Key Takeaways
- VCDPA runs on an opt-out model, not opt-in. You don't need consent before setting most cookies; you need a clear way for visitors to opt out of targeted advertising, data sales, and profiling.
- Explicit, opt-in consent is only required in three situations: processing sensitive personal data, processing a known child's data, or using data for a new purpose beyond what you originally disclosed.
- VCDPA's "sale" definition covers only an exchange for monetary consideration. That's narrower than CCPA, Colorado, and Connecticut, which also count non-cash "valuable consideration."
- VCDPA does not require recognizing Global Privacy Control or any other universal opt-out signal, unlike California, Colorado, and Connecticut.
- Violations can cost up to $7,500 per violation, and Virginia's 30-day cure period, unlike Colorado's and Connecticut's, has no expiration date.
The Virginia Consumer Data Protection Act (VCDPA) took effect January 1, 2023, making Virginia the second US state with a comprehensive privacy law. Its cookie and tracking requirements diverge from GDPR's opt-in model and don't map cleanly onto CCPA's either, so treating VCDPA as "just like the other laws" is a common way to get it wrong.
This guide covers what VCDPA actually requires for cookies specifically: when you need consent, what counts as a "sale" in an ad-tech context, how opt-out rights apply to your banner, and what enforcement looks like.
Secure Privacy is a cookie and consent management platform generating VCDPA-compliant banners alongside CCPA, Colorado, Connecticut, GDPR, and 55+ other privacy frameworks.
Does VCDPA Apply to Your Website?
VCDPA applies if you conduct business in Virginia or target Virginia residents, and you meet either threshold during a calendar year: you control or process the personal data of 100,000 or more Virginia consumers, or you control or process the personal data of 25,000 or more Virginia consumers and derive more than 50% of your gross revenue from selling personal data. Unlike some other state laws, VCDPA sets no separate flat revenue-dollar threshold; meeting either condition above is enough on its own.
VCDPA exempts state government entities, nonprofits, and higher-education institutions, along with data already regulated under sector-specific federal laws like HIPAA, GLBA, and FCRA. Data handled in an employment or B2B context also falls outside VCDPA's definition of "consumer," which covers only a Virginia resident acting in an individual or household context.
When Do You Actually Need Cookie Consent Under VCDPA?
By default, you don't. VCDPA runs on an opt-out model: you can process personal data, including through cookies, without asking permission first, as long as you give consumers a clear way to opt out afterward. That's a meaningfully different starting point than GDPR, which requires opt-in consent before most cookies load.
Three situations flip this default and require upfront, opt-in consent instead: processing sensitive personal data, processing a known child's personal data, or using previously collected data for a new or unrelated purpose. Each is covered below. Outside those three cases, your banner's job is to disclose what you're doing and make opting out easy, not to gate every cookie behind a consent screen.
Where consent is required, VCDPA defines it precisely: "a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data... Consent may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action." On a banner, that means an "Accept" click is valid consent; scrolling, closing the banner, or taking no action is not. Cookies subject to a consent requirement must not load until that affirmative click happens.
What Counts as a "Sale" of Data Under VCDPA (and Why It Matters for Cookies)
This is the part most cookie compliance guides skip, and it changes how you should think about ad-tech and tracking pixels specifically.
VCDPA defines "sale of personal data" as the exchange of personal data for monetary consideration by the controller to a third party. That's it. Unlike CCPA, Colorado's CPA, and Connecticut's CTDPA, VCDPA does not extend "sale" to cover exchanges for other valuable, non-cash consideration.
In practice: if you share visitor data with an ad-tech partner and get paid cash for it, that's a sale under VCDPA and triggers the sale opt-out below. Share the same data for free analytics or reciprocal audience data instead, common in programmatic advertising, and it may not count as a "sale" in Virginia even though the same arrangement likely would in California or Colorado. That data sharing is still regulated processing though: it still belongs in your privacy notice, and if it feeds targeted advertising or profiling, the opt-out rights below still apply regardless of payment.
Opt-Out Rights: Targeted Advertising, Sale, and Profiling
VCDPA gives consumers the right to opt out of three specific kinds of processing:
- Targeted advertising, meaning ads selected based on data about the consumer's activity across unaffiliated websites or apps over time. Ads based on a consumer's current visit or activity within your own site or app don't count as targeted advertising under VCDPA.
- Sale of personal data, as defined above.
- Profiling that produces legal or similarly significant effects, decisions about credit, housing, employment, insurance, healthcare, or similar consequential outcomes made through automated processing.
For a cookie banner, this means your "reject" or "manage preferences" flow needs to actually stop the specific cookies tied to these three purposes once a visitor opts out, not just log the preference. Respond to opt-out requests without undue delay, within 45 days at the latest.
Does VCDPA Require Recognizing Global Privacy Control (GPC)?
No, and this is worth stating plainly since it's a frequent source of confusion. California, Colorado, and Connecticut all require honoring Global Privacy Control or another qualifying universal opt-out signal as a valid opt-out request. VCDPA does not; Virginia's statute contains no universal-opt-out-mechanism language, and no amendment adding one has been enacted.
If your banner already recognizes GPC for CCPA, Colorado, or Connecticut compliance, there's no harm extending that to Virginia visitors too. But building VCDPA compliance alone, a working manual "reject" button is enough; automatic GPC recognition isn't a legal requirement under this law today.
