Virginia
Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Virginia regulates biometric data through the Virginia Consumer Data Protection Act, classifying it as sensitive personal data under Va. Code 59.1-578(A)(5) and requiring opt-in consent before any business collects fingerprints, voiceprints, or iris scans for identification. Virginia has no standalone biometric law; the VCDPA is the state's primary framework, enforced exclusively by the Attorney General.
Virginia does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, Virginia protects biometric data through the Virginia Consumer Data Protection Act (VCDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative opt-in consent.
Governor Ralph Northam signed Senate Bill 1392 into law on March 2, 2021, making Virginia the second state after California to enact a comprehensive consumer data privacy law. The VCDPA took effect on January 1, 2023.
For an overview of Virginia's broader privacy framework, see the parent guide to Virginia Data Privacy Laws.
How the VCDPA Defines Biometric Data

The VCDPA defines biometric data under Va. Code 59.1-575 as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The law draws a clear boundary around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data under the VCDPA. Information collected, used, or stored for health care treatment, payment, or operations under HIPAA is also excluded from the definition.
This definition follows the approach used in several other state comprehensive privacy statutes, including Connecticut and Kentucky. It is narrower than the definition used in Illinois's BIPA, which covers a broader set of biometric identifiers without the same exclusions.
Sensitive Data Classification and Consent Requirements

Under the VCDPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data." This is the highest protection category in the law.
Other categories of sensitive data under Va. Code 59.1-575 include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnoses
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Precise geolocation data
- Personal data collected from a known child under 13
Consent requirement. Controllers must obtain a consumer's opt-in consent before processing sensitive data, including biometric data, under Va. Code 59.1-578(A)(5). This means a business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without first asking for and receiving your affirmative agreement.
The VCDPA defines "consent" as a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data. A buried clause in a terms-of-service agreement or a pre-checked checkbox does not meet this standard. Consent must involve a deliberate action, such as a written statement or other unambiguous affirmative act.
Who Must Comply With the VCDPA
The VCDPA applies to entities that conduct business in Virginia or produce products or services targeted to Virginia residents and meet one of these thresholds under Va. Code 59.1-576:
- Process personal data of 100,000 or more Virginia consumers during a calendar year, or
- Process personal data of 25,000 or more Virginia consumers and derive over 50% of gross revenue from the sale of personal data
The term "sale" under the VCDPA covers only exchanges for monetary consideration. This is narrower than laws in states like California, which also cover non-monetary exchanges of value.
Key Exemptions
The VCDPA carves out several categories of entities and data types from coverage under Va. Code 59.1-576:
Entity exemptions:
- Virginia state and local government agencies
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Entities covered by HIPAA
- Nonprofit organizations
- Institutions of higher education
Data exemptions:
- Protected health information under HIPAA
- Consumer credit reporting data under the Fair Credit Reporting Act (FCRA)
- Data covered by the Family Educational Rights and Privacy Act (FERPA)
- Data under the Driver's Privacy Protection Act (DPPA)
Employee data exemption. The VCDPA excludes personal data collected in an employment context from coverage. If your employer collects your fingerprints for a timekeeping system or uses facial recognition for building access, the VCDPA does not apply to that collection. Virginia has not enacted a separate law regulating employer use of biometric data, though a bill (HB 1215) proposing employer biometric data protections with a $25,000-per-violation penalty was introduced and left in committee.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal data under the VCDPA, Virginia consumers have these rights under Va. Code 59.1-577:
Right to confirm and access. You can ask any covered business whether it is processing your biometric data and request access to that data.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your biometric data in a portable and readily usable format.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, data sales, or profiling that produces legal or similarly significant effects.
Right to non-discrimination. Businesses cannot penalize you for exercising any of these rights by denying goods or services, charging different prices, or providing a different quality of service.
Businesses must respond to consumer rights requests within 45 days under the VCDPA. They can extend this period by an additional 45 days when reasonably necessary, but must notify the consumer of the extension and the reason for it. If a business denies your request, you may appeal, and the business must respond to the appeal within 60 days. If the appeal is denied, the business must provide contact information for filing a complaint with the Virginia Attorney General.
Data Protection Assessments for Biometric Data
Controllers that process sensitive data, including biometric data, must conduct data protection assessments under Va. Code 59.1-580. These assessments apply to processing activities created or generated after January 1, 2023.
A data protection assessment must weigh the benefits of the processing against the potential risks to the consumer, including risks of:
- Unfair or deceptive treatment or unlawful disparate impact
- Financial, physical, or reputational injury
- Intrusion upon solitude or seclusion
- Other substantial injury
The Virginia Attorney General can request these assessments through a civil investigative demand. They remain confidential and exempt from public inspection under Virginia's Freedom of Information Act.
Facial Recognition Technology Restrictions
Virginia goes beyond the VCDPA with separate statutes governing government use of facial recognition technology.
State police. Under Va. Code 52-4.5, Virginia State Police can use facial recognition for 14 authorized purposes, including identifying crime suspects, locating missing persons, and detecting human trafficking. The technology must be evaluated by the National Institute of Standards and Technology (NIST) and demonstrate at least 98% true positive accuracy with minimal demographic performance variations. The statute prohibits real-time tracking of identified individuals and creating databases from live video feeds. Operators who violate these rules face Class 3 misdemeanor charges.
Local law enforcement. Under Va. Code 15.2-1723.2, local law-enforcement agencies face similar restrictions. Effective July 1, 2026, no local law-enforcement agency may purchase or deploy facial recognition technology unless expressly authorized by statute. The technology must remain under the exclusive control of the agency, and data must be kept confidential and accessible only through search warrants.
Higher education. Under Va. Code 23.1-815.1, campus police departments are also prohibited from purchasing or deploying facial recognition technology unless expressly authorized by statute, effective July 1, 2026.
Breach Notification and Biometric Data
Virginia's breach notification law at Va. Code 18.2-186.6 requires businesses to notify affected individuals and the Attorney General when a security breach compromises unencrypted personal information.
The current definition of "personal information" under the breach notification statute covers a first name or initial and last name combined with a Social Security number, driver's license number, financial account numbers, passport number, or military ID. Biometric data is not specifically listed as a triggering data element under this statute.
However, the breach notification law contains a notable provision for consumers: it explicitly preserves an individual's right to recover direct economic damages from a violation. This means that unlike the VCDPA, where enforcement is limited to the Attorney General, Virginia's breach notification statute allows a private right of action for direct economic damages resulting from a breach notification violation. Courts have entertained individual and class action lawsuits under this provision.
The Attorney General can impose civil penalties of up to $150,000 per breach or series of similar breaches discovered during a single investigation.
Enforcement and Penalties

The Virginia Attorney General has exclusive enforcement authority over the VCDPA. There is no private right of action, meaning individual consumers cannot file lawsuits against businesses for VCDPA violations.
The enforcement process works as follows:
- The Attorney General identifies a potential violation and sends written notice identifying the specific provisions at issue
- The business has 30 days to cure the alleged violation
- If the business cures the violation and provides a written statement that it will not engage in further violations, the Attorney General takes no action
- If the business fails to cure, the Attorney General can bring a civil action with penalties of up to $7,500 per violation
- The Attorney General can also recover reasonable investigation expenses, including attorney fees
The 30-day cure period is permanent under the VCDPA. Unlike privacy laws in some other states that have removed or plan to remove their cure periods, Virginia's cure provision remains in effect.
As of early 2026, the Virginia Attorney General's office has focused enforcement activity on the VCDPA's newer provisions, including social media restrictions for minors that took effect January 1, 2026. Attorney General Jay Jones announced in February 2026 that his office intends to fully enforce these provisions.
Consumers can file complaints about potential VCDPA violations with the Virginia Attorney General's Office.
Recent and Pending Legislation
Virginia's biometric privacy landscape continues to develop:
2025 VCDPA amendments. The Virginia General Assembly amended the VCDPA to add protections for reproductive and sexual health information, effective July 1, 2025. These amendments created a new consent requirement before entities can collect, disclose, sell, or disseminate personally identifiable reproductive or sexual health information.
2026 social media provisions. SB 854, signed into law on May 2, 2025, added requirements for social media platforms to use commercially reasonable methods to determine whether users are minors under 16 and to limit minors' use to one hour per day unless a parent consents to increase the limit. These provisions took effect January 1, 2026.
Facial recognition sunset. Effective July 1, 2026, the detailed authorized-use frameworks that had governed local law enforcement (Va. Code 15.2-1723.2) and campus police (Va. Code 23.1-815.1) expired. The current text of both sections instead bars a local or campus police department from purchasing or deploying facial recognition technology at all unless expressly authorized by statute; the NIST 98-percent-accuracy, model-policy, and annual-reporting requirements that applied before July 1, 2026 no longer appear in either section. Virginia State Police's separate authorized-use framework under Va. Code 52-4.5 is unaffected.
Employer biometric data. Virginia has not enacted a standalone employer biometric data law. HB 1215, which would have established requirements for employer capture and destruction of biometric data with penalties up to $25,000 per violation and a private right of action, was left in committee during the 2021 session and has not been reintroduced.
How Virginia Compares to Other States
Virginia's approach to biometric privacy falls in the middle of the spectrum among U.S. states:
Stronger than states with no protections. Many states still lack any specific biometric data protections. Virginia's classification of biometric data as sensitive data requiring consent, combined with its facial recognition restrictions on government, puts it ahead of states that have no privacy framework in place.
Weaker than dedicated biometric privacy laws. States like Illinois, Texas, and Washington have standalone biometric privacy statutes with specific requirements for notice, consent, retention schedules, and data destruction. Illinois's BIPA includes a private right of action that has produced significant litigation and settlements exceeding $1 billion.
Similar to other comprehensive privacy law states. Virginia's approach closely mirrors states like Connecticut, Colorado, and Kentucky, which all classify biometric data as sensitive data within their comprehensive consumer privacy frameworks and require opt-in consent for processing.
Sources and References
This article references Virginia statutes and official state government publications. For the full text of the VCDPA, visit the Virginia Legislative Information System. For guidance on consumer rights and filing complaints, visit the Virginia Attorney General's Office.
This article provides general legal information about Virginia biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Virginia government sources.
More Virginia Laws
Frequently Asked Questions
Does Virginia have a standalone biometric privacy law like Illinois?
No. Virginia does not have a dedicated biometric privacy statute. Instead, the Virginia Consumer Data Protection Act (VCDPA), effective January 1, 2023, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The VCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention schedules, destruction timelines, or private right of action found in Illinois BIPA.
Can I sue a company in Virginia for collecting my fingerprints without consent?
Not under the VCDPA. The Virginia Attorney General has exclusive enforcement authority, and the law explicitly states it does not provide a basis for a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint with the Virginia Attorney General's Office. The AG can investigate and pursue civil penalties of up to $7,500 per violation. However, Virginia's breach notification law (Va. Code 18.2-186.6) does preserve an individual's right to recover direct economic damages if a breach notification violation occurs.
Does the VCDPA protect my biometric data at work?
No. The VCDPA exempts personal data collected in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the VCDPA does not regulate that activity. Virginia does not have a separate law governing employer use of biometric data. A bill (HB 1215) that would have created employer biometric data protections was left in committee in 2021 and has not been reintroduced.
What biometric data does the VCDPA cover?
The VCDPA covers data generated by automatic measurements of biological characteristics used to identify a specific individual. This includes fingerprints, voiceprints, eye retinas, irises, and other unique biological patterns. Photographs, video recordings, audio recordings, and data generated from those recordings are not covered. Data collected for health care treatment, payment, or operations under HIPAA is also excluded from the definition.
How does Virginia regulate facial recognition technology?
Virginia regulates facial recognition through separate statutes that apply to government agencies, not private businesses. State police (Va. Code 52-4.5) can use facial recognition only for authorized purposes using NIST-evaluated technology with at least 98% accuracy, and real-time tracking is prohibited. Effective July 1, 2026, local law enforcement (Va. Code 15.2-1723.2) and campus police (Va. Code 23.1-815.1) may no longer purchase or deploy facial recognition technology at all unless expressly authorized by statute; any technology they remain authorized to use must stay under the agency's exclusive control, with the data kept confidential and accessible only through a search warrant.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the description of Virginia's July 1, 2026 facial-recognition-technology change for local law enforcement and campus police. The current (post-7/1/2026) text of Va. Code 15.2-1723.2 and 23.1-815.1, read directly from law.lis.virginia.gov, does NOT create a 'regulated-use framework' requiring a model policy, a 98% NIST accuracy threshold, or annual reporting -- those requirements existed only in the PRE-7/1/2026 version and were removed. The version now in effect is stricter and simpler: a flat ban on purchasing or deploying facial recognition unless a statute expressly authorizes it. This corrects a section of the article that contradicted the article's own (accurate) description of Va. Code 15.2-1723.2 earlier on the same page. Also removed the unverified claim that Va. Code 52-4.5 (state police) was replaced on the same date -- law.lis.virginia.gov shows only a single, still-captioned 'effective until July 1, 2026' version of that section with no successor text.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 10 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of Virginia, Title 15.2: Counties, Cities and Towns
§ 15.2-1723.2(Effective until July 1, 2026) Facial recognition technology; approval; penaltyIn forcecited in 2 of our articles
A. For purposes of this section: "Authorized use" means the use of facial recognition technology to (i) help identify an individual when there is a reasonable suspicion the individual has committed a crime; (ii) help identify a crime victim, including a victim of online sexual abuse material; (iii) help identify a person who may be a missing person or witness to criminal activity; (iv) help identify a victim of human trafficking or an individual involved in the trafficking of humans, weapons, drugs, or wildlife; (v) help identify an online recruiter of criminal activity, including but not limited to human, weapon, drug, and wildlife trafficking; (vi) help a person who is suffering from a mental or physical disability impairing his ability to communicate and be understood; (vii) help identify a deceased person; (viii) help identify a person who is incapacitated or otherwise unable to identify himself; (ix) help identify a person who is reasonably believed to be a danger to himself or others; (x) help identify an individual lawfully detained; (xi) help mitigate an imminent threat to public safety, a significant threat to life, or a threat to national security, including acts of…
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Also relied on in: Virginia Police Can Now Use Facial Recognition, Under Strict New Rules Effective July 1, 2026
Code of Virginia, Title 18.2: Crimes and Offenses Generally
§ 18.2-186.6Breach of personal information notificationIn forcecited in 3 of our articles
A. As used in this section: "Breach of the security of the system" means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. "Encrypted" means the transformation of data through the use of an algorithmic process into a form in which there is a low probability of assigning meaning without the use of a confidential process or key, or the securing of the information by another method that renders the data elements unreadable or unusable.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Also relied on in: Virginia Data Privacy Laws: VCDPA Consumer Rights Guide (2026), Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Code of Virginia, Title 23.1: Institutions of Higher Education; Other Educational and Cultural Institutions
§ 23.1-815.1(Effective until July 1, 2026) Facial recognition technology; approval; penaltyIn forcecited in 2 of our articles
A. For purposes of this section: "Authorized use" means the use of facial recognition technology to (i) help identify an individual when there is a reasonable suspicion the individual has committed a crime; (ii) help identify a crime victim, including a victim of online sexual abuse material; (iii) help identify a person who may be a missing person or witness to criminal activity; (iv) help identify a victim of human trafficking or an individual involved in the trafficking of humans, weapons, drugs, or wildlife; (v) help identify an online recruiter of criminal activity, including but not limited to human, weapon, drug, and wildlife trafficking; (vi) help a person who is suffering from a mental or physical disability impairing his ability to communicate and be understood; (vii) help identify a deceased person; (viii) help identify a person who is incapacitated or otherwise unable to identify himself; (ix) help identify a person who is reasonably believed to be a danger to himself or others; (x) help identify an individual lawfully detained; (xi) help mitigate an imminent threat to public safety, a significant threat to life, or a threat to national security, including acts of…
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Code of Virginia, Title 52: Police (State)
§ 52-4.5(Effective until July 1, 2026) Facial recognition technology; authorized uses; Department to establish a State Police Model Facial Recognition Technology Policy; penaltyIn force
