Vermont has joined the list of states prioritizing data regulation legislation to reinforce consumer privacy. On June 16, 2026, Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (ACT145) into law. Below is a quick overview of the Act’s provisions and key details.
Who does the Vermont Data Privacy and Online Surveillance Act apply to?
This legislation applies to companies doing business in Vermont or targeting Vermont residents that:
- Process data of at least 35,000 consumers,
- Process sensitive data of at least 3,000 consumers, OR
- Sell personal data of at least 3,000 consumers.
The official ACT145 Summary, released by the Vermont Office of the Attorney General, points out several circumstances that would exempt an organization or its data from these regulations, including data subject to Title V of the Gramm-Leach-Bliley Act, government entities, and most insurance companies.
When does the law take effect?
ACT145 will take effect on January 1, 2028. Organizational operations must be updated to align with the new regulations on or before this date.
The law includes a cure period until June 30, 2029, giving businesses 60 days to address any alleged violations before this date.
What rights are provided to consumers?
The Act provides consumers with enhanced rights to their personal data, including the right to:
- Confirm whether a data controller is processing their data,
- Correct inaccuracies in their reported data,
- Delete their reported data,
- Obtain a copy of their reported data,
- Opt out of the processing of their data for targeted advertising and sale purposes, and
- Receive notice naming third parties that the controller sold their data to.
What are Vermont businesses required to do under ACT145?
The Act provides consumers with enhanced rights to their personal data, including the right to:
Opt-outs:
- Establish opt-out mechanisms for targeted advertising.
- Honor opt-out signals, including those sent through browser extensions and universal settings.
Data protection & minimization practices:
- Provide a clear and publicly accessible policy on the company website to establish data security practices. The policy must indicate whether the controller collects, uses, or sells personal data for the purpose of training large language models.
- Obtain consent before processing or selling sensitive data
- Sensitive data includes race, religion, sexual orientation, health information, biometrics, precise geolocation, and neural data.
- Update data practices to comply with the law’s restrictions on surveillance and targeted advertising:
- Limit collection to personal data that is “reasonably necessary and proportionate” to the intended collection purposes.
- For controllers processing personal data in a way that presents a heightened risk of harm to consumers: A data protection assessment is required to identify and weigh benefits to the controller and risks to consumers.
- For controllers engaging in profiling: A similar impact assessment is required. Both assessments must be sent to the Office of the Attorney General upon request during an investigation.
How is the Act enforced?
The Vermont Attorney General holds exclusive authority to enforce the law in the case of an ACT145 violation.
You can view the full text of the legislation here.
This content is for informational purposes only and shall not constitute legal opinion or advice. Consult your legal counsel to ensure compliance.