Back to Frameworks

Vermont Data Privacy and Online Surveillance Act

United States - Vermont
v9 V.S.A. chapter 61A, subchapter 1, as enacted by 2026 Acts and Resolves No. 145 (S.71), signed 16 June 2026; effective 1 January 2028 (not yet in force)
6 domains
45 controls

Vermont's comprehensive consumer privacy law, 9 V.S.A. chapter 61A (Act 145 of 2026), effective 1 January 2028: low thresholds (35,000 consumers, or 3,000 for sensitive data or sale), rights including access to inferences, a list of data buyers and contestation of significant profiling decisions, consent and necessity for sensitive data including neural and health data, no targeted advertising or sale for teens, opt-out preference signals, a privacy notice disclosing large language model training, data protection and profiling impact assessments, and consumer health data rules for every business, including a geofencing ban near health facilities. Enforced by the Attorney General. Built from the act as enacted, read in full.

Verified

Vermont Data Privacy and Online Surveillance Act is a compliance framework from United States - Vermont with 6 domains and 45 controls that map to 176 other frameworks. The largest domains are Consumer rights and how controllers answer requests (9 V.S.A. § 2415d) – Vermont Data Privacy and Online Surveillance Act (16 controls), Controller duties, privacy notice and request methods (§ 2415e) – Vermont Data Privacy and Online Surveillance Act (16 controls), Deidentified and pseudonymous data; processing under an exemption (§§ 2415h and 2415i) – Vermont Data Privacy and Online Surveillance Act (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Consumer health data (§ 2415k) – Vermont Data Privacy and Online Surveillance Act

3 controls
Controls in the Consumer health data (§ 2415k) – Vermont Data Privacy and Online Surveillance Act domain of Vermont Data Privacy and Online Surveillance Act — 3 controls
CodeTitle
vermont-data-privacy-and-online-surveillance-act::2415k-19 V.S.A. § 2415k(1) and (2) Consumer health data only to staff under a confidentiality duty and to processors under contract
vermont-data-privacy-and-online-surveillance-act::2415k-39 V.S.A. § 2415k(3) No geofencing within 1,850 feet of health care facilities
vermont-data-privacy-and-online-surveillance-act::2415k-49 V.S.A. § 2415k(4) No sale of consumer health data without consent

Consumer rights and how controllers answer requests (9 V.S.A. § 2415d) – Vermont Data Privacy and Online Surveillance Act

16 controls
Controls in the Consumer rights and how controllers answer requests (9 V.S.A. § 2415d) – Vermont Data Privacy and Online Surveillance Act domain of Vermont Data Privacy and Online Surveillance Act — 16 controls
CodeTitle
vermont-data-privacy-and-online-surveillance-act::2415d-a19 V.S.A. § 2415d(a)(1) Right to confirm processing and access, including inferences and significant profiling
vermont-data-privacy-and-online-surveillance-act::2415d-a29 V.S.A. § 2415d(a)(2) Right to correct inaccuracies
vermont-data-privacy-and-online-surveillance-act::2415d-a39 V.S.A. § 2415d(a)(3) Right to delete data provided by or obtained about the consumer
vermont-data-privacy-and-online-surveillance-act::2415d-a49 V.S.A. § 2415d(a)(4) Right to a portable copy of the personal data processed
vermont-data-privacy-and-online-surveillance-act::2415d-a59 V.S.A. § 2415d(a)(5) Right to opt out of targeted advertising, sale and significant automated profiling
vermont-data-privacy-and-online-surveillance-act::2415d-a69 V.S.A. § 2415d(a)(6) Rights after a significant profiling decision: question, reasons, review and, for housing, correction and re-evaluation
vermont-data-privacy-and-online-surveillance-act::2415d-a79 V.S.A. § 2415d(a)(7) Right to a list of third parties to which data was sold
vermont-data-privacy-and-online-surveillance-act::2415d-b29 V.S.A. § 2415d(b)(2) Authorised agents and opt-out technologies
vermont-data-privacy-and-online-surveillance-act::2415d-b39 V.S.A. § 2415d(b)(1) and (3) Requests through the notified means; parents of known children and guardians
vermont-data-privacy-and-online-surveillance-act::2415d-c19 V.S.A. § 2415d(c)(1) Respond within 45 days, one 45-day extension with notice
vermont-data-privacy-and-online-surveillance-act::2415d-c29 V.S.A. § 2415d(c)(2) Explain a refusal with appeal instructions within 45 days
vermont-data-privacy-and-online-surveillance-act::2415d-c39 V.S.A. § 2415d(c)(3) Free once in 12 months; fees only for unfounded, excessive or repetitive requests
vermont-data-privacy-and-online-surveillance-act::2415d-c49 V.S.A. § 2415d(c)(4) Authentication for access-type rights; no authentication for opt-outs except documented fraud
vermont-data-privacy-and-online-surveillance-act::2415d-c59 V.S.A. § 2415d(c)(5) Deletion of third-party-sourced data by suppression record or full opt-out
vermont-data-privacy-and-online-surveillance-act::2415d-d9 V.S.A. § 2415d(d) Appeal process decided within 60 days with a route to the Attorney General
vermont-data-privacy-and-online-surveillance-act::2415d-e9 V.S.A. § 2415d(e) Never disclose sensitive identifiers in an access response

Controller duties, privacy notice and request methods (§ 2415e) – Vermont Data Privacy and Online Surveillance Act

16 controls
Controls in the Controller duties, privacy notice and request methods (§ 2415e) – Vermont Data Privacy and Online Surveillance Act domain of Vermont Data Privacy and Online Surveillance Act — 16 controls
CodeTitle
vermont-data-privacy-and-online-surveillance-act::2415e-a19 V.S.A. § 2415e(a)(1) Collection reasonably necessary and proportionate to disclosed purposes
vermont-data-privacy-and-online-surveillance-act::2415e-a29 V.S.A. § 2415e(a)(2) Consent for any material new purpose
vermont-data-privacy-and-online-surveillance-act::2415e-a39 V.S.A. § 2415e(a)(3) Reasonable data security practices
vermont-data-privacy-and-online-surveillance-act::2415e-a49 V.S.A. § 2415e(a)(4) Sensitive data only with consent and where reasonably necessary; no sale without consent; children under COPPA
vermont-data-privacy-and-online-surveillance-act::2415e-a59 V.S.A. § 2415e(a)(5) No processing in breach of anti-discrimination laws; antibias testing evidence counts
vermont-data-privacy-and-online-surveillance-act::2415e-a69 V.S.A. § 2415e(a)(6) Consent revocation as easy as giving it, honoured within 15 days
vermont-data-privacy-and-online-surveillance-act::2415e-a79 V.S.A. § 2415e(a)(7) No targeted advertising or sale for consumers aged 13 to 17
vermont-data-privacy-and-online-surveillance-act::2415e-a89 V.S.A. § 2415e(a)(8) and (b) No retaliation for exercising rights; loyalty programmes allowed
vermont-data-privacy-and-online-surveillance-act::2415e-a99 V.S.A. § 2415e(a)(9) Covered businesses comply with the Vermont Age-Appropriate Design Code for covered minors
vermont-data-privacy-and-online-surveillance-act::2415e-c19 V.S.A. § 2415e(c)(1) Privacy notice with nine contents, including large language model training
vermont-data-privacy-and-online-surveillance-act::2415e-c29 V.S.A. § 2415e(c)(2) and (4) Publish the notice by a 'privacy' link, in every language used, accessible to people with disabilities
vermont-data-privacy-and-online-surveillance-act::2415e-c39 V.S.A. § 2415e(c)(3) Notice and choice before a retroactive material change
vermont-data-privacy-and-online-surveillance-act::2415e-d19 V.S.A. § 2415e(d)(1) and (2)(A) Secure and reliable request means without a new account
vermont-data-privacy-and-online-surveillance-act::2415e-d2b9 V.S.A. § 2415e(d)(2)(B) Clear and conspicuous opt-out link on the website
vermont-data-privacy-and-online-surveillance-act::2415e-d2c9 V.S.A. § 2415e(d)(2)(C) and (3) Honour opt-out preference signals, even over conflicting settings
vermont-data-privacy-and-online-surveillance-act::2415e-d49 V.S.A. § 2415e(d)(4) Present financial incentive terms when charging after an opt-out signal

Data protection and profiling impact assessments (§ 2415g) – Vermont Data Privacy and Online Surveillance Act

3 controls
Controls in the Data protection and profiling impact assessments (§ 2415g) – Vermont Data Privacy and Online Surveillance Act domain of Vermont Data Privacy and Online Surveillance Act — 3 controls
CodeTitle
vermont-data-privacy-and-online-surveillance-act::2415g-a9 V.S.A. § 2415g(a), (b) and (e) Data protection assessments for heightened-risk processing
vermont-data-privacy-and-online-surveillance-act::2415g-c9 V.S.A. § 2415g(c) Impact assessment for profiling used in significant decisions
vermont-data-privacy-and-online-surveillance-act::2415g-d9 V.S.A. § 2415g(d) Disclose assessments to the Attorney General on request

Deidentified and pseudonymous data; processing under an exemption (§§ 2415h and 2415i) – Vermont Data Privacy and Online Surveillance Act

4 controls
Controls in the Deidentified and pseudonymous data; processing under an exemption (§§ 2415h and 2415i) – Vermont Data Privacy and Online Surveillance Act domain of Vermont Data Privacy and Online Surveillance Act — 4 controls
CodeTitle
vermont-data-privacy-and-online-surveillance-act::2415h-a9 V.S.A. § 2415h(a) Duties of a controller holding deidentified data
vermont-data-privacy-and-online-surveillance-act::2415h-c9 V.S.A. § 2415h(c) and (d) Pseudonymous data carve-out and oversight of disclosed data
vermont-data-privacy-and-online-surveillance-act::2415i-b49 V.S.A. § 2415i(b)(4) Using data to detect and correct bias in significant profiling, only under strict conditions
vermont-data-privacy-and-online-surveillance-act::2415i-f9 V.S.A. § 2415i(f) Processing under an exemption must be necessary, proportionate, secured and proven

Processors and controller-processor contracts (§ 2415f) – Vermont Data Privacy and Online Surveillance Act

3 controls
Controls in the Processors and controller-processor contracts (§ 2415f) – Vermont Data Privacy and Online Surveillance Act domain of Vermont Data Privacy and Online Surveillance Act — 3 controls
CodeTitle
vermont-data-privacy-and-online-surveillance-act::2415f-a9 V.S.A. § 2415f(a) Processor follows instructions and assists the controller
vermont-data-privacy-and-online-surveillance-act::2415f-b9 V.S.A. § 2415f(b)(1) to (4) Binding contract with required processor terms, subcontracting after an opportunity to object
vermont-data-privacy-and-online-surveillance-act::2415f-d9 V.S.A. § 2415f(c) and (d) Role follows conduct: a processor that departs from instructions is a controller

Your Compliance Coverage

If you comply with Vermont Data Privacy and Online Surveillance Act, you already cover:

