Skip to content
DWT logo
People Services Insights
About Offices Careers
Search
People
Services
Insights
About
Offices
Careers
Search
State General Privacy Law Tracker

Virginia

  •  

Code/Regulations

  • Virginia Consumer Data Protection Act (VCDPA)
  • Code: Va. Code Ann §§ 59.1-575-584 (2023)

Effective Date: January 1, 2023

Details

Threshold

Conduct business or produce goods or services that are targeted to Virginia residents, and either:

  1. control or process personal data of more than 100,000 residents’ data per year; or
  2. derive over 50 percent of gross revenue from the sale of personal data of at least 25,000 residents

Definition of "Personal Data"

Any information that is linked or reasonably linkable to an identified or identifiable natural person. Does not include de-identified data or publicly available information. Personal data does not include data from people acting in an employment or commercial context.

Definition of "Sensitive Personal Data"

As with all state general privacy laws, includes the following Personal Data:

  • Race or ethnic origin;
  • Religious beliefs;
  • Citizenship or immigration status;
  • Genetic data;
  • Biometric data;
  • Mental or physical diagnosis; and
  • Sexual orientation.

In addition, Virginia’s definition also includes:

  • Precise geolocation data; and
  • Personal data collected from a known child.

Definition of "Sale"

Exchange of personal data for monetary consideration by controller to third party

Data-Protection Assessments

Required for targeted advertising, sale, sensitive data, certain profiling

Opt-In Consent Required for Processing Sensitive Data 

Yes

Consumer Rights to Confirm Processing, Request Access, Correction, Deletion & Portability

Yes

Consumer Right to Opt Out of Sale

Yes

Consumer Right to Opt Out of Targeted Ads/Sharing

Yes

Consumer Right to Opt Out of Profiling

Yes

Pseudonymous Data Exempt from Consumer Requests

Yes

Appeal Rights

Yes

Universal Opt-Out Mechanism Required Recognition/Date

None

Data of Minors

Process sensitive data of a known child in accordance with COPPA

GLBA Exemption

Yes (entity-level)

HIPAA Exemption

Yes (entity-level)

Applies/Does Not Apply to Personal Information in a Commercial or Employment Context

Does not apply to commercial or employment context; applies in an individual or household context

Nonprofit Exemption

Yes

Private Right of Action

No

Cure Period

30 Days

Cure Period Expiration

None

Enforcement Authority/Damages

Attorney General/up to $7,500 per violation

Disclaimer: States may periodically amend their laws and regulations and such amendments may affect or modify certain legal requirements or compliance obligations. There is no guarantee that this research is up to date as laws and regulations in the state consumer data privacy space continue to evolve. You should consult an attorney to assess the applicability of any existing, new, or proposed state consumer data privacy laws. By accessing this site, you acknowledge your understanding that the underlying content is not a replacement for legal counsel and does not constitute legal advice. 

Searching...
phone with green computer code and security warning
05.31.24
Insights
State Privacy Laws
Heightened Privacy Protections for Children in Virginia Read More
Keyboard close up
02.22.21
Insights
State Privacy Laws
Virginia Poised to Enact Comprehensive Consumer Privacy Law Read More
Your search returned no results. Please try another search or remove search criteria.
DWT logo
©1996-2025 Davis Wright Tremaine LLP. ALL RIGHTS RESERVED. Attorney Advertising. Not intended as legal advice. Prior results do not guarantee a similar outcome.
Media Kit Affiliations Legal notices
Privacy policy Employees DWT Collaborate EEO

SUBSCRIBE
©1996-2025 Davis Wright Tremaine LLP. ALL RIGHTS RESERVED. Attorney Advertising. Not intended as legal advice. Prior results do not guarantee a similar outcome.