification And ErasureAmber
Correction and deletion rights confirmed for 2028.
Claims (1):
S.71 grants consumers rights to access, correct, and delete their personal data held by controllers, effective 1 January 2028.
Restriction And ObjectionAmber
Opt-out rights for targeted advertising, sale, and profiling confirmed.
Claims (1):
Consumers will be entitled to opt out of targeted advertising, the sale of personal data, and profiling used in decisions producing legal or similarly significant effects.
Data PortabilityAmber
Portability right (obtain a copy of data) confirmed with lower-confidence detail.
Claims (1):
S.71 grants consumers a right to obtain a copy of their personal data from controllers.
Deadlines And Response WindowsRed
No confirmed statutory response-window (e.g., 45-day SAR deadline) was located for S.71.
S.71 grants a CTDPA-style rights package (access, correction, deletion, portability, opt-outs) effective 1 January 2028; no rights exist under a comprehensive statute prior to that date.
no periodic updates on record for this sub-brief
Sources and claims (3)
ConfirmedDataGuidance — S.71 grants consumers rights to access, correct, and delete their personal data held by controllers, effective 1 January 2028.observed
ConfirmedDataGuidance — Consumers will be entitled to opt out of targeted advertising, the sale of personal data, and profiling used in decisions producing legal or similarly significant effects.observed
ProbableDataGuidance — S.71 grants consumers a right to obtain a copy of their personal data from controllers.observed
Traffic-light rationale — AmberBreach notification and data-broker security duties are in force now; DPIA/joint-controller duties await 2028.
Sub-modules (7)
Accountability And DpiaAmber
S.71 requires DPIAs for sensitive-data, targeted-advertising, sale, and profiling processing.
Claims (1):
S.71 requires controllers to conduct data protection assessments for processing activities involving sensitive data, targeted advertising, sale of personal data, and profiling, closely resembling Connecticut's DPIA regime.
Dpo RequirementsRed
No DPO appointment threshold was identified for Vermont.
Absence provenance: unavailable. Searched: Vermont S.71 data protection officer requirement.
Ropa RequirementsRed
No records-of-processing obligation was identified for Vermont.
Absence provenance: unavailable. Searched: Vermont records of processing activities requirement.
Joint Controller ArrangementsAmber
Processor contractual-obligation duties confirmed under S.71.
Claims (1):
Processors under S.71 must comply with controllers' contractual instructions regarding the nature and purpose of processing.
Security MeasuresGreen
Data Broker Regulation Act mandates a detailed information security program modeled on GLBA/HIPAA security-rule standards, already in force.
Claims (1):
Vermont's Data Broker Regulation Act mandates that data brokers maintain an information security program including secure user authentication, access controls, encryption, and reasonable monitoring for unauthorized access, modeled on GLBA and HIPAA security-rule standards.
Breach NotificationGreen
Security Breach Notice Act timelines are confirmed and currently in force.
Claims (1):
Under the Vermont Security Breach Notice Act, notification to affected consumers must occur no later than 45 days after discovery of a breach, and notification to the Attorney General must occur within 14 business days of discovery or consumer notification, whichever is sooner.
Retention And DisposalRed
A Document Safe Destruction Act is referenced in secondary sources but its specific disposal timelines were not independently verified.
Vermont maintains a Document Safe Destruction Act governing disposal of records containing personal information; specific disposal timelines were not independently verified in this research pass.
Category narrative27 words
DPIA, security, and breach-notification duties are split between the not-yet-effective S.71 (DPIAs, processor contracts) and the currently in-force Data Broker security program and Security Breach Notice Act.
no periodic updates on record for this sub-brief
Sources and claims (5)
ConfirmedIAPP — S.71 requires controllers to conduct data protection assessments for processing activities involving sensitive data, targeted advertising, sale of personal data, and profiling, closely resembling Connecticut's DPIA regime.observed
ProbableDataGuidance — Processors under S.71 must comply with controllers' contractual instructions regarding the nature and purpose of processing.observed
ConfirmedIAPP — Vermont's Data Broker Regulation Act mandates that data brokers maintain an information security program including secure user authentication, access controls, encryption, and reasonable monitoring for unauthorized access, modeled on GLBA and HIPAA security-rule standards.observed
ConfirmedIAPP — Under the Vermont Security Breach Notice Act, notification to affected consumers must occur no later than 45 days after discovery of a breach, and notification to the Attorney General must occur within 14 business days of discovery or consumer notification, whichever is sooner.observed
UncertainDataGuidance — Vermont maintains a Document Safe Destruction Act governing disposal of records containing personal information; specific disposal timelines were not independently verified in this research pass.observed
Comprehensive absence of a state-level transfer-mechanism regime.