Maps to 176 other frameworks

71 total controls
Family Educational Rights and Privacy Act (FERPA)
3 source controls mapped|5 target controls covered
4%
4%
India DPDP Act
3 source controls mapped|3 target controls covered
4%
Indonesia PDP Law
3 source controls mapped|3 target controls covered
4%
Iowa Consumer Data Protection Act
3 source controls mapped|4 target controls covered
4%
Jamaica Data Protection Act 2020
3 source controls mapped|4 target controls covered
4%
Kentucky Consumer Data Protection Act
3 source controls mapped|3 target controls covered
4%
South Korea PIPA
3 source controls mapped|3 target controls covered
4%
Law No. 172-13 on the Protection of Personal Data
3 source controls mapped|3 target controls covered
4%
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|3 target controls covered
4%
LGPD
3 source controls mapped|3 target controls covered
4%
Malaysia PDPA 2010
3 source controls mapped|5 target controls covered
4%
Mauritius DPA
3 source controls mapped|4 target controls covered
4%
Mexico LFPDPPP
3 source controls mapped|5 target controls covered
4%
Minnesota Consumer Data Privacy Act
3 source controls mapped|4 target controls covered
4%
Montana Consumer Data Privacy Act
3 source controls mapped|4 target controls covered
4%
Nebraska Data Privacy Act
3 source controls mapped|6 target controls covered
4%
New Hampshire Data Privacy Act
3 source controls mapped|5 target controls covered
4%
New Jersey Data Privacy Act
3 source controls mapped|4 target controls covered
4%
Nigeria Data Protection Act 2023 (NDPA)
3 source controls mapped|6 target controls covered
4%
Nigeria Data Protection Regulation (NDPR)
3 source controls mapped|4 target controls covered
4%
NIST SP 800-122
3 source controls mapped|5 target controls covered
4%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
3 source controls mapped|4 target controls covered
4%
Oregon Consumer Privacy Act
3 source controls mapped|5 target controls covered
4%
Pakistan Personal Data Protection Bill 2023
3 source controls mapped|4 target controls covered
4%
PDPA Singapore
3 source controls mapped|5 target controls covered
4%
PDPA Thailand
3 source controls mapped|5 target controls covered
4%
Personal Data Act (personopplysningsloven)
3 source controls mapped|5 target controls covered
4%
Peru DPL
3 source controls mapped|3 target controls covered
4%
POPIA
3 source controls mapped|3 target controls covered
4%
Privacy Act 1988 (Australia)
3 source controls mapped|5 target controls covered
4%
Privacy Act 2020
3 source controls mapped|4 target controls covered
4%
Turkey KVKK
3 source controls mapped|3 target controls covered
4%
Uruguay DPL
3 source controls mapped|4 target controls covered
4%
Indiana Consumer Data Protection Act
3 source controls mapped|3 target controls covered
4%
Liechtenstein DPA
3 source controls mapped|3 target controls covered
4%
Maryland Online Data Privacy Act of 2024
3 source controls mapped|3 target controls covered
4%
NIST Privacy Framework
3 source controls mapped|6 target controls covered
4%
Qatar DPL
3 source controls mapped|2 target controls covered
4%
Taiwan PDPA
3 source controls mapped|2 target controls covered
4%
UK GDPR (UK General Data Protection Regulation)
3 source controls mapped|2 target controls covered
4%
Texas Data Privacy and Security Act (TDPSA)
3 source controls mapped|2 target controls covered
4%
OWASP Top 10 for LLM Applications 2025
2 source controls mapped|3 target controls covered
3%
ISO/IEC 27400:2022
2 source controls mapped|5 target controls covered
3%
ISO/IEC 27011:2024
2 source controls mapped|4 target controls covered
3%
FDA 21 CFR Part 11
2 source controls mapped|5 target controls covered
3%
Georgia Law on Personal Data Protection (2012)
2 source controls mapped|1 target controls covered
3%
ICH E6(R3) - Good Clinical Practice
2 source controls mapped|1 target controls covered
3%
IEEE 7000
2 source controls mapped|4 target controls covered
3%
ISMAP (Japan)
2 source controls mapped|3 target controls covered
3%
Jordan Personal Data Protection Law (Law No. 24 of 2023)
2 source controls mapped|2 target controls covered
3%
Law on Personal Data Protection (Official Gazette No. 42/2020)
2 source controls mapped|1 target controls covered
3%
MARS-E
2 source controls mapped|5 target controls covered
3%
MDS2 (Medical Device)
2 source controls mapped|3 target controls covered
3%
MTCS (Singapore)
2 source controls mapped|4 target controls covered
3%
NIST SP 800-144
2 source controls mapped|3 target controls covered
3%
NIST SP 800-145
2 source controls mapped|3 target controls covered
3%
NIST SP 800-146
2 source controls mapped|3 target controls covered
3%
Paraguay Law on Protection of Personal Data (Law No. 6534/2020)
2 source controls mapped|1 target controls covered
3%
UNESCO Recommendation on the Ethics of AI
2 source controls mapped|3 target controls covered
3%
ISO/IEC 29134:2023
2 source controls mapped|3 target controls covered
3%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|3 target controls covered
3%
FedRAMP Rev 5
2 source controls mapped|3 target controls covered
3%
FISMA
2 source controls mapped|3 target controls covered
3%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|3 target controls covered
3%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|6 target controls covered
3%
Ghana Cybersecurity Act
2 source controls mapped|2 target controls covered
3%
Japan AI Guidelines
2 source controls mapped|3 target controls covered
3%
Kenya Data Protection Act
2 source controls mapped|2 target controls covered
3%
NAIC Insurance Data Security Model Law (MDL-668)
2 source controls mapped|3 target controls covered
3%
Nevada Gaming Control Board Cybersecurity Requirements
2 source controls mapped|4 target controls covered
3%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
2 source controls mapped|3 target controls covered
3%
NIST SP 800-66
2 source controls mapped|2 target controls covered
3%
3%
OECD AI Principles
2 source controls mapped|3 target controls covered
3%
Oman National Cybersecurity Framework
2 source controls mapped|2 target controls covered
3%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|2 target controls covered
3%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
2 source controls mapped|1 target controls covered
3%
SASB Standards
2 source controls mapped|2 target controls covered
3%
Student Privacy Pledge 2020
2 source controls mapped|1 target controls covered
3%
