Virginia
VCDPA Compliance Checklist for Businesses (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 7 primary sources cited on this page. How we verify our legal content

Businesses that process the personal data of Virginia residents face a detailed stack of controller duties under the Virginia Consumer Data Protection Act (VCDPA), Va. Code Ann. sections 59.1-575 through 59.1-584 (section 59.1-585 was repealed in 2022). A separate, freestanding provision, Va. Code Ann. section 59.1-577.1, adds social-media-specific duties toward known minor users, though its enforcement is currently enjoined pending appeal. This nine-step checklist walks through every obligation, from the threshold self-test to processor contracts and enforcement exposure, so you can identify gaps before the Attorney General's 30-day notice letter arrives.
For a plain-language overview of what the VCDPA requires, see the companion explainer.
Step 1: Run the Applicability Self-Test
You are a covered controller under the VCDPA if your business operates in Virginia and clears either of two numerical thresholds. The first threshold is processing the personal data of at least 100,000 Virginia consumers during a calendar year. The second, lower-volume threshold applies to businesses that process data of at least 25,000 consumers AND derive more than 50 percent of gross revenue from selling personal data. Va. Code Ann. section 59.1-576(A).
Notice what the VCDPA does not include: there is no minimum annual revenue floor. Any size business can be covered if it clears the consumer-count thresholds. If neither threshold applies today, revisit the test annually as your data footprint grows, because crossing a threshold mid-year does not trigger retroactive liability but does mean obligations attach for subsequent processing.
Key questions to ask
- How many unique Virginia residents appear in your systems during the calendar year (across all products, services, and website visitors)?
- Do you sell personal data to third parties? If so, what percentage of total gross revenue does that represent?
- Do you do business in Virginia, even if your company is incorporated or headquartered elsewhere?
If your honest answers put you above 100,000 consumers, or above 25,000 with a data-sale revenue majority, proceed through the remaining steps. Otherwise the VCDPA does not apply, but document that conclusion in case the AG or a partner ever asks.
Step 2: Confirm Whether an Entity or Data Exemption Applies
Even if your business clears the numerical threshold, entire entity classes are expressly exempt from the VCDPA under Va. Code Ann. section 59.1-576(B). Exempt entities include nonprofit organizations; financial institutions or data subject to Title V of the Gramm-Leach-Bliley Act; HIPAA-covered entities and their business associates; higher education institutions; and government bodies.
Beyond entity-level exemptions, specific categories of data are excluded from the VCDPA's requirements under section 59.1-576(C), regardless of who holds them. Those data-category carve-outs include: protected health information regulated under HIPAA; consumer credit data regulated by the Fair Credit Reporting Act; education records protected under FERPA; driver's license and motor vehicle record information governed by the Driver's Privacy Protection Act; data handled in compliance with the federal Farm Credit Act; and employment data processed solely in the employment context.
Children's data is not one of those carve-outs. COPPA appears in section 59.1-576 only at subsection (D), which deems a controller that follows COPPA's verifiable parental consent requirements compliant with the VCDPA's own parental consent obligation. That is a safe harbor for one duty, not an exemption from the chapter. Personal data collected from a known child remains sensitive data under section 59.1-575 and stays fully within the statute's scope, with the added duties described in Step 4.
How to apply the dual-check
The entity exemption and the data exemption are independent. A HIPAA-covered hospital is exempt as an entity across the board. A technology company that is not HIPAA-covered may still hold some HIPAA-regulated data streams (if it processes data on behalf of covered entities as a business associate), which are exempt at the data level even though the company itself is not entity-exempt.
The practical step: for each data stream you process, ask (a) does an entity exemption remove the whole organization? and (b) even if the organization is covered, does a data-category exemption remove this specific data type? Apply both checks before treating any stream as VCDPA-regulated.
Step 3: Audit Your Data Minimization and Security Practices
Two foundational controller duties apply once the VCDPA governs your processing. First, you must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which it is processed, as those purposes were disclosed to the consumer. Va. Code Ann. section 59.1-578(A)(1). You cannot collect more than you need, and you cannot later repurpose data in ways that are materially incompatible with the original collection purpose without obtaining fresh consent.
Second, you must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data you process. Va. Code Ann. section 59.1-578(A)(3). The statute does not prescribe specific controls, but the reasonableness standard is calibrated to scale: a company processing five million sensitive records faces a higher burden than one managing 110,000 basic contact records.
