EnglishEspañol
Virginia flag

Virginia

Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Virginia residents after a data breach?

Virginia requires notification without unreasonable delay following discovery of the breach. There is no specific day-count deadline. The entity may take reasonable time to determine the scope of the breach and restore system integrity, and may delay if law enforcement requests it. Once those steps are complete, notification must proceed promptly.

Must every data breach in Virginia be reported to the Attorney General?

Yes. Virginia requires notification to the Office of the Attorney General for all breaches affecting Virginia residents, regardless of the number affected. Many states only require AG notification above a threshold (such as 500 or 1,000), but Virginia requires it for every reportable breach. When notice goes to more than 1,000 persons at one time, the Attorney General and the nationwide consumer reporting agencies must also be told the timing, distribution, and content of that notice.

Can individuals sue for data breach notification violations in Virginia?

Virginia's statute expressly preserves an individual's right to recover direct economic damages from a violation. That language is a savings clause rather than an express grant of a new cause of action, so whether the section itself supports a standalone private suit is not settled by published Virginia appellate authority. Any recovery under it is limited to direct economic damages, meaning provable financial losses. Non-economic damages like emotional distress are not recoverable under this statute.

What is the maximum penalty the Attorney General can impose for a data breach in Virginia?

The Attorney General may impose a civil penalty of up to $150,000 per breach or series of similar breaches discovered in a single investigation. This cap applies per breach event, not per affected individual. Separate from this, the statute preserves an individual's ability to recover direct economic damages.

Does Virginia's data breach notification law cover medical information?

No. Virginia Code 18.2-186.6 covers SSNs, driver's license numbers, financial account data, passport numbers, and military identification numbers, but not medical information. Medical information breaches are governed by a separate statute, Va. Code 32.1-127.1:05, which applies to government bodies and publicly funded entities, not to HIPAA-covered private healthcare providers, who follow the federal HIPAA breach rule instead.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the amendment history to show that Attorney General notification, the $150,000 penalty cap, and the direct economic damages clause all date to the original 2008 enactment rather than 2019, removed an unsupported claim that courts have read the statute as creating a private right of action, dropped a federal electronic-signature condition Virginia does not impose on electronic notice, and restated the 1,000-person consumer reporting agency trigger as notice provided rather than persons affected.

Corrected the redaction safe-harbor description (Social Security numbers and driver's license/state ID/account numbers follow separate rules, not one combined 'last four digits' rule), fixed the consumer-reporting-agency notification threshold to 'more than 1,000 persons' in the key takeaways and FAQ to match the statute and the article's own body text, and clarified that insurance-regulated entities are fully exempt from this notification statute rather than subject to a different enforcement channel.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the scope of Virginia's medical information breach statute (Va. Code 32.1-127.1:05): it applies to government bodies and publicly funded entities, not private healthcare providers generally, which are excluded because they follow federal HIPAA breach rules instead; also noted the employer/payroll AG-notification duty for taxpayer ID numbers under subsection M.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Va. Code 18.2-186.6 - Breach of Personal Information Notification(law.lis.virginia.gov).gov
  2. Va. Code 32.1-127.1:05 - Breach of Medical Information Notification(law.lis.virginia.gov).gov
  3. Virginia Office of the Attorney General(oag.state.va.us).gov
  4. HB 2396 (2019) - Breach Notification Amendments(legacylis.virginia.gov).gov
  5. 2008 Acts of Assembly, ch. 566 - original enactment of Va. Code 18.2-186.6(legacylis.virginia.gov).gov
Share: