June 24, 2026

Vermont Finally Settles On A Consumer Privacy Law

Category:

After several years of back and forth over competing draft proposals, Vermont has finally settled on – and signed into law – a consumer privacy law.

The language of the ultimately successful version is largely taken from the amendments to neighboring Connecticut’s own privacy law, which we wrote about a few weeks back (read here). In perhaps previewing a trend among state legislatures to more closely scrutinize the use of AI and other automated tools in data processing, Vermont becomes the second state to require that a business’s privacy policy contain a statement as to whether the controller collects, uses, or sells personal data for the purpose of training large language models. Similarly, it follows Connecticut and Minnesota in certain enhanced obligations where automated profiling is used for the purposes of making a decision that produces any “legal or similarly significant effect” concerning a consumer, such as more rigorous risk “impact” assessments and the right to question the results of profiling. Decisions that produce “legal or similarly significant effect” by definition include decisions concerning financial or lending services, housing, insurance, education, criminal justice, employment or health care services. While this is not typically applicable to the retail industry, if your business extends consumer credit and uses automated profiling as a tool to do so – it warrants a closer look.

There is an old saying that a camel is a horse designed by a committee.  Vermont’s law bears some scars in its drafting, as well as unique and potentially problematic definitions that may fly under the radar.

  • “Publicly available information,” a straightforward definition in other states, is riddled with exceptions in Vermont. It carves out information that is “collated and combined to create a consumer profile that is made available to a user of a publicly available website,” even if free of charge, and certain information that is made available for sale. Since these exceptions seem to turn solely how on the data is used rather than how it is accessed, the definition itself is puzzling. In short, it is difficult to see a reason why these kinds of data should not be considered “publicly available” if they are in fact, publicly available.
  • The definition of “deidentified data,” which otherwise hews to the norm, obligates one to follow deidentification requirements under federal law concerning protected health information, before one can claim data is truly deidentified. That is not standard, and seems an overly high bar given that these are standards developed for sensitive health information.
  • Also worth noting is the orphan provision contained within the section laying out the details of a contract between a controller and processor.  While otherwise tracking  closely the requirements of other states, Vermont’s law omits the following requirement:

allow, and cooperate with, reasonable assessments by the controller or  the controller’s designated assessor, or the processor may arrange for a  qualified and independent assessor to conduct an assessment of the processor’s policies and technical and organizational measures in support of the  obligations under this Act, using an appropriate and accepted control standard or framework and assessment procedure for such assessments. The processor shall  provide a report of such assessment to the controller upon request.

Instead, there is simply a naked statement that A processor shall  provide a report of such assessment to the controller upon request. As  such, the final sentence is taken in isolation without any context or  explanation as to what “assessment” is being referenced.

As always, our team stands ready to discuss the impacts of these newly-enacted privacy laws with you.

Stacy Stitham | sstitham@brannlaw.com

David Swetnam-Burland | dsb@brannlaw.com

Nathaniel Bessey | nbessey@brannlaw.com

Related News

  • New Jersey’s Summer Surprise: Last-Second Privacy Bill Will Snare More Retailers

    Seemingly out of nowhere, the New Jersey legislature just passed a privacy law that requires immediate attention. The law (1) applies to any business or person who collects, sells, or licenses, the personal information of New Jersey residents; (2) places immediate restrictions on the sale of sensitive personal data to third-party data brokers by anyone;…

  • Illinois Offers Amnesty Program For Remote Sellers

    The 2025 Illinois Tax Delinquency Amnesty Act authorized the Illinois Department of Revenue to offer up two amnesty programs, allowing taxpayers who need to triage historical liabilities – either due to underreporting or non-reporting – to come forward and establish a clean slate with the state. This alert covers the second program, which is designed…