EnglishEspañol
Virginia flag

Virginia

What Is the VCDPA? Virginia's Data Privacy Law Explained

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 11 primary sources cited on this page. How we verify our legal content

What Is the VCDPA? Virginia's Data Privacy Law Explained

Frequently Asked Questions

What is the VCDPA?

The VCDPA, or Virginia Consumer Data Protection Act, is Virginia's comprehensive data privacy law codified at Va. Code Ann. §§ 59.1-575 through 59.1-584. Signed in March 2021 and effective January 1, 2023, it gives Virginia residents rights over their personal data and requires covered businesses to be transparent about collection and use. Virginia was the second state, after California, to enact a law of this scope.

Who does the VCDPA apply to?

The VCDPA applies to for-profit businesses that do business in Virginia or target Virginia residents and meet one of two thresholds: they process personal data of at least 100,000 Virginia consumers per year, OR they process data of at least 25,000 Virginia consumers and derive more than 50% of gross revenue from selling personal data. There is no minimum revenue threshold. Nonprofits, HIPAA-covered entities, GLBA-regulated financial institutions, government bodies, and data already regulated by FERPA, FCRA, or the DPPA are exempt.

What rights do Virginia consumers have under the VCDPA?

Virginia residents have five rights: the right to access and confirm whether their data is being processed, the right to correct inaccurate data, the right to delete their personal data, the right to receive a portable copy, and the right to opt out of targeted advertising, personal data sales, and profiling that produces a legal or similarly significant effect. Controllers must respond within 45 days, with one possible extension of 45 more days with notice.

What is the penalty for violating the VCDPA?

Civil penalties can reach up to $7,500 per violation. The Attorney General can also seek injunctive relief and recover reasonable attorney fees and expenses. Before filing any action, the AG must provide written notice of the violation and a 30-day opportunity to cure. If the business cures the violation and submits a written statement of compliance, no enforcement action can proceed for that violation.

Does the VCDPA have a private right of action?

No. Va. Code Ann. § 59.1-584 expressly prohibits any private right of action under the VCDPA. Enforcement is exclusive to the Virginia Attorney General. Individual consumers cannot sue businesses directly for VCDPA violations, regardless of how serious the violation. This is one of the sharpest contrasts with the CCPA, which provides a limited private right of action for data breaches.

How is the VCDPA different from the CCPA?

Three main differences stand out. First, the VCDPA requires affirmative opt-in consent before processing sensitive personal data; the CCPA and CPRA use an opt-out model. Second, the VCDPA has no private right of action, while the CCPA allows individual consumers to sue for data breaches. Third, the VCDPA has no minimum revenue threshold, so any for-profit entity processing 100,000 Virginia consumers' data is covered regardless of size; the CCPA applies only to businesses meeting one of three thresholds, including $25 million in annual revenue.

What counts as sensitive data under the VCDPA?

Under Va. Code Ann. § 59.1-575, sensitive data includes: personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to uniquely identify a person; personal data collected from a known child; and precise geolocation data. Controllers must obtain opt-in consent before processing any of these categories.

Has the VCDPA been amended since it was enacted?

Yes, several times. HB 707 (2024, effective January 1, 2025) added children's data protections under the VCDPA, including a prohibition on collecting precise geolocation data from children under 13 unless necessary for the service. SB 854 (2025, effective January 1, 2026) would have added social media restrictions for users under 16, limiting daily use to one hour unless a parent consents to more, but a federal court in the Eastern District of Virginia blocked enforcement with a preliminary injunction on February 27, 2026, and Virginia's appeal was pending as of this writing. Va. Code Ann. section 59.1-578 was also further amended in 2026 by SB 338. A separate 2025 law, SB 754 (effective July 1, 2025), protects reproductive and sexual health data, but does so by amending the Virginia Consumer Protection Act, not the VCDPA, and includes its own private right of action.

Updates

Corrected the exemption pinpoint to Va. Code Ann. § 59.1-576(B) and (C) and clarified that the FERPA, FCRA, and Driver’s Privacy Protection Act carve-outs are subsection C data-level exemptions rather than entity exemptions.

Corrected the year of the SB 854 social-media-minors amendment (it is a 2025 law, not 2024), noted that Va. Code section 59.1-578 was further amended in 2026 and softened the amendment-count claim to reflect that, and replaced a dead Attorney General press-release citation with a working archived copy.

Independently fact-checked against the cited primary sources

Corrected two false claims that SB 854's one-hour-per-day social media limit for minors under 16 is already in force. A federal court (E.D. Va.) granted NetChoice a preliminary injunction blocking enforcement on February 27, 2026, and Virginia's appeal was still pending; this matches the site's own sibling Virginia data privacy hub page.

Aligned the FAQ answer (and its FAQPage JSON-LD twin) with the body's correction: SB 854's one-hour-per-day minors limit is enjoined, not in force, as of the Feb 27, 2026 federal preliminary injunction.

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Va. Code Ann. §§ 59.1-575 through 59.1-584 — Virginia Consumer Data Protection Act, Chapter 53 of Title 59.1(law.lis.virginia.gov).gov
  2. Va. Code Ann. § 59.1-575 — Definitions (including 'sensitive data', 'personal data', 'sale of personal data')(law.lis.virginia.gov).gov
  3. Va. Code Ann. § 59.1-576 — Scope and Applicability (100,000/25,000 thresholds; exemptions)(law.lis.virginia.gov).gov
  4. Va. Code Ann. § 59.1-577 — Consumer Rights (access, correct, delete, portability, opt-out; 45-day response)(law.lis.virginia.gov).gov
  5. Va. Code Ann. § 59.1-578 — Controller Responsibilities (sensitive data opt-in consent; HB 707 children's data amendment)(law.lis.virginia.gov).gov
  6. Va. Code Ann. § 59.1-580 — Data Protection Assessments(law.lis.virginia.gov).gov
  7. Va. Code Ann. § 59.1-584 — Enforcement and Penalties (AG-exclusive; 30-day cure; $7,500 per violation; no private right of action)(law.lis.virginia.gov).gov
  8. Virginia LIS — SB 1392 (2021 Regular Session, VCDPA original enacting bill)(lis.virginia.gov).gov
  9. Virginia LIS — SB 754 (2025 Session, reproductive/sexual health data protections under VCPA, eff. July 1, 2025)(lis.virginia.gov).gov
  10. Virginia Attorney General: Data Privacy Day Statement, January 28, 2025 (AG Miyares on consumer data rights; archived, original 404s)(web.archive.org).gov
  11. Virginia Attorney General Jay Jones — Consumer Data Privacy Rights Reminder(oag.state.va.us).gov
Share: