Virginia
Virginia Data Privacy Laws: VCDPA Consumer Rights Guide (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 10 primary sources cited on this page. How we verify our legal content

Virginia's Consumer Data Protection Act (VCDPA), codified at Va. Code Ann. sections 59.1-575 through 59.1-584, took effect January 1, 2023, making Virginia the second state to enact a comprehensive consumer data privacy law. The VCDPA gives residents rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, data sales, and profiling. Enforcement rests exclusively with the Virginia Attorney General, with no private right of action under the core statute.
Since its 2021 passage, the Virginia General Assembly has amended the VCDPA to add children's data protections, clarify nonprofit exemptions, and modify consumer rights. A July 2025 law added separate privacy protections for reproductive and sexual health information. A 2025 social media time-limit law for minors took effect January 1, 2026 but was blocked by a federal preliminary injunction on February 27, 2026. This guide covers Virginia's full data privacy framework as it stands in 2026.
What Is the Virginia Consumer Data Protection Act (VCDPA)?
The VCDPA is Virginia's comprehensive consumer data privacy law. Governor Ralph Northam signed it on March 2, 2021, and it became effective on January 1, 2023. The law is codified at Va. Code Title 59.1, Chapter 53.
The VCDPA gives Virginia consumers specific rights over their personal data and imposes obligations on businesses that collect and process consumer data. The Virginia Attorney General's office has published a consumer summary explaining the law's key provisions.
Unlike California's privacy law, the VCDPA does not create a private right of action for core violations. Only the Virginia Attorney General can enforce the main statute. This distinction matters for both consumers and businesses operating in Virginia.

Key Definitions Under the VCDPA
The VCDPA defines several important terms that determine how the law applies. Under Va. Code 59.1-575, the key definitions include:
Personal data means any information that is linked or reasonably linkable to an identified or identifiable natural person. This does not include de-identified data or publicly available information.
Sensitive data receives heightened protection under the law. It includes data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data used for identification purposes, personal data from a known child, and precise geolocation data.
Consumer means a natural person who is a Virginia resident acting in an individual or household context. The definition excludes people acting in a commercial or employment context.
Controller means the natural or legal person that determines the purposes and means of processing personal data. A processor means an entity that processes personal data on behalf of a controller.
Biometric data means data generated by automatic measurements of biological characteristics, such as fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns used to identify a specific individual. Digital photographs, video or audio recordings, and HIPAA-covered health care data are excluded from this definition.
Precise geolocation data means information that directly identifies the specific location of a natural person with precision and accuracy within a radius of 1,750 feet.
Who Must Comply with the VCDPA?
The VCDPA applies to entities that conduct business in Virginia or produce products or services targeted to Virginia residents and meet one of two thresholds under Va. Code 59.1-576:
- Control or process the personal data of at least 100,000 Virginia consumers during a calendar year, OR
- Control or process the personal data of at least 25,000 Virginia consumers AND derive over 50% of gross revenue from the sale of personal data.
Unlike some state privacy laws, the VCDPA has no revenue-only threshold. A large retailer with high revenue but few Virginia consumers may not be covered. A data broker with modest revenue but significant data volumes likely is covered.
Who Is Exempt from the VCDPA?
The following entities are not subject to the VCDPA:
- Virginia state agencies and political subdivisions
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Entities covered by the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH)
- Nonprofit organizations (including political organizations and certain 501(c)(4) entities, per 2022 amendments by SB 534 and HB 714)
- Institutions of higher education
Certain data categories are also exempt regardless of who holds them. These include data regulated under the Fair Credit Reporting Act (FCRA), the Driver's Privacy Protection Act, the Family Educational Rights and Privacy Act (FERPA), and data processed for employment purposes.
Consumer Rights Under the VCDPA
The VCDPA grants Virginia consumers five core privacy rights under Va. Code 59.1-577. These rights allow consumers to maintain control over how their personal data is collected, used, and shared.
Right to Access and Confirm
Consumers have the right to confirm whether a controller is processing their personal data. If the controller is processing such data, the consumer has the right to access that data.
Right to Correct
Consumers can request that a controller correct inaccuracies in their personal data. The controller must consider the nature of the personal data and the purposes of the processing when responding to correction requests.
Right to Delete
Consumers may request the deletion of personal data that the controller holds about them. This right applies to data the consumer provided directly and to data the controller obtained from other sources.
Under a 2022 amendment (HB 381), controllers that obtained personal data from sources other than the consumer may satisfy a deletion request by either maintaining a minimal record of the request while keeping the data deleted, or opting the consumer out of all processing for non-exempt purposes.
