🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-VT v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing22 sources retrieved model claude-sonnet-5 · 2026-08-06

Vermont, USA

US-VT schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 37 claims · 29 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 28 September 2026.

Lead Signal

Vermont enacted its first comprehensive consumer privacy statute this cycle. The Vermont Data Privacy and Online Surveillance Act, passed as S.71 and codified as Act 145, was signed into law on 16 June 2026 and is codified at 9 V.S.A. Chapter 61A, Sections 2415a through 2415k. It takes effect 1 January 2028. The statute applies to persons conducting business in Vermont or targeting Vermont residents that, in the preceding calendar year, controlled or processed personal data of at least 35,000 consumers, controlled or processed sensitive data of at least 3,000 consumers, or offered personal data for sale involving at least 3,000 consumers; its health-data provisions apply without these numerical thresholds. The legislative path to enactment was notable: Governor Phil Scott vetoed an earlier version of S.71 on 8 June 2026 over concerns about a private-right-of-action design, and the version he signed eight days later, on 16 June 2026, removed that private right of action, leaving the Attorney General as the sole enforcement authority.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute enacted but not yet operative (effective 2028-01-01); current regime remains sectoral/breach-notification only.

Primary frameworkVermont Data Privacy and Online Surveillance Act (S.71, enacted 2026-06-16, effective 2028-01-01); pending that date, Security Breach Notice Act (9 V.S.A. §2435) + Data Broker Regulation Act (9 V.S.A. §§2446-2447) + sector statutes
Traffic-light rationale — AmberComprehensive statute enacted but not yet operative (effective 2028-01-01); current regime remains sectoral/breach-notification only.

Sub-modules (5)

Regulator And AuthorityGreen

AG holds exclusive enforcement power over S.71 and existing breach/broker statutes; no separate DPA exists.

Claims (1):

  • Enforcement power under the Data Privacy and Online Surveillance Act is granted exclusively to the Vermont Attorney General, with no private right of action.

Act And InstrumentsAmber

Instruments span the enacted-not-yet-effective S.71 and the currently in-force breach/broker/sector statutes.

Claims (2):

  • Vermont's Data Privacy and Online Surveillance Act (S.71) was signed into law on 16 June 2026 and enters into force on 1 January 2028.
  • Pending S.71's effective date, personal data protection in Vermont is governed by a combination of the Security Breach Notice Act and sector-specific statutes for health information (18 V.S.A. §§1881-1882) and financial privacy (8 V.S.A. §§10201-10206).

Material ScopeAmber

S.71 thresholds are population-based (35,000/3,000 consumers), not a GDPR-style processing-purpose scope test.

Claims (1):

  • S.71 applies to controllers/processors handling the personal data of at least 35,000 Vermont consumers, or the sensitive data of at least 3,000 consumers, or selling the personal data of at least 3,000 consumers.

Territorial ScopeAmber

S.71 applies extraterritorially to any entity targeting Vermont residents meeting thresholds, regardless of establishment location.

Claims (1):

  • S.71 applies to persons conducting business in Vermont or targeting Vermont residents that meet the applicable processing thresholds.

Regulator Registration And FilingAmber

Data-broker registration is transitioning from AG-office registration (Act 171, 2018) to Secretary-of-State registration under H.211 (phased 2026-2027).

Claims (2):

  • House Bill 211 requires data brokers to annually register with the Vermont Secretary of State and pay a USD900 fee, superseding the prior Attorney-General registry.
  • Under the original Data Broker Regulation Act (Act 171, 2018), data brokers were required to register annually with the Attorney General's office, a regime that remains operative until H.211's registration provisions commence.
Category narrative91 words

The injected seed's disambiguation (no comprehensive VT statute) is now materially STALE: on 16 June 2026 Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (S.71), making <cite index="11-4">Vermont becomes the 23rd state to feature a comprehensive state privacy law</cite>, but <cite index="11-9">The law will enter into force 1 Jan. 2028</cite>. Until that date, Vermont has no comprehensive statute in force; personal data is governed by the Security Breach Notice Act, the Data Broker Regulation Act, and sector overlays. Enforcement authority sits with the Vermont Attorney General throughout.

