Virginia Consumer Data Protection Act
Tier 1 In forceThe VCDPA (signed March 2021, effective 1 January 2023) is Virginia's comprehensive consumer privacy statute. It is the structural opposite of California's regime on two axes that matter most: there is NO private right of action and NO dedicated privacy agency — enforcement is the exclusive province of the Virginia Attorney General. It borrows GDPR-style vocabulary (its consent definition is taken almost verbatim from the GDPR) but pairs it with a business-friendly, permanent 30-day cure period. Consumers who believe their rights are violated cannot sue; they complain to the AG.
Identity
- Citation
- Va. Code sec. 59.1-575 et seq.
- Jurisdiction
- United States
- Sub-jurisdiction
- Virginia
- Type
- comprehensive
- Structure
- Chapter 53 of Title 59.1 of the Code of Virginia.
- Royal assent
- 2 March 2021
- Main commencement
- 1 January 2023
Effective 1 January 2023. Minor-protection provisions (social media restrictions for under-18s) took effect 1 January 2026; separate reproductive/sexual health data protections added by SB 754.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | None found — checked | Applies to controllers conducting business in Virginia or targeting Virginia residents above thresholds; no sub-state carve-out. |
| 2 | Commencement | Asymmetry found | Core law in force 2023; minor-protection provisions took effect 1 January 2026; further amendments (e.g. SB 338 geolocation-sale ban) were pending gubernatorial action at the research date. |
| 3 | Sunset / mandatory review | None found — checked | No sunset. Notably, the 30-day cure period is PERMANENT — unlike Colorado (cure expired 1 January 2025) and Connecticut (cure eliminated), Virginia's cure period has no sunset provision. |
| 4 | Criminal liability | None found — checked | None found — checked. The VCDPA provides civil penalties enforced by the AG; no criminal offences. |
| 5 | Civil liability | None found — checked | None found — checked. There is NO private right of action for core VCDPA violations; only the Attorney General may enforce. (A separate reproductive/sexual health data law, SB 754, sits outside the core VCDPA enforcement model.) Consumers file complaints with the AG's Consumer Privacy Unit. |
| 6 | Regulatory enforcement toolkit | Asymmetry found | Exclusive AG enforcement (Va. Code sec. 59.1-584). The AG must give 30 days' written notice identifying the specific provisions alleged to be violated; if the controller cures within 30 days and gives written assurance, no action follows. Uncured violations expose the controller to civil penalties of up to $7,500 per violation plus injunctive relief and reasonable attorney's fees. |
| 7 | Personal / director liability | None found — checked | None found — checked. No distinct director/officer personal liability provision identified. |
| 8 | Public vs private sector split | None found — checked | One controller/processor regime, with carve-outs for HIPAA, FERPA, GLBA entities, state agencies, non-profits and higher-education institutions — exemptions rather than a public/private split. |
| 9 | Legal-person coverage | Asymmetry found | Protects "consumers" acting in an individual/household context; the VCDPA expressly excludes individuals acting in a commercial or employment context, so employee and B2B data are NOT covered — the opposite of California's post-2023 position. |
| 10 | Exemptions — with conditions | Asymmetry found | Virginia's exemptions are broader and more entity-level than California's: HIPAA covered entities and business associates, GLBA financial institutions, non-profits, higher-education institutions and state bodies are exempt as whole organisations, with further data-level carve-outs. Individuals acting in an employment or commercial context are additionally excluded from the definition of "consumer" itself, so that data never enters scope. Triggers are status under the named regime, applied categorically rather than case by case. |
Regulatory enforcement
- Penalty ceiling
- Civil penalties up to $7,500 per violation, plus reasonable attorney's fees and costs, following an uncured 30-day notice.
Exemptions
Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.
sec. 59.1-576 — Entity and data exemptions
Trigger
Applies where the entity or data falls within a listed federal regime (HIPAA-covered PHI, GLBA-regulated financial data, FERPA education records) or the entity is a state body/non-profit. Availability is assessed by reference to the specific entity or data category.
Employment and commercial-context data are excluded from "consumer" entirely, not merely exempted.
Live issues
Sources
- Secondary Virginia Consumer Data Protection Act (VCDPA) Bloomberg Law
- Regulator The Virginia Consumer Data Protection Act Summary Virginia Office of the Attorney General
- Secondary Virginia Consumer Data Protection Act: Complete 2026 Compliance Guide PrivacyLawMap
Never independently verified — seeded from the prototype.