Traffic-light rationale — RedComprehensive absence of a state-level transfer-mechanism regime.
Sub-modules (6)
Transfer MechanismsRed
No mechanism identified.
Absence provenance: unavailable. Searched: Vermont cross-border data transfer mechanism law.
Claims (1):
No Vermont state-level cross-border data-transfer mechanism (adequacy, SCCs, or BCRs) analogous to the GDPR transfer regime was identified in this research pass.
Absence provenance: unavailable. Searched: Vermont transfer impact assessment requirement.
Data LocalisationRed
No data-localisation mandate identified.
Absence provenance: unavailable. Searched: Vermont data localisation requirement law.
Category narrative33 words
No Vermont-specific cross-border transfer regime (adequacy, SCCs, BCRs, TIA, or data-localisation mandate) was identified. This is a legitimate structural gap consistent with the US's sectoral, non-omnibus approach to international transfers at state level.
Sources and claims (1)
ProbableDataGuidance — No Vermont state-level cross-border data-transfer mechanism (adequacy, SCCs, or BCRs) analogous to the GDPR transfer regime was identified in this research pass.observed
Traffic-light rationale — AmberFinancial, health, and education overlays confirmed; telecoms, employment, insurance sub-modules are gaps.
Sub-modules (7)
Financial Sector OverlayGreen
Financial Privacy Act confirmed.
Claims (1):
Vermont's Financial Privacy Act (8 V.S.A. §§10201-10206) regulates the financial sector's handling of personal financial information, operating alongside the federal Gramm-Leach-Bliley Act.
Health Sector OverlayGreen
Title 18 health information provisions confirmed.
Claims (1):
Health information privacy in Vermont is additionally governed by 18 V.S.A. §§1881-1882, operating alongside the federal HIPAA framework.
Telecoms And EprivacyRed
No Vermont-specific ePrivacy/telecoms statute identified; federal TCPA applies generally.
No Vermont-specific employment-data statute identified.
Absence provenance: unavailable. Searched: Vermont employment data privacy law.
Credit And ScoringAmber
Data Broker Regulation Act eliminated credit-freeze fees; no standalone credit-scoring statute identified beyond federal FCRA.
Claims (1):
Vermont's Data Broker Regulation Act eliminated fees associated with placing or removing consumer credit security freezes.
EducationAmber
Student-data protections and 2026 EdTech registration confirmed.
Claims (1):
The original 2020 Vermont data privacy and consumer protection Act includes provisions for student data privacy, and House Bill 211 (2026) extends registration and disclosure obligations to education-technology providers.
InsuranceRed
No Vermont-specific insurance-sector data statute identified.
Absence provenance: unavailable. Searched: Vermont insurance sector data privacy statute.
Category narrative42 words
Vermont sectoral overlays: financial (Financial Privacy Act, Title 8) and health (Title 18) statutes operate alongside federal GLBA/HIPAA; education sector overlaid by original 2020 student-data provisions and 2026 EdTech registration rules. Telecoms, employment, insurance, and standalone credit-scoring statutes were not independently located.
no periodic updates on record for this sub-brief
Sources and claims (4)
ConfirmedDataGuidance — Vermont's Financial Privacy Act (8 V.S.A. §§10201-10206) regulates the financial sector's handling of personal financial information, operating alongside the federal Gramm-Leach-Bliley Act.observed
ConfirmedDataGuidance — Health information privacy in Vermont is additionally governed by 18 V.S.A. §§1881-1882, operating alongside the federal HIPAA framework.observed
ConfirmedIAPP — Vermont's Data Broker Regulation Act eliminated fees associated with placing or removing consumer credit security freezes.observed
ConfirmedDataGuidance — The original 2020 Vermont data privacy and consumer protection Act includes provisions for student data privacy, and House Bill 211 (2026) extends registration and disclosure obligations to education-technology providers.observed
Traffic-light rationale — AmberOpt-out-signal and advertising opt-out confirmed for 2028; several sub-modules are unaddressed gaps.
Sub-modules (6)
Cookies And TrackersRed
No dedicated cookie/tracker consent statute identified.
Absence provenance: unavailable. Searched: Vermont cookie consent law tracker.
Dark PatternsRed
No dedicated dark-pattern prohibition identified beyond general Consumer Protection Act unfair/deceptive practices.
Absence provenance: unavailable. Searched: Vermont dark patterns privacy law.
Opt Out SignalsAmber
S.71 requires recognition of opt-out preference signals including those from authorized agents.
Claims (1):
S.71 requires controllers and processors to recognize consumer opt-out preference signals, including those transmitted by authorized agents.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room rules identified.
Absence provenance: unavailable. Searched: Vermont data clean room regulation.
Cross Context AdvertisingAmber
Opt-out rights for targeted advertising and sale confirmed for 2028.
Claims (1):
Consumers will be able to opt out of processing for targeted advertising and the sale of personal data under S.71.
Direct MarketingRed
No standalone direct-marketing consent/suppression statute identified.
Absence provenance: unavailable. Searched: Vermont direct marketing consent suppression law.
Category narrative20 words
S.71 introduces opt-out-signal recognition and cross-context-advertising opt-outs effective 2028; no dedicated Vermont cookie-consent, dark-pattern, clean-room, or direct-marketing statute was identified.
Sources and claims (2)
ConfirmedIAPP — S.71 requires controllers and processors to recognize consumer opt-out preference signals, including those transmitted by authorized agents.observed
ConfirmedDataGuidance — Consumers will be able to opt out of processing for targeted advertising and the sale of personal data under S.71.observed
Profiling opt-out and genetic-data regime confirmed; ADM transparency/explanation right and state-surveillance carve-outs are gaps; AI risk-assessment regime is limited to a disclosure duty, not a full assessment mandate.
Primary frameworkS.71 (profiling/AI disclosure, 2028); H.639 Genetic Information Privacy Act (in force); Consumer Protection Act (biometric enforcement)
Traffic-light rationale — AmberProfiling opt-out and genetic-data regime confirmed; ADM transparency/explanation right and state-surveillance carve-outs are gaps; AI risk-assessment regime is limited to a disclosure duty, not a full assessment mandate.
Sub-modules (6)
Profiling RestrictionsAmber
Profiling opt-out confirmed for 2028.
Claims (1):
S.71 grants consumers the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.
Automated Decision Making TransparencyRed
No explicit ADM explanation/transparency right beyond the opt-out was identified.
S.71 imposes an AI/LLM-training disclosure duty, not a full AI risk-assessment regime; an earlier AI Advisory Council proposal (H.121) was vetoed.
Claims (1):
S.71 requires privacy notices to disclose whether a controller collects, uses, or sells personal data to train large language models, without mandating a state-specific AI risk-assessment regime.
Biometric RegimeAmber
No dedicated biometric statute; governance occurs via CPA/Data-Broker-Act enforcement against Clearview AI.
Claims (1):
The Vermont Attorney General's enforcement action against Clearview AI, alleging violations of the Consumer Protection Act and Data Broker Regulation Act through non-consensual collection and sale of facial-recognition data, has proceeded past a motion to dismiss since September 2020, notwithstanding the absence of a dedicated biometric-privacy statute.
Genetic DataGreen
Genetic Information Privacy Act in force since 2026-07-01.
Claims (1):
Vermont's Genetic Information Privacy Act (H.639), signed 15 June 2026 and effective 1 July 2026, restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent to share the data with third parties.
State Surveillance CarveoutsRed
No state-surveillance carve-out provisions were identified.
Absence provenance: unavailable. Searched: Vermont state surveillance national security carveout privacy law.
Category narrative57 words
S.71 grants a profiling opt-out and an AI/LLM-training disclosure obligation (2028); a prior AI Advisory Council proposal (H.121, 2024) was vetoed by the Governor and did not become law. Biometric governance currently rests on Consumer-Protection-Act/Data-Broker-Act enforcement (the ongoing Clearview AI litigation) rather than a dedicated biometric statute. Genetic data has its own statute (H.639, in force 2026-07-01).
no periodic updates on record for this sub-brief
Sources and claims (4)
ConfirmedDataGuidance — S.71 grants consumers the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.observed
ConfirmedIAPP — S.71 requires privacy notices to disclose whether a controller collects, uses, or sells personal data to train large language models, without mandating a state-specific AI risk-assessment regime.observed
ConfirmedDataGuidance — The Vermont Attorney General's enforcement action against Clearview AI, alleging violations of the Consumer Protection Act and Data Broker Regulation Act through non-consensual collection and sale of facial-recognition data, has proceeded past a motion to dismiss since September 2020, notwithstanding the absence of a dedicated biometric-privacy statute.observed
ConfirmedIAPP — Vermont's Genetic Information Privacy Act restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent.observed
Traffic-light rationale — AmberAADC confirmed and enacted-not-yet-effective; parental consent and dependent-adults sub-modules are gaps.