Right to Data Portability
Consumers can obtain a copy of their personal data in a portable and readily usable format that allows them to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
Right to Opt Out
Consumers have the right to opt out of the processing of their personal data for three specific purposes:
- Targeted advertising based on personal data obtained from activities across different businesses, websites, or applications
- Sale of personal data to third parties
- Profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer
Universal Opt-Out Mechanism note: Virginia does not currently require controllers to honor browser-based universal opt-out signals such as the Global Privacy Control (GPC). This distinguishes the VCDPA from Colorado and Connecticut, which do require GPC recognition. Virginia consumers must submit opt-out requests directly to each controller.
How to Exercise Your Rights
To exercise any of these rights, consumers must submit a request to the controller. Controllers must respond within 45 days. They may extend this period by an additional 45 days when reasonably necessary, considering the complexity and number of requests.
Controllers must provide this service free of charge up to twice annually per consumer. If a request is manifestly unfounded, excessive, or repetitive, the controller may charge a reasonable fee or decline to act on the request.
If a controller declines a request, the consumer may appeal. If the appeal is also denied, the consumer can file a complaint with the Virginia Attorney General.

Business Obligations Under the VCDPA
Controllers that fall under the VCDPA must meet several requirements outlined in Va. Code 59.1-578. These obligations are designed to ensure transparency and data minimization.
Data Collection Limitations
Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary for the disclosed purposes. They cannot collect excessive data or use data in ways that are not reasonably necessary for the stated purpose.
Security Requirements
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data. These practices must protect the confidentiality, integrity, and accessibility of personal data.
Privacy Notice Requirements
Controllers must provide consumers with a reasonably accessible, clear privacy notice that includes:
- The categories of personal data processed by the controller
- The purpose for processing personal data
- How consumers may exercise their rights, including the right to appeal a controller's decision
- The categories of personal data shared with third parties
- The categories of third parties with whom personal data is shared
Consent for Sensitive Data
Controllers must not process sensitive data without first obtaining the consumer's consent. Sensitive data categories requiring affirmative consent include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnoses
- Sexual orientation or citizenship status
- Genetic or biometric data for identification purposes
- Precise geolocation data
For data from a known child under age 13, controllers must process such data in accordance with the federal Children's Online Privacy Protection Act (COPPA).
Geolocation sale ban (effective July 1, 2026): SB 338 amended Va. Code 59.1-578 to flatly prohibit controllers from selling or offering to sell a consumer's precise geolocation data, regardless of consent. This is a categorical ban on that specific act, stricter than and separate from the general consent requirement for processing sensitive data.
Data Protection Assessments
Under Va. Code 59.1-580, controllers must conduct and document data protection assessments for certain processing activities. These assessments are required for:
- Processing personal data for targeted advertising
- Selling personal data
- Processing personal data for profiling where profiling presents a foreseeable risk of harm
- Processing sensitive data
- Any processing activities that present a heightened risk of harm to consumers
Each assessment must weigh the benefits of the processing against the potential risks to consumer rights and identify safeguards to reduce risks. The Attorney General may request these assessments during an investigation. They are confidential and exempt from the Virginia Freedom of Information Act.
Processor Obligations
Data processors have specific duties under Va. Code 59.1-579. A processor must:
- Adhere to the instructions of the controller
- Assist the controller in meeting its obligations, including responding to consumer rights requests
- Maintain confidentiality with respect to personal data
- Delete or return all personal data to the controller at the end of the service relationship
- Make available all information necessary to demonstrate compliance
Controllers and processors must enter into a written contract governing the processor's data processing activities. This contract must include instructions for processing, the nature and purpose of the processing, the type of data being processed, and the duration of the processing.
Children's Data Protections
Virginia has enacted progressively stronger protections for children's data through amendments to the VCDPA.
Children Under 13: Known Child Protections (Effective January 1, 2025)
Under amendments enacted by Governor Youngkin on May 17, 2024 (SB 361/HB 707), controllers face additional restrictions when processing personal data from a known child under age 13. Unless the controller first obtains parental consent in accordance with COPPA, they are prohibited from:
- Processing a known child's personal data for targeted advertising
- Selling a known child's personal data
- Profiling a known child in ways that produce legal or similarly significant effects
Controllers also cannot collect precise geolocation data from a known child unless it is reasonably necessary to provide the service and the controller provides an active signal indicating collection is occurring throughout the duration of collection.
Social Media Restrictions for Minors Under 16 (SB 854): Status as of May 2026
Virginia enacted SB 854, adding Va. Code 59.1-577.1, which imposed requirements on social media platforms regarding users under age 16. The law took effect January 1, 2026, and would have required platforms to:
- Determine whether users are minors using commercially reasonable methods
- Limit minor users to one hour per day per service or application
- Allow parents to adjust this time limit via verifiable parental consent
On November 17, 2025, NetChoice filed suit in the U.S. District Court for the Eastern District of Virginia, challenging the law on First Amendment and dormant Commerce Clause grounds. On February 27, 2026, U.S. District Judge Patricia Tolliver Giles granted a preliminary injunction blocking enforcement of the law. The court found that NetChoice was likely to succeed on the merits, particularly because the statute's content-based exemptions (for news, sports, gaming, and entertainment platforms) rendered the law a content-based speech restriction. Virginia Attorney General Jay Jones, who took office January 17, 2026, has appealed the injunction to the Fourth Circuit; the case is now captioned NetChoice v. Jones (No. 26-1252).
The social media time-limit provisions of SB 854 are currently not being enforced while the litigation proceeds.

Reproductive and Sexual Health Data Protections (Effective July 1, 2025)
Governor Youngkin signed SB 754 on March 24, 2025. The law amends the Virginia Consumer Protection Act to prohibit certain entities from obtaining, disclosing, selling, or disseminating any personally identifiable reproductive or sexual health information without consumer consent, effective July 1, 2025.
Several features distinguish SB 754 from the VCDPA:
- Broader applicability: The law applies to any "supplier" engaged in consumer transactions, not just to entities meeting the VCDPA's data-volume thresholds.
- Broader data scope: Protected information includes not only directly collected health data but also data derived, extrapolated, or inferred from non-health-related information, such as proxy, derivative, algorithmic, or emergent data.
- Consent standard: Consent must be a clear affirmative act that is freely given, specific, informed, and unambiguous.
- Private right of action: Unlike core VCDPA violations, SB 754 violations allow consumers to sue directly. A prevailing consumer recovers actual damages or $500, whichever is greater; willful violations allow treble actual damages or $1,000 (whichever is greater), plus reasonable attorney fees and court costs. The Attorney General may also seek injunctions and civil penalties for willful violations.
VCDPA Enforcement and Penalties
Attorney General Enforcement
Under Va. Code 59.1-584, the Virginia Attorney General has exclusive authority to enforce the VCDPA. There is no private right of action for violations of the core statute.
Before taking enforcement action, the Attorney General must provide the controller or processor with written notice identifying the specific provisions believed to be violated. The business then has a 30-day cure period to correct the violation and provide the Attorney General with a written statement confirming that the violation has been cured and that no further violations will occur.
Virginia's cure period is permanent, with no sunset provision. This distinguishes Virginia from Colorado, where the cure period expired January 1, 2025, and Connecticut, which eliminated its cure period. Businesses operating in multiple states should not assume Virginia has followed those states' enforcement tightening.
If the business fails to cure within 30 days, the Attorney General may seek:
- An injunction to restrain violations
- Civil penalties of up to $7,500 per violation
- Reasonable expenses, including attorney fees and investigative costs
Enforcement Activity as of 2026
Virginia Attorney General Jay Jones has not publicly announced any VCDPA civil penalty settlements as of May 2026, but his office is not passive on enforcement. On February 18, 2026, AG Jones announced his office would fully enforce SB 854's social media time-limit provisions against covered platforms, notifying noncompliant companies and applying the standard 30-day cure period before pursuing civil penalties. The AG's Consumer Privacy Unit is actively receiving complaints and investigating potential VCDPA violations. On January 28, 2025, then-AG Jason Miyares issued a public statement on Data Privacy Day highlighting Virginians' consumer data rights and urging consumers to file complaints with the Consumer Privacy Unit.
AG Jones's defense of SB 854's social media provisions against the NetChoice injunction, combined with the February 2026 enforcement announcement, reflects continued attention to digital privacy matters, though the core VCDPA civil-penalty enforcement record remains thin compared to California's CPPA.
Penalty Summary Table
| Violation Type | Maximum Penalty | Enforcement Authority | Private Right of Action |
|---|---|---|---|
| VCDPA violation (per violation) | $7,500 | VA Attorney General | No |
| Data breach notification failure | $150,000 per breach | VA Attorney General | Limited (economic damages) |
| Reproductive health data violation (SB 754) | Actual damages or $500, greater of; treble or $1,000 for willful, greater of | VA AG + private suit | Yes |
Virginia Data Breach Notification Law
Separate from the VCDPA, Virginia's data breach notification law at Va. Code 18.2-186.6 requires notification when personal information is compromised.
What Triggers a Notification
An entity must notify affected individuals when unencrypted or unredacted personal information was, or is reasonably believed to have been, accessed and acquired by an unauthorized person and the breach causes or is reasonably believed to cause identity theft or other fraud.
Personal information that triggers notification includes a consumer's first name or initial plus last name combined with any of the following:
- Social Security number
- Driver's license or state identification card number
- Financial account number, credit card, or debit card number combined with any required security code, access code, or password
- Passport number
- Military identification number

Who Must Be Notified
Entities must notify each affected Virginia resident without unreasonable delay and must also notify the Virginia Attorney General's office. The notification must describe the incident, the types of personal information compromised, protective measures taken, a contact phone number, and advice for consumers to monitor accounts and review credit reports.
Notification Timing
Notice must be provided without unreasonable delay. It may be delayed to determine the scope of the breach and restore system integrity. Law enforcement may also request delays if notification would impede a criminal or civil investigation.
Breach Notification Penalties
The Attorney General may impose civil penalties of up to $150,000 per breach or series of breaches of a similar nature discovered in a single investigation. Individuals may also recover direct economic damages resulting from a failure to notify.
Recent Developments: What Changed in 2024-2026
Several developments have materially changed Virginia's privacy landscape since the VCDPA's January 2023 effective date.
Geolocation Sale Ban (SB 338, effective July 1, 2026): Virginia amended Va. Code 59.1-578 to flatly prohibit controllers from selling or offering to sell a consumer's precise geolocation data, replacing consent-based handling of that specific act with an outright ban.
Children's Data Amendments (SB 361/HB 707, effective January 1, 2025): Virginia added targeted restrictions on processing data from known children under 13, requiring parental consent before using such data for advertising, sales, or profiling.
Reproductive Health Data Law (SB 754, effective July 1, 2025): A standalone consumer protection amendment created the broadest reproductive and sexual health data privacy protections in Virginia's history, with a private right of action, treble damages, and applicability beyond VCDPA thresholds.
Social Media Time Limits for Minors (SB 854, effective January 1, 2026, enforcement blocked): Virginia enacted one-hour daily limits for minor users of social media platforms, but a federal court granted a preliminary injunction on February 27, 2026, blocking enforcement pending appeal.
Virginia AI Act Vetoed (March 24, 2025): Governor Youngkin vetoed HB 2094, the High-Risk Artificial Intelligence Developer and Deployer Act, which would have created obligations for developers and deployers of high-risk AI systems including anti-discrimination assessments. Virginia has no comprehensive AI regulation as of May 2026.
AG Jones Enforces Social Media Minor Protections (February 18, 2026): New Attorney General Jay Jones, sworn in January 17, 2026, announced his office would fully enforce SB 854's social media time-limit provisions against covered platforms, using the standard 30-day cure notice process ahead of any civil penalty action.
AG Miyares on Privacy Day (January 28, 2025): Then-AG Jason Miyares publicly highlighted consumer data rights and urged Virginians to file complaints with the Consumer Privacy Unit, signaling continued attention to the law even without public enforcement actions.
Federal Overlay: Laws That Apply in Virginia
Virginia consumers and businesses must account for several federal privacy laws that operate alongside the VCDPA.
TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025): This federal law criminalizes the nonconsensual publication of intimate images and AI-generated sexual deepfakes. Platform takedown obligations, requiring removal of flagged content within 48 hours, became effective May 19, 2026. The Federal Trade Commission enforces compliance with civil penalties up to $53,088 per violation. Covered platforms that received formal warning letters from FTC Chairman Andrew Ferguson include Meta, Apple, Microsoft, TikTok, Reddit, Snapchat, and X.
HIPAA: Covered entities and their business associates in Virginia are subject to HIPAA's Privacy Rule (45 C.F.R. Part 164) and Security Rule. HIPAA-covered entities are exempt from the VCDPA for data processed in their HIPAA-regulated capacity, but Virginia's SB 754 reproductive health law may impose independent consent requirements on some health-adjacent services that are not HIPAA-covered entities.
GLBA: Financial institutions subject to the Gramm-Leach-Bliley Act are exempt from the VCDPA. The FTC's Safeguards Rule (16 C.F.R. Part 314, updated 2023) continues to apply.
FCRA and FACTA: Consumer reporting agencies and furnishers in Virginia operate under the Fair Credit Reporting Act and the Fair and Accurate Credit Transactions Act. FCRA-regulated data is exempt from VCDPA coverage.
COPPA: Operators of websites or online services directed to children under 13 must comply with the Children's Online Privacy Protection Act (15 U.S.C. 6501 et seq.), enforced by the FTC. The VCDPA's known-child provisions operate in coordination with, not as a replacement for, COPPA.
FTC Act Section 5: The Federal Trade Commission may bring deception and unfairness actions against entities that violate privacy promises or fail to maintain reasonable data security, regardless of VCDPA applicability. This provides a federal baseline that applies to Virginia companies below VCDPA thresholds.
APRA status: The American Privacy Rights Act, a bipartisan federal comprehensive privacy bill introduced in 2024, expired at the end of the 118th Congress in January 2025 without being enacted. As of May 2026, no comprehensive federal privacy legislation has been reintroduced. The VCDPA therefore remains in force without federal preemption.

Practical Compliance Steps for Businesses
Businesses that meet VCDPA thresholds or anticipate reaching them should take the following steps.
Determine applicability: Confirm whether you process personal data of 100,000 or more Virginia consumers, or 25,000 or more while deriving more than 50% of revenue from data sales. Review exemptions, particularly GLBA, HIPAA, nonprofit status, and FERPA.
Update your privacy notice: The VCDPA requires a clear, accessible privacy notice disclosing categories of personal data, purposes, third-party sharing, and how to submit consumer rights requests. The notice must explain how consumers can appeal a denied request.
Build a consumer rights workflow: You need a documented process to receive, verify, and respond to access, correction, deletion, portability, and opt-out requests within 45 days (extendable to 90 days with notice).
Audit sensitive data flows: Identify all processing of sensitive data categories, particularly precise geolocation, biometric, genetic, health, and known-child data. Confirm you have affirmative consent mechanisms in place before any processing.
Conduct data protection assessments: Document assessments for targeted advertising, data sales, profiling, sensitive data, and any high-risk processing. Keep them confidential and available for AG review.
Execute processor contracts: Review all vendor agreements. Contracts with data processors must comply with Va. Code 59.1-579, including instructions, purpose limitations, and post-termination data return or deletion.
Review children's data practices: If you operate services likely to reach known children under 13, implement COPPA-compliant parental consent before processing their data for advertising, sales, or profiling.
Monitor the SB 854 litigation: If you operate a social media platform that would be covered by the one-hour daily limit law, watch the Fourth Circuit appeal in NetChoice v. Jones (No. 26-1252). Enforcement remains blocked, but the outcome of the appeal will determine whether compliance is required.
Establish a TAKE IT DOWN Act process: Covered platforms must have a 48-hour notice-and-removal process for nonconsensual intimate imagery as of May 19, 2026. FTC enforcement is active.
How the VCDPA Compares to Other State Privacy Laws
Virginia's VCDPA shares many features with privacy laws in other states but has several notable distinctions:
- No private right of action for core violations: Unlike California's CCPA, the VCDPA does not allow consumers to sue businesses directly (except for reproductive health data under SB 754)
- No opt-in for data sales: Virginia uses an opt-out model rather than requiring opt-in consent for data sales
- Permanent cure period: Virginia's 30-day cure period has no sunset; Colorado's expired January 1, 2025 and Connecticut's has been eliminated
- No UOOM/GPC obligation: Virginia does not require controllers to honor browser-based universal opt-out signals
- No dedicated privacy agency: The Virginia AG, not a dedicated agency like California's CPPA, handles all enforcement
- Narrower applicability thresholds: The 100,000-consumer or 25,000-plus-50%-revenue test is relatively high; smaller data processors may not be covered
Other Virginia Laws and Related Guides
Explore additional Virginia and data privacy legal resources on Recording Law:
- Virginia Recording Laws
- Alabama Data Privacy Laws
- California Data Privacy Laws
- Colorado Data Privacy Laws
- Connecticut Data Privacy Laws
- Texas Data Privacy Laws
- View All State Data Privacy Laws
The information on this page is for general informational purposes only and does not constitute legal advice. Data privacy laws change frequently. For advice about your specific situation, consult a licensed attorney in Virginia.
In-depth guides
- What Is the VCDPA? Virginia's Data Privacy Law Explained
- VCDPA Consumer Rights: Exercise Your Virginia Privacy Rights
- VCDPA Compliance Checklist for Businesses (2026)
More Virginia Laws
Frequently Asked Questions
Does Virginia have a comprehensive data privacy law?
Yes. Virginia enacted the Consumer Data Protection Act (VCDPA), codified at Va. Code 59.1-575 through 59.1-584, effective January 1, 2023. Virginia was the second state in the U.S. to pass a comprehensive consumer data privacy law. The VCDPA grants residents rights to access, correct, delete, and port their data, and to opt out of targeted advertising, data sales, and profiling.
Can I sue a company for violating the VCDPA?
