Cure Period

Reviewed by PrivacyLawMap editorial teamLast verified: July 23, 2026

Definition

A window of time (usually 30-60 days) that a business is given to fix a privacy violation after being notified, before enforcement action is taken. Many early state privacy laws included cure periods, but the trend is toward removing them to strengthen enforcement.

Legal Definition

Under the VCDPA (Va. Code 59.1-584): the AG must provide 30 days' written notice and a cure opportunity before bringing an enforcement action; the statute does not include a cure-period sunset. Iowa's ICDPA includes a permanent 90-day cure period. Tennessee offers a 60-day cure period with affirmative defense provisions.

State Laws Using This Term

Practical Example

A state attorney general notifies a company that its privacy policy does not meet legal requirements. The company has 30 days to update the policy and come into compliance. If it does so within the cure period, no penalty is imposed.

Related Terms

Frequently Asked Questions

Are cure periods permanent?

Not always. Several states include sunset provisions that eliminate or weaken mandatory cure periods after an initial compliance window. Virginia's 30-day VCDPA cure period is permanent. Connecticut's mandatory cure period sunsetted December 31, 2024, Colorado's sunsetted January 1, 2025, New Hampshire's became discretionary January 1, 2026, and New Jersey's temporary mandatory period ended July 1, 2026 (NJ Division of Consumer Affairs NJDPL FAQ, date_retrieved: 2026-07-23).