Virginia VCDPA

Compliance The Web Exposure Company

Virginia VCDPA

Virginia Consumer Data Protection Act

The VCDPA gives residents the right to access, correct, delete, and port their personal data, and to opt out of sale, targeted advertising, and profiling. Non-compliance invites Attorney General enforcement and damages consumer confidence, but aligning every data flow with these rights is demanding. Security teams need to verify that scripts, trackers, and cookies respect opt-out preferences and consent requirements for sensitive data.

Try for free
Virginia VCDPA privacy compliance monitoring

How Reflectiz Meets Every VCDPA Requirement

Requirement → Reflectiz Solution
Right to Access & Delete

Consumer Rights Fulfillment

Reflectiz inventories all components collecting personal data so teams can locate and act on access, correction, deletion, and portability requests with confidence.

Right to Opt-Out

Opt-Out of Sale, Targeted Ads & Profiling

The Privacy Dashboard identifies trackers that continue sharing data after opt-out or that fail to honor universal opt-out signals.

Right to Privacy

Sensitive Data Consent

Reflectiz surfaces scripts that collect sensitive data and confirms whether opt-in consent was captured before they fired.

Right to Know

Third-Party Vendor Oversight

Complete visibility into third- and fourth-party vendors and the personal data they access, transmit, or expose.

Reduces Regulatory Risk & Saves Time

Automated tracker detection dashboard Streamlined compliance operations Unified compliance management dashboard

Virginia VCDPA at a Glance

Key Facts
Key facts about the Virginia Consumer Data Protection Act (VCDPA)
Full nameVirginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq. Signed March 2, 2021, and in effect since January 1, 2023, as the second comprehensive state privacy law after California’s.
Who it applies toBusinesses that operate in Virginia or target Virginia residents and, in a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while earning over 50% of gross revenue from selling personal data.
ExemptionsState and local government bodies, nonprofits, institutions of higher education, financial institutions covered by the Gramm-Leach-Bliley Act, and HIPAA covered entities and business associates. Employee and business-to-business data fall outside the law.
Consumer rightsConfirm and access, correct, delete, and get a portable copy of personal data. Opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects.
Sensitive dataOpt-in consent comes first. Covers data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data used to identify a person; a known child’s data; and precise geolocation.
Precise geolocationSelling data that locates a person within 1,750 feet is banned outright as of July 1, 2026 (SB 338), regardless of consent.
Children’s dataA known child’s data (under 13) must be processed under COPPA. Since January 1, 2025, using it for targeted advertising, sale, or profiling requires parental consent (SB 361).
Targeted advertisingAds selected from a consumer’s activity across nonaffiliated websites over time, the typical job of an ad pixel. It requires a clear, conspicuous disclosure, an opt-out, and a data protection assessment.
Response deadlines45 days to answer a consumer request, with one 45-day extension. Appeals get a written decision within 60 days. Requests are free up to twice a year.
Universal opt-outNot required. Unlike Colorado, Connecticut, and Texas, Virginia does not mandate honoring signals such as Global Privacy Control.
EnforcementThe Virginia Attorney General only, with no private right of action. The Attorney General must give 30 days’ written notice to cure before suing, and that cure period does not expire.
PenaltiesUp to $7,500 per violation, plus injunctions and the Attorney General’s investigation costs, including attorney fees.

Virginia VCDPA FAQ

Common Questions

What is the Virginia VCDPA?

The Virginia Consumer Data Protection Act (VCDPA) is Virginia’s comprehensive consumer privacy law, codified at Va. Code § 59.1-575 et seq. Signed in March 2021 and in effect since January 1, 2023, it was the second state privacy law after California’s. It gives Virginia residents rights over their personal data and requires opt-in consent before a business processes sensitive data.

Who must comply with the VCDPA?

Any business that operates in Virginia or targets Virginia residents and, in a calendar year, controls or processes personal data of at least 100,000 consumers, or of at least 25,000 consumers while earning over 50% of gross revenue from selling personal data. Government bodies, nonprofits, higher education institutions, financial institutions covered by the Gramm-Leach-Bliley Act, and HIPAA-regulated entities are exempt.

What rights does the VCDPA give consumers?

Virginia consumers can confirm and access the personal data a business holds, correct it, delete it, and get a portable copy. They can also opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects. Businesses must respond within 45 days, with one 45-day extension, and must offer an appeal process.

What counts as sensitive data under the VCDPA?

Sensitive data is personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data used to identify a person; data from a known child; and precise geolocation. Businesses need opt-in consent before processing it, and since July 1, 2026, selling precise geolocation data is banned outright.

Does the VCDPA require honoring Global Privacy Control?

No. Unlike Colorado, Connecticut, and Texas, Virginia does not require businesses to honor universal opt-out signals such as Global Privacy Control. Virginia consumers can still opt out of targeted advertising and sale directly, and every tracker on your site must respect that choice. Sites that serve several states usually honor Global Privacy Control anyway, so a tracker that ignores it is a multi-state risk.

What are the penalties for violating the VCDPA?

The Virginia Attorney General enforces the law exclusively and can seek civil penalties of up to $7,500 per violation, plus injunctions and investigation costs, including attorney fees. There is no private right of action. Before suing, the Attorney General must give 30 days’ written notice, and a business that cures the violation within that window and confirms it in writing avoids the action.

How does Reflectiz support VCDPA compliance?

Reflectiz monitors your website remotely, with no code changes, and inventories every script, pixel, and cookie that collects personal data. It flags trackers that keep sharing data for targeted advertising or sale after a consumer opts out, detects sensitive data collected without opt-in consent, and maps every third- and fourth-party vendor that receives the data. Your privacy notice states the policy. Reflectiz shows what your site actually does.

Last reviewed September 2026. This page summarizes the Virginia VCDPA for general information and is not legal advice. Related: CCPA, Texas TDPSA, Illinois BIPA, GDPR, and the Reflectiz Privacy Hub.

Ready for VCDPA? Know Your Web Exposure.

See every script, tag, and tracker on your site, and whether it honors opt-outs and sensitive-data consent, in one continuous, agentless view.

Start Free