Sub-modules (5)
Age VerificationAmber
AADC uses a 2%-of-users likely-accessed-by-minor test rather than direct age verification.
Claims (1):
Vermont's Age-Appropriate Design Code Act (S.69), signed 12 June 2025 and effective 1 January 2027, applies to online services 'reasonably likely to be accessed by a minor,' defined as services where at least 2% of users are aged 2 to 17.
Parental ConsentRed
No Vermont-specific parental-consent mechanism distinct from federal COPPA was identified.
Absence provenance: unavailable. Searched: Vermont parental consent children's data law.
Minor Profiling BansAmber
AADC imposes high-default-privacy-setting and data-minimization obligations for minors.
Claims (1):
The AADC imposes obligations such as high default privacy settings, data minimization, and transparency on covered businesses offering online services to minors.
Education SettingsAmber
Student-data and EdTech provisions confirmed (see sectoral_watch.education).
Claims (1):
The original 2020 Vermont data privacy and consumer protection Act includes provisions for student data privacy, and House Bill 211 (2026) extends registration and disclosure obligations to education-technology providers.
Dependent AdultsRed
No Vermont-specific dependent-adults data-protection provision was identified.
Vermont's Age-Appropriate Design Code Act (S.69, signed 2025-06-12, effective 2027-01-01) governs minors' online experience via a 2%-of-users threshold rather than direct age verification; S.71 layers additional minors' protections from 2028. No Vermont-specific parental-consent mechanism distinct from federal COPPA, and no dependent-adults provision, were identified.
no periodic updates on record for this sub-brief
Sources and claims (2)
ConfirmedDataGuidance — Vermont's Age-Appropriate Design Code Act (S.69), signed 12 June 2025 and effective 1 January 2027, applies to online services 'reasonably likely to be accessed by a minor,' defined as services where at least 2% of users are aged 2 to 17.observed
ConfirmedDataGuidance — The AADC imposes obligations such as high default privacy settings, data minimization, and transparency on covered businesses offering online services to minors.observed
Traffic-light rationale — AmberActive enforcement precedent exists; regulator funding/capacity data is a gap.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
Data-broker civil penalties and S.71's cure-period mechanism confirmed.
Claims (2):
Data brokers that fail to register under Vermont's Data Broker Regulation Act are liable for a civil penalty of $50 per day, capped at $10,000 per year, plus unpaid registration fees, recoverable by the Attorney General through the Civil Division of the Superior Court.
S.71 provides a 60-day cure period for violations, expiring 30 June 2029, after which the Attorney General is no longer required to offer businesses an opportunity to cure before pursuing enforcement.
Enforcement Activity IndexGreen
Clearview AI litigation and a $264,000 settlement demonstrate active AG enforcement.
Claims (1):
The Vermont Attorney General reached a $264,000 settlement with a company that exposed the Social Security numbers of 660 Vermont residents for failing to comply with the Security Breach Notice Act's notification timeframes.
Regulator Funding And CapacityRed
No funding or headcount data for the AG's Consumer Protection Division was located.
The general Consumer Protection Act's private right of action can function as a collective-redress avenue for non-S.71 privacy-adjacent claims.
Claims (1):
Vermont's general Consumer Protection Act contains a private right of action permitting recovery of attorney's fees and exemplary damages of up to three times the consideration paid, which has historically been invoked in privacy-adjacent claims.
Private Right Of ActionAmber
S.71 itself excludes a private right of action; the general CPA's PRA remains available for other consumer-protection claims.
Claims (2):
S.71 grants enforcement power exclusively to the Attorney General and does not create a private right of action for consumers.
Vermont's general Consumer Protection Act contains a private right of action permitting recovery of attorney's fees and exemplary damages of up to three times the consideration paid, which has historically been invoked in privacy-adjacent claims.
Recent Developments 180DGreen
Three privacy statutes enacted within the last 180 days.
Claims (1):
Within the past 180 days, Vermont enacted three privacy-related statutes: the Data Privacy and Online Surveillance Act (S.71), a data-broker/EdTech registration law (H.211), and the Genetic Information Privacy Act (H.639), all signed by Governor Phil Scott on 15-16 June 2026.
Category narrative78 words
Current enforcement rests on Data Broker Act penalties and general Consumer Protection Act unfair/deceptive authority, evidenced by the ongoing Clearview AI suit and a $264,000 breach-notification settlement; from 2028, S.71 adds a dedicated AG enforcement track with a 60-day cure period (expiring 2029-06-30) and explicitly excludes a private right of action, while the general CPA's separate private right of action remains available for non-S.71 claims. Within the last 180 days, three privacy statutes (S.71, H.211, H.639) were enacted.
no periodic updates on record for this sub-brief
Sources and claims (6)
ConfirmedVermont Legislature — Data brokers that fail to register under Vermont's Data Broker Regulation Act are liable for a civil penalty of $50 per day, capped at $10,000 per year, plus unpaid registration fees, recoverable by the Attorney General through the Civil Division of the Superior Court.observed
ConfirmedIAPP — S.71 provides a 60-day cure period for violations, expiring 30 June 2029, after which the Attorney General is no longer required to offer businesses an opportunity to cure before pursuing enforcement.observed
ConfirmedIAPP — The Vermont Attorney General reached a $264,000 settlement with a company that exposed the Social Security numbers of 660 Vermont residents for failing to comply with the Security Breach Notice Act's notification timeframes.observed
ConfirmedIAPP — S.71 grants enforcement power exclusively to the Attorney General and does not create a private right of action for consumers.observed
ConfirmedIAPP — Vermont's general Consumer Protection Act contains a private right of action permitting recovery of attorney's fees and exemplary damages of up to three times the consideration paid, which has historically been invoked in privacy-adjacent claims.observed
ConfirmedIAPP — Within the past 180 days, Vermont enacted three privacy-related statutes: the Data Privacy and Online Surveillance Act (S.71), a data-broker/EdTech registration law (H.211), and the Genetic Information Privacy Act (H.639), all signed by Governor Phil Scott on 15-16 June 2026.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
9.52
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Vermont, USA
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 29 source(s) in the cumulative register.
regulator_and_framework, controller_processor_duties (breach/security), sectoral_watch (financial/health), enforcement_and_redress (data-broker penalties, Clearview AI litigation), and algorithmic_biometric_and_surveillance_governance (genetic data, Clearview AI) rest on T1/T2 sources with reasonably high confidence. Data-subject-rights and adtech modules rely primarily on T2 secondary reporting (IAPP/DataGuidance) of S.71's enacted-but-not-yet-effective text rather than the bill's primary statutory text, which was not directly retrievable via the allowlisted hostnames in this pass. Cross-border/adequacy, telecoms, employment, insurance, dependent-adults, DPO, and ROPA sub-modules are explicit T4-equivalent gaps (no comprehensive-regime finding) rather than silent omissions. CRITICAL FINDING: the injected seed's disambiguation note ('Vermont has NO comprehensive state consumer-privacy statute') is now stale as of this run's dispatch date — Vermont enacted a comprehensive statute (S.71) on 2026-06-16, effective 2028-01-01. jurisdiction_status was set to in_transition to reflect this enacted-but-not-yet-operative status rather than reproducing the seed's now-superseded unregulated characterization.
Unresolved questions (6):
What is S.71's exact statutory consumer-request response-window (days) for access/deletion requests?
Does S.71 enumerate a specific list of 'sensitive data' categories, and how many (Priestley's earlier HB121 draft cited 10 categories — unconfirmed whether S.71 retained this count)?
Is there a DPO-appointment threshold or ROPA obligation anywhere in Vermont's enacted or forthcoming statutes?
What are the Vermont Document Safe Destruction Act's specific retention/disposal timelines?
Does Vermont's AADC retain or drop a DPIA requirement, given the general industry trend noted of states removing DPIA obligations from AADC bills?
Discrepancy noted: one source described the Vermont AADC as effective 'January 2026' while three other sources consistently state 1 January 2027 — the latter was adopted as the primary finding pending confirmation.