Vermont has now passed the Vermont Data Privacy and Online Surveillance Act, enacted through S.71 as Act 145 on June 16, 2026. The law takes effect on January 1, 2028, so if your website collects data from Vermont residents, you have time to prepare.
That includes reviewing your cookie compliance setup, other trackers, targeted advertising, data sales, sensitive-data processing, consumer health data, and the consent and opt-out controls connected to them.
You need to understand what your tracking technologies collect, where that data goes and what it is used for. Start by mapping those data flows against your current privacy controls.
What Is the Vermont Data Privacy and Online Surveillance Act and When Does It Take Effect?
The statutory short title is Vermont Data Privacy and Online Surveillance Act. Governor Phil Scott signed S.71 as Act 145 on June 16, 2026, and the Act becomes effective January 1, 2028.
The law is separate from Vermont’s H.121, whose veto was sustained in 2024, and from measures such as the Age-Appropriate Design Code Act, Act 138/H.211, An act relating to data brokers and personal information, and the Security Breach Notice Act.
The rights and obligations below begin on January 1, 2028 unless noted otherwise.
Does Vermont’s Privacy Law Apply to Your Business?
Subject to exemptions, § 2415b generally applies to a person conducting business in Vermont or producing products or services targeted to Vermont residents that, during the preceding calendar year, meets any one of these alternative thresholds:
- Controls or processes personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction
- Controls or processes sensitive data of at least 3,000 consumers, subject to the payment-transaction exclusion
- Offers for sale in trade or commerce the personal data of at least 3,000 consumers
The consumer-health-data provisions have broader applicability and are not limited by the general numerical thresholds.
The Act contains both entity-level and data-level exemptions, including exemptions involving government entities, specified regulated entities and certain data subject to Title V of the Gramm-Leach-Bliley Act.
A “consumer” is a Vermont-resident individual, excluding specified commercial and employment contexts. Personal data includes derived data and unique identifiers when linked or reasonably linkable to an identified or identifiable individual or relevant device.
What Rights Do Vermont Consumers Have?
Subject to statutory conditions and exceptions, Vermont consumers can:
- Confirm whether a controller is processing their personal data
- Access their personal data
- Correct inaccuracies
- Delete qualifying personal data
- Obtain qualifying data in a portable format
- Opt out of certain processing
- Request a list of third parties to which the controller sold their personal data
The opt-out right covers:
- Targeted advertising
- Sale of personal data
- Profiling in furtherance of an automated decision that produces a legal or similarly significant effect concerning the consumer
For qualifying profiling, and where feasible, consumers may also question the result, obtain the reason for the decision and review relevant personal data. For certain housing decisions, they may also correct inaccurate personal data used in the profiling and have the decision reevaluated using the corrected data.
If the controller does not maintain a consumer-specific list of third parties to which it sold the consumer’s personal data, it may instead provide a list of all third parties to which it sold personal data, subject to the Act’s trade-secret limitation.
Controllers generally have 45 days to respond to a consumer request. One additional 45-day extension is available when reasonably necessary and properly notified. Appeals generally must be answered within 60 days.
What Does Vermont’s Law Mean for Cookies, Tracking and Advertising?
Vermont does not impose a blanket cookie-consent rule. What matters is what a tracker collects, who receives the data and how that data is used.
Review:
- Advertising pixels
- Third-party advertising cookies
- Remarketing tags
- Analytics and conversion tracking
- Session replay tools
- Social-media pixels
- Affiliate tracking
- Device and mobile advertising identifiers
- IP-address-based tracking
- Geolocation technologies
- Customer-data platforms
- Cross-site or cross-app tracking tools
For each technology, determine whether it involves:
- Personal data
- Sensitive data
- Consumer health data
- A sale of personal data
- Targeted advertising
- Profiling
- Disclosure to a third party
- A processor relationship
- A new or incompatible processing purpose
- A qualifying opt-out preference signal
CookieScript uses five configurable cookie categories, including Strictly Necessary, Performance, Functionality, Unclassified and a targeting/marketing category. These can help organise tracking controls, but they are implementation categories, not statutory Vermont categories.
Sale of Personal Data
Vermont defines a sale as an exchange of personal data with a third party for monetary or other valuable consideration, subject to statutory exclusions.
Relevant exclusions can include qualifying disclosures:
- To processors
- To affiliates
- At the consumer’s direction
- As part of certain business transactions
Not every disclosure to a third-party tracker is automatically a statutory sale.
The analysis depends on the recipient, contractual relationship, consideration exchanged and actual data flow.
Targeted Advertising
Targeted advertising is legally distinct from sale. Vermont generally covers advertising selected using personal data obtained or inferred from a consumer’s activities over time and across nonaffiliated websites or online applications.
The definition excludes specified activities, including:
- Advertising based on activities within a controller’s own website or online application
- Advertising based on the context of the consumer’s current search query, website visit or online application
- Advertising directed to a consumer in response to the consumer’s request for information or feedback
- Processing personal data solely to measure or report advertising frequency, performance or reach
A remarketing pixel, for example, may fall within Vermont’s targeted-advertising rules even when the associated data flow does not qualify as a sale.
When Does Vermont Require Consent?
Act 145 requires consent for specific higher-risk activities rather than for every cookie or every form of personal-data processing.
Sensitive Data
Under § 2415e, covered controllers need consent before processing sensitive data and separately before selling sensitive data.
Sensitive data includes:
- Racial or ethnic origin
- Religious beliefs
- Sex life or sexual orientation
- Nonbinary or transgender status
- Citizenship or immigration status
- Specified mental or physical health information
- Consumer health data
- Genetic data
- Biometric data or information derived from biometric data
- Personal data of a person the controller knows, or wilfully disregards, is a child
- Precise geolocation
- Neural data
- Specified financial-account credentials
- Specified government-issued identification information
Sensitive-data processing must also be reasonably necessary in relation to the purposes for which the data is collected.
The Act uses a COPPA-linked definition of “child”, while separate provisions address consumers aged 13–17. Act 145 separately restricts targeted advertising and sale involving consumers in that age group when its specific knowledge standard is met, subject to the Age-Appropriate Design Code cross-reference.
Valid consent must involve a clear affirmative act that is:
- Freely given
- Specific
- Informed
- Unambiguous
Consent obtained through dark patterns does not qualify. Withdrawal must be at least as easy as giving consent, and covered processing must stop as soon as practicable and no later than 15 days after the withdrawal request.
Consumer Health Data and Geofencing
Businesses below Vermont’s general numerical thresholds should still check whether their websites, apps or vendors collect or process consumer health data.
Under § 2415k:
- Employee or contractor access to consumer health data is limited to people subject to a contractual or statutory duty of confidentiality
- Processor access must comply with the Act’s processor requirements
- Consumer health data cannot be sold or offered for sale without the required consent
A controller may not use a geofence within 1,850 feet of a health care facility, including certain mental-health and reproductive or sexual-health facilities, for prohibited health-data-related identification, tracking, collection or notification. The restriction applies to those uses rather than geofencing generally.
It is separate from Vermont’s definition of precise geolocation data, which uses a 1,750-foot radius.
Does Vermont Require Global Privacy Control?
Act 145 requires covered controllers to recognise qualifying opt-out preference signals for targeted advertising and/or sale when the statutory conditions are met.
A consumer’s choice can be communicated through:
- Browser settings
- Browser extensions
- Global device settings
- Other qualifying technological mechanisms
- An authorised agent
Global Privacy Control (GPC) is the most familiar practical example, but GPC is not the statutory category itself. A signal must satisfy Act 145’s statutory conditions; not every browser setting will necessarily qualify.
Privacy Notices, Assessments and Other Controller Obligations
Controllers must limit collection to personal data that is reasonably necessary and proportionate in relation to the purposes for which the data is processed.
Before relying on consent for a tracker, controllers should first assess whether the collection is reasonably necessary and proportionate for the disclosed purpose. A materially new purpose that is neither reasonably necessary nor compatible with the original purpose can require consent.
Privacy notices must reflect what is actually happening on the website. Required information includes:
- Categories of personal data processed
- Purposes and a description of processing
- How consumers can exercise their rights
- How consumers can appeal a refusal
- Categories of personal data sold
- Categories of third parties to which personal data is sold
- A clear and conspicuous disclosure of targeted-advertising processing and any sale of personal data to a third party for targeted advertising
- A required contact mechanism
- Whether personal data is collected, used or sold to train large language models
- The month and year the privacy notice was most recently updated
Controllers should compare these disclosures against their live cookies, scripts, tags and vendor data flows, not just an internal privacy inventory.
Under § 2415g, controllers must conduct data protection assessments for processing activities that present a heightened risk of harm. The Act expressly includes:
- Processing personal data for targeted advertising
- Sale of personal data
- Processing sensitive data
- Specified profiling that presents the risks identified by the Act
A separate impact assessment for profiling applies when profiling is used to make a decision that produces a legal or similarly significant effect.
These assessment requirements:
- Apply to processing activities created or generated after January 1, 2028
- Are not retroactive
- Can be satisfied by a reasonably similar assessment prepared under another applicable law
Whether an advertising, analytics or technology vendor is a controller or processor depends on what it actually does with personal data, not how it describes its service.
Act 145 also directs the Vermont Attorney General to issue and update compliance guidance, which businesses should monitor during the preparation period.
How Vermont Compares With GDPR, ePrivacy and Other U.S. Privacy Laws
- GDPR and the EU ePrivacy Directive: The GDPR regulates personal-data processing through several lawful bases, while the eprivacy Directive separately addresses storing or accessing information on a user’s device. Vermont instead combines data minimisation, opt-outs, preference signals and affirmative consent for specified processing.
- U.S. state privacy laws: The Connecticut Data Privacy Act (CTDPA) provides a useful comparison for consumer rights, targeted-advertising and sale opt-outs, and universal opt-out mechanisms. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is particularly relevant to Global Privacy Control and opt-outs from sale or sharing.
Similarities with other state laws can help with implementation, but they do not make another state’s privacy configuration automatically compliant with Act 145.
Vermont Privacy Compliance Checklist Before January 2028
- Confirm whether the general Act or broader consumer-health-data provisions apply
- Inventory cookies, pixels, SDKs, scripts and other trackers
- Map purposes, data flows and third-party recipients
- Identify data flows that may constitute a sale of personal data
- Identify targeted advertising separately from sale
- Flag sensitive data and consumer health data
- Review data minimisation, purpose limitation and retention practices
- Implement consent where Act 145 requires it
- Implement sale and targeted-advertising opt-outs and qualifying preference-signal handling
- Update the privacy notice to match production
- Review processor contracts and required assessments
- Re-scan and retest before January 1, 2028 and after material changes
Test the Controls, Not Just the Banner
Test:
- Default tracker behaviour
- Sale opt-outs
- Targeted-advertising opt-outs
- GPC and other qualifying preference signals
- Sensitive-data consent
- Withdrawal of consent
- Preference changes
- Third-party network requests
- Tag-manager behaviour
Browser developer tools and Google Tag Manager Preview mode can show whether tags and requests actually stop. Teams using GTM can also test GPC signals in Google Tag Manager.
Recording a privacy choice without changing the relevant processing is not enough.
Vermont Privacy Law Enforcement and the Temporary 60-Day Cure Period
The Vermont Attorney General enforces Act 145 through the Vermont Consumer Protection Act. The enacted legislation does not create a private right of action.
Act 145 does not set its own fixed per-violation fine. Violations are enforced through the Vermont Consumer Protection Act. As of September 2026, 9 V.S.A. § 2458 allows a court to impose a civil penalty of up to $10,000 for each unfair or deceptive act or practice, alongside other available relief.
From January 1, 2028 through June 30, 2029, the Attorney General must provide notice before bringing an action when the Attorney General determines that a violation can be cured. The cure period is 60 days. This temporary procedure is not a general compliance grace period and does not continue after June 30, 2029 under the enacted law.
During 2025 testimony on S.71, Vermont Attorney General Charity Clark described her office’s approach to resolving violations without litigation:
“It is rare for us to bring a lawsuit where it is possible to instead bring an actor into compliance outside of court.”
— Vermont Attorney General Charity Clark, written testimony on S.71, March 13, 2025
Clark made that statement while arguing that a statutory cure period was unnecessary. The final Act nevertheless includes the temporary 60-day cure procedure described above.
Managing Vermont Website Privacy Controls With CookieScript
CookieScript is a Consent Management Platform (CMP) that Google includes among the CMP partners available for Consent Mode setup. It is also a Google-certified CMP with Gold tier status.
If you are preparing your website for Act 145, the most useful CookieScript features include:
- Cookie Scanner to identify cookies, scripts and other trackers operating on the website
- Cookie Banner and preference controls to present consent and opt-out choices
- User consent recording to document consent and preference changes
- Third-party cookie and script blocking to control trackers based on the configured privacy choice
- Automatic script blocking to prevent selected scripts from running until the required condition is met
- Geo targeting to apply location-specific privacy configurations
- Consent events to trigger downstream changes when a user updates their preferences
- Google Tag Manager integration to connect privacy choices with tag behaviour
- Global Privacy Control and broader privacy-regulation support for qualifying opt-out signals
- Automatic monthly scanning to identify changes in cookies and tracking technologies over time
These tools can help you put privacy choices into practice, but they cannot decide whether a particular data flow legally counts as a sale, targeted advertising, sensitive-data processing or another category under Act 145. You still need to understand what your website collects, where the data goes and how each tracker is used.
For example, third-party cookie and script blocking needs to be configured around the actual tags, trackers and processing on your website.
CookieScript also offers additional features that may be useful for other privacy and consent requirements, including:
- Google Consent Mode v2
- Advanced reporting
- Privacy Policy Generator
- Cookie Policy Generator
- IAB TCF integration
- Multilingual consent banners
A 14-day free trial of the Plus plan is also available without requiring a credit card.
Conclusion
For website operators, a Cookie Banner is only one part of Act 145 compliance: the underlying data flows, processing purposes and vendor relationships determine which controls are actually needed.
Frequently Asked Questions
When does the Vermont Data Privacy and Online Surveillance Act take effect?
The Act takes effect on January 1, 2028. Enacted as S.71/Act 145 in June 2026, 2026 and 2027 are preparation years.
Which businesses are covered by Vermont’s privacy law?
Subject to exemptions, the general triggers are the personal data of at least 35,000 consumers, sensitive data of at least 3,000 consumers, or personal data of at least 3,000 consumers offered for sale in trade or commerce, with the relevant payment-transaction exclusions. Consumer-health-data provisions have broader applicability and should be assessed separately.
Does Vermont require Cookie Consent?
No blanket opt-in rule applies to every cookie. A website must instead assess the data collected and the purpose of each tracker to determine whether consent, an opt-out or another requirement applies.
Can Vermont consumers opt out of targeted advertising?
Yes. When Act 145 takes effect, covered consumers will be able to opt out of targeted advertising. That right is separate from the sale opt-out, so advertising can fall within the targeted-advertising rules even where the same activity is not a statutory sale.
What counts as a sale of personal data in Vermont?
A sale generally involves exchanging personal data with a third party for monetary or other valuable consideration, subject to statutory exclusions. Processor disclosures, consumer-directed disclosures and qualifying corporate transactions can fall outside the definition, so not every third-party data transfer is a sale.
Does Vermont require websites to honour Global Privacy Control?
When Act 145 takes effect, covered controllers will need to recognise qualifying opt-out preference signals for targeted advertising and/or sale. GPC is the best-known practical example, but it is not itself the statutory category, and the signal must satisfy Vermont’s conditions.
When does Vermont require opt-in consent?
When Act 145 takes effect, consent will be required for covered sensitive-data processing and separately for the sale of sensitive data. Section 2415k also prohibits selling or offering consumer health data for sale without first obtaining consent. Consent must involve a clear affirmative act that is freely given, specific, informed and unambiguous, and dark-pattern agreement does not qualify.
How is the Vermont Data Privacy and Online Surveillance Act enforced?
The Vermont Attorney General enforces the Act through the Vermont Consumer Protection Act, and Act 145 creates no private right of action. A temporary 60-day cure procedure applies from January 1, 2028 through June 30, 2029 when the Attorney General determines that the violation can be cured.

