AuditXYZ

Compliance Framework

Virginia Consumer Data Protection Act (VCDPA)

The VCDPA is Virginia's comprehensive consumer data protection law, granting residents rights over their personal data and imposing obligations on businesses regarding data processing, consent, and protection assessments.

$5,000–$75,0002–6 months2021 (enforced January 1, 2023)
Issuing BodyVirginia General Assembly
First Published2021-03-02
Latest Version2021 (enforced January 1, 2023)
Typical Cost$5,000–$75,000
Typical Timeline2–6 months
Audit RequiredNo
Audit FrequencyNo mandatory external audit. Data protection assessments required for targeted advertising, profiling, sale of personal data, and sensitive data processing.
Geographyus-virginia

VCDPA: The Complete Guide

The Virginia Consumer Data Protection Act was the second comprehensive state privacy law enacted in the United States, signed into law in March 2021 and effective January 1, 2023. The VCDPA established the template for a wave of similar state privacy laws: controller-processor framework, risk-based data protection assessments, opt-out rights for targeted advertising, and AG-only enforcement without a private right of action. Understanding the VCDPA is essential not just for Virginia compliance but for navigating the broader US state privacy law landscape, where many states have adopted the Virginia model with modifications.

What the VCDPA Is and Who Enforces It

The VCDPA was enacted by the Virginia General Assembly and codified at Virginia Code Section 59.1-571 et seq. Enforcement authority rests exclusively with the Virginia Attorney General, who may bring civil actions in the Circuit Court of the City of Richmond. There is no private right of action under the VCDPA — consumers cannot sue businesses directly for violations.

Before initiating enforcement, the Attorney General must provide the business with a 30-day written cure notice identifying the alleged violation. If the business cures the violation within 30 days, no enforcement proceeds. Civil penalties reach $7,500 per violation of the VCDPA.

Virginia has been monitoring its law's implementation since the January 2023 effective date. The AG's office has issued informal guidance and engaged with industry on specific interpretation questions. By mid-2025, Virginia had not initiated high-profile public enforcement actions, but the cure period framework has been used to address identified violations through informal remediation.

Territorial and Material Scope

The VCDPA applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and during a calendar year either:

  • Control or process the personal data of at least 100,000 Virginia consumers, or
  • Control or process the data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data.

Virginia's thresholds focus on Virginia consumers specifically (not a national consumer total), which means the threshold is harder to meet for businesses with limited Virginia exposure but easy to meet for businesses with large, national consumer datasets.

Significant exemptions apply:

  • Entities and data regulated by HIPAA, the Gramm-Leach-Bliley Act (GLBA), FERPA, and several other federal laws.
  • Nonprofit organizations and institutions of higher education.
  • State government entities.
  • Financial institutions and data covered by GLBA.

These exemptions mean many healthcare entities, financial services firms, and nonprofits face reduced or modified VCDPA obligations.

Controller-Processor Framework

The VCDPA explicitly adopts a GDPR-like controller-processor framework:

Controllers determine the purpose and means of processing personal data. They bear the primary compliance burden including implementing privacy notices, responding to consumer rights requests, conducting assessments, and executing processor contracts.

Processors process personal data on behalf of controllers under written contracts (data processing agreements). Controllers must enter into contracts with processors limiting processing to specified purposes, requiring confidentiality, and obligating processors to assist controllers with compliance. Processors have independent obligations including data security and demonstrating deletion or return of data.

This two-tier structure differs from the CCPA's business/service provider framework but achieves similar results in defining who bears compliance responsibility for shared data.

Five Consumer Rights

The VCDPA grants Virginia consumers five core rights:

  1. Right to access — Confirm whether a controller is processing personal data and access that data.
  2. Right to correct — Correct inaccuracies in personal data.
  3. Right to delete — Delete personal data, including personal data provided by or obtained about the consumer.
  4. Right to obtain a copy — Receive personal data in a portable and readily usable format where technically feasible.
  5. Right to opt out — Opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects on the consumer.

Controllers must respond to consumer rights requests within 45 days, with a 45-day extension available where reasonably necessary with notice to the consumer. Where a request is denied, the consumer must receive a notice of reasons and an appeals process. Controllers must respond to appeals within 60 days.

Sensitive Data Processing

The VCDPA defines sensitive personal data to include: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation or gender identity, immigration status, financial data, genetic or biometric data used for unique identification, data of known children, and precise geolocation.

Processing sensitive data requires prior opt-in consent from the consumer. Controllers must present a clear notice and opportunity to consent before processing commences. This is a distinct deviation from CCPA's default opt-out model and brings the VCDPA closer to GDPR's approach for special categories.

Data Protection Assessments

Controllers must conduct data protection assessments for processing activities that present a heightened risk, specifically:

  • Targeted advertising.
  • Sale of personal data.
  • Profiling that presents a foreseeable risk of financial, physical, or reputational injury, or intrusion upon solitude.
  • Processing of sensitive data.

Assessments must weigh the benefits of the processing against potential privacy risks to consumers, taking into account available safeguards. The Virginia AG may request a relevant data protection assessment in connection with an investigation, and controllers must provide it.

Purpose Limitation and Data Minimization

The VCDPA requires controllers to:

  • Limit collection to personal data that is adequate, relevant, and reasonably necessary in relation to the disclosed purposes.
  • Not process personal data for purposes incompatible with the disclosed purposes without obtaining consent.
  • Provide consumers with a reasonably accessible, clear, and meaningful privacy notice disclosing categories of personal data processed, processing purposes, how rights may be exercised, categories of personal data shared with third parties, and categories of third parties.

