Businesses operating in Vermont have roughly 18 months to prepare for one of the nation’s most expansive state privacy laws, a statute that legal analysts say departs from the increasingly standardized framework adopted by most states. The new statute applies to smaller companies than in other states while imposing more demanding compliance obligations for artificial intelligence, profiling and consumer health data.
The Vermont Data Privacy and Online Surveillance Act, signed into law this month and scheduled to take effect Jan. 1, 2028, is modeled on Connecticut’s 2025 privacy framework but goes considerably further in several areas, according to an analysis by law firm Shook, Hardy & Bacon. Unlike many recently enacted state privacy statutes that largely follow a common template, Vermont lowers the thresholds for coverage while adding new substantive restrictions that businesses will need to address well before the law becomes effective.
The law’s most significant distinction is its broader scope, per Shook. Most comprehensive state privacy laws rely primarily on thresholds based on the number of consumers whose personal data a company processes and, or in some cases the percentage of revenue derived from data sales. Vermont instead adds standalone coverage triggers for companies processing sensitive data or selling personal data, even if they fall below traditional volume or revenue thresholds.
Specifically, the law generally applies to businesses operating in Vermont or targeting Vermont residents if they process personal data for at least 35,000 residents, process sensitive data for at least 3,000 residents, or sell the personal data of at least 3,000 Vermont residents. According to the Shook analysis, only Connecticut employs a comparable framework, meaning companies that previously assumed they fell outside state privacy laws may nevertheless be covered in Vermont.
The law also strengthens substantive obligations beyond those found in most state privacy statutes. Businesses will be prohibited from selling personal data or using it for targeted advertising when they know, or willfully disregard, that the individual is a teenager. Companies using AI or automated decision-making systems will face expanded profiling obligations and must disclose whether personal data is used or sold to train large language models.
Related: Massachusetts Lawmakers Unanimously Pass Comprehensive Privacy Protections
The compliance requirements themselves are also more demanding. Controllers must conduct more detailed data protection impact assessments for certain profiling activities, provide consumers with information about filing complaints with the state attorney general after appeals are denied, and treat neural data, government identification numbers and financial account information as sensitive data. The law also prohibits geofencing around healthcare facilities to collect or use consumer health information, requires consent withdrawals to be honored within 15 days, and emphasizes compliance with anti-discrimination laws in a manner that explicitly links enforcement to AI bias testing.
Another notable departure from other state laws is the restriction on repurposing sensitive data. According to the analysis, Vermont requires that processing of sensitive data remain reasonably necessary for the purpose for which it was originally collected, even when consumer consent has been obtained. That limitation could significantly narrow the flexibility many organizations currently rely on when developing new products or AI applications.
Consumers also receive enhanced rights beyond the standard rights of access, correction, deletion and opt-out. Vermont residents may request inferences derived from their personal data and obtain information identifying third parties that purchased their data.
Consumer health data receives particularly strong protections. Even companies falling below the law’s general applicability thresholds must comply with specific requirements when processing health-related information, including executing data processing agreements before sharing the data, limiting collection and use, obtaining consent before selling or offering to sell the information, and restricting employee access.
Shook, Hardy & Bacon recommends that businesses begin compliance efforts well before the 2028 effective date by evaluating whether the law’s lower thresholds apply, updating data inventories to identify newly regulated information such as neural and teenage data, reviewing whether AI models rely on personal data for training, inventorying automated decision-making systems, and assessing practices involving teenage users.