Tanzania Personal Data Protection Act 2022
2 source controls mapped|4 target controls covered
3%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
2 source controls mapped|3 target controls covered
3%
UNICEF Policy Guidance on AI for Children (2021)
2 source controls mapped|2 target controls covered
3%
UK AI Regulation Framework
2 source controls mapped|2 target controls covered
3%
Trinidad and Tobago Data Protection Act 2011
2 source controls mapped|4 target controls covered
3%
TSA Pipeline Cybersecurity Directives
2 source controls mapped|2 target controls covered
3%
TISAX - Trusted Information Security Assessment Exchange
2 source controls mapped|2 target controls covered
3%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
1%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
1 source controls mapped|3 target controls covered
1%
ISO/IEC 23837:2023
1 source controls mapped|1 target controls covered
1%
FIDO2 / WebAuthn
1 source controls mapped|2 target controls covered
1%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
1%
Global Cross-Border Privacy Rules (Global CBPR) Forum
1 source controls mapped|1 target controls covered
1%
HL7 FHIR Security Framework
1 source controls mapped|1 target controls covered
1%
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
1 source controls mapped|2 target controls covered
1%
Israel Protection of Privacy Law (5741-1981)
1 source controls mapped|3 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|2 target controls covered
1%
Kids Online Safety Act (KOSA)
1 source controls mapped|2 target controls covered
1%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
1%
MITRE D3FEND
1 source controls mapped|1 target controls covered
1%
NIST AI 600-1: Generative AI Profile
1 source controls mapped|1 target controls covered
1%
NIST SP 800-123
1 source controls mapped|1 target controls covered
1%
NIST SP 800-137
1 source controls mapped|1 target controls covered
1%
NIST SP 800-61 Rev. 3
1 source controls mapped|1 target controls covered
1%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
1%
NIST SP 800-88
1 source controls mapped|1 target controls covered
1%
NIST SP 800-92
1 source controls mapped|1 target controls covered
1%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
1%
O-RAN WG11 Security Specification
1 source controls mapped|1 target controls covered
1%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
1%
OWASP API Security Top 10 - 2023
1 source controls mapped|1 target controls covered
1%
OWASP ASVS
1 source controls mapped|1 target controls covered
1%
OWASP MASVS
1 source controls mapped|1 target controls covered
1%
OWASP SAMM
1 source controls mapped|1 target controls covered
1%
PTES
1 source controls mapped|1 target controls covered
1%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
1%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|1 target controls covered
1%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
1%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
1%
SLSA
1 source controls mapped|1 target controls covered
1%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
1%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
1%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
1 source controls mapped|1 target controls covered
1%
South Africa Promotion of Access to Information Act (PAIA)
1 source controls mapped|1 target controls covered
1%
1%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|1 target controls covered
1%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
1%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
1%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|3 target controls covered
1%
GS1 Global Standards - Supply Chain Traceability and Data Security
1 source controls mapped|2 target controls covered
1%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|3 target controls covered
1%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
1%
IEEE 1686
1 source controls mapped|4 target controls covered
1%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
1%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
1%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
1%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|2 target controls covered
1%
UK Gambling Commission LCCP and Remote Technical Standards
1 source controls mapped|1 target controls covered
1%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
1%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
1%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
1%
FATF Recommendation 16 - Payment Transparency (Travel Rule)
1 source controls mapped|1 target controls covered
1%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|2 target controls covered
1%
FSSC 22000 - Food Safety System Certification
1 source controls mapped|1 target controls covered
1%
GAMP 5 - Good Automated Manufacturing Practice
1 source controls mapped|1 target controls covered
1%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
1 source controls mapped|1 target controls covered
1%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
1%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|2 target controls covered
1%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
1 source controls mapped|1 target controls covered
1%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
1%
IRM/AIRMIC/ALARM A Risk Management Standard (2002)
1 source controls mapped|2 target controls covered
1%
Lloyd's of London Cyber Insurance Requirements and Underwriting Standards
1 source controls mapped|2 target controls covered
1%
NERC CIP
1 source controls mapped|1 target controls covered
1%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|2 target controls covered
1%
NIST SP 800-30
1 source controls mapped|3 target controls covered
1%
NIST SP 800-37
1 source controls mapped|2 target controls covered
1%
NIST SP 800-39
1 source controls mapped|1 target controls covered
1%
OECD Recommendation on Artificial Intelligence (2024 Update)
1 source controls mapped|2 target controls covered
1%
Own Risk and Solvency Assessment (ORSA) - NAIC Model Act
1 source controls mapped|2 target controls covered
1%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
1%
SEC Climate Disclosure Rule
1 source controls mapped|1 target controls covered
1%
Section 508 - ICT Accessibility (Revised)
1 source controls mapped|2 target controls covered
1%
HITECH Act
1 source controls mapped|2 target controls covered
1%