Practical audit steps
- Map all personal data flows: what you collect, where it is stored, who can access it, and how long you retain it.
- Compare the collection scope against the disclosed purposes in your current privacy notice. Close any gap.
- Review your security program against the volume and sensitivity of data you hold. Document the assessment.
- Establish a data retention schedule so data is deleted when it is no longer necessary for disclosed purposes.

Step 4: Identify Sensitive Data and Obtain Opt-In Consent
The VCDPA's most important departure from a pure opt-out framework is its requirement for affirmative opt-IN consent before processing sensitive data. This consent must be obtained before processing begins, not offered as a post-collection opt-out. Va. Code Ann. section 59.1-578(A)(5).
The VCDPA defines sensitive data at section 59.1-575 to include: data revealing racial or ethnic origin; religious beliefs; mental or physical health diagnoses; sexual orientation; citizenship or immigration status; genetic data; biometric data processed for the purpose of uniquely identifying a natural person; personal data collected from a known child; and precise geolocation data (typically defined as latitude and longitude within a radius sufficient to identify a home address or other specific location).
Selling or offering to sell precise geolocation data is prohibited outright under Va. Code Ann. section 59.1-578(A)(6), regardless of consent. This is not one of the categories that opt-in consent unlocks: obtaining a valid opt-in for sensitive data does not permit the sale of precise geolocation data. If any part of your business model involves selling or licensing location data to a third party, that practice must stop entirely for Virginia consumers rather than being gated behind a consent flow.
Steps for sensitive data compliance
Go through each sensitive category and ask whether any of your products, analytics tools, advertising platforms, health questionnaires, or user profiles touch that category. The list is broader than many businesses expect: a wellness app that asks users to log mental health symptoms, a retail loyalty program that collects precise GPS coordinates, and an HR system that records religious affiliation all involve sensitive data.
For each sensitive data stream you identify, you need a granular, informed opt-in consent mechanism that: (1) clearly describes what sensitive data is being collected; (2) explains the purpose of processing; and (3) provides a genuine choice to decline without losing the core service (to the extent possible). Bundled consent or pre-checked boxes will not satisfy an affirmative opt-in standard.
Known-child data carries duties beyond consent
For sensitive data concerning a known child, the VCDPA requires processing in accordance with COPPA's verifiable parental consent rules rather than a generic opt-in. Va. Code Ann. section 59.1-578(A)(5).
Consent is only the gate. A 2026 amendment (2026, c. 820) added Va. Code Ann. section 59.1-578(F), which layers standalone limits on top of it. Subject to obtaining consent from the child's parent or legal guardian under COPPA, a controller may not process personal data collected from a known child:
- for targeted advertising, for the sale of that data, or for profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer;
- unless the processing is reasonably necessary to provide the online service, product, or feature;
- for any purpose other than the one disclosed when the data was collected, or one reasonably necessary for and compatible with that disclosed purpose; or
- for longer than is reasonably necessary to provide the online service, product, or feature.
Precise geolocation has its own rule. A controller may not collect precise geolocation data from a known child unless that data is reasonably necessary to provide the online service, product, or feature, and then only for the time necessary to provide it, and only while giving the child a signal that the collection is occurring, which must remain available to the child for the entire duration of the collection. Va. Code Ann. section 59.1-578(F)(2).
These duties are independent of the exemption analysis in Step 2. A child-directed offering also triggers its own data protection assessment under section 59.1-580(B), covered in Step 6.
Step 5: Update Your Privacy Notice
Controllers must make their privacy notice reasonably accessible and clear. Va. Code Ann. section 59.1-578(C) specifies that the notice must disclose: (1) the categories of personal data the controller processes; (2) the purpose or purposes of that processing; (3) how consumers may exercise their five rights under the VCDPA and how to appeal a denied request; (4) the categories of personal data the controller shares with third parties; and (5) the categories of third parties with whom the controller shares personal data.
If you sell personal data to third parties or process it for targeted advertising, you must also add a clear and conspicuous disclosure of that practice and the manner in which a consumer may exercise their opt-out right. Va. Code Ann. section 59.1-578(D). A buried one-line sentence in a 10,000-word privacy policy is unlikely to satisfy "clear and conspicuous."