no periodic updates on record for this sub-brief

Sources and claims (7)
  1. ConfirmedIAPP — Enforcement power under the Data Privacy and Online Surveillance Act is granted exclusively to the Vermont Attorney General, with no private right of action.observed
  2. ConfirmedDataGuidance — Vermont's Data Privacy and Online Surveillance Act (S.71) was signed into law on 16 June 2026 and enters into force on 1 January 2028.observed
  3. ConfirmedDataGuidance — Pending S.71's effective date, personal data protection in Vermont is governed by a combination of the Security Breach Notice Act and sector-specific statutes for health information (18 V.S.A. §§1881-1882) and financial privacy (8 V.S.A. §§10201-10206).observed
  4. ConfirmedIAPP — S.71 applies to controllers/processors handling the personal data of at least 35,000 Vermont consumers, or the sensitive data of at least 3,000 consumers, or selling the personal data of at least 3,000 consumers.observed
  5. ProbableDataGuidance — S.71 applies to persons conducting business in Vermont or targeting Vermont residents that meet the applicable processing thresholds.observed
  6. ConfirmedIAPP — House Bill 211 requires data brokers to annually register with the Vermont Secretary of State and pay a USD900 fee, superseding the prior Attorney-General registry.observed
  7. ConfirmedIAPP — Under the original Data Broker Regulation Act (Act 171, 2018), data brokers were required to register annually with the Attorney General's office, a regime that remains operative until H.211's registration provisions commence.observed

#

Consent/threshold model confirmed; formal lawful-basis taxonomy and anonymisation safe-harbours not confirmed in research.

Primary frameworkS.71 (consent-and-threshold model); H.639 Genetic Information Privacy Act (special category)
Traffic-light rationale — AmberConsent/threshold model confirmed; formal lawful-basis taxonomy and anonymisation safe-harbours not confirmed in research.

Sub-modules (4)

Lawful BasesRed

No enumerated Art.6-equivalent basis list identified; gap noted explicitly rather than assumed.

Claims (1):

  • No GDPR Article-6-equivalent enumerated list of lawful processing bases was identified for Vermont; S.71 relies on a consent-and-threshold model rather than an enumerated basis taxonomy.

Special CategoriesAmber

Genetic data is treated as a discrete special category under H.639.

Claims (1):

  • Vermont's Genetic Information Privacy Act (H.639), signed 15 June 2026 and effective 1 July 2026, restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent to share the data with third parties.

Pseudonymisation And AnonymisationRed

No Vermont-specific pseudonymisation/anonymisation safe-harbour definitions were located.

Absence provenance: unavailable. Searched: Vermont S.71 pseudonymisation definition, Vermont anonymisation safe harbour privacy law.

Category narrative38 words

S.71 does not adopt a GDPR Article-6-style enumerated lawful-basis list; it instead gates obligations on consumer consent plus quantitative thresholds. Vermont's Genetic Information Privacy Act (H.639) creates a discrete special-category regime for genetic data effective 1 July 2026.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainIAPP — No GDPR Article-6-equivalent enumerated list of lawful processing bases was identified for Vermont; S.71 relies on a consent-and-threshold model rather than an enumerated basis taxonomy.observed
  2. ConfirmedIAPP — S.71 requires consumer consent for processing sensitive data, with the sensitive-data threshold (3,000 consumers) triggering these obligations, departing from Connecticut's law which contains no comparable trigger.observed
  3. ConfirmedIAPP — Vermont's Genetic Information Privacy Act (H.639), signed 15 June 2026 and effective 1 July 2026, restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent to share the data with third parties.observed

#

Rights are enacted but not yet exercisable; statutory response-window details not confirmed.

Primary frameworkS.71 (Vermont Data Privacy and Online Surveillance Act)
Traffic-light rationale — AmberRights are enacted but not yet exercisable; statutory response-window details not confirmed.

