{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/virginia",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/virginia.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/virginia",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/virginia/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/virginia/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "virginia",
    "frontmatter": {
      "title": "Virginia Consumer Privacy Law (VCDPA)",
      "description": "The Virginia Consumer Data Protection Act gives Virginia consumers rights over their personal data and imposes notice, contracting, and consent duties on controllers above defined thresholds — the model for many state privacy laws, it is enforced exclusively by the Attorney General with a permanent 30-day cure period and provides no private right of action.",
      "state": "Virginia",
      "lastReviewed": "2026-06-04",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Va. Code §§ 59.1-575 et seq. (Virginia Consumer Data Protection Act)",
        "appliesTo": "Persons doing business in Virginia (or targeting residents) that control or process the data of 100,000+ consumers a year, or 25,000+ while deriving over 50% of gross revenue from selling data — no revenue floor; nonprofits exempt",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's",
        "regulator": "Virginia Attorney General (exclusive)",
        "bottomLine": "If you meet the 100,000-consumer (or 25,000 plus majority-data-sale) threshold in Virginia, the VCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — enforced by the Attorney General with a permanent 30-day cure period and no consumer lawsuits.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Virginia Consumer Data Protection Act VCDPA",
        "Virginia privacy policy requirements",
        "Virginia privacy notice contents",
        "VCDPA applicability thresholds",
        "VCDPA sensitive data consent",
        "VCDPA processor contract requirements",
        "Virginia Attorney General privacy enforcement",
        "VCDPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-vcdpa-apply",
        "label": "Does the Virginia Consumer Data Protection Act apply to your business?",
        "heading": "Does the Virginia Consumer Data Protection Act apply to your business?",
        "answerText": "It turns on consumer volume, not revenue. The VCDPA applies to persons that do business in Virginia or target its residents and that, in a calendar year, control or process the personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data.",
        "sources": [
          {
            "id": "stat-576-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-576",
            "citation": "Va. Code § 59.1-576(A).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-576/",
            "proposition": "The VCDPA applies to persons doing business in Virginia or targeting its residents that control or process the data of at least 100,000 consumers, or 25,000+ while deriving over 50% of gross revenue from selling personal data.",
            "verbatimQuote": "This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-576-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Virginia privacy policy contain?",
        "heading": "What must your Virginia privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purpose for processing, how consumers exercise their rights, the categories of personal data shared with third parties, and the categories of those third parties.",
        "sources": [
          {
            "id": "stat-578-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-578",
            "citation": "Va. Code § 59.1-578(C).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-578/",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice listing the categories of personal data processed, the purpose for processing, how consumers exercise and appeal their rights, the categories of personal data shared with third parties, and the categories of those third parties.",
            "verbatimQuote": "reasonably accessible, clear, and meaningful privacy notice that includes: 1. The categories of personal data processed by the controller; 2. The purpose for processing personal data; 3. How consumers may exercise their consumer rights pursuant § 59.1-577, including how a consumer may appeal a controller's decision with regard to the consumer's request; 4. The categories of personal data that the controller shares with third parties, if any; and 5. The categories of third parties, if any, with whom the controller shares personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-578-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A contract between a controller and a processor must govern the processor's data processing on the controller's behalf — so a data processing agreement is a statutory requirement, not a best practice.",
        "sources": [
          {
            "id": "stat-579-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-579",
            "citation": "Va. Code § 59.1-579(B).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-579/",
            "proposition": "A contract between a controller and a processor must govern the processor's data processing performed on behalf of the controller.",
            "verbatimQuote": "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-579-contract"
          },
          {
            "id": "stat-579-terms",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-579",
            "citation": "Va. Code § 59.1-579(B).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-579/",
            "proposition": "The controller-processor contract must set forth processing instructions, the nature and purpose of processing, the type of data, the duration, and the parties' rights and obligations, and must require the processor to maintain confidentiality, delete or return data at the controller's direction, make compliance information available, cooperate with assessments, and bind subcontractors by written contract.",
            "verbatimQuote": "The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties. The contract shall also include requirements that the processor shall: 1. Ensure that each person processing personal data is subject to a duty of confidentiality with respect to the data; 2. At the controller's direction, delete or return all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law; 3. Upon the reasonable request of the controller, make available to the controller all information in its possession necessary to demonstrate the processor's compliance with the obligations in this chapter; 4. Allow, and cooperate with, reasonable assessments by the controller or the controller's designated assessor; alternatively, the processor may arrange for a qualified and independent assessor to conduct an assessment of the processor's policies and technical and organizational measures in support of the obligations under this chapter using an appropriate and accepted control standard or framework and assessment procedure for such assessments. The processor shall provide a report of such assessment to the controller upon request; and 5. Engage any subcontractor pursuant to a written contract in accordance with subsection C that requires the subcontractor to meet the obligations of the processor with respect to the personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-579-terms"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. A controller may not process a consumer's sensitive data without first obtaining consent, and for a known child it must instead follow the federal Children's Online Privacy Protection Act. Sensitive data includes data revealing race or ethnicity, religious beliefs, a health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data; data from a known child; and precise geolocation.",
        "sources": [
          {
            "id": "stat-578-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-578",
            "citation": "Va. Code § 59.1-578(A)(5).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-578/",
            "proposition": "A controller may not process a consumer's sensitive data without consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-578-consent"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the VCDPA?",
        "heading": "Can a consumer sue your business under the VCDPA?",
        "answerText": "No. The Attorney General has exclusive authority to enforce the VCDPA, so there is no private right of action for consumers. Before suing, the Attorney General must give 30 days' written notice of the specific alleged violations and a chance to cure.",
        "sources": [
          {
            "id": "stat-584-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-584",
            "citation": "Va. Code § 59.1-584(A).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-584/",
            "proposition": "The Attorney General has exclusive authority to enforce the VCDPA — there is no private right of action.",
            "verbatimQuote": "The Attorney General shall have exclusive authority to enforce the provisions of this chapter.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-584-enforce"
          },
          {
            "id": "stat-584-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Va. Code § 59.1-584",
            "citation": "Va. Code § 59.1-584(B).",
            "url": "https://law.lis.virginia.gov/vacode/59.1-584/",
            "proposition": "Before bringing an action, the Attorney General must give 30 days' written notice identifying the specific provisions allegedly violated.",
            "verbatimQuote": "30 days' written notice identifying the specific provisions of this chapter the Attorney General alleges have been or are being violated.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/virginia#src-stat-584-cure"
          }
        ]
      }
    ]
  }
}