Privacy notice checklist
| Required element | Covered? |
|---|---|
| Categories of personal data processed | |
| Purposes of processing | |
| How to submit a consumer rights request | |
| How to appeal a denied request (with AG contact) | |
| Categories of data shared with third parties | |
| Categories of third parties receiving data | |
| Sale or targeted-advertising disclosure (if applicable) | |
| Opt-out mechanism for sale and targeted advertising (if applicable) |
Review your notice against each row above. If any cell is blank, update the notice before your next compliance review date.
For a detailed walkthrough of each consumer right, including access, correction, deletion, portability, and opt-out, see the consumer rights under the VCDPA spoke.
Step 6: Conduct and Document Data Protection Assessments
Written Data Protection Assessments (DPAs) are mandatory for five categories of processing under Va. Code Ann. section 59.1-580(A):
- Processing personal data for targeted advertising
- Selling personal data
- Processing personal data for profiling that produces legal or other similarly significant effects on consumers
- Processing sensitive data
- Any other processing that presents a reasonably foreseeable heightened risk of harm to consumers
A sixth, independent trigger sits outside subsection A. Under Va. Code Ann. section 59.1-580(B), any controller that offers an online service, product, or feature directed to consumers the controller has actual knowledge are children must conduct a DPA for that service, product, or feature, addressing its purpose, the categories of known children's personal data it processes, and the purposes for which that data is processed. This applies even when the offering does not independently trigger one of the five categories above, so a child-directed product with no targeted advertising, no data sales, and no profiling can still require its own DPA.
Each assessment must document the benefits flowing from the processing activity, the potential risks to consumer rights and interests, and the safeguards in place to reduce those risks. The statute directs controllers to weigh benefits against risks in light of the use of de-identified data, consumer expectations, and the context of the processing relationship. Va. Code Ann. section 59.1-580(C).
Scope and timing rules
One assessment may cover a comparable set of processing operations rather than requiring a separate document for every individual campaign or data-sharing agreement. However, the DPA requirement applies only to processing activities created or generated after January 1, 2023. Va. Code Ann. section 59.1-580(G). You do not need to retroactively assess processing activities that were fully set up before that date, but any new or materially modified processing since then requires an assessment.
AG demand and confidentiality
The Attorney General may request completed assessments via a civil investigative demand to evaluate compliance. Va. Code Ann. section 59.1-580(D). Completed assessments are confidential under Virginia's Freedom of Information Act and retain any attorney-client privilege or work-product protections that would otherwise apply. Keep completed DPAs on file and treat them as attorney-sensitive documents from the outset.
What a DPA should contain
A defensible DPA typically includes: a description of the processing activity and the data involved; the legitimate business purpose or benefit; a risk analysis identifying the types of consumer harm that could result (financial, reputational, physical, discriminatory); the safeguards and mitigating controls in place; and a conclusion weighing whether benefits outweigh residual risks. There is no prescribed format in the statute, but the AG's ability to demand these documents means vague or boilerplate assessments carry real risk.

Step 7: Execute Processor Contracts
Every vendor, service provider, or other third party that processes personal data on your behalf must be governed by a binding written controller-processor contract before they begin processing. Va. Code Ann. section 59.1-579(B).
The contract must be binding and must clearly set forth five scope elements: the instructions for processing data; the nature and purpose of the processing; the type of data subject to processing; the duration of the processing; and the rights and obligations of both parties. All five are statutory requirements, and a contract that defines the work but never fixes its duration or allocates the parties' rights and obligations is incomplete on its face.
Mandatory contract provisions
Beyond the scope elements, the contract must require the processor to:
- Maintain confidentiality: All personnel who access personal data must be subject to binding confidentiality obligations.
- Delete or return data: Upon termination or request, the processor must delete or return all personal data to the controller.
- Demonstrate compliance: The processor must provide information sufficient for the controller to verify its compliance with the VCDPA.
- Cooperate with audits: The processor must submit to and cooperate with reasonable audits or independent third-party assessments of its practices.
- Flow down to sub-processors: Any sub-processors the processor engages must be bound by a written contract meeting equivalent obligations.
Vendor inventory
Before drafting or updating contracts, build a complete vendor inventory. List every third party that touches personal data you control: cloud infrastructure providers, analytics vendors, marketing platforms, payment processors, CRM tools, and any SaaS platforms that ingest data from your systems. Each relationship either qualifies as a processor (acting under your instructions) or a third party (with its own controller role), and the distinction determines whether a DPA or a data-sharing agreement is the correct instrument.