Coverage is not the same as your position

This page shows what Vermont Data Privacy and Online Surveillance Act overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Vermont Data Privacy and Online Surveillance Act and who does it apply to?

Vermont Data Privacy and Online Surveillance Act is a compliance framework from United States - Vermont with 6 domains and 45 controls. Vermont's comprehensive consumer privacy law, 9 V.S.A. chapter 61A (Act 145 of 2026), effective 1 January 2028: low thresholds (35,000 consumers, or 3,000 for sensitive data or sale), rights including access to inferences, a list of data buyers and contestation of significant profiling decisions, consent and necessity for sensitive data including neural and health data, no targeted advertising or sale for teens, opt-out preference signals, a privacy notice disclosing large language model training, data protection and profiling impact assessments, and consumer health data rules for every business, including a geofencing ban near health facilities. Enforced by the Attorney General. Built from the act as enacted, read in full. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Vermont Data Privacy and Online Surveillance Act actually require?

Vermont Data Privacy and Online Surveillance Act has 45 controls organised across 6 domains. The largest domains are Consumer rights and how controllers answer requests (9 V.S.A. § 2415d) – Vermont Data Privacy and Online Surveillance Act (16 controls), Controller duties, privacy notice and request methods (§ 2415e) – Vermont Data Privacy and Online Surveillance Act (16 controls), Deidentified and pseudonymous data; processing under an exemption (§§ 2415h and 2415i) – Vermont Data Privacy and Online Surveillance Act (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Vermont Data Privacy and Online Surveillance Act do I already cover?

Vermont Data Privacy and Online Surveillance Act maps to 176 other compliance frameworks. The top mapping partners are Family Educational Rights and Privacy Act (FERPA) (4% coverage), Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) (4% coverage), India DPDP Act (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Vermont Data Privacy and Online Surveillance Act?

Start your Vermont Data Privacy and Online Surveillance Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Vermont Data Privacy and Online Surveillance Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required