Vermont has become the latest state to enact a consumer privacy law, and several of its provisions will land squarely on companies that handle large volumes of consumer data.
Gov. Phil Scott signed Senate Bill 71, the Vermont Data Privacy and Online Surveillance Act, on June 16. The law takes effect Jan. 1, 2028, and the state attorney general holds exclusive enforcement authority. A 60-day cure period runs through June 30, 2029, after which it expires. There is no private right of action.
The statute closely tracks Connecticut’s privacy framework, but its coverage thresholds rank among the broadest in the country. The law applies to entities doing business in Vermont, or targeting Vermont residents, that control or process the data of at least 35,000 consumers, process the sensitive data of at least 3,000 consumers, or sell the data of at least 3,000 consumers. Analysts note the 35,000 figure represents roughly 5.4% of the state population, the highest share covered by any state privacy law and a number many mid-sized collection operations will clear.
For the ARM industry, the familiar exemptions matter most. The Act exempts GLBA-regulated financial institutions at the entity level and carves out FCRA-covered data and GLBA-covered data at the data level. Even so, collection agencies and debt buyers should not assume those carve-outs cover their full operations, since data that falls outside a furnisher’s FCRA activity may still be in scope.
Two provisions stand out. First, the law’s consumer health data rules apply to any business serving Vermont residents, with no threshold at all. Those rules restrict access to health data, require consent before any sale, and bar the use of a geofence within 1,850 feet of a health care facility. Medical debt collectors should take note. Second, controllers must disclose in their privacy notices whether they process personal data to train large language models, a first-of-its-kind requirement that arrives as the industry expands its use of AI.
Vermont consumers gain the rights to confirm, access, correct, delete and obtain copies of their data, plus the ability to opt out of targeted advertising, data sales, and profiling that produces a legal or similarly significant effect. Controllers must respond to requests within 45 days and honor opt-out preference signals.
.




