Virginia Consumer Data Protection Act
The Virginia Consumer Data Protection Act (VCDPA) is a comprehensive state privacy law that gives people in Virginia more control over their personal data and was enacted in 2021. It lets Virginia consumers make certain requests about their data, such as confirming whether a business is processing it, and requires businesses handling that data to protect it. It applies specifically to Virginia and differs from privacy laws in other US states and other jurisdictions.
The VCDPA is a comprehensive consumer privacy statute codified in the Code of Virginia (Title 59.1, Chapter 53), enacted in 2021, that regulates the processing of the personal data of Virginia consumers. It assigns distinct obligations to a controller (the party that determines the purposes and means of processing) and a processor (a party that processes personal data on behalf of the controller), and it establishes consumer rights exercisable against the controller, including the right to confirm whether the controller is processing the consumer's personal data. Controllers are required to establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and availability of personal data. Note that the VCDPA should not be treated as interchangeable with the CCPA/CPRA, the EU or UK GDPR, or other US state privacy laws, as scoping, definitions, and obligations differ. This entry summarizes the law's identity, roles, and general nature; it does not detail applicability thresholds, defined exemptions, consumer rights procedures, cross-border transfer mechanics, retention rules, or enforcement provisions, which should be confirmed against the statutory text and current guidance.
Why it matters
The VCDPA is one of the comprehensive US state privacy statutes that emerged following California's lead, and it signals that organizations can no longer rely on a single US privacy program keyed only to the CCPA/CPRA. Because it was enacted in 2021 and codified in the Code of Virginia (Title 59.1, Chapter 53), businesses that process the personal data of Virginia consumers must evaluate their obligations against the specific text of this statute rather than assuming that compliance with another state's law, or with the EU or UK GDPR, satisfies it. Scoping, defined terms, and obligations differ across regimes, and treating them as interchangeable is a common and material error.
The law also allocates responsibilities along a controller-processor distinction, which matters for accountability. Under the VCDPA, the controller (the party that determines the purposes and means of processing) generally bears the direct consumer-facing obligations, while a processor acts on the controller's behalf. Consumer rights, such as the right to confirm whether the controller is processing the consumer's personal data, are exercisable against the controller. Organizations should be clear about which role they occupy for each processing activity, because that classification drives who owes what.
Beyond consumer rights, the VCDPA requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and availability of personal data. This ties governance decisions to demonstrable security controls, and accountability under such frameworks generally requires evidence of implementation, not merely stated intent. This entry does not cover applicability thresholds, exemptions, rights-handling procedures, retention, cross-border transfer mechanics, or enforcement, which should be confirmed against the statutory text and current guidance from the Virginia Office of the Attorney General.
Who it's relevant to
Inside VCDPA
Common questions
Answers to the questions practitioners most commonly ask about VCDPA.