Consent for Children's Personal Data
If you knowingly collect personal data from a child under 13, you need verifiable parental consent before processing it. VCDPA doesn't spell out its own verification methods; it points instead to the methods already approved under the Children's Online Privacy Protection Act (COPPA): a signed consent form returned by mail, fax, or electronic scan; verification through a payment method like a credit card, with a nominal charge that can be refunded or waived; a video conference call confirming the parent's identity; or a government-issued ID submitted alongside a signed consent form. Once a consumer turns 13, VCDPA's child-specific rules no longer apply.
Consent for Sensitive Personal Data
VCDPA treats the following as sensitive personal data, requiring opt-in consent before processing: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, or citizenship/immigration status; genetic or biometric data used to uniquely identify a person; personal data collected from a known child; and precise geolocation data.
For cookies specifically, this category most often comes up with precise geolocation tracking and known-child data. If a cookie or SDK collects either, get explicit, opt-in consent through your banner or a dedicated prompt before it fires, not just a disclosure the visitor can ignore.
Consent for New or Unrelated Purposes
If you collect data for one stated purpose and later want to use it for something else, for example, using fitness-app data collected for service delivery to build ad-targeting profiles instead, that new use requires fresh, opt-in consent. Same if you ask for data beyond what a product actually needs: without consent, you can't collect that extra data at all.
Privacy Notice and Data Protection Assessments
Because most VCDPA consent has to be "informed," your privacy notice is what makes consent valid. It needs to disclose the categories of personal data you collect, the purpose for each, and the categories of third parties data is shared with. You can only process data for purposes outside your notice if you get separate consent for that new purpose, and you should review and update it whenever your actual data practices change.
Because sensitive-data and children's-data processing both require consent, VCDPA also expects a data protection assessment before undertaking that processing: weigh the benefits against the risks to the consumer, confirm the processing is genuinely necessary, and document the safeguards in place (encryption, access controls, data minimization). Keep these on file; the Attorney General can request them during an investigation.
Beyond opting out, Virginia consumers can also request to know what categories of their data you've collected, request deletion of data collected with their consent, and request proof that they gave consent, timestamped banner logs work for this. Respond to all of these within VCDPA's 45-day window.
Compliance Checklist for Your Cookie Banner
- Default to opt-out for standard processing; reserve pre-consent gating for sensitive data, children's data, and new-purpose processing.
- Make "Accept" and "Reject" equally accessible; don't require more clicks to opt out than to opt in.
- Stop the actual cookies tied to targeted advertising, sale, and consequential profiling the moment a visitor opts out, not just on the next page load.
- Check each ad-tech integration against VCDPA's monetary-consideration "sale" definition before assuming it needs the sale opt-out.
- Gate any cookie or SDK collecting precise geolocation or known-child data behind explicit consent.
- Keep your privacy notice current with what your cookies actually collect and share.
- Store consent records (timestamp, banner version, choice made) so you can answer a proof-of-consent request.
- Respond to opt-out and access requests within 45 days.
A consent management platform that already separates these rules by law, rather than applying one universal opt-in flow to every visitor, closes most of this checklist without a manual rebuild for Virginia specifically.
Penalties for Non-Compliance
The Virginia Attorney General is the only enforcer; VCDPA has no private right of action, so consumers can't sue directly. Enforcement carries real weight: civil penalties of up to $7,500 per violation, with no separate lower tier for unintentional violations, plus injunctive relief through state court. At scale the penalties add up fast: 100 violations could reach $750,000, and 1,000 could reach $7.5 million.
Before filing suit, the Attorney General must give 30 days' written notice of the specific violations. Fix them in that window and confirm in writing they're cured and won't recur, and no action follows. That cure period has no sunset date, unlike Colorado's (expired January 1, 2025) and Connecticut's (expired January 1, 2024).
FAQ
Does VCDPA require cookie consent by default?
No. VCDPA runs on an opt-out model. You can process data through cookies without upfront consent unless you're processing sensitive data, a known child's data, or using data for a new purpose beyond what you disclosed.
What's the actual VCDPA penalty for a cookie compliance violation?
Up to $7,500 per violation, a single figure with no separate lower tier. There's no accurate "$2,500 unintentional / $7,500 intentional" split under VCDPA; that structure belongs to CCPA, not Virginia's law.
Does sharing cookie data with an ad-tech partner count as a "sale" under VCDPA?
Only if you receive monetary consideration for it. VCDPA's sale definition is limited to cash exchanges, unlike CCPA, Colorado, and Connecticut, which also count non-monetary "valuable consideration." A data-sharing arrangement paid in services rather than cash may not trigger VCDPA's sale opt-out even if it would under those other laws.
Do I need to honor Global Privacy Control (GPC) signals under VCDPA?
No. Unlike California, Colorado, and Connecticut, VCDPA does not require recognizing GPC or any other universal opt-out signal. A working manual opt-out option in your banner satisfies the law.
How long does Virginia give me to fix a violation before enforcement?
30 days from the Attorney General's written notice, and this cure period has no expiration date, unlike Colorado's and Connecticut's, both already sunset.
What personal information counts as "sensitive" for cookie consent purposes?
Data revealing racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, or immigration status; genetic or biometric identification data; a known child's data; and precise geolocation data. Any cookie or SDK collecting these needs opt-in consent first.



