8 minutes read

Louisiana and Vermont Data Privacy Laws: What Businesses Need to Know

Louisiana and Vermont Data Privacy Laws What Businesses Need to Know - icon

Table of Contents

Introduction

Louisiana and Vermont are part of a wave of comprehensive privacy laws sweeping across the United States. Vermont is the 23rd state to enact a consumer data privacy law, joining California, Virginia, the Colorado Privacy Act, the Oregon Consumer Privacy Act, and others in creating a de facto national framework for data protection. Louisiana’s Data Privacy Act goes into effect January 1, 2027, while Vermont’s law, formally the Vermont Data Privacy and Online Surveillance Act, becomes enforceable on January 1, 2028.

Both laws follow a controller-and-processor model similar to Virginia and Connecticut. They are consumer-focused (B2C), meaning they apply to how businesses handle personal data of individuals acting in a personal capacity. Employment and B2B data are generally carved out from the scope. The laws sit atop sector-specific federal statutes such as HIPAA, GLBA, and COPPA, so existing obligations under those regimes remain unchanged.

Who Must Comply?

The first step is determining whether these laws apply to your business. The applicability thresholds differ between the two states, and understanding them is critical before investing in compliance work.

Louisiana’s LDPA applies to controllers and processors doing business in Louisiana or targeting its residents who meet at least one of the following:

  • Annual gross revenue exceeding $25 million
  • Processing personal data from 75,000 or more consumers, households, or devices per year
  • Deriving 50% or more of annual revenue from selling personal data

Louisiana’s law follows a CCPA-style applicability threshold based on revenue and data processing, which means many mid-market brands already tracking these metrics for California will find the scoping exercise familiar.

Vermont’s VDPOSA applies to controllers and processors conducting business in Vermont or targeting Vermont residents who meet any of these criteria:

  • Process personal data of at least 35,000 consumers annually
  • Process sensitive data of at least 3,000 consumers
  • Sell the personal data of at least 3,000 consumers

Vermont’s law uses lower thresholds for triggering compliance requirements for sensitive data processing. A SaaS company collecting health or biometric personal data from just a few thousand Vermont residents would be in scope, even if it is a relatively small operation.

Both laws include standard entity-level exemptions for GLBA financial institutions, HIPAA covered entities, higher education institutions, and certain nonprofits, as well as data-level exemptions for FCRA, FERPA, and other regulated data. Note that the Nebraska data privacy act, Connecticut data privacy act, and Oregon consumer privacy act use similar but not identical thresholds, so a unified multi-state scoping analysis is recommended for any business operating across states.

Make Your Shopify Store GDPR & Cookie Compliant in Minutes
Automatically manage cookie consent, block tracking before user approval, and stay compliant with GDPR, CCPA, LGPD, UK GDPR and Google Consent Mode v2 β€” without coding.

What Counts as Personal and Sensitive Data?

Both LDPA and Vermont data privacy law define personal data broadly as information linked or reasonably linkable to an identified or identifiable natural person, excluding data that has been properly de-identified or is publicly available. Vermont defines personal data broadly, including derived data, meaning data inferred or generated from other information about a consumer also counts.

Sensitive data includes health, financial, and biometric information under both laws. The key categories that trigger stricter rules include:

  • Precise geolocation data
  • Genetic or biometric data used for identification
  • Children’s data
  • Consumer health data and medical information
  • Financial account numbers and authentication credentials
  • Race, ethnicity, religious beliefs, and citizenship or immigration status

Vermont expands the definition of sensitive data compared to Louisiana by adding neural data (information derived from brain or nervous system function), highly detailed financial information, and certain inferred health or behavioral traits. These broader categories are significant for businesses involved in profiling, AI-driven personalization, and the provision of consumer health data.

