Virginia Consumer Data Protection Act (VCDPA): 2026 Compliance Guide
Table of Contents
The Virginia Consumer Data Protection Act (VCDPA) is Virginia's comprehensive privacy law. It gives residents the right to access, correct, delete, and port their personal data, and to opt out of its sale, targeted advertising, and profiling used to make significant decisions. Businesses that decide how that data is used have to honor those rights and keep the data secure.
It applies to any business targeting Virginia residents that, in a calendar year, processes data on 100,000 or more consumers, or 25,000 or more while earning over half its revenue from selling data. There is no revenue-dollar threshold, so size alone never triggers it.
Virginia defines a sale as an exchange for money only, narrower than California or Colorado, and it does not require honoring Global Privacy Control. Sensitive data needs opt-in consent.
Only the attorney general enforces the VCDPA, with penalties up to $7,500 per violation, a permanent 30-day cure period, and no private right of action. The law took effect January 1, 2023 and has since been amended, most recently for minors and children's data.
Most privacy coverage treats the state laws as interchangeable. Virginia is where that assumption breaks. It has the narrowest definition of a sale in the country, no universal opt-out signal to honor, and a cure period that never expires.
For your website, that changes the actual work. The same ad pixel that counts as a sale in California may not be one in Virginia, and the Global Privacy Control signal you have to honor in Colorado carries no legal weight here. This guide covers the current law, with the emphasis where you need it: who is covered, what your site has to do, and where Virginia is genuinely different.
What is the VCDPA?
The Virginia Consumer Data Protection Act is Virginia's comprehensive consumer privacy law, in force since January 1, 2023. It was the second such law in the country after California, and the first to pass on the model most other states then copied. It grants Virginia residents rights over their personal data and sets duties for the businesses that decide how that data is used, which the statute calls controllers.
The law sits at Va. Code § 59.1-575 and following. The Virginia attorney general's office is the sole enforcer, and it has amended the act several times since 2023, most recently around children's and minors' data.
How the VCDPA has changed
Virginia passed the law in 2021, and it took effect January 1, 2023. Amendments have come steadily since. 2022 added the appeal right and reworked enforcement. 2024 tightened children's-data duties and assessments. 2025 added the social-media rules for minors and a set of new definitions. 2026 sharpened the children's-data obligations again. The version described here reflects the current code.
For where Virginia sits among all 20 state laws, see the U.S state law tracker.
Does the VCDPA apply to your business?
You are covered if you conduct business in Virginia (or target Virginia residents) and, in a calendar year, either:
- Control or process personal data of at least 100,000 Virginia consumers, or
- Control or process personal data of at least 25,000 Virginia consumers and derive more than 50% of gross revenue from the sale of personal data.
There is no revenue-dollar threshold. A company with $500 million in revenue and 10,000 Virginia customers is outside the law; a data broker with 30,000 Virginia consumers and 60% of revenue from data sales is inside it. Size alone decides nothing.
You do not need a Virginia office or any physical presence in the state. Targeting Virginia residents and crossing a threshold is enough, wherever you are based. Vendors can also be pulled in indirectly: a processor that serves a covered controller inherits VCDPA obligations by contract, whatever its own size.
Only Virginia residents acting for themselves count. People acting in a commercial or employment context do not, so your B2B contacts and your own employees fall outside the VCDPA entirely. That is broader relief than California gives, where employee and B2B data eventually came into scope.
The worked example: a SaaS company with 120,000 Virginia users crosses the first threshold and is covered. A 20,000-consumer analytics startup that makes most of its money selling audience data crosses the second. A 15,000-customer retailer that never sells data crosses neither, no matter how large its revenue.

Who's exempt
Some organizations are exempt as whole entities, not just for specific data. Virginia carves out state and local government bodies, financial institutions and the data they hold under the federal Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofits, and higher-education institutions.
The HIPAA exemption runs at the entity level, so a HIPAA-covered organization is outside the VCDPA even for its marketing data. The GLBA carve-out reaches both the institution and GLBA-regulated data.
Other exemptions run at the data level. Protected health information under HIPAA, consumer-report data under the FCRA, education records under FERPA, driver data under the DPPA, Farm Credit Act data, and most research data are all carved out. De-identified data and publicly available information sit outside the law as well.
Employment and B2B data deserve a separate flag: because the term consumer excludes commercial and employment contexts, data about job applicants, employees, contractors, and business contacts is outside the VCDPA, with no sunset that pulls it back in.
