iQ Cookie State Law Series
Cookie & Privacy Law in Vermont
Law not yet in effect. Vermont’s VDPOSA becomes enforceable January 1, 2028 — the furthest-out effective date in this series. This guide reflects the law as signed, current as of August 2026. Note also that Vermont has a separate data broker registration law (amended via H.211 in 2026) that is not covered here — don’t confuse the two when reading other Vermont privacy coverage.
Educational purposes only — not legal advice. This guide is intended to help you understand Vermont’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Vermont’s VDPOSA (S.71 / Act 145) was signed June 16, 2026 by Governor Phil Scott as the 24th comprehensive state privacy law, but its effective date — January 1, 2028 — is the furthest out of any state in this series. It brings the lowest sensitive-data threshold in the country and a genuinely novel right to question profiling decisions. Its 60-day cure period is generous but time-limited, running only through June 30, 2029.
Vermont does not have a separate cookie law within the VDPOSA. Cookie compliance will flow from the Act itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology. Note that Vermont’s data broker registration requirements are governed by a different statute entirely.
Who does it apply to?
The VDPOSA covers controllers that meet at least one of these thresholds:
Controlled or processed personal data of 35,000 or more Vermont residents (payment-only data excluded).
Controlled or processed sensitive data of 3,000 or more Vermont residents — the lowest sensitive-data bar in the series.
Offered for sale personal data of 3,000 or more Vermont residents.
Government entities, HIPAA-covered entities (except hybrid entities), state/federally chartered banks and credit unions, SEC/DFR-regulated financial professionals, healthcare providers with HIPAA-compliant data, insurance-regulated entities, and certain news/media organizations are exempt. Consumer health data provisions apply to any covered entity doing business in Vermont regardless of threshold.
Consumer rights
Once in effect, Vermont residents whose data is covered by the VDPOSA will have one of the richest rights sets in this series:
Businesses will need to respond within the statutory window described in the Act. There is no private right of action — only the Attorney General can enforce.
What makes Vermont different
The lowest sensitive-data threshold in the country. Just 3,000 Vermont residents’ sensitive data triggers coverage — a dramatically lower bar than the 25,000-to-100,000-consumer thresholds most peer states use, meaning small businesses that handle any meaningful amount of sensitive data should assume they’re in scope.
A right to question profiling decisions, similar to Minnesota’s. Consumers will be able to review the data behind a profiling decision and receive the reasoning — a rights category only a handful of states in this series include.
Neural data is explicitly sensitive. Vermont adds neural data to its sensitive data list alongside genetic and biometric data — forward-looking language given growing consumer neurotechnology, and not yet common across this series.
A long but explicitly time-limited cure period. Sixty days is generous, but it only runs from the January 1, 2028 effective date through June 30, 2029 — after that, cure becomes fully discretionary, similar to the pattern used in several already-in-effect states.
Don’t confuse this with Vermont’s separate data broker law. H.211, amended in 2026, tightened Vermont’s data broker registration statute independently of the VDPOSA — higher fees, a $20,000 surety bond, and its own January 1, 2027 effective date. The two laws regulate different things and have different timelines.
Sensitive data & children
Processing sensitive data will require opt-in consent before any collection begins. Sensitive data includes:
Data from known children under 13 is classified as sensitive data by default, requiring COPPA-compliant handling. This is the longest and most detailed sensitive data list in the series so far.
What this will mean for your cookies
| Cookie / data type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (health, biometric, neural, financial) | Opt-in required | Gate these behind affirmative consent before they fire — low 3,000-resident threshold applies. |
| Sale / targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism. |
| GPC / universal opt-out signals | Required | Confirm your consent tool honors GPC by the effective date. |
| Profiling / decisioning cookies | Explainability required | If cookies feed profiling decisions, be ready to explain and let consumers review the data. |
| Any cookies — known children | COPPA-aligned consent | Verifiable parental consent required. |
Enforcement
The Vermont Attorney General will have exclusive enforcement authority, treating violations as breaches of the state’s consumer protection statute. Specific civil penalty amounts had not been confirmed in available sources as of this writing — check final regulations as the effective date approaches.
Your action checklist
With over a year before the effective date, there is real time to prepare — use it:
Check the low sensitive-data threshold carefully. Just 3,000 Vermont residents’ sensitive data puts you in scope — a much lower bar than most other thresholds in this series.
Don’t conflate this with Vermont’s data broker law. If you’re a data broker, you likely need separate compliance work for H.211’s January 1, 2027 requirements — a full year before the VDPOSA itself takes effect.
Plan for a profiling-explanation process. Build this alongside your other automated-decision infrastructure if you already built one for Minnesota.
Classify neural and financial data as sensitive now. If you collect either, start treating them as sensitive ahead of the formal deadline.
Build GPC recognition into your roadmap. Required under the VDPOSA once in effect.
Recheck this guide well before January 2028. With over a year of runway, expect implementing regulations, penalty specifics, and possibly amendments before enforcement begins.
Review vendor contracts. Any processor handling Vermont resident data will need a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 25 of 25 · Series complete