A. For purposes of this section: "Authorized use" means the use of facial recognition technology to (i) help identify an individual when there is a reasonable suspicion the individual has committed a crime; (ii) help identify a crime victim, including a victim of online sexual abuse material; (iii) help identify a person who may be a missing person or witness to criminal activity; (iv) help identify a victim of human trafficking or an individual involved in the trafficking of humans, weapons, drugs, or wildlife; (v) help identify an online recruiter of criminal activity, including but not limited to human, weapon, drug, and wildlife trafficking; (vi) help a person who is suffering from a mental or physical disability impairing his ability to communicate and be understood; (vii) help identify a deceased person; (viii) help identify a person who is incapacitated or otherwise unable to identify himself; (ix) help identify a person who is reasonably believed to be a danger to himself or others; (x) help identify an individual lawfully detained; (xi) help mitigate an imminent threat to public safety, a significant threat to life, or a threat to national security, including acts of…
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Code of Virginia, Title 59.1: Trade and Commerce
§ 59.1-575DefinitionsIn forcecited in 8 of our articles
As used in this chapter, unless the context requires a different meaning: "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means (i) ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; (ii) control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (iii) the power to exercise controlling influence over the management of a company. "Authenticate" means verifying through reasonable means that the consumer, entitled to exercise his consumer rights in § 59.1-577, is the same consumer exercising such consumer rights with respect to the personal data at issue. "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Also relied on in: Virginia Smart Glasses Recording Laws, VCDPA Compliance Checklist for Businesses (2026), VCDPA Consumer Rights: Exercise Your Virginia Privacy Rights
§ 59.1-576Scope; exemptionsIn forcecited in 5 of our articles
A. This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. B. This chapter shall not apply to any (i) body, authority, board, bureau, commission, district, or agency of the Commonwealth or of any political subdivision of the Commonwealth; (ii) financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.); (iii) covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the Health Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Also relied on in: What Is the VCDPA? Virginia's Data Privacy Law Explained, Virginia Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 59.1-577Personal data rights; consumersIn forcecited in 7 of our articles
A. A consumer may invoke the consumer rights authorized pursuant to this subsection at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the known child. A controller shall comply with an authenticated consumer request to exercise the right: 1. To confirm whether or not a controller is processing the consumer's personal data and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Also relied on in: How to Submit a Data Deletion Request (2026), Virginia Ring Doorbell Laws: What You Need to Know in 2026
§ 59.1-578Data controller responsibilities; transparencyIn forcecited in 5 of our articles
A. A controller shall: 1. Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; 2. Except as otherwise provided in this chapter, not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; 3. Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue; 4. Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
§ 59.1-580Data protection assessmentsIn forcecited in 4 of our articles
A. A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data: 1. The processing of personal data for purposes of targeted advertising; 2. The sale of personal data; 3. The processing of personal data for purposes of profiling, where such profiling presents a reasonably foreseeable risk of (i) unfair or deceptive treatment of, or unlawful disparate impact on, consumers; (ii) financial, physical, or reputational injury to consumers; (iii) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; or (iv) other substantial injury to consumers; 4. The processing of sensitive data; and 5. Any processing activities involving personal data that present a heightened risk of harm to consumers. B.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
§ 59.1-584Enforcement; civil penalty; expensesIn forcecited in 6 of our articles
A. The Attorney General shall have exclusive authority to enforce the provisions of this chapter. B. Prior to initiating any action under this chapter, the Attorney General shall provide a controller or processor 30 days' written notice identifying the specific provisions of this chapter the Attorney General alleges have been or are being violated. If within the 30-day period the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action shall be initiated against the controller or processor. C. If a controller or processor continues to violate this chapter following the cure period in subsection B or breaches an express written statement provided to the Attorney General under that subsection, the Attorney General may initiate an action in the name of the Commonwealth and may seek an injunction to restrain any violations of this chapter and civil penalties of up to $7,500 for each violation under this chapter.
Official text (excerpt) · as of 2026-07-29 · Read the full section at law.lis.virginia.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Virginia Consumer Data Protection Act (Full Text)(law.lis.virginia.gov).gov
- Va. Code 59.1-575 - VCDPA Definitions(law.lis.virginia.gov).gov
- Va. Code 59.1-576 - Scope and Exemptions(law.lis.virginia.gov).gov
- Va. Code 59.1-577 - Consumer Personal Data Rights(law.lis.virginia.gov).gov
- Va. Code 59.1-578 - Data Controller Responsibilities(law.lis.virginia.gov).gov
- Va. Code 59.1-580 - Data Protection Assessments(law.lis.virginia.gov).gov
- Va. Code 59.1-584 - VCDPA Enforcement(law.lis.virginia.gov).gov
- Va. Code 18.2-186.6 - Breach Notification(law.lis.virginia.gov).gov
- Va. Code 52-4.5 - Facial Recognition Technology (State Police)(law.lis.virginia.gov).gov
- Va. Code 15.2-1723.2 - Facial Recognition (Local Law Enforcement)(law.lis.virginia.gov).gov
- Va. Code 23.1-815.1 - Facial Recognition (Campus Police)(law.lis.virginia.gov).gov
- Virginia Attorney General - Consumer Data Privacy Rights(oag.state.va.us).gov
- Senate Bill 1392 (2021) - VCDPA Enactment(lis.virginia.gov).gov