EnglishEspañol
Virginia flag

Virginia

VCDPA Compliance Checklist for Businesses (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 7 primary sources cited on this page. How we verify our legal content

VCDPA Compliance Checklist for Businesses (2026)

Frequently Asked Questions

Does the VCDPA apply to nonprofits?

No. Nonprofit organizations are expressly exempt from the VCDPA under Va. Code Ann. section 59.1-576(B). A nonprofit that processes personal data of 500,000 Virginia residents has no obligations under the statute. Note, however, that a nonprofit may still have obligations under HIPAA, COPPA, or other federal laws depending on the data it handles.

Is children's data exempt from the VCDPA because COPPA already covers it?

No. The data-category exemptions in Va. Code Ann. section 59.1-576(C) do not include children's or COPPA-regulated data. Section 59.1-576(D) only provides that a controller complying with COPPA's verifiable parental consent requirements is deemed compliant with any parental consent obligation under the chapter, which is a safe harbor for that one duty. Personal data collected from a known child is sensitive data under section 59.1-575, is subject to the standalone advertising, sale, profiling, purpose-limitation, retention, and precise geolocation limits of section 59.1-578(F), and independently triggers a data protection assessment under section 59.1-580(B).

What is the difference between a controller and a processor under the VCDPA?

A controller is the entity that determines the purposes and means of processing personal data. A processor handles personal data solely on behalf of and under the instructions of a controller. The distinction matters because controllers carry the primary compliance burden: drafting the privacy notice, obtaining sensitive-data consent, conducting data protection assessments, and honoring consumer requests. Processors must be governed by a written contract meeting Va. Code Ann. section 59.1-579(B) and can only process data as instructed by the controller.

When does the VCDPA require opt-in consent versus opt-out?

Opt-IN affirmative consent is required before processing sensitive data, as defined in Va. Code Ann. section 59.1-575 (racial or ethnic origin, health diagnoses, biometrics, precise geolocation, children's data, and several other categories). Opt-OUT rights apply to three specific uses: targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects. For all other processing, neither opt-in nor opt-out consent is required as long as the processing is consistent with disclosed purposes.

Is there a private right of action under the VCDPA?

No. Va. Code Ann. section 59.1-584(E) states that the VCDPA shall not be construed as providing the basis for a private right of action. Only the Virginia Attorney General can bring enforcement actions. This is a meaningful structural difference from some state biometric laws (like Illinois BIPA), which allow individuals to sue directly and have generated hundreds of millions of dollars in class action settlements.

How long does the VCDPA cure period last, and will it expire?

The cure period is 30 days from the AG's written notice of a violation. As of the statute's current text, the cure period does not have a scheduled sunset date. This distinguishes Virginia from some states (such as Connecticut and Colorado) whose privacy laws included cure periods only for a limited number of years. Virginia's cure period remains in effect unless the General Assembly amends the statute.

What records do I need to keep for a VCDPA data protection assessment?

The VCDPA does not prescribe a specific DPA format. At minimum, an assessment should document the processing activity, the benefits of processing, the potential risks to consumers, the safeguards applied, and a written conclusion weighing benefits against residual risks. The Attorney General may request assessments via a civil investigative demand under section 59.1-580(D). Completed assessments are confidential under Virginia's Freedom of Information Act and retain applicable attorney-client privilege, so involvement of legal counsel during drafting is advisable.

Are employee records exempt from the VCDPA?

Yes. Personal data processed solely in the context of an employment relationship, including job applicant data, current employee data, emergency contact information, and data necessary for benefits administration, falls within the data-category exemptions of Va. Code Ann. section 59.1-576(C). Employers do not owe their Virginia employees VCDPA rights (access, correction, deletion, portability, or opt-out) for data processed in that employment context.

Do data protection assessment requirements apply to processing that started before 2023?

No. Va. Code Ann. section 59.1-580(G) provides that the DPA requirements are not retroactive and apply only to processing activities created or generated after January 1, 2023. If a processing activity was fully established before that date and has not been materially modified, no DPA is required for that legacy activity. New or materially changed processing activities after January 1, 2023, require an assessment regardless of when the underlying data was collected.

Updates

Corrected the exemptions section: children's data is not exempt from the VCDPA. Added the known-child processing and precise geolocation duties under Va. Code Ann. section 59.1-578(F), and completed the list of mandatory processor-contract terms under section 59.1-579(B).

Removed a sensitive-data category (gender identity) that is not in the VCDPA's statutory definition, added two current-law obligations the checklist had omitted (the outright ban on selling precise geolocation data and the separate data-protection-assessment requirement for services directed to children), and corrected the cited statute range to drop a repealed section.

Independently fact-checked against the cited primary sources

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Va. Code Ann. section 59.1-575 (VCDPA Definitions)(law.lis.virginia.gov).gov
  2. Va. Code Ann. section 59.1-576 (VCDPA Scope and Exemptions)(law.lis.virginia.gov).gov
  3. Va. Code Ann. section 59.1-577 (Consumer Rights)(law.lis.virginia.gov).gov
  4. Va. Code Ann. section 59.1-578 (Controller Duties; Transparency)(law.lis.virginia.gov).gov
  5. Va. Code Ann. section 59.1-579 (Processor Obligations; Contracts)(law.lis.virginia.gov).gov
  6. Va. Code Ann. section 59.1-580 (Data Protection Assessments)(law.lis.virginia.gov).gov
  7. Va. Code Ann. section 59.1-584 (Enforcement; Civil Penalty)(law.lis.virginia.gov).gov
Share: