California vs Virginia Privacy Law Comparison

Understanding the differences between California's CCPA/CPRA and Virginia's VCDPA is essential for businesses operating across state lines. California's law became effective January 1, 2020, while Virginia's law took effect January 1, 2023. Below is a detailed side-by-side comparison covering applicability thresholds, consumer rights, enforcement, and more.

Reviewed by PrivacyLawMap editorial team · Last verified: 2026-08-13

Start with the California data privacy law guide and the Virginia data privacy law guide for the full state-specific thresholds, rights, source links, and checklist steps behind this comparison.

To weigh the real-world stakes behind these two laws, see documented CCPA/CPRA fines and privacy penalties from actual state enforcement actions in the penalties tracker.

CCPA/CPRA vs VCDPA: the key differences at a glance

The biggest difference between California's CCPA/CPRA and Virginia's VCDPA (as of 2026) is that California's CCPA/CPRA grants consumers a private right of action (the ability to sue directly in some circumstances), while Virginia's VCDPA is enforced only by regulators.

  • Maximum civil penalty: CCPA/CPRA up to $7,988 per violation vs VCDPA up to $7,500 per violation.
  • Right to cure: CCPA/CPRA has no cure period vs VCDPA with 30-day cure period.
  • Private right of action: yes under CCPA/CPRA vs no under VCDPA.
  • Universal opt-out (GPC) signals: must be honored under CCPA/CPRA vs not mandated under VCDPA.
  • Effective date: CCPA/CPRA since January 1, 2020 vs VCDPA since January 1, 2023.

Primary sources: CCPA/CPRA Full Text (California Legislative Information) · VCDPA Full Text (Virginia Code Title 59.1, Chapter 53) · Verified 2026-08-13.

Swipe the table sideways to see every state column.

Category
California
CCPA/CPRA
Virginia
VCDPA
Thresholds & Applicability
Effective Date
Jan 1, 2020Jan 1, 2023
Revenue Threshold
$25MNone
Consumer Count
100,000100,000
Data Sale % Threshold
50%50%
Consumer Rights
Right to Access
Right to Deletion
Right to Correction
Opt-Out of Sale
Opt-Out Targeted Ads
Opt-Out Profiling
Limit Sensitive Data
Right to Appeal
Private Right of Action
Enforcement & Compliance
Universal Opt-Out Required
Cure Period
None30 days
Penalty / Violation
$7,988$7,500
Enforcement Body
California Privacy Protection Agency (CPPA) and California Attorney GeneralVirginia Attorney General
Sensitive Data Consent
Opt-InOpt-In
Data Broker Provisions
California has a separate Data Broker Registration law (SB 362 — the California Delete Act, effective 2024) requiring data brokers to register with the CPPA, pay annual fees, and comply with the Delete Request and Opt-out Platform (DROP). The DROP system launched January 1, 2026 for consumer registration; starting August 1, 2026, data brokers must access the DROP at least every 45 days to process deletion requests. Non-registration carries fines of $200 per day. Failure to process deletion requests incurs $200 per request per day of non-compliance. The CPPA launched a Data Broker Enforcement Strike Force in January 2026 to actively pursue non-compliant brokers. Separately, the Delete Act requires every registered data broker to undergo an independent third-party audit of its Delete Act compliance beginning January 1, 2028 and once every three years thereafter (Civil Code §1798.99.86); brokers must keep the audit report for at least six years and submit it to CalPrivacy upon written request. This triennial data-broker audit is distinct from the CCPA cybersecurity audit and applies regardless of a broker's revenue.The VCDPA does not include specific data broker registration requirements. Data brokers are subject to the same obligations as other controllers under the law.

Highlighted rows indicate differences between the two states

California vs Virginia: Common Questions

Not sure if California or Virginia privacy laws apply to you?

Our free calculator analyzes your business details and tells you exactly which state privacy laws you need to comply with.

Use Our Calculator