Source: site
This makes Vermont the 23rd state to pass a comprehensive consumer data privacy framework. The law takes effect Jan. 1, 2028.
Vermont has enacted a comprehensive data privacy statute, the Vermont Data Privacy and Online Surveillance Act (S.71), making it one of the latest states to adopt a California‑style consumer privacy framework with some notable twists that matter for lenders, servicers, and collectors operating nationally.
Overview: What Vermont Just Did
The Vermont Legislature passed S.71, the Vermont Data Privacy and Online Surveillance Act (VDPOSA), after several years of failed efforts and a prior gubernatorial veto of a stronger 2024 privacy bill. Governor Phil Scott signed S.71 on June 16, 2026, and the law will take effect January 1, 2028, giving covered businesses roughly 18 months to prepare. With this enactment, Vermont becomes roughly the 24th state with a comprehensive consumer privacy law, further raising the baseline for data governance expectations in the financial services ecosystem.
VDPOSA sits alongside, and does not replace, Vermont’s existing breach notification and sector‑specific privacy statutes, including earlier laws governing data breach notices and student data protections. It also complements Vermont’s Age‑Appropriate Design Code (the “Kids Code”), which was signed in 2025 and takes effect January 1, 2027, to address online harms and data practices involving minors.
Scope and Who Is Covered
VDPOSA applies to entities that conduct business in Vermont or offer products or services to Vermont residents and meet certain data‑volume thresholds. As summarized in law‑firm analyses of S.71, a controller will generally be in scope if in the prior calendar year it:
-
Controlled or processed personal data of at least 35,000 Vermont residents (excluding data processed solely for completing a payment transaction).
-
Controlled or processed sensitive personal data of at least 3,000 Vermont residents.
-
Offered to sell the personal data of at least 3,000 consumers.
The law includes exemptions for many entities and data sets already regulated under federal regimes such as HIPAA and the Gramm‑Leach‑Bliley Act (GLBA), which will be especially relevant for depository institutions and certain financial services providers. However, GLBA coverage does not automatically extend to every affiliate, vendor, or non‑traditional product line, so non‑bank lenders, fintechs, servicers, and third‑party collectors may find that parts of their operations are squarely in scope.
Consumer Rights: Access, Deletion, Opt‑Outs, and Profiling
VDPOSA grants Vermont consumers a familiar bundle of rights that now appear in most state privacy laws, with some important nuances.
Key rights include:
-
Access and confirmation: Consumers can confirm whether a controller is processing their personal data and obtain access to that data, including inferences and information about profiling used in decisions with legal or similarly significant effects.
-
Correction: Consumers can require controllers to correct inaccuracies, taking into account the nature of the data and the purposes of processing.
-
Deletion: Consumers can request deletion of personal data the controller has collected from or about them.
-
Data portability: Consumers can receive a copy of their personal data in a portable, readily usable format, enabling transmission to another controller.
-
Opt‑out rights: Consumers may opt out of targeted advertising, the sale of personal data, and certain types of automated profiling.
VDPOSA goes further than some peers by providing a right to human review and explanation when automated profiling is used to make decisions with legal or similarly significant effects—specifically noting housing‑related decisions. Consumers can question the result, obtain information about the logic involved, review data used in the decision, correct inaccuracies, and request reevaluation, which could intersect with credit, tenancy, and collections‑related analytics.
Sensitive Data, Minors, and Online Design
The law imposes heightened requirements for “sensitive data,” including health information, biometric identifiers, precise geolocation, and data about minors. Controllers must obtain clear, informed consent before processing sensitive personal data, reflecting a broader Vermont policy trend to treat certain categories as requiring opt‑in rather than opt‑out.
These protections complement the Vermont Kids Code, the state’s age‑appropriate design law, which covers online services accessed by minors under 18 and takes effect January 1, 2027. That separate statute sets a duty of care for businesses serving minors online, restricts certain dark patterns, limits late‑night push notifications, and tightly constrains data collection and retention for age‑assurance purposes. Together, VDPOSA and the Kids Code create a layered privacy regime that is particularly protective of minors’ data in digital environments.
Enforcement, Penalties, and Cure Period
VDPOSA assigns exclusive enforcement authority to the Vermont Attorney General, rather than authorizing broad private lawsuits. Consumer advocates have criticized the law as weaker than a 2024 bill that contained strong data‑minimization rules, robust civil rights protections, and a private right of action, but was vetoed by the Governor.
Civil penalties under S.71 may reach up to 10,000 dollars per violation, creating substantial exposure for systemic non‑compliance. From January 1, 2028, through June 30, 2029, the Attorney General must provide written notice and a 60‑day cure period before bringing an enforcement action, giving businesses a limited “on‑ramp” window to remediate issues identified by regulators. After that period, companies should expect stricter, less forgiving enforcement.
Implications for Credit, Collections, and Fintech
For creditors, servicers, and collection agencies, Vermont’s move reinforces that state privacy laws are becoming a permanent and increasingly complex part of the regulatory landscape. Even where GLBA or other federal exemptions apply, many collection and servicing shops rely on marketing vendors, analytics providers, and alternative‑data‑driven tools that may fall outside traditional financial‑institution carve‑outs and thus trigger VDPOSA duties.
The law’s opt‑out provisions for targeted advertising and the sale of data, as well as its requirements around profiling and human review, may intersect with lead‑generation, credit decisioning, skip‑tracing, and collections‑strategy optimization tools that use automated models and consumer profiling. Vermont’s focus on minors and sensitive data also means firms using mobile geolocation, biometric authentication, or health‑adjacent data (for example, medical‑debt collections) should reassess their data inventories, consent flows, and vendor contracts in light of the new law.
A to do list for collection agencies:
Here is a focused, operations‑oriented “to do” list tailored for collection agencies preparing for Vermont’s new Data Privacy and Online Surveillance Act (effective January 1, 2028).
1. Confirm Whether You Are In Scope
-
Map Vermont exposure: Identify how many Vermont consumers’ records you hold or process across all systems (CRM, dialer, collection platform, skip‑trace tools, marketing).
-
Check thresholds: Determine whether you meet the law’s applicability triggers (e.g., 35,000+ Vermont consumers’ personal data or 3,000+ with sensitive data / data sales).
2. Build or Update a Data Inventory
-
Catalog data flows: Document what personal data you collect, from whom (creditor, consumer, vendors), where it is stored, and with whom you share it, including skip‑trace providers and letter vendors.
-
Tag sensitive and minor data: Flag health‑related information, biometric data, precise geolocation, and any data tied to consumers under 18, as these carry extra obligations.
3. Tighten Data Minimization and Purpose Limits
-
Reduce data collection: Limit collection and retention to data that is reasonably necessary and proportionate to disclosed collection and recovery purposes.
-
Lock down re‑use: Prohibit repurposing consumer data (for example, for new analytics or marketing) unless it is compatible with the original purpose or you obtain renewed consent.
4. Stand Up Consumer Rights Handling
-
Build intake channels: Add or refine web forms, phone scripts, and mail options to accept Vermont consumer requests (access, correction, deletion, portability, opt‑outs).
-
Implement procedures and SLAs: Create step‑by‑step workflows so requests are authenticated, logged, routed, fulfilled, and closed within 45 days (plus possible 45‑day extension).
5. Implement Opt‑Outs for Ads, Sales, and Profiling
-
Identify “sales” and targeted ads: Review any data monetization, affiliate sharing, or targeted advertising that involves Vermont accounts.
-
Honor signals: Configure systems and vendors to respect Vermont opt‑out choices, including browser‑based or universal preference signals where used.
6. Address Automated Profiling and Scoring
-
Inventory models: List any automated tools used for segmentation, dialer prioritization, litigation scoring, or settlement offers that could impact consumers’ legal or financial situation.
-
Enable human review: Design a process for Vermont consumers to challenge profiling‑based outcomes, obtain an explanation, correct underlying data, and trigger re‑evaluation.
7. Update Privacy Notices and Consumer Communications
-
Rewrite privacy notices: Ensure your privacy policy clearly explains categories of data collected, purposes, consumers’ rights, opt‑out mechanisms, and whether you use data to train AI or LLMs.
-
Add Vermont‑specific content: Include Vermont‑specific rights language and instructions that align with your operational capabilities and documented procedures.
8. Strengthen Vendor and Client Contract Management
-
Re‑paper vendor contracts: Add data‑protection terms for service providers (mail houses, dialer providers, skip‑trace vendors, analytics firms) to ensure they honor Vermont rights and limits.
-
Align with creditor clients: Coordinate with originating creditors on division of controller/processor roles, consumer‑facing notices, and who will handle which types of Vermont requests.
9. Enhance Security and Access Controls
-
Review technical safeguards: Validate encryption, access controls, logging, and incident‑response procedures against the “reasonable security practices” standard in the law.
-
Restrict health‑related data: Ensure only personnel with a contractual or statutory duty of confidentiality can access any consumer health data involved (for example, medical debt).
10. Conduct Data Protection Impact Assessments
-
Identify high‑risk processing: Flag activities involving targeted advertising, the sale of data, profiling that may affect consumers’ finances or legal rights, and sensitive data use.
-
Document assessments: For each high‑risk activity, record purpose, risks, mitigations, data categories, performance metrics, transparency measures, and monitoring plans, and retain documentation for the AG on request.
11. Train Staff and Update Playbooks
-
Train front‑line teams: Educate collectors, call‑center staff, and compliance teams on Vermont consumer rights, request handling, and how to recognize Vermont accounts.
-
Update scripts and SOPs: Revise call scripts, letter templates, and standard operating procedures to integrate Vermont‑specific opt‑out language and response steps.
12. Plan Around the Cure Period and Timeline
-
Use the runway: Build a project plan now to be ready by January 1, 2028, rather than relying on the temporary 60‑day cure period that runs only through mid‑2029.
-
Monitor rulemaking and guidance: Track any Vermont AG guidance or enforcement actions so you can fine‑tune your program before the cure window ends.







