Source: site

Vermont has enacted a new comprehensive data privacy law that will significantly change how many businesses collect, use, and monetize Vermonters’ personal information, with important implications for credit, collections, and financial services providers operating in or targeting the state.
Legislative background and timeline
After more than two years of debate and a prior gubernatorial veto of an earlier, stronger bill in 2024, Vermont lawmakers ultimately coalesced around S.71, the “Vermont Data Privacy and Online Surveillance Act.” The Legislature passed S.71 in late May 2026, reviving the state’s push to join the growing roster of states with comprehensive privacy regimes after Governor Phil Scott rejected the previous Vermont Data Privacy Act over concerns about its private right of action and burdens on businesses.
The final bill represents a political compromise: it preserves core consumer rights and baseline limits on data use, but scales back some of the more aggressive provisions that drew opposition from industry and the governor’s office. The Act is structured with a long runway: if signed, it becomes effective January 1, 2028, with an initial cure period for violations extending through mid‑2029.
Scope, thresholds, and who is covered
The Act applies broadly to entities that do business in Vermont or offer products or services to Vermont residents, but it incorporates thresholds designed to avoid sweeping in every small business. A company is covered if, in the prior calendar year, it met at least one of the following criteria: controlled or processed personal data of at least 35,000 Vermont residents; controlled or processed sensitive personal data of at least 3,000 Vermont residents; or offered to sell the personal data of at least 3,000 consumers.
The law also includes exemptions for many federally regulated entities and datasets already subject to frameworks such as HIPAA and the Gramm‑Leach‑Bliley Act. For credit and collections stakeholders, that means traditional GLBA‑regulated financial institutions and some of their data flows will be carved out, but affiliated non‑bank service providers, data brokers, ad‑tech vendors, and ancillary fintech products could still be directly in scope depending on how they structure their operations and what data they process. Vermont’s move layers on top of existing state laws, including the separate Vermont “Kids Code” enacted in 2025, which already imposes heightened design and data‑use obligations for online services accessed by minors.
At‑a‑glance: Vermont S.71 core elements
Key consumer rights and business obligations
S.71 grants Vermonters a familiar but still meaningful set of privacy rights that mirror elements of other state privacy frameworks while adding some Vermont‑specific twists. Consumers gain the right to access and confirm whether a controller is processing their personal data (including inferences), correct inaccuracies, delete personal data, and obtain a portable copy in a readily usable format that can be transmitted to another controller.
Vermonters also receive opt‑out rights for targeted advertising, the sale of personal data, and profiling in furtherance of automated decisions that produce legal or similarly significant effects, such as decisions about housing, credit, employment, or essential services. Where automated profiling is used for consequential decisions, individuals can question results, be informed of the reasoning, review the underlying data, and, for housing decisions, correct inaccurate information and seek reevaluation, which may have spillover relevance for credit‑adjacent tenant‑screening and collections strategy tools.
The law requires enhanced transparency through privacy notices, consumer consent for the processing of sensitive personal data, and reasonable data security practices. It also targets “dark patterns” and requires that consent and user interfaces not be designed to subvert or impair consumer choice, echoing themes that are increasingly common in state privacy and children’s‑design codes. Controllers will need to review their data‑minimization practices, ensure they can respond to requests within statutory timelines, and maintain records and assessments for high‑risk processing.
Sensitive data, minors, and online surveillance
S.71 singles out several categories of “sensitive data” for heightened protection, including health information, biometric identifiers, precise geolocation, and data related to minors. Companies generally must obtain explicit consent to process sensitive data and are restricted from selling or offering to sell consumer health data without prior consent, directly implicating data brokers and health‑adjacent fintech products that track payment or spending patterns tied to medical services.
The Act adopts a broad concept of “online surveillance,” framing limits on tracking, profiling, and the use of personal information for behavioral advertising without meaningful consumer control. It arrives on the heels of Vermont’s Age‑Appropriate Design Code (“Kids Code”), which takes effect January 1, 2027, and imposes stringent default privacy settings and data‑use restrictions for online services accessed by minors under 18, including prohibitions on certain push notifications and limitations on adult‑minor interactions on platforms. Together, these frameworks will require firms in the credit and collections ecosystem—especially those experimenting with consumer‑facing portals, mobile apps, and digital engagement tools—to carefully align user experience, consent flows, and monitoring practices with Vermont’s expectations.
Enforcement, penalties, and implications for credit and collections
Unlike the vetoed 2024 bill, S.71 centralizes enforcement authority in the Vermont Attorney General and does not create a private right of action, a key concession to business interests and one reason consumer advocates have criticized the final product as too weak. Civil penalties can reach up to $10,000 per violation, and from January 1, 2028 through June 30, 2029, the Attorney General must provide written notice and a 60‑day opportunity to cure before initiating an enforcement action, providing a limited transition period.
For credit grantors, servicers, collection agencies, and data‑driven fintechs, Vermont’s new law adds another layer to an already fragmented state privacy landscape, even if some GLBA‑covered activities benefit from statutory exemptions. Firms that rely heavily on data enrichment, marketing lists, lead generation, and advanced analytics for account management and recovery will need to map Vermont‑resident data, assess whether they meet the Act’s thresholds, and ensure they can honor access, deletion, and opt‑out rights without undermining core risk management and compliance obligations under federal laws like the FDCPA, FCRA, and TCPA.
With an effective date in 2028, organizations have time to prepare, but many will want to integrate Vermont’s requirements into broader multi‑state privacy programs rather than treat S.71 as a one‑off. For industry readers of Credit and Collection News, the practical next steps include: conducting a Vermont‑specific data inventory; reviewing vendor and data‑broker relationships; aligning privacy notices and consent flows with S.71; and monitoring forthcoming guidance from the Vermont Attorney General, which will likely shape how aggressively the new law is enforced in practice.






