USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Vermont Privacy & Data Security Laws

Every statute below can apply to a business handling Vermont residents' data, depending on your revenue, the number of Vermont consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Not yet effective — signed Jun 16, 2026, effective Jan 1, 2028
Vermont Data Privacy and Online Surveillance Act
VDPOSA

Newly enacted, not yet in force, and notably strict once it takes effect: applies at 35,000+ Vermont residents (excluding payment-only data). Separately — not fully captured by the numbers here — it applies at just 3,000+ residents if you process sensitive data or offer personal data for sale, among the lowest thresholds nationally. Consumer health-data provisions apply to any entity doing business in Vermont regardless of size. No blanket nonprofit exemption — the only nonprofit carve-outs are for insurance-fraud-detection organizations and enrollment-verification reporting services provided to postsecondary schools (not the schools themselves). The financial-institution exemption is narrower than most other states': it covers state/federally chartered banks, credit unions, SEC/state-regulated investment professionals, and entities regulated under Vermont insurance law — not every GLBA-regulated business.

Act 145 (2026) / S.71, exact codification pending (expected in 9 V.S.A.)Read statute →

Data Security & Breach Notification · 1

Varies by state
Vermont data breach notification law
VT Breach Notification
Verify details

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

State breach-notification statute (citation pending verification)

Data Broker Registration & Duties · 1

Jan 1, 2019; 2026 amendments effective Jan 1, 2027
Vermont Data Broker Regulation, as amended in 2026
VT Data Broker Law

The first state data-broker law in the country. Brokers register annually with the Secretary of State by January 31 and must maintain a written information security program. A June 16, 2026 amendment — signed the same day as Vermont's comprehensive privacy law — adds breach-notification duties specific to brokers, expands required disclosures to cover sensitive data and sharing with government agencies, foreign entities, and AI developers, imposes a $20,000 bond requirement, and directs the Secretary of State to build a universal deletion mechanism. Those changes take effect Jan 1, 2027.

9 V.S.A. §§ 2430, 2446–2447 (Act 171 of 2018, amended Jun 16, 2026)Read statute →