No, not for core VCDPA violations. The VCDPA includes no private right of action. Only the Virginia Attorney General may enforce the law. Consumers who believe their rights have been violated should file a complaint with the AG's Consumer Privacy Unit. However, Virginia's separate reproductive and sexual health data protection law (SB 754, effective July 1, 2025) does allow private lawsuits: a prevailing consumer recovers actual damages or $500, whichever is greater, and treble damages or $1,000 (whichever is greater) for willful violations.
What are the penalties for violating Virginia data privacy laws?
The Virginia Attorney General may seek civil penalties of up to $7,500 per VCDPA violation, plus injunctive relief and attorney fees. For data breach notification failures under Va. Code 18.2-186.6, the AG may impose penalties up to $150,000 per breach. Before any VCDPA enforcement, the AG must give the business a 30-day written notice and opportunity to cure the violation.
Has Virginia's 30-day cure period expired?
No. Virginia's VCDPA cure period is permanent and has no sunset provision. This distinguishes Virginia from Colorado, where the cure period expired January 1, 2025, and Connecticut, which eliminated its cure period. Virginia businesses continue to receive a 30-day window to address noticed violations before the AG may initiate civil penalty proceedings.
Does the VCDPA protect children's data?
Yes. The VCDPA includes multiple layers of children's protection. For known children under age 13, a 2024 amendment (SB 361/HB 707, effective January 1, 2025) prohibits controllers from processing their data for targeted advertising, sales, or profiling without parental consent. A separate 2024 law (SB 854) would have imposed one-hour daily limits on minor use of social media platforms, but that law is currently blocked by a federal court preliminary injunction as of February 27, 2026.
What businesses are exempt from the VCDPA?
The VCDPA exempts Virginia state agencies, nonprofits, institutions of higher education, political organizations, entities subject to the Gramm-Leach-Bliley Act, and entities covered by HIPAA and HITECH. Certain data types are also exempt, including FCRA-regulated data, FERPA-protected data, and data processed solely for employment purposes.
Does Virginia require businesses to honor the Global Privacy Control?
No. The VCDPA does not require controllers to recognize browser-based universal opt-out signals such as the Global Privacy Control. Virginia consumers must submit opt-out requests directly to each controller. This contrasts with Colorado and Connecticut, which mandate GPC recognition.
Did Virginia pass an AI law?
No. The Virginia legislature passed HB 2094, the High-Risk Artificial Intelligence Developer and Deployer Act, in the 2025 session, but Governor Youngkin vetoed it on March 24, 2025. His veto message cited concerns about economic growth and the burden on small firms. Virginia has no comprehensive AI regulation as of May 2026.
What is the TAKE IT DOWN Act and how does it affect Virginians?
The TAKE IT DOWN Act (Pub. L. 119-12) is a federal law signed on May 19, 2025, that criminalizes the nonconsensual publication of intimate images and AI-generated sexual deepfakes. Platform takedown obligations, requiring removal of flagged content within 48 hours, became effective May 19, 2026 and are enforced by the FTC. The law operates alongside Virginia's state privacy framework and applies to covered platforms regardless of whether they are otherwise subject to the VCDPA.
Updates
Corrected the citation link for the VCDPA enforcement provision to point to Va. Code 59.1-584 itself, and narrowed the stated codification range to 59.1-575 through 59.1-584 because 59.1-585 was repealed in 2022.
Corrected the sitting attorney general (Jay Jones, in office since January 17, 2026), added SB 338's outright ban on selling precise geolocation data effective July 1, 2026, added SB 754's statutory damage minimums, and fixed the changelog entry and citations that carried the earlier errors.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: Updated the social media SB 854 section to reflect the preliminary injunction blocking enforcement (NetChoice v. Jones, E.D. Va., Feb 27, 2026) and Virginia's appeal to the Fourth Circuit. Note: this refresh also changed the attorney general's name to Jason Miyares in error; corrected August 2026 (Jay Jones has served as attorney general since January 17, 2026). Confirmed VCDPA cure period is permanent with no sunset provision (distinguishes from CO/CT). Added Virginia AI Act section (HB 2094 vetoed by Gov. Youngkin, March 24, 2025). Added TAKE IT DOWN Act federal overlay (platform obligations effective May 19, 2026). Added SB 754 reproductive health law detail (private right of action, treble damages, effective July 1, 2025). Added Universal Opt-Out and GPC section (Virginia does not require GPC recognition). Added Practical Compliance Steps section. Added Federal Overlay section. Expanded FAQ from 5 to 9 questions. Expanded SourcesList from 9 to 17 citations.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Virginia, Title 59.1: Trade and Commerce
§ 59.1-577Personal data rights; consumersIn forcecited in 9 of our articles
A. A consumer may invoke the consumer rights authorized pursuant to this subsection at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the known child. A controller shall comply with an authenticated consumer request to exercise the right: 1. To confirm whether or not a controller is processing the consumer's personal data and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at law.lis.virginia.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Eweka (District Court, E.D. Virginia 2025)“…e the VCDPA protects consumer’s private personal data, see Va Code Ann. § 59.1-577, it explicitly gives Virginia’s Attorne…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to Submit a Data Deletion Request (2026), Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026), VCDPA Compliance Checklist for Businesses (2026)
§ 59.1-578Data controller responsibilities; transparencyIn forcecited in 5 of our articles
A. A controller shall: 1. Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; 2. Except as otherwise provided in this chapter, not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; 3. Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue; 4. Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: VCDPA Consumer Rights: Exercise Your Virginia Privacy Rights, What Is the VCDPA? Virginia's Data Privacy Law Explained
§ 59.1-576Scope; exemptionsIn forcecited in 5 of our articles
A. This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. B. This chapter shall not apply to any (i) body, authority, board, bureau, commission, district, or agency of the Commonwealth or of any political subdivision of the Commonwealth; (ii) financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.); (iii) covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the Health Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Virginia Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 59.1-575DefinitionsIn forcecited in 8 of our articles
As used in this chapter, unless the context requires a different meaning: "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means (i) ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; (ii) control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (iii) the power to exercise controlling influence over the management of a company. "Authenticate" means verifying through reasonable means that the consumer, entitled to exercise his consumer rights in § 59.1-577, is the same consumer exercising such consumer rights with respect to the personal data at issue. "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Virginia Smart Glasses Recording Laws, Virginia Ring Doorbell Laws: What You Need to Know in 2026
§ 59.1-577.1Social media platforms; responsibilities and prohibitions related to minorsIn forcecited in 4 of our articles
A. For purposes of this section, "minor" means any natural person younger than 16 years of age. B. Any controller or processor that operates a social media platform shall (i) use commercially reasonable methods, such as a neutral age screen mechanism, to determine whether a user is a minor and (ii) limit a minor's use of such social media platform to one hour per day, per service or application, and allow a parent to give verifiable parental consent to increase or decrease the daily time limit. C. Information collected for the purpose of determining a user's age shall not be used for any purpose other than age determination and provision of age-appropriate experiences. For purposes of this section, any controller or processor that operates a social media platform shall treat a user as a minor if the user's device communicates or signals that the user is or shall be treated as a minor, including through a browser plug-in or privacy setting, device setting, or other mechanism. D.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Age Verification Laws by State (2026): The 27-State Table, Debunked
§ 59.1-579Responsibility according to role; controller and processorIn forcecited in 2 of our articles
A. A processor shall adhere to the instructions of a controller and shall assist the controller in meeting its obligations under this chapter. Such assistance shall include: 1. Taking into account the nature of processing and the information available to the processor, by appropriate technical and organizational measures, insofar as this is reasonably practicable, to fulfill the controller's obligation to respond to consumer rights requests pursuant to § 59.1-577. 2. Taking into account the nature of processing and the information available to the processor, by assisting the controller in meeting the controller's obligations in relation to the security of processing the personal data and in relation to the notification of a breach of security of the system of the processor pursuant to § 18.2-186.6 in order to meet the controller's obligations. 3. Providing necessary information to enable the controller to conduct and document data protection assessments pursuant to § 59.1-580. B. A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
§ 59.1-580Data protection assessmentsIn forcecited in 4 of our articles
A. A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data: 1. The processing of personal data for purposes of targeted advertising; 2. The sale of personal data; 3. The processing of personal data for purposes of profiling, where such profiling presents a reasonably foreseeable risk of (i) unfair or deceptive treatment of, or unlawful disparate impact on, consumers; (ii) financial, physical, or reputational injury to consumers; (iii) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; or (iv) other substantial injury to consumers; 4. The processing of sensitive data; and 5. Any processing activities involving personal data that present a heightened risk of harm to consumers. B.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
§ 59.1-584Enforcement; civil penalty; expensesIn forcecited in 6 of our articles
A. The Attorney General shall have exclusive authority to enforce the provisions of this chapter. B. Prior to initiating any action under this chapter, the Attorney General shall provide a controller or processor 30 days' written notice identifying the specific provisions of this chapter the Attorney General alleges have been or are being violated. If within the 30-day period the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action shall be initiated against the controller or processor. C. If a controller or processor continues to violate this chapter following the cure period in subsection B or breaches an express written statement provided to the Attorney General under that subsection, the Attorney General may initiate an action in the name of the Commonwealth and may seek an injunction to restrain any violations of this chapter and civil penalties of up to $7,500 for each violation under this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Eweka (District Court, E.D. Virginia 2025)“…neral the “exclusive authority” to enforce its provisions, Va. Code Ann. § 59.1-584. Second, Plaintiff has not plausi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Virginia, Title 18.2: Crimes and Offenses Generally
§ 18.2-186.6Breach of personal information notificationIn forcecited in 4 of our articles
A. As used in this section: "Breach of the security of the system" means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. "Encrypted" means the transformation of data through the use of an algorithmic process into a form in which there is a low probability of assigning meaning without the use of a confidential process or key, or the securing of the information by another method that renders the data elements unreadable or unusable.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at law.lis.virginia.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Moss v. Trent (District Court, W.D. Virginia 2025)“…he Virginia Personal Information Breach Notifications Act, Va. Code § 18.2-186.6, by failing to provide adequate notic…”
- Griffey v. Magellan Health Incorporated (District Court, D. Arizona 2021)“…breach was untimely, 26 thus establishing a claim under Va. Code § 18.2-186.6. (Doc. 30 ¶¶ 245–253.) Flanders 27 s…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026), Virginia Identity Theft Laws: Penalties and the Identity Theft Passport
United States Code Title 15
§ 6501DefinitionsIn force
In this chapter: The term “child” means an individual under the age of 13. The term “operator”— means any person who operates a website located on the Internet or an online service and who collects or maintains personal information from or about the users of or visitors to such website or online service, or on whose behalf such information is collected or maintained, where such website or online service is operated for commercial purposes, including any person offering products or services for sale through that website or online service, involving commerce— among the several States or with 1 or more foreign nations; in any territory of the United States or in the District of Columbia, or between any such territory and— another such territory; or any State or foreign nation; or between the District of Columbia and any State, territory, or foreign nation; but does not include any nonprofit entity that would otherwise be exempt from coverage under section 45 of this title. The term “Commission” means the Federal Trade Commission.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 34 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- In Re Nickelodeon Consumer Privacy Litigation (Court of Appeals for the Third Circuit 2016, 827 F.3d 262)“…ition of personally identifiable information”). 151 15 U.S.C. § 6501(8). 152 15 U.S.C. § 6809(4).…”
- Netchoice, LLC v. Bonta (Court of Appeals for the Ninth Circuit 2026)“…ed by the Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–06, and facially invalid under the Dorm…”
- CARA JONES V. GOOGLE LLC (Court of Appeals for the Ninth Circuit 2022)“…The Children’s Online Privacy Protection Act (“COPPA”), 15 U.S.C. §§ 6501–06, gives the Federal Trade Commission…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Virginia Consumer Data Protection Act (VCDPA) - Full Text(law.lis.virginia.gov).gov
- VCDPA Definitions - Va. Code 59.1-575(law.lis.virginia.gov).gov
- VCDPA Consumer Rights - Va. Code 59.1-577(law.lis.virginia.gov).gov
- VCDPA Controller Responsibilities - Va. Code 59.1-578(law.lis.virginia.gov).gov
- VCDPA Data Protection Assessments - Va. Code 59.1-580(law.lis.virginia.gov).gov
- Virginia Data Breach Notification Law - Va. Code 18.2-186.6(law.lis.virginia.gov).gov
- Virginia AG - Consumer Data Protection Act Summary(oag.state.va.us).gov
- Virginia AG - Database Breach Notification Requirements(oag.state.va.us).gov
- Virginia AG Jay Jones - Data Privacy Rights Reminder (March 4, 2026)(oag.state.va.us).gov
- Virginia SB 754 - Reproductive and Sexual Health Data Privacy (effective July 1, 2025)(orrick.com)
- Virginia Governor Vetoes AI Bill (HB 2094), March 24, 2025 - Davis Polk(davispolk.com)
- Virginia Social Media Restrictions for Minors Blocked - DLA Piper (Feb 2026)(privacymatters.dlapiper.com)
- NetChoice v. Miyares Complaint (E.D. Va., filed Nov 17, 2025)(netchoice.org)
- Virginia AG to Enforce VCDPA Social Media Provisions - Hunton Andrews Kurth (Feb 2026)(hunton.com)
- TAKE IT DOWN Act - FTC Compliance Guidance (effective May 19, 2026)(ftc.gov).gov
- Virginia Children's Privacy Amendments (SB 361/HB 707) - Davis Wright Tremaine(dwt.com)
- VCDPA Enforcement; civil penalty; expenses - Va. Code 59.1-584(law.lis.virginia.gov)