Step 8: Build Consumer Request Workflows and Appeal Mechanisms
Virginia consumers have five rights under the VCDPA: the right to know what personal data a controller holds about them; the right to correct inaccuracies; the right to delete their data; the right to obtain a portable copy of their data; and the right to opt out of sale, targeted advertising, and certain profiling. Va. Code Ann. section 59.1-577.
Controllers must respond to authenticated requests within 45 days. One extension of up to an additional 45 days is permitted if the controller notifies the consumer within the initial period that additional time is needed and explains why.
The appeal requirement
If you deny a request, you must inform the consumer of the reason and provide them with a process to appeal the decision. If the appeal is also denied, you must provide the consumer with information about how to contact the Attorney General to submit a complaint. This two-tier appeal chain must be described in your privacy notice under the "how to exercise rights" section required by section 59.1-578(C).
The appeal mechanism is not optional and is not satisfied by a generic "contact us" email address. Build a dedicated, documented appeals process with written denials, documented reasoning, and a clear AG referral step.
For full detail on each right, request timelines, and how to authenticate requests without overcollecting identity data, see the companion consumer rights under the VCDPA spoke.
Step 9: Understand Enforcement, the Cure Period, and Penalty Exposure
The VCDPA is enforced exclusively by the Virginia Attorney General. There is no private right of action. Va. Code Ann. section 59.1-584(A) and (E). No individual consumer, plaintiff's law firm, or class can sue your company for a VCDPA violation. That said, AG-only enforcement is not a safe harbor.
The 30-day cure period
Before filing an enforcement action, the AG must give a controller or processor 30 days' written notice identifying the specific provisions alleged to have been violated. Va. Code Ann. section 59.1-584(B). If you cure the violation within that 30-day window and provide written confirmation of the cure, the AG may not bring an enforcement action for that specific violation.
The cure period does not have a sunset date in the current statute. Unlike some other state privacy laws that phase out cure periods after a fixed number of years, Virginia's cure period remains available as of the current text of the law.
Penalty exposure
If the 30-day cure period expires without a satisfactory cure, the AG may seek: injunctions requiring compliance; civil penalties of up to $7,500 per violation; and recovery of reasonable expenses including attorney fees. Va. Code Ann. section 59.1-584(C) and (D).
The per-violation structure is significant. A single marketing campaign that processes sensitive data without opt-in consent for 50,000 Virginia consumers does not produce one violation; depending on how the AG counts violations, it could produce 50,000. Build compliance before you receive notice, not after.
Compliance program elements
- Designate an internal owner for VCDPA compliance with documented authority and budget.
- Maintain a compliance calendar: annual applicability threshold review, privacy notice review, DPA review for new processing activities, and vendor contract audit.
- Train staff who handle personal data on the sensitive-data consent rules, the consumer request workflows, and escalation procedures.
- Keep all DPAs, processor contracts, and consent records in a documented, retrievable system. If the AG sends a civil investigative demand, you need to produce these within a short window.
For the full Virginia data privacy law overview, including how the VCDPA compares to other state privacy laws, see the parent page.
Related guides
- What Is the VCDPA? Virginia's Data Privacy Law Explained
- VCDPA Consumer Rights: Exercise Your Virginia Privacy Rights
- Virginia Data Privacy Laws: VCDPA Consumer Rights Guide (2026)
- Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026)
- US State Privacy Laws Comparison Chart (2026)
More Virginia Laws
Frequently Asked Questions
Does the VCDPA apply to nonprofits?
No. Nonprofit organizations are expressly exempt from the VCDPA under Va. Code Ann. section 59.1-576(B). A nonprofit that processes personal data of 500,000 Virginia residents has no obligations under the statute. Note, however, that a nonprofit may still have obligations under HIPAA, COPPA, or other federal laws depending on the data it handles.
Is children's data exempt from the VCDPA because COPPA already covers it?
No. The data-category exemptions in Va. Code Ann. section 59.1-576(C) do not include children's or COPPA-regulated data. Section 59.1-576(D) only provides that a controller complying with COPPA's verifiable parental consent requirements is deemed compliant with any parental consent obligation under the chapter, which is a safe harbor for that one duty. Personal data collected from a known child is sensitive data under section 59.1-575, is subject to the standalone advertising, sale, profiling, purpose-limitation, retention, and precise geolocation limits of section 59.1-578(F), and independently triggers a data protection assessment under section 59.1-580(B).
