Last updated
Who this affects: This page tracks Vermont’s VDPOSA, which governs controllers and processors.
Who it applies to: Entities that do business in Vermont or target its residents, and meet: 35,000+ consumers, or sensitive data of 3,000+ consumers, or offered for sale in trade or commerce the personal data of 3,000+ consumers; some provisions apply under a separate test (see below).
Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.VDPOSA takes effect
The law, in plain English
VDPOSA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.
These are the highlights we judge most important, not everything VDPOSA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.
The comprehensive law
VDPOSA (S.71) is Vermont’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.
What the law gives consumers
Who the law governs
Exemptions
Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.
Timeline
This state currently has one dated milestone on the books.
Source: primary citation
Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.