Virginia Consumer Data Protection Act (VCDPA) 2026 Guide
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
Quick answer
The Virginia Consumer Data Protection Act (VCDPA) 2026 update is straightforward: the core VCDPA has applied since January 1, 2023, and SB 338 adds a July 1, 2026 ban on selling or offering to sell precise geolocation data. The law applies to businesses processing data of 100,000+ Virginia consumers (or 25,000+ with 50%+ revenue from data sales), carries $7,500-per-violation penalties, includes a permanent 30-day cure period, and grants 8 consumer rights.
What Is the Virginia Consumer Data Protection Act?
The Virginia Consumer Data Protection Act (VCDPA) was the second comprehensive state privacy law in the United States, signed into law on March 2, 2021, and effective since January 1, 2023. Virginia’s framework has become the model for more than a dozen subsequent state privacy laws, making the VCDPA one of the most influential pieces of data privacy legislation in the country.
Unlike California’s CCPA/CPRA, which leans consumer-friendly, the VCDPA strikes a balance between protecting consumer rights and maintaining a business-friendly regulatory environment — notably through its permanent 30-day cure period and the absence of a private right of action.
Use our Privacy Law Calculator to check whether the VCDPA applies to your organization.
Related 2026 compliance routes
- Compare Virginia’s SB 338 geolocation-sale ban with the stricter Oregon Consumer Privacy Act compliance guide, which covers Oregon’s no-cure-period model, nonprofit coverage, and GPC obligations.
- Map VCDPA profiling assessments against broader AI data privacy state-law compliance duties when automated systems use consumer data for significant decisions.
- If your multi-state program also includes California, check the CCPA cybersecurity audit requirements for 2026 so risk-assessment and audit calendars stay aligned.
VCDPA 2026 at a Glance
- Effective date: January 1, 2023.
- Who must comply: Controllers doing business in Virginia or targeting Virginia residents that process data for 100,000+ Virginia consumers, or 25,000+ consumers while deriving over 50% of gross revenue from personal data sales.
- Core rights: Access, correction, deletion, portability, opt out of sale, opt out of targeted advertising, opt out of certain profiling, and appeal.
- Response clock: 45 days for consumer rights requests, with one 45-day extension for complex requests.
- Enforcement: Virginia Attorney General only, with a permanent 30-day cure period and penalties up to $7,500 per violation.
- 2026 change: SB 338 was approved by the Governor on April 13, 2026 and takes effect July 1, 2026, adding a ban on selling or offering to sell consumers’ precise geolocation data. Sources checked May 27, 2026: SB 338 enrolled text and Virginia Code § 59.1-575 precise geolocation definition.
Who Does the VCDPA Apply To?
The VCDPA applies to entities that conduct business in Virginia or that produce products or services targeted to Virginia residents, and that meet either of the following thresholds (OR logic):
- Tier 1: Control or process personal data of at least 100,000 consumers during a calendar year; OR
- Tier 2: Control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.
The law applies to all entity types — for-profit and nonprofit alike. However, it exempts government entities, higher education institutions, entities subject to GLBA and HIPAA (at the entity level), and certain insurance-related entities.
Notably, the VCDPA counts “consumers” as Virginia residents acting in an individual or household context — it excludes individuals acting in a commercial or employment context.
Consumer Rights Under the VCDPA
Virginia residents have the following rights under the VCDPA:
- Right to access: Confirm whether a controller is processing their personal data and access that data.
- Right to correction: Correct inaccuracies in their personal data.
- Right to deletion: Delete personal data provided by or obtained about the consumer.
- Right to data portability: Obtain a copy of their personal data in a portable, readily usable format.
- Right to opt out of sale: Opt out of the sale of their personal data.
- Right to opt out of targeted advertising: Opt out of the processing of personal data for targeted advertising.
- Right to opt out of profiling: Opt out of profiling that produces legal or similarly significant effects.
- Right to appeal: Appeal a controller’s refusal to take action on a request, with the right to contact the AG if the appeal is denied.
Controllers must respond to consumer requests within 45 days, with a possible 45-day extension for complex requests. Requests must be fulfilled free of charge, up to twice per year.
Sensitive Data and Consent Requirements
The VCDPA requires opt-in consent before processing sensitive personal data. Sensitive data includes:
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic or biometric data processed for identification purposes
- Precise geolocation data within a 1,750-foot radius
- Personal data of known children under 13 (COPPA-aligned)
For consumers aged 13–17, the VCDPA requires consent before processing data for targeted advertising or the sale of personal data.
Enforcement and Penalties
The VCDPA is enforced exclusively by the Virginia Attorney General. There is no private right of action, meaning individual consumers cannot sue businesses for VCDPA violations.
Key enforcement details:
- 30-day cure period: The AG must provide written notice of a violation and allow 30 days to cure. This cure period is permanent — it has no sunset provision, unlike states such as Colorado (expired Jan 1, 2025) and Connecticut (eliminated).
- Penalties: Up to $7,500 per violation, plus reasonable attorney fees and costs.
- Injunctive relief: The AG can seek to restrain ongoing violations.
Virginia AG Jay Jones initially moved to prioritize enforcement of the VCDPA’s minor-protection provisions (SB 854) when they took effect January 1, 2026 — but that enforcement is now paused by a federal court (see the enforcement track record below).
VCDPA Enforcement Actions: The 2026 Track Record
Have any websites been fined for VCDPA violations? As of June 3, 2026, no controller or website has been publicly fined or named in a settlement under the VCDPA’s general consumer-data provisions. That is not the same as “no enforcement” — it reflects how Virginia’s framework is structured:
- Cure notices are private. The permanent 30-day cure period means the AG sends written notice and most controllers fix the issue within 30 days. Those notices are not published unless the controller fails to cure and the AG files suit, so resolved matters rarely surface in a press release.
- No private right of action. Only the Virginia AG can enforce the VCDPA, so there is no plaintiffs’-bar docket of consumer class actions — the opposite of Illinois BIPA or California’s limited CCPA data-breach private right.
- The Consumer Privacy Unit is active. The AG’s office accepts and investigates VCDPA complaints even though outcomes are usually non-public.
The one high-profile VCDPA enforcement push — the SB 854 minor social-media restrictions — is currently blocked by a federal court. On February 27, 2026, U.S. District Judge Patricia Tolliver Giles (Eastern District of Virginia) granted a preliminary injunction halting enforcement of the one-hour-per-day minor social-media limit while the case proceeds, finding the law likely violates the First Amendment because it is not content-neutral and fails strict scrutiny. The case is NetChoice v. Jones, No. 1:25-cv-2067 (E.D. Va.): NetChoice filed suit November 17, 2025, Virginia moved to dismiss January 26, 2026, and the injunction issued February 27, 2026. Sources retrieved June 3, 2026: NetChoice case page (NetChoice v. Jones) and the Syracuse Law Review case note.
June 2026 update — the SB 854 fight moved to appeal. Virginia did not accept the February ruling: on March 3, 2026 Attorney General Jay Jones appealed the preliminary injunction to the U.S. Court of Appeals for the Fourth Circuit, and the Commonwealth filed its opening appellate brief on April 15, 2026. As of June 21, 2026 the appeal is still pending and the one-hour minor social-media limit stays unenforced until the Fourth Circuit rules. Critically, the appeal touches only the SB 854 minor time-limit — it does not affect the VCDPA’s general consumer-data provisions, which remain in force the entire time. Sources retrieved June 21, 2026: Hunton Andrews Kurth, “Virginia Appeals Preliminary Injunction Barring Enforcement of Age-Based Restrictions” and the NetChoice v. Jones case page.
What this means for your business: the VCDPA’s core privacy duties — privacy notices, the eight consumer rights, sensitive-data opt-in consent, and data protection assessments — remain fully in force and enforceable. Only the SB 854 minor time-limit provision is enjoined. A clean compliance program plus a prompt response to any AG cure notice is still the practical way to avoid penalties. Compare Virginia’s quiet record with the public settlements under other state privacy law penalties — California, Texas, and Connecticut have all announced enforcement actions while Virginia’s record stays consistent with its business-friendly framing.
GPC and Universal Opt-Out
Unlike California, Colorado, Connecticut, and several other states, the VCDPA does not currently require businesses to honor universal opt-out mechanisms such as Global Privacy Control (GPC). However, businesses may voluntarily honor GPC signals as a best practice, and doing so can help with compliance in multi-state operations.
Check our GPC Compliance Checker to see which states require GPC recognition for your business.
2026 Updates: What’s New for the VCDPA
- Minor protections (SB 854, effective January 1, 2026 — enforcement enjoined): New social-media restrictions require platforms to use a neutral age-screen for users under 16 and limit those minors to one hour per day per service. Enforcement is on hold: a federal court preliminarily enjoined the time-limit provision on February 27, 2026 (NetChoice v. Jones, E.D. Va.) on First Amendment grounds.
- SB 338 — Geolocation data sale ban (signed April 13, 2026): Governor Abigail Spanberger approved SB 338 as Chapter 820, effective July 1, 2026. The amendment adds a controller responsibility not to sell or offer to sell precise geolocation data concerning a consumer. Virginia joins Maryland and Oregon in banning geolocation data sales, while still treating most other sensitive data through opt-in consent rather than an outright sale ban.
- Business-friendly cure period remains: The 30-day cure period has no sunset provision, making Virginia one of the more forgiving enforcement environments for compliant businesses.
- No GPC mandate yet: Virginia still does not require businesses to honor universal opt-out signals, though several other states with VCDPA-model laws have added this requirement.
VCDPA Amendment Timeline (2021–2026)
The VCDPA has been amended in nearly every Virginia General Assembly session since enactment. The full chapter text is consolidated at Code of Virginia, Title 59.1, Chapter 53 (retrieved May 18, 2026); the running explainer maintained by the Virginia Attorney General’s Office (PDF) tracks early changes.
- 2021 — Original enactment (HB 2307 / SB 1392): Signed by Governor Ralph Northam on March 2, 2021 with an effective date of January 1, 2023, making Virginia the second US state with a comprehensive consumer privacy law.
- 2022 — Pre-effective-date cleanup (HB 381, HB 714, SB 534): Approved by Governor Glenn Youngkin on April 11, 2022. Created a data-broker-friendly carve-out from the right to delete (controllers obtaining personal data from a source other than the consumer may opt the consumer out of further processing instead of deleting), redefined “nonprofit” to include political organizations and certain 501(c)(4) groups, and abolished the planned Consumer Privacy Fund. See Bloomberg Law’s VCDPA amendments overview and the IAPP recap (both retrieved May 18, 2026).
- 2024 — Children’s data (HB 707 / SB 361): Added stricter rules for processing personal data of known children. Controllers must obtain verifiable parental consent before collecting or processing a known child’s personal data or precise geolocation data and must minimize the categories and retention of that data.
- 2025 — Minor social media restrictions (SB 854): Took effect January 1, 2026. Requires social media platforms to use a neutral age-screening mechanism to identify users under 16 and to limit those minors’ use to one hour per day per service, unless a parent gives verifiable parental consent to a different limit. Virginia AG Jay Jones announced full enforcement on January 1, 2026 (see Hunton Andrews Kurth’s coverage and AG Jones’s January 2026 privacy-rights reminder, both retrieved May 18, 2026). Enforcement is currently enjoined: on February 27, 2026 the U.S. District Court for the Eastern District of Virginia granted a preliminary injunction halting the one-hour minor limit in NetChoice v. Jones, No. 1:25-cv-2067, on First Amendment grounds. Virginia appealed to the Fourth Circuit on March 3, 2026 and filed its opening brief April 15, 2026; the appeal remains pending and the provision stays unenforced as of June 21, 2026 (retrieved June 21, 2026).
- 2026 — Geolocation sale ban (SB 338): Approved by Governor Abigail Spanberger on April 13, 2026; effective July 1, 2026. Prohibits controllers from selling or offering to sell precise geolocation data concerning a consumer. Primary text: SB 338 enrolled bill and the amended § 59.1-575 precise-geolocation definition (retrieved May 18, 2026).
Read the deep dive on Virginia SB 338 for an implementation walk-through tailored to advertising, analytics, and data-broker stacks.
How the VCDPA Compares to Other State Privacy Laws
- Most-copied framework: The VCDPA model has been adopted (with variations) by Connecticut, Colorado, Indiana, Iowa, Tennessee, and more than 10 other states.
- Permanent cure period: Unlike Colorado (expired), Connecticut (eliminated), Oregon (eliminated), and Montana (eliminated), Virginia’s cure period is permanent.
- No GPC requirement: Virginia, Utah, Iowa, Indiana, and Tennessee do not require GPC — most newer laws do.
- Middle-range penalties: $7,500/violation is below Colorado ($20,000) and Maryland ($10K/$25K) but standard among VCDPA-model states.
- No private right of action: Like most state privacy laws (except California under limited circumstances), the VCDPA relies solely on AG enforcement.
Use our state privacy law comparison chart to see how Virginia compares across all 21 state privacy laws.
VCDPA Compliance Checklist — 7 Steps for 2026
- Determine applicability — Assess whether your organization meets the VCDPA thresholds (100K consumers OR 25K consumers + 50% revenue from data sales). Use the Privacy Law Calculator.
- Update privacy notices — Include all required disclosures: categories of personal data processed, purposes of processing, consumer rights, how to exercise those rights, categories of third parties you share data with, and whether you sell data or use it for targeted advertising.
- Build consumer rights workflows — Create intake, verification, and fulfillment processes for all eight consumer rights. Configure 45-day response timelines. Establish an appeals process with AG complaint contact info.
- Obtain sensitive data consent — Implement opt-in consent mechanisms for all sensitive data categories. Review processing of children’s data (under 13) and teen data (13–17) for advertising and sale purposes.
- Conduct data protection assessments — Perform assessments for targeted advertising, sale of personal data, processing of sensitive data, and profiling activities that carry significant risk. Document and retain these assessments.
- Review processor contracts — Ensure all data processor agreements meet VCDPA requirements: clear processing instructions, duty of confidentiality, subprocessor requirements, audit rights, and deletion/return obligations upon contract end.
- Implement the SB 338 geolocation ban — By July 1, 2026, stop selling or offering to sell precise geolocation data concerning Virginia consumers. Audit SDKs, analytics vendors, adtech partners, and data broker contracts for location-data transfers that may be characterized as sales.
For implementation support, use the Virginia Compliance Checklist, the Geolocation Compliance Checker, the DSAR Request Manager, and the Privacy Policy Generator.
Frequently Asked Questions
What is the Virginia consumer data protection law?
The Virginia Consumer Data Protection Act (VCDPA) is Virginia’s comprehensive consumer data privacy law. It was the second such law in the United States, signed on March 2, 2021 and effective January 1, 2023. Codified at §§ 59.1-575 to 59.1-585 of the Code of Virginia, it grants Virginia residents eight consumer rights over their personal data and obligates controllers and processors that meet the 100,000-consumer or 25,000-consumer-plus-50%-of-revenue thresholds to honor those rights, conduct data protection assessments, and contract appropriately with processors. It is enforced exclusively by the Virginia Attorney General; there is no private right of action.
How does the Virginia Consumer Data Protection Act protect consumers?
The VCDPA protects Virginia consumers in five concrete ways. (1) Eight individual rights: access, correction, deletion, data portability, opt-out of sale, opt-out of targeted advertising, opt-out of profiling with significant effects, and the right to appeal a controller’s denial. (2) Opt-in consent for sensitive data (race, religion, health, sexuality, immigration status, genetic or biometric IDs, precise geolocation, and data of children under 13). (3) A 45-day response window for any consumer rights request, with one 45-day extension for complex requests. (4) Mandatory data protection assessments before high-risk processing such as targeted advertising, sale, or profiling. (5) Enforcement teeth: the Virginia AG can seek injunctive relief and civil penalties of up to $7,500 per violation, plus attorney’s fees.
What changed in the VCDPA in 2026?
Two VCDPA-related changes matter in 2026. First, Virginia’s minor-protection rules for social media platforms (SB 854) took effect January 1, 2026, but a federal court preliminarily enjoined the one-hour daily time limit on February 27, 2026; Virginia appealed to the Fourth Circuit on March 3, 2026 and that appeal was still pending as of June 21, 2026, so the time-limit provision is not being enforced. Second, SB 338 was approved by the Governor on April 13, 2026 and takes effect July 1, 2026, adding a direct prohibition on selling or offering to sell precise geolocation data concerning Virginia consumers.
Does Virginia ban the sale of precise geolocation data?
Yes. Beginning July 1, 2026, SB 338 amends the VCDPA to prohibit controllers from selling or offering to sell precise geolocation data concerning a consumer. Businesses that use mobile SDKs, advertising networks, analytics vendors, or data brokers should inventory whether any Virginia consumer location data is transferred for monetary or other sale-like consideration and stop those transfers before the effective date.
What are the three core rules of the Virginia data protection act?
The VCDPA boils down to three core rules every covered controller must follow. Rule 1 — Transparency: publish a privacy notice that lists the categories of data collected, the purposes, the third parties with whom data is shared, and how consumers can exercise their rights and appeal a denial. Rule 2 — Consumer rights: set up an intake-and-fulfillment workflow that honors all eight VCDPA rights within 45 days, free of charge twice per year, and includes an internal appeal route. Rule 3 — Risk control: document data protection assessments before any high-risk processing, get opt-in consent before processing sensitive data, and contractually bind processors to confidentiality, audit, and deletion obligations. Failure on any of the three exposes the controller to a $7,500-per-violation fine after the 30-day cure window.
