Skip to main content
VDPOSA Compliance: Eight Questions DPOs Are Actually AskingLaws and Regulations
4 min readFor DPOs (Data Protection Officers)

VDPOSA Compliance: Eight Questions DPOs Are Actually Asking

Privacy teams are grappling with the Vermont Data Privacy and Online Surveillance Act (VDPOSA), effective January 1, 2028. If you've built a multi-state privacy program around Connecticut or Colorado's framework, Vermont's law might seem familiar but introduces costly nuances. Here are the key questions and insights for aligning your compliance strategy.

Can We Integrate Vermont into Our Connecticut Compliance Program?

Not entirely. While VDPOSA mirrors the Connecticut Data Privacy Act in structure, covering controller/processor roles, consumer rights, and data protection assessments, Vermont introduces four distinct provisions:

  • Neural data is classified as sensitive, requiring Prior Consent.
  • There's a geofencing ban within 1,850 feet of health facilities for consumer health data.
  • Privacy notices must disclose if personal data is used to train large language models.
  • Consumers can request the specific third parties their data was sold to, not just categories.

If your Connecticut compliance relies on category-level transparency or lacks provisions for neurotechnology data, adjustments are necessary. You're not starting over, but "Connecticut-compliant" won't suffice for a Vermont audit.

Are We Exempt If We Don't Meet the 35,000-Consumer Threshold?

Not necessarily. VDPOSA applies to businesses processing data of 35,000 or more consumers, sensitive data of 3,000 or more, or offering data of 3,000 or more for sale. However, consumer health data rules apply to anyone doing business in Vermont or targeting its residents, regardless of volume.

This means wellness apps, telehealth platforms, or fitness trackers must comply if they process data identifying a consumer's health condition. Vermont's definition of "consumer health data" is broad, including gender-affirming care, reproductive health, and mental health data. HIPAA compliance won't exempt you unless you're a covered entity acting in that capacity.

Review your data flows for any health-related information. If found, assume the consumer health data section applies.

What Counts as Neural Data, and Should We Be Concerned?

Neural data involves information from an individual's central nervous system activity. Vermont classifies it as sensitive data. Even if you're not directly involved with brain-computer interfaces, the definition might include wellness wearables and biometric devices measuring neurological signals.

You need consumer consent before processing or selling neural data. Investigate if any third-party SDKs or hardware partners generate neural data. If you're integrating biometric sensors or working with neurotechnology vendors, map those data flows now.

How Do We Comply with the Geofencing Ban Around Health Facilities?

You can't use geofencing within 1,850 feet of health care facilities to identify, track, collect data, or send notifications about consumer health data. This is stricter than most states.

Audit your geofence radius settings and exclude Vermont health facilities. The 1,850-foot radius is specific. Maintain an updated list of Vermont health facilities by coordinating with your location-data vendor or building exclusion zones.

Consider what counts as a notification "about" consumer health data. If a message relates to health, wellness, or medical services, treat it as covered and stay outside the 1,850-foot perimeter.

Must We Disclose AI Training in Our Privacy Notice?

Yes. Vermont mandates that controllers disclose if personal data is used to train large language models. This is a pioneering state-level AI disclosure requirement.

If you're using user data for LLM purposes, like customer service automation or content generation, your privacy notice must reflect this. Even if you're not doing it now but plan to, consider updating your notice proactively.

Expect other states to follow Vermont's lead. This is likely the beginning of a trend.

What Does "Specific List of Third Parties" Mean for Data Sales Transparency?

Vermont allows consumers to request the actual names of third parties their data was sold to, not just categories. If you don't maintain consumer-specific lists, you must provide a list of all third-party buyers, unless it reveals a trade secret.

This demands higher transparency. If you're selling data to ad networks, data brokers, or analytics vendors, maintain either per-consumer sale records or a master list of all third-party buyers. Review your data-sales agreements and document any trade secret claims under Vermont law.

Should We Honor Global Privacy Control for Vermont Users?

Yes. VDPOSA requires controllers to support a recognized universal opt-out signal, like Global Privacy Control (GPC), for opting out of targeted advertising and data sales.

Configure your CMP to recognize GPC headers as valid opt-out requests for Vermont residents. Ensure the opt-out mechanism is as easy as the original consent flow. Vermont's statute specifies that the universal opt-out mechanism "must not make use of a default setting," meaning users must enable it themselves.

Where Should We Focus Our Compliance Efforts Before January 2028?

Begin with consumer health data. Map data flows that could identify health status, including wearables, telehealth integrations, and wellness features. If processing such data for Vermont residents, the consumer health data section applies.

Next, audit your third-party data sales. Update your master list of buyers and confirm any trade secret relationships. Prepare this list for consumer requests.

Finally, update your privacy notice for LLM training and review geofencing logic for location-based health marketing. These provisions are likely to surprise teams but are straightforward to address early.

VDPOSA takes effect January 1, 2028. Use the time to address neural data, health-facility geofencing, AI disclosures, and third-party naming. Treat this as a 2027 priority to avoid a last-minute rush.

You Might Also Like