The Consortium of Privacy Regulators has added a new member to its ranks. On Aug. 4, 2026, Vermont Attorney General Charity Clark announced that Vermont has joined the bipartisan coalition of state privacy regulators and attorneys general that works to coordinate the implementation and enforcement of state consumer privacy laws.

In a previous GT Alert, we covered the April 2025 launch of the Consortium. Vermont’s addition marks its latest expansion and reflects the continued trend toward coordinated multistate privacy enforcement.

Link to Vermont’s New Privacy Law and Enforcement Focus Vermont’s New Privacy Law and Enforcement Focus

Vermont’s participation in the Consortium follows the June 2026 enactment of the Vermont Data Privacy and Online Surveillance Act, the state’s comprehensive consumer privacy law, which is scheduled to take effect in 2028.

“Vermonters should not have to give up their privacy to participate in modern life,” Attorney General Clark said in a statement. “Whether we’re shopping online, using social media, or simply carrying a smartphone, companies are collecting enormous amounts of our personal information. Vermont’s new privacy law gives each of us greater control over corporate use of our data, and joining this Consortium will help my office work with other states to enforce those protections effectively and hold companies accountable when they violate the law.”

The announcement also emphasized Vermont’s prior success participating in multistate privacy and consumer protection matters, noting that collaborative efforts have secured more than $8 million in settlements for the state over the past five years while also producing improvements to companies’ privacy and data security practices.

“We welcome the opportunity to collaborate with the Green Mountain State as jurisdictions nationwide continue working together,” Michael Macko, head of enforcement at the California Privacy Protection Agency (CalPrivacy), said in a statement. “These partnerships benefit consumers and promote a predictable, rights-oriented enforcement landscape for businesses.”

“Big businesses are harnessing more and more data about us,” said Tom Kemp, CalPrivacy’s executive director. “Collaboration across states empowers consumers and leads to better privacy protections for everyone.”

Link to An Expanding Enforcement Coalition An Expanding Enforcement Coalition

Consortium members now include CalPrivacy and state attorneys general from California, Colorado, Connecticut, Delaware, Indiana, New Hampshire, New Jersey, Maryland, Minnesota, Oregon, and Vermont.

The Consortium’s continued expansion may suggest that regulators view coordinated enforcement as an increasingly important mechanism for addressing data practices and privacy violations, which often cross state lines.

While the Consortium itself does not publicly announce joint investigations as a matter of course, participating regulators have increasingly coordinated privacy enforcement efforts. One such example of coordinated enforcement by state attorneys general includes:

  • Global Privacy Control (GPC) Investigative Sweep (Sept. 9, 2025). A joint effort by CalPrivacy and the attorneys general for California, Colorado, and Connecticut, the sweep investigated businesses that allegedly failed to recognize or honor GPC opt-out signals and related consumer opt-out rights.

Link to Takeaways for Businesses Takeaways for Businesses

Vermont’s decision to join the Consortium of Privacy Regulators underscores the continued growth of coordinated state privacy enforcement. What began in 2025 as a coalition of eight privacy regulators has evolved into a broader network of states with comprehensive privacy laws and active enforcement programs.

As privacy enforcement becomes increasingly collaborative, businesses may see regulators continue to share expertise and coordinate enforcement priorities, particularly where data practices affect consumers across multiple jurisdictions. Consequently, privacy compliance gaps identified in one jurisdiction may draw attention from regulators in other states. Companies should consider evaluating their privacy compliance programs, consumer rights request processes, privacy notices, and data governance practices with a multistate enforcement environment in mind.

Photo of Timothy A. Butler Timothy A. Butler

Tim Butler helps companies thrive by developing tailored strategies to address their regulatory compliance challenges and vigorously defending them in government enforcement actions and bet-the-company lawsuits.

A former prosecuting attorney for the Federal Trade Commission (FTC) and former senior official in the Georgia…

Tim Butler helps companies thrive by developing tailored strategies to address their regulatory compliance challenges and vigorously defending them in government enforcement actions and bet-the-company lawsuits.

A former prosecuting attorney for the Federal Trade Commission (FTC) and former senior official in the Georgia Attorney General’s Office, Tim has led the defense of dozens of government investigations and enforcement actions brought by the FTC, the Consumer Financial Protection Bureau (CFPB), and the various state attorneys general. Tim also regularly defends clients in bet-the-company lawsuits, including complex business disputes and consumer class actions alleging privacy, false advertising, and unfair or deceptive business practice claims.

Tim is an experienced guide for companies struggling with regulatory complexity. He offers clear advice that helps his clients meet the demands of the ever-growing set of laws and regulations governing data privacy and cybersecurity, advertising and marketing practices, and consumer financial products and services. Clients rely on Tim’s business-minded and practical strategies to address their most difficult regulatory compliance challenges.

A graduate of the University of Chicago and Stanford Law School, Tim is a prolific author and regularly speaks to industry and trade groups about the evolving privacy landscape, about cutting-edge issues affecting payments and fintech companies, and about developments at the FTC, the CFPB, and within the state attorneys general community.

Photo of Matthew White Matthew White

Matt White guides clients through regulatory compliance challenges and represents clients in regulatory and civil investigations and litigation.

Matt has counseled fintech and payment companies on regulatory compliance matters, including those involving the Electronic Fund Transfer Act, the Fair Credit Reporting Act, the…

Matt White guides clients through regulatory compliance challenges and represents clients in regulatory and civil investigations and litigation.

Matt has counseled fintech and payment companies on regulatory compliance matters, including those involving the Electronic Fund Transfer Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the Truth in Lending Act, and their respective implementing regulations (Regulations E, V, P, and Z). Adept with the Consumer Financial Protection Bureau’s (CFPB) Prepaid Rule, Matt has provided guidance regarding prepaid cards and related compliance.

Matt has also aided clients in developing regulatory compliant products and functionalities, including an earned wage access program, reimbursement prepaid card programs, new merchant cash advance products, and tokenized payment capabilities. In connection with products on which Matt advises, he has also negotiated high-stakes technology sales agreements involving complex regulatory issues, including compliance with data privacy laws, financial regulations, and card network rules.

Beyond helping clients strategize for regulatory complexity, Matt also helps clients navigate government investigations and enforcement actions brought by the Federal Trade Commission (FTC), CFPB, and state attorneys general.

Photo of Cody B. Davis Cody B. Davis

Cody Davis advises clients on regulatory compliance, data privacy, and consumer protection matters within the financial technology sector, with a focus on payments, emerging platforms, and evolving regulatory frameworks. He works with companies navigating complex federal and state requirements, including regulatory compliance, government…

Cody Davis advises clients on regulatory compliance, data privacy, and consumer protection matters within the financial technology sector, with a focus on payments, emerging platforms, and evolving regulatory frameworks. He works with companies navigating complex federal and state requirements, including regulatory compliance, government investigations, and risk management across the fintech ecosystem.

Cody also has prior experience working with clients in the health care space on mergers and acquisitions as well as regulatory compliance with HIPAA, state telehealth rules, and facility licensure requirements.