What is the penalty for violating the VCDPA?
The Virginia Attorney General can seek civil penalties of up to $7,500 per violation, plus reasonable attorney’s fees and investigative costs, and injunctive relief to stop ongoing violations. Unlike most other state privacy laws, the VCDPA’s 30-day cure period is permanent — it has no sunset date. The AG must give written notice and 30 days to fix the violation before pursuing penalties. There is no private right of action: consumers cannot sue businesses for VCDPA violations directly, only file complaints with the AG.
Does the VCDPA apply to nonprofits?
Yes. Unlike some state privacy laws that exempt nonprofits, the VCDPA applies to all entity types, including nonprofits, if they meet the applicability thresholds (100K consumers, or 25K consumers + 50% revenue from data sales). HIPAA-covered entities, GLBA-covered financial institutions, government bodies, and higher education institutions are exempt at the entity level.
Does the VCDPA cover employee data?
No. The VCDPA defines “consumer” as a Virginia resident acting in an individual or household context, and explicitly excludes individuals acting in a commercial or employment context. So job applicants, employees, and B2B contacts are outside the VCDPA — this is a major contrast with California’s CCPA/CPRA, which removed its employee/B2B carve-out in 2023.
How does the VCDPA interact with HIPAA?
The VCDPA exempts HIPAA-covered entities and business associates at the entity level — a broader exemption than some other state privacy laws that only exempt PHI as a data type. However, an entity-level exemption only goes as far as the entity’s HIPAA-regulated activity. A hospital’s marketing site, advertising tags, and visitor analytics still need to be analyzed separately if they meet thresholds independently. For a state-by-state breakdown of when state privacy law supersedes HIPAA and which states use entity-level versus data-level carve-outs, see our HIPAA exemption matrix covering all 21 comprehensive laws.
What is Virginia’s main privacy law?
Virginia’s main privacy law is the Virginia Consumer Data Protection Act (VCDPA), codified at Code of Virginia §§ 59.1-575 to 59.1-585. People search for it as “Virginia privacy law,” “Virginia data privacy law,” or “Virginia consumer data protection act” — they all describe the same statute. Outside the VCDPA itself, the only other Virginia consumer data law that materially affects most businesses is Virginia’s breach-notification statute (Va. Code § 18.2-186.6). The VCDPA itself absorbed Virginia’s prior “Government Data Collection and Dissemination Practices Act” obligations for private-sector data.
Have there been any VCDPA enforcement actions?
Yes — but mostly behind the scenes. The Virginia Attorney General’s Consumer Privacy Unit accepts and investigates VCDPA complaints and issues 30-day cure notices, but those notices are not made public unless a controller fails to cure and the AG sues. The one publicly visible VCDPA enforcement effort is the SB 854 minor social-media restrictions, and that effort is currently blocked by a federal court: on February 27, 2026 a U.S. District Judge for the Eastern District of Virginia granted a preliminary injunction in NetChoice v. Jones, No. 1:25-cv-2067, halting the one-hour minor limit on First Amendment grounds. Virginia appealed that injunction to the U.S. Court of Appeals for the Fourth Circuit on March 3, 2026 and filed its opening brief on April 15, 2026; as of June 21, 2026 the appeal is still pending and the minor time-limit remains unenforced (sources retrieved June 21, 2026). The VCDPA’s core privacy duties remain fully enforceable throughout.
Has anyone been fined under the VCDPA?
No public VCDPA settlements or civil-penalty actions against websites or controllers have been announced as of June 21, 2026. The statute’s permanent 30-day cure period — combined with the Virginia AG’s practice of issuing cure notices that are not publicly disclosed unless the controller fails to fix the violation — means most enforcement is resolved before it shows up in a press release. The highest-profile enforcement push, the SB 854 minor social-media restrictions, was preliminarily enjoined by a federal court on February 27, 2026 (NetChoice v. Jones, E.D. Va.) and remains on hold pending Virginia’s appeal to the Fourth Circuit (filed March 3, 2026). Compare with other state privacy law penalties — California, Texas, and Connecticut have publicly disclosed settlements while Virginia’s enforcement record so far is consistent with its business-friendly framing.
This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 29, 2026. Last verified: July 1, 2026.
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.