What counts as sensitive data
Sensitive data gets the strictest treatment: opt-in consent before you process it. Virginia's categories are narrower than the newer state laws. They are:
- Personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status
- Genetic or biometric data processed to uniquely identify a person
- Personal data collected from a known child (under 13)
- Precise geolocation data, meaning a location within 1,750 feet
Precise geolocation carries an extra rule: you cannot sell it or offer it for sale at all, consent or not. For sensitive data collected from a known child, you follow the verifiable-parental-consent process under COPPA instead of the standard opt-in.
Consent, wherever the VCDPA requires it, means a clear affirmative act that is freely given, specific, informed, and unambiguous. A pre-checked box or a buried disclosure does not count.
Consumer rights under the VCDPA
Virginia residents have five rights, and a covered business has to honor them. A resident can:
- Confirm and access. Ask whether you process their data and get a copy of it.
- Correct inaccuracies in the data you hold.
- Delete data you have collected or obtained about them.
- Port a copy of the data they provided, in a usable, portable format.
- Opt out of the sale of their data, targeted advertising, and profiling used to make decisions with legal or similarly significant effects.
A parent or legal guardian exercises these rights for a known child. That profiling opt-out is narrower than it sounds: it covers only automated profiling that feeds a decision about lending or credit, housing, insurance, education, employment, healthcare, or access to basic necessities. Everyday personalization is not covered.
The mechanics are where compliance actually lives:
- Respond within 45 days. You can extend once by another 45 days for a genuinely complex or high-volume request, as long as you tell the consumer why within the first 45.
- Free, up to twice a year. Further or excessive requests can carry a reasonable fee. You can also decline one that is manifestly unfounded, excessive, or repetitive, but you carry the burden of proving it is.
- Verify identity first. You do not have to act on a request you cannot authenticate by commercially reasonable means, and you can ask for more information to do so. Consumers may also use an authorized agent to submit an opt-out.
- Offer an appeal. If you deny a request, give the consumer a conspicuous way to appeal, respond within 60 days, and if you still say no, point them to the attorney general to file a complaint.
One deletion wrinkle: when the data came from someone other than the consumer, you can satisfy the delete right either by keeping a record of the request plus the minimum data needed to honor it, or by opting the consumer out of processing instead.
What the VCDPA requires from your website
Your website needs a compliant privacy notice, working opt-out mechanics for sale and targeted advertising, and opt-in consent before anything touches sensitive data. Virginia's narrower sale definition changes how the first two play out, so it is worth getting the definition right before you build.
Is your website selling data?
In Virginia, a sale is the exchange of personal data for monetary consideration only. This is the single biggest way the VCDPA differs from California, Colorado, and Connecticut, which all count exchanges for other valuable consideration too. An arrangement where you hand data to an ad-tech partner for better targeting rather than for cash may not be a sale in Virginia even though it is one in California.
Targeted advertising is regulated separately and does not depend on the sale definition. So a Meta pixel that shares browsing data to target ads triggers the targeted-advertising opt-out even if it is not a sale. The practical result: you still need the opt-out, you just reach it through a different door than you would in California.
Targeted advertising has a specific meaning: ads shown based on a person's activity across nonaffiliated sites and apps over time. Four things are carved out and do not trigger the opt-out:
- Ads based only on activity within your own site or app
- Contextual ads keyed to the current page
- Ads served in response to the consumer's own request
- Processing only to measure or report ad performance, reach, or frequency
First-party analytics and simple conversion measurement, in other words, are not the target here.
Virginia also has no separate concept of a data share. California splits selling from sharing, where sharing means disclosing data for cross-context behavioral advertising. Virginia routes that same data flow through the targeted-advertising opt-out instead, so you are always weighing two tests, sale and targeted advertising, never three.
The statute also lists what is never a sale: disclosure to a processor acting for you, disclosure to provide a product the consumer requested, transfers to an affiliate, data the consumer deliberately made public, and data transferred as part of a merger or acquisition.
To check your own site, list every third-party tag and ask two questions of each. Does data leave your control for money? That is a sale. Does it leave to help target ads across other sites? That is targeted advertising.
A Google Analytics 4 tag set to basic measurement is usually neither; a Meta Pixel or a Google Ads remarketing tag is almost always targeted advertising; an affiliate tag that pays you for passing identifiable click data can be a sale. Whenever either answer is yes, that visitor needs a working opt-out.

Cookie consent and third-party scripts
Virginia runs an opt-out model for ordinary personal data. You may load analytics and advertising scripts for a Virginia visitor, but once they opt out of sale or targeted advertising, those scripts have to stop. Sensitive data flips the model to opt-in: nothing that processes it runs before the visitor consents.
Virginia does not require you to honor Global Privacy Control or any universal opt-out signal. That is a real legal difference from Colorado, California, and Connecticut, where honoring GPC is mandatory. Many businesses still honor GPC everywhere because they operate in those states anyway, but in Virginia alone it is a choice, not a duty.
Building the opt-out
Virginia does not mandate a specific link. There is no required Do-Not-Sell-or-Share label the way California has it. What Virginia requires is that the opt-out actually works and is easy to find.
In practice that means three things: a visible control, such as a Your Privacy Choices link; a request path a consumer can complete without creating an account; and tracker gating so that once someone opts out, the sale and targeted-advertising tags stop firing.
The mechanism matters more than the label. A link that opts a visitor out on paper while the pixels keep running is the failure the attorney general looks for.
What your privacy notice must include
Virginia requires a reasonably accessible, clear privacy notice with a defined contents list: the categories of personal data you process, the purpose for processing, how consumers exercise their rights including how to appeal, the categories of data you share with third parties, and the categories of third parties you share with.
If you sell personal data or process it for targeted advertising, you have a second duty: disclose that clearly and conspicuously, and give consumers the way to opt out. A notice that buries the opt-out, or omits it, is the gap the attorney general looks for first.
One mechanical rule sits alongside the notice: you cannot force a consumer to create a new account to exercise a right, though you may require them to use an account they already have.
Service provider or third party?
Data you hand to a processor working under your instructions, like your email platform or your hosting provider, is not a sale and not a third-party disclosure. Data that goes to a party that uses it for its own purposes can be both.
The dividing line is the contract and the actual use. If a vendor reuses your visitor data to improve its own products or serve other clients, treat it as a third party and gate it behind the opt-out.
Whether a vendor is a processor or a third party is a fact-based question about what it actually does with the data, not what the contract labels it. And neither role escapes liability: a processor that ignores your instructions and decides its own purposes can be treated as a controller and held to a controller's duties. A quick test:
- Vendor uses the data only on your documented instructions, for you: processor, not a sale.
- Vendor reuses the data for its own products or other clients: third party, gate it behind the opt-out.
Processor contract requirements
A processor carries direct duties, not just contract terms. It has to follow your documented instructions and actively help you meet the law: assisting with consumer-rights requests, with data security and breach notification, and with the information you need to run data protection assessments.
On top of that, Virginia does not leave the processor relationship to a handshake. Every processor must be bound by a contract that sets out the processing instructions, the nature and purpose of processing, the type of data, the duration, and each side's obligations. The contract has to require the processor to:
- Bind everyone who processes the data to a duty of confidentiality
- Delete or return all personal data at the end of the service, unless the law requires keeping it
- Make available, on request, the information needed to show it complies
- Allow and cooperate with reasonable assessments, or supply an independent assessor's report
- Impose these same terms on any subcontractor by written contract
If your data processing agreements predate the VCDPA, this is the clause list to check them against.
How Enzuzo handles this: Enzuzo's consent management platform detects where a visitor is, applies Virginia's opt-out and consent rules, blocks trackers until the right consent state exists, and keeps timestamped records. Teams typically go live in one to three days. Book a demo to see it live.
Your duties as a controller
Beyond the website mechanics, the VCDPA puts a set of standing duties on the controller.
Data minimization. Limit collection to what is adequate, relevant, and reasonably necessary for the purposes you disclose.
Purpose limitation. Processing data for a new purpose that is neither reasonably necessary to nor compatible with the disclosed purpose needs the consumer's consent first.
Reasonable security. Keep administrative, technical, and physical safeguards appropriate to the volume and nature of the data.
No discrimination. You cannot deny goods, charge more, or degrade service because a consumer exercised a right. A bona fide loyalty or rewards program is allowed, and you may still decline to offer a product that genuinely needs data the consumer withheld.
Consent for sensitive data. No sensitive data processing without opt-in consent, and no sale of precise geolocation at all.
One backstop applies to all of these: any contract term that tries to make a consumer waive or limit their rights is void and unenforceable.

De-identified and pseudonymous data
Stripping identifiers does not end your obligations. If you hold de-identified data, Virginia requires you to take reasonable measures so it cannot be tied back to a person, publicly commit to keeping it de-identified, and contractually bind anyone you share it with to the same.
Pseudonymous data, where you keep the identifying key separate under real controls, is partly relieved from the access, correction, deletion, and portability rights, but only while that separation holds and you oversee the recipients who receive it.
What the VCDPA does not restrict
The duties above come with broad carve-outs. Nothing in the VCDPA stops you from complying with the law, responding to legal process, cooperating with law enforcement, defending legal claims, completing a transaction the consumer asked for, protecting someone's life or safety, or detecting and preventing fraud and security incidents.
Internal operations get room too: internal research, product improvement, fixing technical errors, and processing a consumer would reasonably expect are all permitted. If you lean on one of these, you carry the burden of showing it applies, and the processing still has to stay reasonably tied to that purpose.
Data protection assessments
Virginia requires a documented data protection assessment before certain higher-risk processing. Under Va. Code § 59.1-580, you must assess and document processing for targeted advertising, the sale of personal data, sensitive-data processing, profiling that carries a foreseeable risk of harm, and any processing that presents a heightened risk of harm to consumers.
A separate assessment applies to any online product or feature directed at consumers you actually know are children. Assessments are confidential and exempt from public-records requests, but the attorney general can compel one through a civil investigative demand. The requirement is not retroactive: it applies only to processing created or generated after January 1, 2023.
Minors and the VCDPA
Virginia protects minors through two different regimes with two different age lines, which is easy to conflate.
For a known child under 13, sensitive-data rules and COPPA apply: you handle their data under COPPA's verifiable-parental-consent process, and you cannot use it for targeted advertising, sale, or profiling behind significant decisions. Meeting COPPA's verifiable-parental-consent standard is treated as meeting Virginia's parental-consent requirement.
Successive amendments in 2024 and 2026 tightened these duties. Beyond consent, you may process a known child's data only as far as is reasonably necessary to provide your service, only for the purposes you disclosed, and only for as long as you actually need it.
Collecting precise geolocation from a known child is allowed only when necessary, only for the time it is needed, and only while a signal shows the child that collection is happening.
A separate 2025 amendment added social-media rules for minors under 16. Covered platforms must use a neutral age-screening method, default a minor's use of the service to one hour per day per service (adjustable with verifiable parental consent), and treat a user as a minor if their device signals it.
Two guardrails come with it: a platform may use age-verification data only to confirm age, and it cannot withhold, degrade, or raise the price of the service because a minor will not exceed the one-hour default. If you run a social platform, this is a distinct obligation from the children's-data rules above.
How to comply with the VCDPA
If the VCDPA reaches you, compliance comes down to a short, concrete list:
- Map your data and trackers. Inventory what personal data you collect and every third-party tag, pixel, and SDK that sends data off your site.
- Classify each flow. For each tag, decide whether it is a sale (data for money), targeted advertising (cross-site ad targeting), or neither, using the two-question test above.
- Build the opt-out. Give visitors a working way to opt out of sale and targeted advertising, and gate the relevant tags so they stop on opt-out. No account required to use it.
- Update your privacy notice. Cover the required contents, disclose any sale or targeted advertising with the opt-out method, and explain how to exercise and appeal rights.
- Stand up rights intake. A workflow that verifies identity, answers within 45 days, and handles appeals within 60.
- Get consent for sensitive data, and sign processor contracts. Opt-in before any sensitive-data processing, and a compliant data processing agreement with every processor.
- Run data protection assessments for targeted advertising, sales, sensitive data, and risky profiling, and keep them on file.
Most of this is website and paperwork, not engineering, and a consent platform handles the tracker-gating and record-keeping parts.

Penalties and enforcement: what actually happens
The attorney general has exclusive authority to enforce the VCDPA. There is no private right of action, so consumers cannot sue you directly under this law. The attorney general can open an investigation and issue a civil investigative demand on reasonable cause to believe the law is being broken.
Enforcement runs through a permanent 30-day cure period. Before any action, the attorney general must give you 30 days' written notice of the specific violations. If you cure them within that window and confirm in writing that they are fixed and will not recur, no action follows.
Unlike Colorado, Connecticut, and several other states whose cure periods have sunset, Virginia's right to cure has no expiration date in the current statute.
If a violation continues past the cure period, or you break the written promise, the attorney general can seek an injunction and civil penalties of up to $7,500 per violation. Penalties and recovered fees go into the state's Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund.
The practical effect of the permanent cure period is that public VCDPA penalties have been rare. For most businesses, the realistic exposure is not a surprise fine but a notice letter, usually about a missing opt-out or a deficient privacy notice, followed by 30 days to fix it. That makes the privacy notice and the opt-out the two things worth getting right before anyone comes looking.
