Two state privacy laws arrived within three weeks of each other this summer — Louisiana's LDPA in late May, and Vermont's on June 16, when Governor Phil Scott signed the Data Privacy and Online Surveillance Act. Louisiana's is a solid, conventional privacy law. Vermont's is something else: the name alone — Online Surveillance Act — tells you which problem its drafters were aiming at.
Why this one is different
Most state privacy laws are cousins of the same template: rights to access, correct, delete and port your data; opt-outs for ads and sales; opt-in for a narrow list of "sensitive" categories. The VDPOSA includes all of that — access (including inferences drawn about you), correction, deletion, portability, opt-outs, authorized agents, 45-day response windows.
But it departs from the template in three places that matter enormously for facial privacy: how it defines biometric data, what it makes companies say about AI training, and who it applies to. Each deserves its own section.
The biometric definition — the loophole, closed
Nearly every biometric privacy law in America shares the same quiet limitation: it protects biometric data processed for the purpose of uniquely identifying a person. That purpose clause is a loophole you can drive a scraper through. A company can collect face data and argue it isn't "identifying" anyone — it's just analyzing demographics, or measuring engagement, or, in a framing that made headlines, studying "bone structure" rather than identity.
Vermont deletes the loophole. Under the VDPOSA, biometric data is protected regardless of the purpose it's collected or used for. If it's biometric, it's sensitive; if it's sensitive, processing requires explicit opt-in consent, and selling it without that consent is off the table. The law extends the same treatment to neural data — information generated by measuring the activity of your central nervous system — making Vermont one of only a handful of states to see that category coming.
The AI-training disclosure — a window into the black box
The VDPOSA's most novel requirement: covered businesses must disclose in their privacy policy whether personal data is collected, used, or sold for training large language models or AI — with the policy's last-updated date shown, and the disclosure accessible from mobile app settings, not buried three links deep.
We wrote recently about the difference between being indexed by a face-search engine and being baked into a model's training data — and about how the training side is nearly impossible to act on individually, because you usually can't even find out whether your data was used. Vermont's answer is to attack the knowing problem: companies must say, in plain sight, whether that's what they're doing with your data. Disclosure isn't deletion. But you can't exercise a single right about AI training if nobody has to tell you it's happening — and Vermont just made them tell you.
Thresholds and teeth
Applicability thresholds are where privacy laws quietly go to die — set them high enough and most of the industry walks under them. Vermont set some of the lowest in the country:
Processing sensitive data — which includes biometrics — for just 3,000 Vermonters puts a business in scope. There's no blanket nonprofit exemption, and consumer-health-data handlers are covered at any size. Enforcement is exclusive to the Vermont Attorney General under the state's Consumer Protection Act, at up to $10,000 per violation — with each affected consumer counting as a separate violation. A 60-day cure period runs from January 1, 2028 through June 30, 2029, then expires.
What this means for your face
Face-search engines are, structurally, everything this law was written about: they collect biometric data from people who never opted in, at a scale that clears a 3,000-person threshold millions of times over. Vermont's purpose-blind biometric definition means the usual defenses — "we're not identifying anyone", "it's just analysis" — don't map onto the statute at all.
As with Louisiana, the honest caveat is that rights don't exercise themselves, and there's no private right of action — the practical path is filing requests, keeping the receipts, and escalating through the AG. That's the work we do daily: our removal requests cite the strongest applicable law for each person, and when the VDPOSA takes effect in January 2028, Vermonters' requests gain the broadest biometric backing any US state has written.
This article is general information, not legal advice. If you need advice about your specific situation, talk to a lawyer licensed in Vermont.
New laws. Same job: getting your face out.
FacePrivacy files removal requests with the major face-search engines, citing the privacy laws that apply to you — and keeps filing as stronger laws like the VDPOSA come online.
Protect your face →