Louisiana law requires clear notices when selling sensitive data, and both states generally require opt-in consumer consent before processing sensitive personal data, particularly for uses such as targeted advertising, personal data sales, or profiling that has legal or similarly significant effects. Compared to other frameworks such as the Utah Consumer Privacy Act and Maryland’s Online Data Privacy Act, the scope of sensitive data is expanding, raising the bar for compliance with privacy protection acts nationwide.

man holding tablet

Core Consumer Rights Under Louisiana and Vermont Laws

Both laws grant consumers a familiar bundle of rights over their personal data, aligned with the GDPR and the Connecticut Data Privacy Act model. Here is what each right entails:

Right

Louisiana

Vermont

Access

Consumers can request access to their personal data

Same, plus right to access profiling information

Correction

Consumers can request correction of inaccuracies in their data

Same

Deletion

Consumers can request deletion of their personal data

Same

Data portability

Portable copy in usable format

Same

Opt-out of targeted advertising

Yes

Yes

Opt-out of data sales

Consumers can opt-out of targeted advertising and data sales

Same

Profiling transparency

Limited

Right to access inferences and profiling with similarly significant effects

Third-party disclosure

On request

Vermont consumers can obtain a list of third parties that sold their data

In Louisiana, controllers are required to respond to consumer requests within 45 days, with the possibility of one extension.Vermont follows a comparable timeline. Both states require clear privacy notices detailing data collection and consumer rights, and both require businesses to provide this information free of charge and to offer a clear appeals process when consumer rights requests are denied.

Vermont’s law includes a right to access profiling information, giving consumers visibility into inferences generated about them, especially where profiling has legal or similarly significant effects. These rights interact with centralized deletion platforms and registered data brokers’ obligations, making it easier for individuals but more operationally demanding for businesses to handle consumer requests at scale.

Targeted Advertising, Data Sales, and Online Surveillance

Both LDPA and Vermont’s law place heavy emphasis on targeted advertising, the sale of personal data, and online tracking, all of which are directly relevant to e-commerce and ad-tech-driven businesses operating in multiple states.

Both laws define targeted advertising as advertising based on tracking a consumer across sites or apps over time to predict preferences. Businesses in both states must allow consumers to opt-out of targeted advertising and data sales through prominent controls and, in many cases, universal opt-out mechanisms. Configuring your site to detect signals like Global Privacy Control is becoming a baseline expectation.

Louisiana defines “sale” as exchanging personal data for value, monetary or otherwise, similar to the California Consumer Privacy Act, Colorado, and Texas. Vermont uses a similarly broad concept that captures common data-sharing arrangements with ad networks, analytics platforms, data brokers, and affiliates. Louisiana forbids selling sensitive data without prior consent if over 50% of revenue comes from data sales. Vermont prohibits the sale of sensitive data without prior consumer consent, regardless of revenue mix.

Vermont’s online surveillance act aspects go further: stronger limits on cross-site tracking, obligations for registered data brokers, and heightened transparency around monitoring tools, session replay, and third-party pixels. These restrictions matter for any business that collects consumer data through marketing scripts. Tools like Pandectes help automatically block tracking technologies until valid consent is obtained, and honor opt-out signals for targeted advertising in a consent-first era.

A Google-Approved Consent Platform for Shopify
Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.

Both states require clear, accessible privacy notices and, for high-risk processing, formal data protection assessments (also referred to as data protection impact assessments under the GDPR).

Privacy notice requirements under both laws include:

  • Categories of personal and sensitive data collected
  • Purposes of processing
  • Categories of third parties receiving data (including data brokers and ad tech providers)
  • Description of consumer rights and how to exercise them
  • Disclosure of any sale of personal data or use of data for targeted advertising

Vermont requires additional disclosures when personal data is used to train large language models or other AI systems. Vermont mandates that businesses disclose the personal data used to train models, a requirement that goes beyond most existing comprehensive privacy laws. Businesses must also describe profiling activities that may produce legal or similarly significant effects on consumers.

Both states require data protection assessments for high-risk activities. Specifically, Louisiana requires data protection assessments for targeted advertising, the sale of personal data, and the processing of sensitive data. Vermont requires businesses to conduct data protection assessments for sensitive data, profiling, and large-scale online surveillance programs. Businesses must document data protection assessments and make them available to the Attorney General on request.

Businesses must limit data collection to what is necessary in Louisiana, a data minimization principle that also applies in Vermont. If you already conduct data protection assessments for GDPR, the Colorado Privacy Act, or Connecticut, you can often adapt those documents to satisfy the requirements of Louisiana and Vermont, reducing duplication while staying aligned with comprehensive state privacy laws.

woman on desk

Enforcement, Penalties, and Cure Periods

In both Louisiana and Vermont, enforcement authority lies with the state Attorney General under each state’s consumer protection law and security act frameworks. Both states’ privacy laws are enforced by their respective Attorneys General with no private right of action for general violations.

Louisiana: The Louisiana Attorney General has exclusive enforcement authority. Violations of Louisiana’s law are treated as deceptive trade practices under Louisiana’s Unfair Trade Practices and Consumer Protection Law, with civil penalties that can reach $5,000 per violation. Louisiana’s law includes a 30-day notice-and-cure period. Louisiana provides a 30-day compliance cure period that ends on July 31, 2027. After that date, the AG can pursue enforcement without first offering a chance to cure.

Vermont: Vermont’s Attorney General also has exclusive enforcement authority for violations of the Vermont Consumer Protection Act and the Online Surveillance Act. No private right of action exists under Vermont’s law. Vermont’s law has a 60-day cure period for violations. Vermont offers a 60-day cure period that extends to June 30, 2029, after which the AG is no longer required to offer a cure opportunity.

The cure period should be treated as an opportunity to fix isolated issues, not a substitute for a full compliance program. Repeat or willful violations are unlikely to qualify for leniency. Enforcement models in Louisiana and Vermont resemble those in Nebraska, Oregon, and Connecticut, but contrast with California’s separate privacy protection agency and limited private right of action for security breaches. For a deeper look at how state privacy laws are being enforced in practice, it is worth reviewing recent actions by AGs.

Practical Compliance Steps for Online Businesses and Shopify Stores

Even small, remote-first brands can fall within scope if they have sufficient annual revenue or traffic from residents of Louisiana or Vermont. Here are the concrete steps to take now:

  1. Map personal data flows: Identify which consumers are residents of Louisiana or Vermont, what personal data you process from them, and how much sensitive data you handle. This determines whether you meet the applicability thresholds.
  2. Update your privacy notice: Ensure it covers categories of consumer data collected, purposes of processing, third-party disclosures, consumer rights, and any use of data for AI training. Vermont’s AI disclosure rules require specific language.
  3. Implement or refine cookie banners and consent management: Your cookie consent banner must block non-essential tracking scripts until valid consent is obtained and support opt-out of targeted advertising.
  4. Build consumer rights request workflows: Create processes to receive, authenticate, and respond to consumer requests within 45 days, including appeals handling.
  5. Review processor contracts: Ensure your agreements with ad networks, analytics vendors, and other processors include obligations to support compliance, limit data collection, and implement reasonable security measures, including physical data security practices.
  6. Conduct data protection assessments: For targeted advertising, sensitive data processing, and profiling, you must conduct data protection assessments and keep them available for AG review.

Tools like the Pandectes GDPR Compliance app for Shopify can help automate cookie consent, respect universal opt-out mechanisms, log consent history, and adapt banners based on user location, supporting LDPA, Vermont law, GDPR, CCPA, and LGPD from a single dashboard.

Businesses operating across multiple U.S. states should consider a harmonized baseline that meets the strictest requirements rather than maintaining fragmented, state-by-state privacy notices. Early planning and automation make multi-state compliance manageable, even for small teams.

Conclusion

Louisiana and Vermont’s data privacy laws mark important steps in the evolving U.S. privacy landscape, introducing robust consumer rights and business obligations. Businesses operating in these states must carefully assess applicability, update privacy practices, and implement compliance measures such as data protection assessments and consumer rights workflows. Leveraging tools like Pandectes can simplify adherence to these complex laws, helping businesses protect consumers’ personal data while maintaining trust and avoiding enforcement risks.

Ultimately, integrating technology solutions that support consent management, enable the deletion of personal data, and facilitate consumer rights requests can streamline compliance and foster consumer confidence in data-handling practices.

Make Your Shopify Store Fully GDPR & CCPA Compliant Today
Pandectes GDPR Compliance App for Shopify
Share
Subscribe to learn more
pandectes