US Privacy Law Virginia, USA

Virginia VCDPA: Consumer Data Protection Act Guide

Virginia's VCDPA explained: thresholds, consumer rights, sensitive-data consent, data protection assessments, the permanent cure period, and AG enforcement.

Regulation

Virginia Consumer Data Protection Act, Va. Code 59.1-575 et seq., effective January 1, 2023

Max Penalty

Up to $7,500 per violation, plus injunctive relief and attorney fees

Enforcing Authority

Virginia Attorney General

Official Source

www.oag.state.va.us

Executive Summary

  • The VCDPA (effective January 1, 2023) was the second comprehensive state privacy law and the template most states copied: controller/processor architecture, rights with opt-outs, sensitive-data consent, and assessments.
  • It applies to businesses controlling or processing personal data of 100,000+ Virginia consumers annually, or 25,000+ with over 50% of gross revenue from selling personal data; there is no revenue-only trigger.
  • Consumers hold rights to access, correct, delete, portability, and to opt out of targeted advertising, sale, and significant-decision profiling; sensitive data requires opt-in consent.
  • Virginia is comparatively business-friendly: a permanent 30-day cure period, entity-level HIPAA/GLBA exemptions, no universal opt-out mandate, and employment/B2B data excluded.
  • Enforcement is exclusive to the Attorney General at up to $7,500 per violation; there is no private right of action, and amendments have stayed narrow (minors' provisions and reproductive-health protections added through 2024-2025).

Virginia wrote the compromise that became the American default: GDPR’s vocabulary (controllers, processors, assessments) with business-calming edits, monetary-only “sale,” entity-level exemptions, a permanent cure period, and no private right of action. A dozen states copied it nearly clause-for-clause, which gives VCDPA compliance outsized leverage: build here, adjust for Colorado’s stricter rules, and the lineage states mostly inherit.

LawVCDPA, Va. Code 59.1-575 et seq.
EffectiveJanuary 1, 2023
Max penalty$7,500 per violation; permanent 30-day cure
RegulatorVirginia AG
StatuteVa. Code 59.1-575 et seq.

Compliance essentials

Rights handling on the Virginia clock. 45 days to respond (one 45-day extension), free twice annually per consumer, with a mandatory appeal process: denials must offer an internal appeal, and appeal denials must point consumers to the AG’s complaint portal, a distinctive VCDPA artifact most multistate DSAR platforms now template. See the unified intake guide.

Opt-out surface without UOOM. Targeted advertising, sale, and profiling opt-outs must be offered, but Virginia never mandated universal signals. Most controllers honor GPC anyway for the states that do; treating Virginia as the floor and Colorado as the spec avoids gating logic.

Consent for sensitive data. The opt-in duty arrived before most companies’ consent tooling did; health inference, precise location, and biometric identifiers are the usual unlicensed processing found in audits. Note the 1,750-foot geolocation radius (California uses 1,850 feet), an SDK-level configuration detail.

Processor contracts. Va. Code 59.1-579 requires processing contracts with confidentiality, deletion/return, sub-processor flow-down, and audit cooperation terms, GDPR Article 28’s shape, satisfiable by the same DPA that papers CCPA service providers.

Assessments filed nowhere, ready always. Unlike California’s submission regime, Virginia assessments live in your drawer until a civil investigative demand; the state assessment matrix shows how one document serves all.

For where Virginia sits against its stricter siblings, Colorado, Connecticut, Texas, see the state comparison. And check the observable basics, trackers, targeted-ad flows, notice accuracy, with a free scan.

Frequently Asked Questions

Who must comply with the VCDPA?

Persons that conduct business in Virginia or target Virginia residents and during a calendar year control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data. 'Consumer' excludes people acting in commercial or employment contexts, so B2B and HR data are out. Entity-level exemptions cover financial institutions subject to GLBA, HIPAA covered entities and business associates, nonprofits, and higher education.

What is 'sale' under Virginia law, and why does it matter?

Narrower than California: sale means exchange of personal data for monetary consideration only. Sharing data with ad platforms without payment is not a 'sale,' but it usually is 'targeted advertising,' which carries its own opt-out. The practical difference shows up in disclosures and in the 25,000-consumer threshold (which turns on revenue from sales strictly defined).

What does the sensitive-data consent duty require?

Opt-in consent before processing sensitive data: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data for identification, personal data of a known child, and precise geolocation (within 1,750 feet). Consent must be a clear affirmative act; for children's data, COPPA-compliant parental consent suffices. A 2023 amendment layered additional limits on reproductive and sexual health data.

How does the 30-day cure period work?

Before initiating an action, the AG must give written notice and 30 days to cure; if the controller cures and provides an express written statement that the violation will not recur, no action proceeds. Unlike Colorado, Connecticut, and California, Virginia's cure right never sunsets, which materially lowers first-strike enforcement risk, though repeat or uncured violations expose the full $7,500 per violation plus injunctions.

What are data protection assessments and when are they required?

Documented assessments weighing benefits against risks (with mitigations) for: targeted advertising, sale, significant-decision profiling with specified risks, sensitive-data processing, and any processing presenting a heightened risk of harm. The AG can obtain them via civil investigative demand, and they are confidential and privileged in the AG's hands. One assessment set shared with Colorado/California obligations is the efficient build.

Regulatory Crosswalk

Colorado CPAConnecticut CTDPACCPAGDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.