Virginia Consumer Data Protection Act (VCDPA)
· About Virginia Consumer Data Protection Act (VCDPA)
Key Takeaways
- The Virginia Consumer Data Protection Act (VCDPA) applies to qualifying controllers and processors handling personal data of Virginia consumers and has been in force since 1 January 2023.[4][8]
- The Act is enforced by the Virginia Attorney General, and private rights of action are not provided; enforcement is through civil investigation and penalties under the Attorney General’s authority.[4][8]
- A 2026 amendment prohibits controllers from selling or offering to sell precise geolocation data concerning a consumer, effective 1 July 2026.[4][8]
- The VCDPA generally applies only to entities that control or process data of 100,000 or more consumers in a calendar year, or 25,000 or more consumers if at least 50% of gross revenue comes from the sale of personal data.[4]
- Covered businesses must provide consumer rights, data minimization, purpose limitation, data protection assessments for certain processing, and reasonable security practices.[4][8]
- Civil penalties can reach $7,500 per violation, and the Attorney General may seek injunctive relief and recover investigative costs.[4][8]
What It Is
The VCDPA is Virginia’s comprehensive privacy law governing the processing of personal data of Virginia residents acting in an individual or household context, with separate definitions for controller, processor, consumer, personal data, and sensitive data.[4][8] It is codified in Virginia Code Chapter 53 and enforced by the Virginia Attorney General.[4][8]
The core Act was adopted by the Virginia General Assembly in 2021, signed into law the same year, and became effective on 1 January 2023.[4][8] Virginia later amended the statute in 2026 to add a prohibition on selling precise geolocation data, effective 1 July 2026.[4][8]
The VCDPA also has key implementation dates tied to compliance obligations rather than a phased regulator rulemaking regime; the statute’s operative obligations became enforceable when the law took effect on 1 January 2023, and the geolocation sale ban separately began on 1 July 2026.[4][8]
Who Must Comply
The VCDPA applies to controllers and processors that conduct business in Virginia or produce products or services targeted to Virginia residents, and that meet the statutory thresholds.[4] A controller or processor is covered if it controls or processes personal data of 100,000 consumers during a calendar year, or if it controls or processes personal data of 25,000 consumers and derives more than 50% of gross revenue from the sale of personal data.[4]
The law has extraterritorial reach because it applies based on the volume of Virginia consumer data processed and business targeting, not merely physical presence in Virginia.[4] In practice, an out-of-state company can be covered if it meets the thresholds and targets Virginia consumers.[4]
The statute excludes certain organizations and data types, including data governed by federal regimes such as HIPAA, GLBA, FCRA, and certain nonprofit activities, and it does not apply to governmental entities.[4] It also contains entity and data-level carve-outs for specified operational contexts and anonymized data.[4]
Core Requirements
- Provide consumer rights. Controllers must offer rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale of personal data, and certain profiling decisions.[4][8]
- Limit collection and use. Controllers must limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes and may not process personal data for purposes incompatible with those disclosed absent notice and consent.[4]
- Handle sensitive data with consent. Controllers must obtain consumer consent before processing sensitive data, and for known children the law imposes tighter rules for precise geolocation collection.[4]
- Maintain reasonable security. Controllers must implement, and processors must follow, reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data.[4][8]
- Conduct data protection assessments. Controllers must assess processing activities that present heightened risk, including targeted advertising, sale of personal data, profiling, sensitive data processing, and certain uses involving de-identified data.[4]
- Enter processor contracts. Controllers must use contracts that govern processing instructions, confidentiality, security, subcontracting, and deletion/return obligations.[4]
- Stop selling precise geolocation data. From 1 July 2026, controllers may not sell or offer to sell precise geolocation data concerning a consumer.[4][8]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Core VCDPA effective date | 1 January 2023 | General controller and processor obligations became enforceable.[4][8] | | Precise geolocation sale ban effective | 1 July 2026 | Controllers may not sell or offer to sell precise geolocation data concerning a consumer.[4][8] |
The maximum civil penalty under the VCDPA is $7,500 per violation.[4][8] The Attorney General may also seek injunctive relief and recover reasonable expenses incurred in investigating and preparing the case, including attorney’s fees.[4][8] The statute does not create a private right of action.[4][8]
How to Comply
- Map data and roles. Identify whether the organization is a controller, processor, or both, and document data flows for Virginia consumers.
- Check thresholds annually. Verify whether the organization meets the 100,000-consumer or 25,000-consumer-plus-revenue threshold and whether any exemptions apply.
- Classify personal and sensitive data. Build a current data inventory that distinguishes personal data, sensitive data, and precise geolocation data.
- Update notices and rights handling. Publish a compliant privacy notice and operationalize intake for access, correction, deletion, portability, and opt-out requests.
- Implement security controls. Use a control framework aligned with ISO 27001 and NIST CSF 2.0 for governance, access control, logging, incident response, and vendor management.
- Run data protection assessments. Document assessments for targeted advertising, profiling, sensitive data processing, and any activity that may now involve precise geolocation data.
- Fix vendor contracts. Ensure processor agreements cover instructions, confidentiality, security, subcontractor controls, deletion, and audit/support commitments.
- Align AI and privacy governance. Where personal data supports automated decision-making or model training, align governance to ISO 42001 for lifecycle controls and accountability, then reconcile with VCDPA notices and opt-out rights.
Related Regulations
- Virginia Online Safety and Age-Appropriate Design Code Act: This law focuses on online service design and child safety, so companies subject to both regimes should coordinate notices, age-related controls, and data minimization.
- Colorado Privacy Act: Colorado’s privacy law is structurally similar, but state-by-state differences in opt-out mechanics and profiling rules can create multi-state compliance divergence.
- Connecticut Data Privacy Act: Connecticut’s law overlaps heavily with VCDPA obligations, yet its definitions and enforcement expectations differ enough to require jurisdiction-specific mapping.
- California Consumer Privacy Act / CPRA: California is broader in several respects, especially around household data and statutory rights architecture, so Virginia compliance should not be treated as a substitute.
- Virginia consumer protection and data breach laws: Breach notification and unfair trade practice risks can arise alongside VCDPA violations, especially if privacy disclosures are inaccurate or security controls are weak.
FAQ
Does the VCDPA apply to companies outside Virginia?
Yes, if the company targets Virginia residents and meets the statutory volume or revenue thresholds.[4] Physical presence in Virginia is not required for coverage.[4] A company with out-of-state headquarters can still be a covered controller or processor if its Virginia consumer data footprint is large enough.[4]
Does the law ban all geolocation data sales?
No. The 2026 amendment bans the sale or offering for sale of precise geolocation data only, not all forms of location data.[4][8] The statutory definition is location information that directly identifies a person within a radius of 1,750 feet.[4] More general or aggregated location data is not within that definition, although other VCDPA duties may still apply.[4]
Is consent always required to process sensitive data?
Yes, the VCDPA requires consumer consent before a controller processes sensitive data.[4] The rule is separate from ordinary consumer opt-outs and applies because sensitive data is treated as higher-risk processing.[4] Known-child precise geolocation collection is subject to additional conditions.[4]
Does the VCDPA give consumers a private right to sue?
No. Enforcement is reserved to the Virginia Attorney General.[4][8] Consumers generally cannot sue directly under the VCDPA itself, although other legal theories may still exist under different laws.[4][8] Civil penalties and injunctive relief can still be significant.[4][8]
When did the geolocation amendment take effect?
The precise geolocation sale ban became effective on 1 July 2026.[4][8] That date matters for sales, vendor arrangements, and ad-tech or location-based analytics programs involving Virginia consumers.[4][8] Organizations should also review any contracts signed before that date to ensure no post-effective-date prohibited sale continues.[4][8]
Sources
- Virginia Code, Chapter 53. Consumer Data Protection Act
- Virginia Code, Chapter 53. Consumer Data Protection Act (current chapter page)
- Virginia Attorney General, VCDPA FAQ Update 7.2026
- Consumer Reports, Virginia governor signs location privacy amendment
- Sheppard Mullin, Virginia tightens rules on monetizing precise geolocation data
- DataGuidance, Virginia: Consumer Data Protection Act amended to prohibit sale of precise geolocation data
- Privacy Rights Clearinghouse, Virginia Consumer Data Protection Act overview
- NIST Cybersecurity Framework 2.0
- ISO/IEC 27001 overview
- ISO/IEC 42001 overview
Put it into practice
- Generate the policy: Virginia CDPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)