VA

Virginia Privacy Law

Virginia Consumer Data Protection Act

Effective: January 1, 2023ActiveReviewed by PrivacyLawMap editorial teamLast verified: January 1, 2023

Overview

The Virginia Consumer Data Protection Act (VCDPA) was the second comprehensive state privacy law in the United States, signed into law on March 2, 2021, and effective January 1, 2023. The VCDPA established a framework that many subsequent state laws have followed — including Connecticut, Indiana, and Iowa — balancing consumer privacy rights with a business-friendly approach to regulation.

The VCDPA provides Virginia residents with rights to access, correct, delete, and obtain a portable copy of their personal data, as well as the right to opt out of the sale of personal data, targeted advertising, and profiling. Unlike California's CCPA/CPRA, the VCDPA does not include a private right of action, leaving enforcement exclusively to the Virginia Attorney General.

The law applies to entities that conduct business in Virginia or target Virginia residents and that control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data. The VCDPA provides a permanent 30-day cure period for violations (unlike Colorado and Connecticut, whose cure periods have sunset). Penalties can reach $7,500 per violation.

In 2026, Virginia passed SB 338 to ban the sale of precise geolocation data, joining Maryland and Oregon with dedicated geolocation privacy protections. The legislature also enacted social media restrictions for minors effective January 1, 2026, requiring platforms to limit screen time and disable addictive design features for users under 18. The Virginia AG has signaled active enforcement of both new provisions.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

100,000+
Virginia consumers' data processed
25,000+ consumers
AND 50%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • SB 338 signed into law by Governor Spanberger on April 13, 2026 — bans the sale of precise geolocation data effective July 1, 2026. Virginia is now the third state (after Maryland and Oregon) to enact dedicated geolocation data sale prohibitions.
  • New social media restrictions for minors took effect January 1, 2026 — platforms must limit screen time and disable addictive design features for users under 18
  • Virginia AG Jay Jones announced in February 2026 intent to fully enforce minor protections, beginning with 30-day cure notices to non-compliant platforms
  • VCDPA 30-day cure period remains permanently in effect (no sunset provision, unlike Colorado and Connecticut) — one of the more business-friendly enforcement approaches among comprehensive state privacy laws
  • Virginia AG continues to build enforcement capacity with focus on children's data protection and geolocation data practices
  • SB 338 takes effect July 1, 2026 — controllers selling precise geolocation data to data brokers must cease sales by that date or face $7,500 per violation penalties
  • No universal opt-out requirement yet — Virginia is one of few comprehensive privacy law states that does not mandate GPC recognition

Enforcement Details

Enforced By
Virginia Attorney General
Penalty Per Violation
$7,500
Cure Period
30 days
Private Right of Action
No — AG enforcement only

Notable Enforcement Actions

Undisclosed (Major Retailer)

VCDPA · Notable enforcement action

Consent decree — corrective measures required

Virginia AG issued first VCDPA enforcement action against a national retailer for failing to provide adequate opt-out mechanisms for targeted advertising and data sales. The company was required to implement compliant opt-out processes within 30 days under the cure period provision.

June 15, 2024

Passport Labs (Passport Parking)

VCDPA · Notable enforcement action

$150,000

Parking app company collected precise geolocation data beyond what was necessary for services and shared it with data brokers without consumer consent. Virginia AG found the company failed to conduct required data protection assessments for high-risk processing.

March 12, 2025

Multiple EdTech Companies

VCDPA · Notable enforcement action

Cure notice issued — compliance required within 30 days

Virginia AG sent cure notices to several education technology companies for processing student data for targeted advertising purposes, failing to obtain opt-in consent for sensitive data (children's data), and lacking transparent privacy notices.

September 8, 2025

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusBiometric data for identification

Universal Opt-Out / GPC Requirements

No Universal Opt-Out Requirement

The VCDPA does not currently require businesses to recognize universal opt-out mechanisms such as GPC. However, businesses may voluntarily honor such signals as a best practice.

Minor / Child Protections

The VCDPA requires opt-in consent before processing personal data of known children under 13, consistent with COPPA. For consumers aged 13-17, businesses must obtain consent before processing data for targeted advertising or sale. Effective January 1, 2026, Virginia enacted social media restrictions for minors requiring platforms to limit screen time and disable addictive design features for users under 18. The Virginia AG has indicated these provisions will be actively enforced.

Compliance Checklist

  1. 1Determine whether your organization meets VCDPA applicability thresholds: (a) process personal data of 100,000+ Virginia consumers, or (b) process data of 25,000+ Virginia consumers and derive 50%+ of gross revenue from data sales. Check exemptions — HIPAA-covered entities, GLBA-regulated financial institutions, nonprofits, and higher education institutions are exempt.
  2. 2Conduct a data inventory to map what personal data you collect about Virginia consumers, including categories of data, processing purposes, third-party sharing, and data retention periods. Identify any sensitive data categories (racial/ethnic origin, health data, sexual orientation, biometrics, children's data, precise geolocation).
  3. 3Update your privacy notice to include all VCDPA-required disclosures: categories of personal data processed, purposes of processing, how consumers can exercise their rights, categories of data shared with third parties, and contact information. Privacy notices must be reasonably accessible and clear.
  4. 4Implement consumer rights request processes with a 45-day response window (extendable by 45 additional days with notice). Support requests for access, correction, deletion, portability, and opt-out of sale/targeted advertising/profiling.
  5. 5Obtain opt-in consent before processing any sensitive personal data. This includes data about health, race, religion, sexual orientation, biometrics, children's data, and precise geolocation. Consent must be freely given, specific, informed, and unambiguous.
  6. 6Conduct and document data protection assessments (DPAs) for each processing activity that presents a heightened risk of harm: targeted advertising, sale of personal data, profiling with legal or significant effects, sensitive data processing, and any processing involving minors' data.
  7. 7Establish a consumer appeals process: if you deny a consumer rights request, provide a mechanism for the consumer to appeal. You must respond to appeals within 60 days and include instructions for filing a complaint with the Virginia AG if the appeal is denied.
  8. 8Review data processor agreements to ensure they include VCDPA-required terms: clear processing instructions, confidentiality obligations, deletion/return of data requirements, audit rights, and subprocessor management obligations.
  9. 9Comply with SB 338 (signed April 13, 2026, effective July 1, 2026): if your business sells precise geolocation data, cease all sales by July 1, 2026 to comply with the geolocation data sale ban. Audit data broker relationships involving location data and terminate any agreements that involve selling Virginia consumers' precise geolocation.
  10. 10Ensure minor protections compliance: platforms serving users under 18 must limit screen time features, disable addictive design patterns, and obtain parental consent for children under 13 consistent with COPPA. Monitor Virginia AG enforcement guidance for specific technical requirements.
Put VCDPA Into Practice on Your SiteSponsored

Termly builds and maintains a Virginia-ready privacy policy, a cookie consent banner, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests VCDPA grants.

Start Free with Termly

Virginia Privacy Law FAQ

Official Resources