Sub-modules (5)

Access RightAmber

Access right confirmed for 2028 effective date.

Claims (1):

  • S.71 grants consumers rights to access, correct, and delete their personal data held by controllers, effective 1 January 2028.

Rectification And ErasureAmber

Correction and deletion rights confirmed for 2028.

Claims (1):

  • S.71 grants consumers rights to access, correct, and delete their personal data held by controllers, effective 1 January 2028.

Restriction And ObjectionAmber

Opt-out rights for targeted advertising, sale, and profiling confirmed.

Claims (1):

  • Consumers will be entitled to opt out of targeted advertising, the sale of personal data, and profiling used in decisions producing legal or similarly significant effects.

Data PortabilityAmber

Portability right (obtain a copy of data) confirmed with lower-confidence detail.

Claims (1):

  • S.71 grants consumers a right to obtain a copy of their personal data from controllers.

Deadlines And Response WindowsRed

No confirmed statutory response-window (e.g., 45-day SAR deadline) was located for S.71.

Absence provenance: unavailable. Searched: Vermont S.71 consumer request response deadline days.

Category narrative26 words

S.71 grants a CTDPA-style rights package (access, correction, deletion, portability, opt-outs) effective 1 January 2028; no rights exist under a comprehensive statute prior to that date.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedDataGuidance — S.71 grants consumers rights to access, correct, and delete their personal data held by controllers, effective 1 January 2028.observed
  2. ConfirmedDataGuidance — Consumers will be entitled to opt out of targeted advertising, the sale of personal data, and profiling used in decisions producing legal or similarly significant effects.observed
  3. ProbableDataGuidance — S.71 grants consumers a right to obtain a copy of their personal data from controllers.observed

#

Breach notification and data-broker security duties are in force now; DPIA/joint-controller duties await 2028.

Primary frameworkSecurity Breach Notice Act (9 V.S.A. §2435); Data Broker Regulation Act; S.71 (DPIA/processor duties, 2028)
Traffic-light rationale — AmberBreach notification and data-broker security duties are in force now; DPIA/joint-controller duties await 2028.

Sub-modules (7)

Accountability And DpiaAmber

S.71 requires DPIAs for sensitive-data, targeted-advertising, sale, and profiling processing.

Claims (1):

  • S.71 requires controllers to conduct data protection assessments for processing activities involving sensitive data, targeted advertising, sale of personal data, and profiling, closely resembling Connecticut's DPIA regime.

Dpo RequirementsRed

No DPO appointment threshold was identified for Vermont.

Absence provenance: unavailable. Searched: Vermont S.71 data protection officer requirement.

Ropa RequirementsRed

No records-of-processing obligation was identified for Vermont.

Absence provenance: unavailable. Searched: Vermont records of processing activities requirement.

Joint Controller ArrangementsAmber

Processor contractual-obligation duties confirmed under S.71.

Claims (1):

  • Processors under S.71 must comply with controllers' contractual instructions regarding the nature and purpose of processing.

Security MeasuresGreen

Data Broker Regulation Act mandates a detailed information security program modeled on GLBA/HIPAA security-rule standards, already in force.

Claims (1):

  • Vermont's Data Broker Regulation Act mandates that data brokers maintain an information security program including secure user authentication, access controls, encryption, and reasonable monitoring for unauthorized access, modeled on GLBA and HIPAA security-rule standards.

Breach NotificationGreen

Security Breach Notice Act timelines are confirmed and currently in force.

Claims (1):

  • Under the Vermont Security Breach Notice Act, notification to affected consumers must occur no later than 45 days after discovery of a breach, and notification to the Attorney General must occur within 14 business days of discovery or consumer notification, whichever is sooner.

Retention And DisposalRed

A Document Safe Destruction Act is referenced in secondary sources but its specific disposal timelines were not independently verified.

Absence provenance: unavailable. Searched: Vermont Document Safe Destruction Act disposal timeline text.

Claims (1):

  • Vermont maintains a Document Safe Destruction Act governing disposal of records containing personal information; specific disposal timelines were not independently verified in this research pass.
Category narrative27 words

DPIA, security, and breach-notification duties are split between the not-yet-effective S.71 (DPIAs, processor contracts) and the currently in-force Data Broker security program and Security Breach Notice Act.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedIAPP — S.71 requires controllers to conduct data protection assessments for processing activities involving sensitive data, targeted advertising, sale of personal data, and profiling, closely resembling Connecticut's DPIA regime.observed
  2. ProbableDataGuidance — Processors under S.71 must comply with controllers' contractual instructions regarding the nature and purpose of processing.observed
  3. ConfirmedIAPP — Vermont's Data Broker Regulation Act mandates that data brokers maintain an information security program including secure user authentication, access controls, encryption, and reasonable monitoring for unauthorized access, modeled on GLBA and HIPAA security-rule standards.observed
  4. ConfirmedIAPP — Under the Vermont Security Breach Notice Act, notification to affected consumers must occur no later than 45 days after discovery of a breach, and notification to the Attorney General must occur within 14 business days of discovery or consumer notification, whichever is sooner.observed
  5. UncertainDataGuidance — Vermont maintains a Document Safe Destruction Act governing disposal of records containing personal information; specific disposal timelines were not independently verified in this research pass.observed

#

Comprehensive absence of a state-level transfer-mechanism regime.

Traffic-light rationale — RedComprehensive absence of a state-level transfer-mechanism regime.

Sub-modules (6)

Transfer MechanismsRed

No mechanism identified.

Absence provenance: unavailable. Searched: Vermont cross-border data transfer mechanism law.

Claims (1):

  • No Vermont state-level cross-border data-transfer mechanism (adequacy, SCCs, or BCRs) analogous to the GDPR transfer regime was identified in this research pass.

Adequacy ReceivedRed

Not applicable at US state level.

Absence provenance: unavailable. Searched: Vermont adequacy decision received.

Adequacy GrantedRed

Not applicable at US state level.

Absence provenance: unavailable. Searched: Vermont adequacy decision granted.

Sccs And BcrsRed

No state-level SCC/BCR framework identified.

Absence provenance: unavailable. Searched: Vermont standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: unavailable. Searched: Vermont transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate identified.

Absence provenance: unavailable. Searched: Vermont data localisation requirement law.

Category narrative33 words

No Vermont-specific cross-border transfer regime (adequacy, SCCs, BCRs, TIA, or data-localisation mandate) was identified. This is a legitimate structural gap consistent with the US's sectoral, non-omnibus approach to international transfers at state level.

Sources and claims (1)
  1. ProbableDataGuidance — No Vermont state-level cross-border data-transfer mechanism (adequacy, SCCs, or BCRs) analogous to the GDPR transfer regime was identified in this research pass.observed

#

Financial, health, and education overlays confirmed; telecoms, employment, insurance sub-modules are gaps.

Primary framework8 V.S.A. §§10201-10206 (Financial Privacy Act); 18 V.S.A. §§1881-1882 (health information)
Traffic-light rationale — AmberFinancial, health, and education overlays confirmed; telecoms, employment, insurance sub-modules are gaps.

Sub-modules (7)

Financial Sector OverlayGreen

Financial Privacy Act confirmed.

Claims (1):

  • Vermont's Financial Privacy Act (8 V.S.A. §§10201-10206) regulates the financial sector's handling of personal financial information, operating alongside the federal Gramm-Leach-Bliley Act.

Health Sector OverlayGreen

Title 18 health information provisions confirmed.

Claims (1):

  • Health information privacy in Vermont is additionally governed by 18 V.S.A. §§1881-1882, operating alongside the federal HIPAA framework.

Telecoms And EprivacyRed

No Vermont-specific ePrivacy/telecoms statute identified; federal TCPA applies generally.

Absence provenance: unavailable. Searched: Vermont ePrivacy telecoms cookie law.

Employment DataRed

No Vermont-specific employment-data statute identified.

Absence provenance: unavailable. Searched: Vermont employment data privacy law.

Credit And ScoringAmber

Data Broker Regulation Act eliminated credit-freeze fees; no standalone credit-scoring statute identified beyond federal FCRA.

Claims (1):

  • Vermont's Data Broker Regulation Act eliminated fees associated with placing or removing consumer credit security freezes.

EducationAmber

Student-data protections and 2026 EdTech registration confirmed.

Claims (1):

  • The original 2020 Vermont data privacy and consumer protection Act includes provisions for student data privacy, and House Bill 211 (2026) extends registration and disclosure obligations to education-technology providers.

InsuranceRed

No Vermont-specific insurance-sector data statute identified.

Absence provenance: unavailable. Searched: Vermont insurance sector data privacy statute.

Category narrative42 words

Vermont sectoral overlays: financial (Financial Privacy Act, Title 8) and health (Title 18) statutes operate alongside federal GLBA/HIPAA; education sector overlaid by original 2020 student-data provisions and 2026 EdTech registration rules. Telecoms, employment, insurance, and standalone credit-scoring statutes were not independently located.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedDataGuidance — Vermont's Financial Privacy Act (8 V.S.A. §§10201-10206) regulates the financial sector's handling of personal financial information, operating alongside the federal Gramm-Leach-Bliley Act.observed
  2. ConfirmedDataGuidance — Health information privacy in Vermont is additionally governed by 18 V.S.A. §§1881-1882, operating alongside the federal HIPAA framework.observed
  3. ConfirmedIAPP — Vermont's Data Broker Regulation Act eliminated fees associated with placing or removing consumer credit security freezes.observed
  4. ConfirmedDataGuidance — The original 2020 Vermont data privacy and consumer protection Act includes provisions for student data privacy, and House Bill 211 (2026) extends registration and disclosure obligations to education-technology providers.observed

#

Opt-out-signal and advertising opt-out confirmed for 2028; several sub-modules are unaddressed gaps.

Primary frameworkS.71 (Vermont Data Privacy and Online Surveillance Act)
Traffic-light rationale — AmberOpt-out-signal and advertising opt-out confirmed for 2028; several sub-modules are unaddressed gaps.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent statute identified.

Absence provenance: unavailable. Searched: Vermont cookie consent law tracker.

Dark PatternsRed

No dedicated dark-pattern prohibition identified beyond general Consumer Protection Act unfair/deceptive practices.

Absence provenance: unavailable. Searched: Vermont dark patterns privacy law.

Opt Out SignalsAmber

S.71 requires recognition of opt-out preference signals including those from authorized agents.

Claims (1):

  • S.71 requires controllers and processors to recognize consumer opt-out preference signals, including those transmitted by authorized agents.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Absence provenance: unavailable. Searched: Vermont data clean room regulation.

Cross Context AdvertisingAmber

Opt-out rights for targeted advertising and sale confirmed for 2028.

Claims (1):

  • Consumers will be able to opt out of processing for targeted advertising and the sale of personal data under S.71.

Direct MarketingRed

No standalone direct-marketing consent/suppression statute identified.

Absence provenance: unavailable. Searched: Vermont direct marketing consent suppression law.

Category narrative20 words

S.71 introduces opt-out-signal recognition and cross-context-advertising opt-outs effective 2028; no dedicated Vermont cookie-consent, dark-pattern, clean-room, or direct-marketing statute was identified.

Sources and claims (2)
  1. ConfirmedIAPP — S.71 requires controllers and processors to recognize consumer opt-out preference signals, including those transmitted by authorized agents.observed
  2. ConfirmedDataGuidance — Consumers will be able to opt out of processing for targeted advertising and the sale of personal data under S.71.observed

#

Profiling opt-out and genetic-data regime confirmed; ADM transparency/explanation right and state-surveillance carve-outs are gaps; AI risk-assessment regime is limited to a disclosure duty, not a full assessment mandate.

Primary frameworkS.71 (profiling/AI disclosure, 2028); H.639 Genetic Information Privacy Act (in force); Consumer Protection Act (biometric enforcement)
Traffic-light rationale — AmberProfiling opt-out and genetic-data regime confirmed; ADM transparency/explanation right and state-surveillance carve-outs are gaps; AI risk-assessment regime is limited to a disclosure duty, not a full assessment mandate.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling opt-out confirmed for 2028.

Claims (1):

  • S.71 grants consumers the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.

Automated Decision Making TransparencyRed

No explicit ADM explanation/transparency right beyond the opt-out was identified.

Absence provenance: unavailable. Searched: Vermont S.71 automated decision-making explanation right.

Ai Risk AssessmentsAmber

S.71 imposes an AI/LLM-training disclosure duty, not a full AI risk-assessment regime; an earlier AI Advisory Council proposal (H.121) was vetoed.

Claims (1):

  • S.71 requires privacy notices to disclose whether a controller collects, uses, or sells personal data to train large language models, without mandating a state-specific AI risk-assessment regime.

Biometric RegimeAmber

No dedicated biometric statute; governance occurs via CPA/Data-Broker-Act enforcement against Clearview AI.

Claims (1):

  • The Vermont Attorney General's enforcement action against Clearview AI, alleging violations of the Consumer Protection Act and Data Broker Regulation Act through non-consensual collection and sale of facial-recognition data, has proceeded past a motion to dismiss since September 2020, notwithstanding the absence of a dedicated biometric-privacy statute.

Genetic DataGreen

Genetic Information Privacy Act in force since 2026-07-01.

Claims (1):

  • Vermont's Genetic Information Privacy Act (H.639), signed 15 June 2026 and effective 1 July 2026, restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent to share the data with third parties.

State Surveillance CarveoutsRed

No state-surveillance carve-out provisions were identified.

Absence provenance: unavailable. Searched: Vermont state surveillance national security carveout privacy law.

Category narrative57 words

S.71 grants a profiling opt-out and an AI/LLM-training disclosure obligation (2028); a prior AI Advisory Council proposal (H.121, 2024) was vetoed by the Governor and did not become law. Biometric governance currently rests on Consumer-Protection-Act/Data-Broker-Act enforcement (the ongoing Clearview AI litigation) rather than a dedicated biometric statute. Genetic data has its own statute (H.639, in force 2026-07-01).

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedDataGuidance — S.71 grants consumers the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.observed
  2. ConfirmedIAPP — S.71 requires privacy notices to disclose whether a controller collects, uses, or sells personal data to train large language models, without mandating a state-specific AI risk-assessment regime.observed
  3. ConfirmedDataGuidance — The Vermont Attorney General's enforcement action against Clearview AI, alleging violations of the Consumer Protection Act and Data Broker Regulation Act through non-consensual collection and sale of facial-recognition data, has proceeded past a motion to dismiss since September 2020, notwithstanding the absence of a dedicated biometric-privacy statute.observed
  4. ConfirmedIAPP — Vermont's Genetic Information Privacy Act restricts direct-to-consumer genetic testing companies from selling residents' genetic data absent explicit consumer consent.observed

#

AADC confirmed and enacted-not-yet-effective; parental consent and dependent-adults sub-modules are gaps.

Primary frameworkVermont Age-Appropriate Design Code Act (S.69); S.71 minors' provisions
Traffic-light rationale — AmberAADC confirmed and enacted-not-yet-effective; parental consent and dependent-adults sub-modules are gaps.

Sub-modules (5)

Age VerificationAmber

AADC uses a 2%-of-users likely-accessed-by-minor test rather than direct age verification.

Claims (1):

  • Vermont's Age-Appropriate Design Code Act (S.69), signed 12 June 2025 and effective 1 January 2027, applies to online services 'reasonably likely to be accessed by a minor,' defined as services where at least 2% of users are aged 2 to 17.

Minor Profiling BansAmber

AADC imposes high-default-privacy-setting and data-minimization obligations for minors.

Claims (1):

  • The AADC imposes obligations such as high default privacy settings, data minimization, and transparency on covered businesses offering online services to minors.

Education SettingsAmber

Student-data and EdTech provisions confirmed (see sectoral_watch.education).

Claims (1):

  • The original 2020 Vermont data privacy and consumer protection Act includes provisions for student data privacy, and House Bill 211 (2026) extends registration and disclosure obligations to education-technology providers.

Dependent AdultsRed

No Vermont-specific dependent-adults data-protection provision was identified.

Absence provenance: unavailable. Searched: Vermont dependent adults elderly data protection law.

Category narrative44 words

Vermont's Age-Appropriate Design Code Act (S.69, signed 2025-06-12, effective 2027-01-01) governs minors' online experience via a 2%-of-users threshold rather than direct age verification; S.71 layers additional minors' protections from 2028. No Vermont-specific parental-consent mechanism distinct from federal COPPA, and no dependent-adults provision, were identified.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ConfirmedDataGuidance — Vermont's Age-Appropriate Design Code Act (S.69), signed 12 June 2025 and effective 1 January 2027, applies to online services 'reasonably likely to be accessed by a minor,' defined as services where at least 2% of users are aged 2 to 17.observed
  2. ConfirmedDataGuidance — The AADC imposes obligations such as high default privacy settings, data minimization, and transparency on covered businesses offering online services to minors.observed

#

Active enforcement precedent exists; regulator funding/capacity data is a gap.

Primary frameworkVermont Consumer Protection Act; Data Broker Regulation Act; S.71 (from 2028)
Traffic-light rationale — AmberActive enforcement precedent exists; regulator funding/capacity data is a gap.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Data-broker civil penalties and S.71's cure-period mechanism confirmed.

Claims (2):

  • Data brokers that fail to register under Vermont's Data Broker Regulation Act are liable for a civil penalty of $50 per day, capped at $10,000 per year, plus unpaid registration fees, recoverable by the Attorney General through the Civil Division of the Superior Court.
  • S.71 provides a 60-day cure period for violations, expiring 30 June 2029, after which the Attorney General is no longer required to offer businesses an opportunity to cure before pursuing enforcement.

Enforcement Activity IndexGreen

Clearview AI litigation and a $264,000 settlement demonstrate active AG enforcement.

Claims (1):

  • The Vermont Attorney General reached a $264,000 settlement with a company that exposed the Social Security numbers of 660 Vermont residents for failing to comply with the Security Breach Notice Act's notification timeframes.

Regulator Funding And CapacityRed

No funding or headcount data for the AG's Consumer Protection Division was located.

Absence provenance: unavailable. Searched: Vermont Attorney General Consumer Protection Division budget headcount.

Collective Redress And Class ActionsAmber

The general Consumer Protection Act's private right of action can function as a collective-redress avenue for non-S.71 privacy-adjacent claims.

Claims (1):

  • Vermont's general Consumer Protection Act contains a private right of action permitting recovery of attorney's fees and exemplary damages of up to three times the consideration paid, which has historically been invoked in privacy-adjacent claims.

Private Right Of ActionAmber

S.71 itself excludes a private right of action; the general CPA's PRA remains available for other consumer-protection claims.

Claims (2):

  • S.71 grants enforcement power exclusively to the Attorney General and does not create a private right of action for consumers.
  • Vermont's general Consumer Protection Act contains a private right of action permitting recovery of attorney's fees and exemplary damages of up to three times the consideration paid, which has historically been invoked in privacy-adjacent claims.

Recent Developments 180DGreen

Three privacy statutes enacted within the last 180 days.

Claims (1):

  • Within the past 180 days, Vermont enacted three privacy-related statutes: the Data Privacy and Online Surveillance Act (S.71), a data-broker/EdTech registration law (H.211), and the Genetic Information Privacy Act (H.639), all signed by Governor Phil Scott on 15-16 June 2026.
Category narrative78 words

Current enforcement rests on Data Broker Act penalties and general Consumer Protection Act unfair/deceptive authority, evidenced by the ongoing Clearview AI suit and a $264,000 breach-notification settlement; from 2028, S.71 adds a dedicated AG enforcement track with a 60-day cure period (expiring 2029-06-30) and explicitly excludes a private right of action, while the general CPA's separate private right of action remains available for non-S.71 claims. Within the last 180 days, three privacy statutes (S.71, H.211, H.639) were enacted.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedVermont Legislature — Data brokers that fail to register under Vermont's Data Broker Regulation Act are liable for a civil penalty of $50 per day, capped at $10,000 per year, plus unpaid registration fees, recoverable by the Attorney General through the Civil Division of the Superior Court.observed
  2. ConfirmedIAPP — S.71 provides a 60-day cure period for violations, expiring 30 June 2029, after which the Attorney General is no longer required to offer businesses an opportunity to cure before pursuing enforcement.observed
  3. ConfirmedIAPP — The Vermont Attorney General reached a $264,000 settlement with a company that exposed the Social Security numbers of 660 Vermont residents for failing to comply with the Security Breach Notice Act's notification timeframes.observed
  4. ConfirmedIAPP — S.71 grants enforcement power exclusively to the Attorney General and does not create a private right of action for consumers.observed
  5. ConfirmedIAPP — Vermont's general Consumer Protection Act contains a private right of action permitting recovery of attorney's fees and exemplary damages of up to three times the consideration paid, which has historically been invoked in privacy-adjacent claims.observed
  6. ConfirmedIAPP — Within the past 180 days, Vermont enacted three privacy-related statutes: the Data Privacy and Online Surveillance Act (S.71), a data-broker/EdTech registration law (H.211), and the Genetic Information Privacy Act (H.639), all signed by Governor Phil Scott on 15-16 June 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct9.52
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Vermont, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 29 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (breach/security), sectoral_watch (financial/health), enforcement_and_redress (data-broker penalties, Clearview AI litigation), and algorithmic_biometric_and_surveillance_governance (genetic data, Clearview AI) rest on T1/T2 sources with reasonably high confidence. Data-subject-rights and adtech modules rely primarily on T2 secondary reporting (IAPP/DataGuidance) of S.71's enacted-but-not-yet-effective text rather than the bill's primary statutory text, which was not directly retrievable via the allowlisted hostnames in this pass. Cross-border/adequacy, telecoms, employment, insurance, dependent-adults, DPO, and ROPA sub-modules are explicit T4-equivalent gaps (no comprehensive-regime finding) rather than silent omissions. CRITICAL FINDING: the injected seed's disambiguation note ('Vermont has NO comprehensive state consumer-privacy statute') is now stale as of this run's dispatch date — Vermont enacted a comprehensive statute (S.71) on 2026-06-16, effective 2028-01-01. jurisdiction_status was set to in_transition to reflect this enacted-but-not-yet-operative status rather than reproducing the seed's now-superseded unregulated characterization.

Unresolved questions (6):

  • What is S.71's exact statutory consumer-request response-window (days) for access/deletion requests?
  • Does S.71 enumerate a specific list of 'sensitive data' categories, and how many (Priestley's earlier HB121 draft cited 10 categories — unconfirmed whether S.71 retained this count)?
  • Is there a DPO-appointment threshold or ROPA obligation anywhere in Vermont's enacted or forthcoming statutes?
  • What are the Vermont Document Safe Destruction Act's specific retention/disposal timelines?
  • Does Vermont's AADC retain or drop a DPIA requirement, given the general industry trend noted of states removing DPIA obligations from AADC bills?
  • Discrepancy noted: one source described the Vermont AADC as effective 'January 2026' while three other sources consistently state 1 January 2027 — the latter was adopted as the primary finding pending confirmation.

Escalate to primary-source review: yes