Last updated: October 1, 2026
Virginia was the second US state to pass a comprehensive data privacy law. The Virginia Consumer Data Protection Act (VCDPA) took effect on January 1, 2023, and gives Virginia residents rights over the personal data that businesses collect about them.
This guide covers who the law applies to, what rights consumers get, what your business must do to comply, and what happens if you don't. Every legal detail below is checked against the current VCDPA statute text and the Virginia Attorney General's consumer protection office, not secondary summaries, so you can rely on it even if you've read older guides that are now out of date.
What is the Virginia Consumer Data Protection Act?
The VCDPA is Virginia's first comprehensive data privacy law. Governor Ralph Northam signed it on March 2, 2021, and it became enforceable on January 1, 2023.
Like most US state privacy laws, the VCDPA runs on an opt-out model. You can process a consumer's personal data by default. The consumer has to actively exercise a right to stop you, rather than you needing their upfront consent, except for sensitive data and processing involving children, which do require opt-in consent.
The VCDPA has been amended several times since 2021. The most consequential recent change is Senate Bill 338, which bans the sale of precise geolocation data starting July 1, 2026, making Virginia the third state with a geolocation-sale ban. A separate 2026 law restricting social media use by minors under 16 is currently tied up in federal litigation (NetChoice v. Jones) and is not fully in effect. If your business touches either geolocation data or minors' data, treat these as live compliance risks, not settled law.
Does the VCDPA apply to your business?
The VCDPA applies to any business that conducts business in Virginia, or targets products and services to Virginia residents, and meets at least one of these two thresholds during a calendar year:
- Controls or processes the personal data of 100,000 or more Virginia residents, or
- Controls or processes the personal data of 25,000 or more Virginia residents and derives more than 50% of gross revenue from selling personal data.
There's no revenue floor and no employee-count test, unlike California's CCPA. A small company can trigger the law purely through data volume.
Virginia's 25,000-consumer threshold is roughly in the middle of the pack among state privacy laws. Arkansas, for comparison, set its own threshold even lower at 25,000 consumers with no revenue test at all, which pulls in more mid-sized businesses than Virginia's law does.
Who is exempt from the VCDPA?
The law carves out full exemptions for:
- State and local government bodies
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Entities and business associates covered by HIPAA
- Nonprofit organizations
- Institutions of higher education
- Data governed by the Fair Credit Reporting Act (FCRA), to the extent it's FCRA-regulated data
The law also excludes employment-context data and de-identified or publicly available data from its definition of "personal data" entirely, so those categories sit outside its scope rather than being exempt as such.
What rights do Virginia consumers have?
Consumers covered by the VCDPA can:
- Confirm whether a business is processing their personal data
- Access the personal data a business holds about them
- Correct inaccuracies in that data
- Delete personal data a business holds about them
- Obtain a portable copy of their data in a usable format
- Opt out of three specific uses: targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects
Virginia does not grant a general right to opt out of all processing, only the three uses listed above. That's narrower than CCPA's opt-out scope and worth flagging to stakeholders who assume every state law works the same way.
How fast must you respond to a request?
Your business must respond within 45 days of receiving a verified request. If the request is unusually complex, you get one 45-day extension, which means 90 days total in the rare case you need it. You have to tell the consumer about the extension and explain why within the initial 45-day window; you can't just go silent and claim the extension later.
Responses must be free unless a request is excessive or clearly unfounded, in which case you can charge a reasonable fee or decline to act.
Do you need consent to process personal data?
Generally, no. The VCDPA's opt-out model means you can process ordinary personal data without asking first. You need affirmative opt-in consent in two situations:
- Sensitive data, including racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify someone, children's data, and precise geolocation data.
- Processing for a new purpose that wasn't disclosed in your privacy notice at the time you originally collected the data.
As of July 1, 2026, the sale of precise geolocation data is banned outright under SB 338, regardless of consent, so opt-in consent alone no longer covers that specific use.
What does a VCDPA-compliant privacy notice need?
Your privacy notice has to tell consumers, at minimum:
- The categories of personal data you process
- Your purposes for processing it
- How consumers can exercise their rights and appeal a denied request
- The categories of personal data you share with third parties, if any
- The categories of third parties you share data with, if any
- Whether you sell personal data or process it for targeted advertising
If you sell personal data or use it for targeted advertising or certain profiling, your notice must disclose that clearly and explain how to opt out.
When do you need a data protection assessment?
The VCDPA calls these data protection assessments (other states often call the same document a DPIA, data protection impact assessment, or PIA; they're functionally the same exercise). You're required to complete one before you:
- Process data for targeted advertising
- Sell personal data
- Use profiling that could lead to unfair treatment, financial or physical harm, reputational damage, or an unreasonable intrusion into someone's private affairs
- Process sensitive data
- Run any other processing activity that presents a heightened risk of harm to consumers
Outside those triggers, an assessment isn't legally required, but it's still good practice. If you've never built one, our free DPIA templates give you a working starting structure rather than a blank page.
The Attorney General can request your assessments as part of an investigation. Keep them current and keep them in writing.
Who enforces the VCDPA, and what are the penalties?
Only the Virginia Attorney General can enforce the VCDPA. Consumers have no private right of action, meaning an individual cannot sue your business directly over a VCDPA violation no matter how serious it is.
Before the AG can take action, they must give you 30 days' written notice identifying the specific violations. If you fix the problem within that window and confirm in writing that it's fixed and won't recur, the AG cannot proceed.
This 30-day cure period has no sunset date. That's a meaningful difference from several other state privacy laws (Colorado and Connecticut, for example, both had cure periods expire on a fixed schedule). Virginia's right to cure remains available indefinitely under the current statute, not just during an initial grace window after the law took effect.
If you don't cure the violation, the Attorney General can sue and seek civil penalties of up to $7,500 per violation, plus reasonable expenses and attorney's fees. Each affected consumer typically counts as a separate violation, so the exposure scales with how many people were affected, not just how many incidents occurred.
A correction worth making explicitly: you'll find a lot of guides online, including older versions of this one, citing a two-tier "$2,500 for unintentional violations, $7,500 for intentional violations" penalty structure. We checked the current statute directly (Va. Code § 59.1-584), and that two-tier figure does not appear in the text. The VCDPA sets a single civil penalty cap of up to $7,500 per violation, with no separate lower tier for unintentional conduct. That $2,500/$7,500 split is a real number, but it belongs to California's CCPA, not Virginia's law, and it appears to have been carried over by mistake across a lot of secondary sources.
How does the VCDPA compare to other state privacy laws?
The VCDPA shares its basic structure, opt-out processing, a consumer rights list, and AG-only enforcement, with most other US state privacy laws, including Colorado's and Utah's. Where it differs most is in the details: its 25,000-consumer threshold sits in the middle of the field, its cure period is permanent rather than time-limited, and its penalty structure is a flat $7,500 cap rather than a tiered one.
| Feature | Virginia (VCDPA) | California (CCPA) |
|---|---|---|
| Lower consumer threshold | 25,000 + 50% revenue from sale | No consumer-count threshold; revenue/volume based |
| Private right of action | No | Yes, limited to certain data breaches |
| Cure period | Permanent, 30 days | None (as of 2023 CPRA amendments) |
| Civil penalty | Up to $7,500 flat | $2,500 / $7,500 tiered |
| Opt-out scope | Targeted ads, sale, profiling | Sale/share, targeted advertising, and more |
If you operate across multiple states, our Colorado Privacy Act compliance guide and Utah Consumer Privacy Act overview walk through the same categories for those laws, so you can line them up side by side against the table above.
How to prepare your business for VCDPA compliance
- Map your data. Identify every system that touches Virginia residents' personal data, and confirm whether you cross either applicability threshold.
- Audit your vendors. Under the VCDPA, you're typically the "controller" and tools like your CRM, ad platforms, and analytics providers are "processors." You need a written data processing agreement with each one.
- Update your privacy notice to cover the disclosures listed above, including whether you sell data or use it for targeted advertising.
- Build (or confirm) your consumer rights workflow, so access, correction, deletion, and opt-out requests get verified and answered inside the 45-day window.
- Run data protection assessments for targeted advertising, sales, profiling, and sensitive-data processing before you start those activities, not after.
- Minimize what you collect. The less personal data you hold, the smaller your exposure if a request, an audit, or a breach happens.
A consent management platform can handle the opt-out signal capture and the privacy notice disclosures described above, but the vendor audits and data protection assessments still need a person who owns them internally.
Frequently asked questions
Does the VCDPA require opt-in consent for all data processing?
No. Ordinary personal data can be processed on an opt-out basis. Opt-in consent is required only for sensitive data categories, processing children's data, and using data for a new purpose not disclosed at collection.
Can a Virginia resident sue a business directly under the VCDPA?
No. The VCDPA has no private right of action. Only the Virginia Attorney General can bring an enforcement action.
Is there still a chance to fix a violation before being fined?
Yes. The Attorney General must give 30 days' written notice before pursuing penalties, and this cure period has no expiration date under the current statute, unlike some other states where the cure period has already sunset.
What's the maximum fine under the VCDPA?
Up to $7,500 per violation, as set out in Va. Code § 59.1-584. There is no separate, lower $2,500 tier in the current law, despite that figure circulating widely online.
Does the VCDPA cover employee data?
No. Personal data processed in the employment context falls outside the VCDPA's definition of "consumer," so HR and employee records aren't covered by this particular law.
How does the VCDPA treat the sale of geolocation data?
As of July 1, 2026, selling precise geolocation data is banned outright under SB 338, separate from and in addition to the general opt-out right for data sales.
This article reflects the VCDPA as currently codified at Va. Code Title 59.1, Chapter 53 and public guidance from the Office of the Virginia Attorney General, current as of October 2026. It does not constitute legal advice.


