iQ Cookie  State Law Series

State 25 of 25 · Vermont

Cookie & Privacy Law in Vermont

Published August 2026
Effective Jan 1, 2028
Signed Jun 16, 2026

Law not yet in effect. Vermont’s VDPOSA becomes enforceable January 1, 2028 — the furthest-out effective date in this series. This guide reflects the law as signed, current as of August 2026. Note also that Vermont has a separate data broker registration law (amended via H.211 in 2026) that is not covered here — don’t confuse the two when reading other Vermont privacy coverage.

Educational purposes only — not legal advice. This guide is intended to help you understand Vermont’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
VDPOSA
S.71 (Act 145)
SIGNED
Jun 16, 2026
Effective Jan 1, 2028
CURE PERIOD
60 days
Through Jun 30, 2029 only
STATE RANK
#24
To enact a law

The short version

Vermont’s VDPOSA (S.71 / Act 145) was signed June 16, 2026 by Governor Phil Scott as the 24th comprehensive state privacy law, but its effective date — January 1, 2028 — is the furthest out of any state in this series. It brings the lowest sensitive-data threshold in the country and a genuinely novel right to question profiling decisions. Its 60-day cure period is generous but time-limited, running only through June 30, 2029.

Vermont does not have a separate cookie law within the VDPOSA. Cookie compliance will flow from the Act itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology. Note that Vermont’s data broker registration requirements are governed by a different statute entirely.

Vermont General Assembly — Official Text
Data Privacy and Online Surveillance Act — S.71 (Act 145, 2026)

Who does it apply to?

The VDPOSA covers controllers that meet at least one of these thresholds:

PATH 1

Controlled or processed personal data of 35,000 or more Vermont residents (payment-only data excluded).

PATH 2

Controlled or processed sensitive data of 3,000 or more Vermont residents — the lowest sensitive-data bar in the series.

PATH 3

Offered for sale personal data of 3,000 or more Vermont residents.

Government entities, HIPAA-covered entities (except hybrid entities), state/federally chartered banks and credit unions, SEC/DFR-regulated financial professionals, healthcare providers with HIPAA-compliant data, insurance-regulated entities, and certain news/media organizations are exempt. Consumer health data provisions apply to any covered entity doing business in Vermont regardless of threshold.

Consumer rights

Once in effect, Vermont residents whose data is covered by the VDPOSA will have one of the richest rights sets in this series:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Sale, targeted advertising, and profiling
Question profiling
Review data used and receive reasoning
Know recipients
Get a list of third parties data was disclosed to
Appeal
60-day response deadline for denied requests

Businesses will need to respond within the statutory window described in the Act. There is no private right of action — only the Attorney General can enforce.

What makes Vermont different

The lowest sensitive-data threshold in the country. Just 3,000 Vermont residents’ sensitive data triggers coverage — a dramatically lower bar than the 25,000-to-100,000-consumer thresholds most peer states use, meaning small businesses that handle any meaningful amount of sensitive data should assume they’re in scope.

A right to question profiling decisions, similar to Minnesota’s. Consumers will be able to review the data behind a profiling decision and receive the reasoning — a rights category only a handful of states in this series include.

Neural data is explicitly sensitive. Vermont adds neural data to its sensitive data list alongside genetic and biometric data — forward-looking language given growing consumer neurotechnology, and not yet common across this series.

A long but explicitly time-limited cure period. Sixty days is generous, but it only runs from the January 1, 2028 effective date through June 30, 2029 — after that, cure becomes fully discretionary, similar to the pattern used in several already-in-effect states.

Don’t confuse this with Vermont’s separate data broker law. H.211, amended in 2026, tightened Vermont’s data broker registration statute independently of the VDPOSA — higher fees, a $20,000 surety bond, and its own January 1, 2027 effective date. The two laws regulate different things and have different timelines.

Sensitive data & children

Processing sensitive data will require opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Sex life / sexual orientation
Nonbinary / transgender status
Immigration status
Health condition and data
Genetic / biometric data
Precise geolocation
Neural data
Financial information
Government ID numbers
Children’s data (under 13)

Data from known children under 13 is classified as sensitive data by default, requiring COPPA-compliant handling. This is the longest and most detailed sensitive data list in the series so far.

What this will mean for your cookies

Cookie / data typeRequirementWhat to do
Sensitive data cookies (health, biometric, neural, financial)Opt-in requiredGate these behind affirmative consent before they fire — low 3,000-resident threshold applies.
Sale / targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism.
GPC / universal opt-out signalsRequiredConfirm your consent tool honors GPC by the effective date.
Profiling / decisioning cookiesExplainability requiredIf cookies feed profiling decisions, be ready to explain and let consumers review the data.
Any cookies — known childrenCOPPA-aligned consentVerifiable parental consent required.

Enforcement

TBD
Penalty amount not yet specified in guidance
60 days
Through Jun 30, 2029 only
AG only
No private right of action

The Vermont Attorney General will have exclusive enforcement authority, treating violations as breaches of the state’s consumer protection statute. Specific civil penalty amounts had not been confirmed in available sources as of this writing — check final regulations as the effective date approaches.

Your action checklist

With over a year before the effective date, there is real time to prepare — use it:

1

Check the low sensitive-data threshold carefully. Just 3,000 Vermont residents’ sensitive data puts you in scope — a much lower bar than most other thresholds in this series.

2

Don’t conflate this with Vermont’s data broker law. If you’re a data broker, you likely need separate compliance work for H.211’s January 1, 2027 requirements — a full year before the VDPOSA itself takes effect.

3

Plan for a profiling-explanation process. Build this alongside your other automated-decision infrastructure if you already built one for Minnesota.

4

Classify neural and financial data as sensitive now. If you collect either, start treating them as sensitive ahead of the formal deadline.

5

Build GPC recognition into your roadmap. Required under the VDPOSA once in effect.

6

Recheck this guide well before January 2028. With over a year of runway, expect implementing regulations, penalty specifics, and possibly amendments before enforcement begins.

7

Review vendor contracts. Any processor handling Vermont resident data will need a written agreement specifying processing instructions and confidentiality obligations.

Getting ready for Vermont’s 2028 deadline?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 25 of 25  ·  Series complete