What is the difference between a controller and a processor under the VCDPA?
A controller is the entity that determines the purposes and means of processing personal data. A processor handles personal data solely on behalf of and under the instructions of a controller. The distinction matters because controllers carry the primary compliance burden: drafting the privacy notice, obtaining sensitive-data consent, conducting data protection assessments, and honoring consumer requests. Processors must be governed by a written contract meeting Va. Code Ann. section 59.1-579(B) and can only process data as instructed by the controller.
When does the VCDPA require opt-in consent versus opt-out?
Opt-IN affirmative consent is required before processing sensitive data, as defined in Va. Code Ann. section 59.1-575 (racial or ethnic origin, health diagnoses, biometrics, precise geolocation, children's data, and several other categories). Opt-OUT rights apply to three specific uses: targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects. For all other processing, neither opt-in nor opt-out consent is required as long as the processing is consistent with disclosed purposes.
Is there a private right of action under the VCDPA?
No. Va. Code Ann. section 59.1-584(E) states that the VCDPA shall not be construed as providing the basis for a private right of action. Only the Virginia Attorney General can bring enforcement actions. This is a meaningful structural difference from some state biometric laws (like Illinois BIPA), which allow individuals to sue directly and have generated hundreds of millions of dollars in class action settlements.
How long does the VCDPA cure period last, and will it expire?
The cure period is 30 days from the AG's written notice of a violation. As of the statute's current text, the cure period does not have a scheduled sunset date. This distinguishes Virginia from some states (such as Connecticut and Colorado) whose privacy laws included cure periods only for a limited number of years. Virginia's cure period remains in effect unless the General Assembly amends the statute.
What records do I need to keep for a VCDPA data protection assessment?
The VCDPA does not prescribe a specific DPA format. At minimum, an assessment should document the processing activity, the benefits of processing, the potential risks to consumers, the safeguards applied, and a written conclusion weighing benefits against residual risks. The Attorney General may request assessments via a civil investigative demand under section 59.1-580(D). Completed assessments are confidential under Virginia's Freedom of Information Act and retain applicable attorney-client privilege, so involvement of legal counsel during drafting is advisable.
Are employee records exempt from the VCDPA?
Yes. Personal data processed solely in the context of an employment relationship, including job applicant data, current employee data, emergency contact information, and data necessary for benefits administration, falls within the data-category exemptions of Va. Code Ann. section 59.1-576(C). Employers do not owe their Virginia employees VCDPA rights (access, correction, deletion, portability, or opt-out) for data processed in that employment context.
Do data protection assessment requirements apply to processing that started before 2023?
No. Va. Code Ann. section 59.1-580(G) provides that the DPA requirements are not retroactive and apply only to processing activities created or generated after January 1, 2023. If a processing activity was fully established before that date and has not been materially modified, no DPA is required for that legacy activity. New or materially changed processing activities after January 1, 2023, require an assessment regardless of when the underlying data was collected.
Updates
Corrected the exemptions section: children's data is not exempt from the VCDPA. Added the known-child processing and precise geolocation duties under Va. Code Ann. section 59.1-578(F), and completed the list of mandatory processor-contract terms under section 59.1-579(B).
Removed a sensitive-data category (gender identity) that is not in the VCDPA's statutory definition, added two current-law obligations the checklist had omitted (the outright ban on selling precise geolocation data and the separate data-protection-assessment requirement for services directed to children), and corrected the cited statute range to drop a repealed section.
Independently fact-checked against the cited primary sources
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Virginia, Title 59.1: Trade and Commerce
§ 59.1-578Data controller responsibilities; transparencyIn forcecited in 5 of our articles
A. A controller shall: 1. Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; 2. Except as otherwise provided in this chapter, not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; 3. Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue; 4. Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Virginia Data Privacy Laws: VCDPA Consumer Rights Guide (2026), Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026), VCDPA Consumer Rights: Exercise Your Virginia Privacy Rights
§ 59.1-576Scope; exemptionsIn forcecited in 5 of our articles
A. This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. B. This chapter shall not apply to any (i) body, authority, board, bureau, commission, district, or agency of the Commonwealth or of any political subdivision of the Commonwealth; (ii) financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.); (iii) covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the Health Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Virginia Employee Monitoring Laws: Workplace Surveillance and Social Media (2026), What Is the VCDPA? Virginia's Data Privacy Law Explained
§ 59.1-580Data protection assessmentsIn forcecited in 4 of our articles
A. A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data: 1. The processing of personal data for purposes of targeted advertising; 2. The sale of personal data; 3. The processing of personal data for purposes of profiling, where such profiling presents a reasonably foreseeable risk of (i) unfair or deceptive treatment of, or unlawful disparate impact on, consumers; (ii) financial, physical, or reputational injury to consumers; (iii) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; or (iv) other substantial injury to consumers; 4. The processing of sensitive data; and 5. Any processing activities involving personal data that present a heightened risk of harm to consumers. B.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
§ 59.1-579Responsibility according to role; controller and processorIn forcecited in 2 of our articles
A. A processor shall adhere to the instructions of a controller and shall assist the controller in meeting its obligations under this chapter. Such assistance shall include: 1. Taking into account the nature of processing and the information available to the processor, by appropriate technical and organizational measures, insofar as this is reasonably practicable, to fulfill the controller's obligation to respond to consumer rights requests pursuant to § 59.1-577. 2. Taking into account the nature of processing and the information available to the processor, by assisting the controller in meeting the controller's obligations in relation to the security of processing the personal data and in relation to the notification of a breach of security of the system of the processor pursuant to § 18.2-186.6 in order to meet the controller's obligations. 3. Providing necessary information to enable the controller to conduct and document data protection assessments pursuant to § 59.1-580. B. A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
§ 59.1-577Personal data rights; consumersIn forcecited in 7 of our articles
A. A consumer may invoke the consumer rights authorized pursuant to this subsection at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the known child. A controller shall comply with an authenticated consumer request to exercise the right: 1. To confirm whether or not a controller is processing the consumer's personal data and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at law.lis.virginia.gov
Cited in 1 court opinionsMost recently applied by a court: 2025
Leading cases:
- Eweka (District Court, E.D. Virginia 2025)“…e the VCDPA protects consumer’s private personal data, see Va Code Ann. § 59.1-577, it explicitly gives Virginia’s Attorne…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to Submit a Data Deletion Request (2026), Virginia Ring Doorbell Laws: What You Need to Know in 2026
§ 59.1-584Enforcement; civil penalty; expensesIn forcecited in 6 of our articles
A. The Attorney General shall have exclusive authority to enforce the provisions of this chapter. B. Prior to initiating any action under this chapter, the Attorney General shall provide a controller or processor 30 days' written notice identifying the specific provisions of this chapter the Attorney General alleges have been or are being violated. If within the 30-day period the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action shall be initiated against the controller or processor. C. If a controller or processor continues to violate this chapter following the cure period in subsection B or breaches an express written statement provided to the Attorney General under that subsection, the Attorney General may initiate an action in the name of the Commonwealth and may seek an injunction to restrain any violations of this chapter and civil penalties of up to $7,500 for each violation under this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Cited in 1 court opinionsMost recently applied by a court: 2025
Leading cases:
- Eweka (District Court, E.D. Virginia 2025)“…neral the “exclusive authority” to enforce its provisions, Va. Code Ann. § 59.1-584. Second, Plaintiff has not plausi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 59.1-575DefinitionsIn forcecited in 8 of our articles
As used in this chapter, unless the context requires a different meaning: "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means (i) ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; (ii) control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (iii) the power to exercise controlling influence over the management of a company. "Authenticate" means verifying through reasonable means that the consumer, entitled to exercise his consumer rights in § 59.1-577, is the same consumer exercising such consumer rights with respect to the personal data at issue. "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Virginia Smart Glasses Recording Laws
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Va. Code Ann. section 59.1-575 (VCDPA Definitions)(law.lis.virginia.gov).gov
- Va. Code Ann. section 59.1-576 (VCDPA Scope and Exemptions)(law.lis.virginia.gov).gov
- Va. Code Ann. section 59.1-577 (Consumer Rights)(law.lis.virginia.gov).gov
- Va. Code Ann. section 59.1-578 (Controller Duties; Transparency)(law.lis.virginia.gov).gov
- Va. Code Ann. section 59.1-579 (Processor Obligations; Contracts)(law.lis.virginia.gov).gov
- Va. Code Ann. section 59.1-580 (Data Protection Assessments)(law.lis.virginia.gov).gov
- Va. Code Ann. section 59.1-584 (Enforcement; Civil Penalty)(law.lis.virginia.gov).gov