VCDPA vs CCPA
Virginia and California cover the same ground and diverge on almost every detail. California, under the CCPA and its update the CPRA, is broader: more businesses in scope, a wider sale definition, mandatory GPC, and employee and B2B data included. Virginia is narrower and more business-friendly, and those differences change what your site actually has to do.
| Point | Virginia (VCDPA) | California (CCPA/CPRA) |
|---|---|---|
| Thresholds | 100K consumers, or 25K + >50% revenue from sale | $25M revenue, 100K consumers, or 50% revenue from data |
| Sale definition | Monetary consideration only | Monetary OR other valuable consideration |
| Data-share category | None; handled via the targeted-ad opt-out | Separate category for cross-context ad data |
| Universal opt-out (GPC) | Not required | Required |
| Required opt-out link | No specific link mandated | Do-Not-Sell-or-Share link required |
| Profiling opt-out | Yes, for significant-effects decisions | Yes, plus broader automated-decision rules |
| Private lawsuits | No | Breaches only |
| Fines | Up to $7,500 per violation | $2,500-$7,500 per violation |
| Cure period | Permanent 30 days | None (expired 2023) |
| Employee / B2B data | Fully excluded | Included |
The upshot: if you already comply with California, you have most of the operational pieces for Virginia, but Virginia's monetary-only sale definition and its lack of a mandated opt-out link mean you cannot simply clone your California banner and call it done.
Full 20-state comparison: state law tracker.
FAQ
Who must comply with the VCDPA?
Any business that targets Virginia residents and, in a year, controls or processes personal data of 100,000+ Virginia consumers, or 25,000+ consumers while earning more than half its revenue from selling data. There is no revenue-dollar threshold, so a large company with few Virginia customers can be exempt. Employee and B2B data do not count toward the totals.
What counts as selling data under the VCDPA?
Exchanging personal data for money. Virginia's definition is monetary-only, narrower than California's and Colorado's, which also cover exchanges for other valuable consideration. Handing data to an ad partner for better targeting rather than for cash may not be a sale in Virginia, though it can still trigger the separate targeted-advertising opt-out. Disclosures to a processor, to fulfill a consumer's request, or to an affiliate are never sales.
Does the VCDPA require honoring Global Privacy Control?
Virginia does not require businesses to recognize GPC or any universal opt-out browser signal, which sets it apart from California, Colorado, and Connecticut. Consumers exercise the opt-out by request instead. Many businesses honor GPC anyway because they operate in states that mandate it, but in Virginia it is optional.
What are the penalties under the VCDPA, and is there a cure period?
The attorney general can seek up to $7,500 per violation, and there is no private right of action. Virginia has a permanent 30-day cure period: before any action, the AG must give 30 days' written notice, and fixing the issue in that window avoids penalties. Unlike several states, this cure right does not expire.
What is a data protection assessment under the VCDPA?
A documented risk assessment you must complete before higher-risk processing: targeted advertising, selling data, processing sensitive data, risky profiling, or any processing with a heightened risk of harm, plus online features directed at known children. Assessments are confidential but the attorney general can compel one. The requirement applies only to processing created after January 1, 2023.
How is the VCDPA different from the CCPA?
Virginia has no revenue-dollar threshold, defines sale as monetary-only, does not require honoring GPC, permanently excludes employee and B2B data, and keeps a permanent 30-day cure period. California is broader on all of these: it covers more businesses, a wider sale definition, mandatory GPC, employee and B2B data, and no cure period. Virginia is generally the more business-friendly of the two.
Has anyone been fined under the VCDPA?
Public penalties have been rare, largely because the permanent 30-day cure period lets businesses fix problems before an action begins. Enforcement is exclusive to the attorney general and tends to start as a notice letter about a missing opt-out or a deficient privacy notice, not a headline fine. The low visibility is a feature of the cure-first design, not evidence that the law is unenforced.
Does the VCDPA protect children's and minors' data?
Yes, through two regimes. Data from a known child under 13 is sensitive data handled under COPPA's parental-consent rules, and it cannot be used for targeted advertising, sale, or profiling behind significant decisions.
A separate 2025 amendment covers social-media platforms and minors under 16, requiring neutral age screening, a default one-hour-per-day use limit adjustable with parental consent, and recognition of a device signal that a user is a minor.
Check your consent setup against the VCDPA, and the other 19 states → Book a demo
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.