These principles are analogous to GDPR's purpose limitation and data minimization obligations, though less prescriptively defined in the VCDPA.

VCDPA vs. GDPR and Sibling State Laws

The VCDPA shares approximately 60% structural overlap with the GDPR and approximately 65% with the CCPA. Key points of comparison:

  • Lawful basis vs. opt-out — VCDPA uses opt-out for most processing (like CCPA) but requires opt-in for sensitive data (like GDPR special categories).
  • Controller-processor — VCDPA adopts this structure explicitly; CCPA uses business/service provider instead.
  • No private right of action — Unlike CCPA's data breach private right of action, VCDPA enforcement is AG-only.
  • Assessments — VCDPA's data protection assessments parallel GDPR DPIAs in requiring a documented risk-benefit analysis.

Among US state laws, the CPA (Colorado) shares approximately 80% overlap and adds universal opt-out mechanism (GPC) recognition. The CTDPA also mirrors VCDPA at approximately 85% overlap. The CPRA is California's more GDPR-aligned counterpart, adding data minimization, cybersecurity audits, and the CPPA enforcement body.

For organizations managing multi-state US privacy compliance, building on VCDPA compliance is an efficient foundation — the Colorado, Connecticut, and Virginia laws share enough structure that a single unified compliance program can address all three with jurisdiction-specific adjustments.

Compliance Steps and Timeline

PhaseActivitiesTypical Duration
AssessmentApplicability analysis, data inventory, threshold calculation2-3 weeks
DesignPrivacy notice update, opt-out mechanisms, sensitive data consent3-5 weeks
ImplementationConsumer rights workflows, processor contracts, DPA execution3-6 weeks
OngoingData protection assessments, rights fulfillment, guidance monitoringContinuous

Key compliance steps:

  1. Determine applicability — Assess whether processing thresholds are met for Virginia consumers.
  2. Map data flows — Identify all personal and sensitive data processing activities.
  3. Consent mechanisms — Implement opt-in consent for sensitive data processing before processing begins.
  4. Consumer rights — Build request intake, identity verification, response, and appeals workflows meeting 45-day deadlines.
  5. Data protection assessments — Conduct and document assessments for targeted advertising, sale, profiling, and sensitive data processing.
  6. Processor contracts — Execute data processing agreements meeting VCDPA requirements with all processors.
  7. Privacy notice — Update to disclose categories, purposes, rights, and opt-out methods.

How Privacy Automation Helps

VCDPA compliance — especially consumer rights fulfillment across multiple US states simultaneously — is well-suited to automation. TruePrivacy covers the VCDPA alongside CCPA, CPRA, CPA, and CTDPA within its 12-plus framework portfolio. AI data discovery across 128-plus sources supports data mapping needed for accurate privacy disclosures and assessment scope definitions. DSR automation manages the 45-day response window across multiple simultaneous state law obligations.

At $5,000 per year with 24-hour onboarding and an AuditXYZ score of 88/100, TruePrivacy is a practical fit for mid-market organizations managing a growing portfolio of US state privacy laws. See best privacy management tools and the TruePrivacy vs OneTrust comparison.

Frequently Asked Questions

How does the VCDPA define "sale" of personal data? The VCDPA defines "sale" as the exchange of personal data for monetary consideration by the controller to a third party. This is narrower than the CCPA/CPRA definition, which also includes non-monetary consideration and sharing for cross-context behavioral advertising. Under the VCDPA, providing data to a third-party advertiser in exchange for ad targeting services may not constitute a "sale" — instead, it may be captured under "targeted advertising" which triggers the opt-out right separately.

Do we need separate consent for each category of sensitive data? The VCDPA requires consent before processing sensitive personal data but does not mandate category-by-category separate consents the way Korea's PIPA does. A single consent notice covering all sensitive categories being processed is generally acceptable provided the notice clearly identifies what sensitive data is being collected and why. Bundling sensitive data consent with general terms of service in a way that obscures the sensitive data processing is not sufficient.

What must a VCDPA data protection assessment include? The VCDPA does not prescribe a specific format, but assessments must weigh the benefits of the processing against the privacy risks to consumers, considering factors including the type of data involved, the context of the processing, the nature of the risk, and available safeguards. The AG's guidance points to a documented, analytical record of this weighing process as the expected output.

Does the 30-day cure period still apply? Yes, the VCDPA includes a 30-day cure period without a sunset date — it is not limited in time the way California's cure period was before being substantially curtailed under the CPRA. The AG must provide 30 days' written notice identifying the violation before initiating a civil action. If the violation is cured within 30 days, no action proceeds. This cure-first model provides meaningful protection against first-violation enforcement.

Are B2B data flows subject to VCDPA opt-out rights? The VCDPA defines "consumer" as a Virginia resident acting in an individual or household context — not in a commercial or employment context. This means that personal data processed in a purely B2B context (such as business contact information exchanged for professional purposes) is generally outside the VCDPA's consumer rights scope. However, if personal data crosses the line from purely commercial use into consumer profile building or targeted advertising, VCDPA obligations may be triggered.

Request a VCDPA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

CCPAMedium65%
GDPRMedium60%

Related frameworks

Get matched with a VCDPA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools