June 24, 2026
Vermont Finally Settles On A Consumer Privacy Law
After several years of back and forth over competing draft proposals, Vermont has finally settled on – and signed into law – a consumer privacy law.
The language of the ultimately successful version is largely taken from the amendments to neighboring Connecticut’s own privacy law, which we wrote about a few weeks back (read here). In perhaps previewing a trend among state legislatures to more closely scrutinize the use of AI and other automated tools in data processing, Vermont becomes the second state to require that a business’s privacy policy contain a statement as to whether the controller collects, uses, or sells personal data for the purpose of training large language models. Similarly, it follows Connecticut and Minnesota in certain enhanced obligations where automated profiling is used for the purposes of making a decision that produces any “legal or similarly significant effect” concerning a consumer, such as more rigorous risk “impact” assessments and the right to question the results of profiling. Decisions that produce “legal or similarly significant effect” by definition include decisions concerning financial or lending services, housing, insurance, education, criminal justice, employment or health care services. While this is not typically applicable to the retail industry, if your business extends consumer credit and uses automated profiling as a tool to do so – it warrants a closer look.
There is an old saying that a camel is a horse designed by a committee. Vermont’s law bears some scars in its drafting, as well as unique and potentially problematic definitions that may fly under the radar.
- “Publicly available information,” a straightforward definition in other states, is riddled with exceptions in Vermont. It carves out information that is “collated and combined to create a consumer profile that is made available to a user of a publicly available website,” even if free of charge, and certain information that is made available for sale. Since these exceptions seem to turn solely how on the data is used rather than how it is accessed, the definition itself is puzzling. In short, it is difficult to see a reason why these kinds of data should not be considered “publicly available” if they are in fact, publicly available.
- The definition of “deidentified data,” which otherwise hews to the norm, obligates one to follow deidentification requirements under federal law concerning protected health information, before one can claim data is truly deidentified. That is not standard, and seems an overly high bar given that these are standards developed for sensitive health information.
- Also worth noting is the orphan provision contained within the section laying out the details of a contract between a controller and processor. While otherwise tracking closely the requirements of other states, Vermont’s law omits the following requirement:
allow, and cooperate with, reasonable assessments by the controller or the controller’s designated assessor, or the processor may arrange for a qualified and independent assessor to conduct an assessment of the processor’s policies and technical and organizational measures in support of the obligations under this Act, using an appropriate and accepted control standard or framework and assessment procedure for such assessments. The processor shall provide a report of such assessment to the controller upon request.
Instead, there is simply a naked statement that A processor shall provide a report of such assessment to the controller upon request. As such, the final sentence is taken in isolation without any context or explanation as to what “assessment” is being referenced.
As always, our team stands ready to discuss the impacts of these newly-enacted privacy laws with you.
Stacy Stitham | sstitham@brannlaw.com
David Swetnam-Burland | dsb@brannlaw.com
Nathaniel Bessey | nbessey@brannlaw.com