Skip to main content
Category: Privacy Regulations

Virginia Consumer Data Protection Act

Also known as: VCDPA, Virginia Consumer Data Protection Act, Consumer Data Protection Act (Virginia), Virginia CDPA
Simply put

The Virginia Consumer Data Protection Act (VCDPA) is a comprehensive state privacy law that gives people in Virginia more control over their personal data and was enacted in 2021. It lets Virginia consumers make certain requests about their data, such as confirming whether a business is processing it, and requires businesses handling that data to protect it. It applies specifically to Virginia and differs from privacy laws in other US states and other jurisdictions.

Formal definition

The VCDPA is a comprehensive consumer privacy statute codified in the Code of Virginia (Title 59.1, Chapter 53), enacted in 2021, that regulates the processing of the personal data of Virginia consumers. It assigns distinct obligations to a controller (the party that determines the purposes and means of processing) and a processor (a party that processes personal data on behalf of the controller), and it establishes consumer rights exercisable against the controller, including the right to confirm whether the controller is processing the consumer's personal data. Controllers are required to establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and availability of personal data. Note that the VCDPA should not be treated as interchangeable with the CCPA/CPRA, the EU or UK GDPR, or other US state privacy laws, as scoping, definitions, and obligations differ. This entry summarizes the law's identity, roles, and general nature; it does not detail applicability thresholds, defined exemptions, consumer rights procedures, cross-border transfer mechanics, retention rules, or enforcement provisions, which should be confirmed against the statutory text and current guidance.

Why it matters

The VCDPA is one of the comprehensive US state privacy statutes that emerged following California's lead, and it signals that organizations can no longer rely on a single US privacy program keyed only to the CCPA/CPRA. Because it was enacted in 2021 and codified in the Code of Virginia (Title 59.1, Chapter 53), businesses that process the personal data of Virginia consumers must evaluate their obligations against the specific text of this statute rather than assuming that compliance with another state's law, or with the EU or UK GDPR, satisfies it. Scoping, defined terms, and obligations differ across regimes, and treating them as interchangeable is a common and material error.

The law also allocates responsibilities along a controller-processor distinction, which matters for accountability. Under the VCDPA, the controller (the party that determines the purposes and means of processing) generally bears the direct consumer-facing obligations, while a processor acts on the controller's behalf. Consumer rights, such as the right to confirm whether the controller is processing the consumer's personal data, are exercisable against the controller. Organizations should be clear about which role they occupy for each processing activity, because that classification drives who owes what.

Beyond consumer rights, the VCDPA requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and availability of personal data. This ties governance decisions to demonstrable security controls, and accountability under such frameworks generally requires evidence of implementation, not merely stated intent. This entry does not cover applicability thresholds, exemptions, rights-handling procedures, retention, cross-border transfer mechanics, or enforcement, which should be confirmed against the statutory text and current guidance from the Virginia Office of the Attorney General.

Who it's relevant to

Privacy and compliance leads at businesses processing Virginia consumers' data
Organizations that determine the purposes and means of processing Virginia consumers' personal data typically act as controllers under the VCDPA and bear the direct consumer-facing obligations, including responding to requests such as confirmation of processing. These teams should assess coverage against the statutory text rather than assuming that a program built for another state's law meets Virginia's requirements, since scoping and definitions differ across regimes.
Data protection officers and governance leads
Those responsible for privacy governance need to map each processing activity to a controller or processor role, because that classification drives which obligations apply. They should also ensure the controller's reasonable administrative, technical, and physical security practices are documented and demonstrable, since accountability under such frameworks generally requires evidence of implementation, not merely stated intent.
Vendors and service providers acting as processors
Parties that process personal data on behalf of a controller act as processors under the VCDPA. While the controller generally holds the consumer-facing obligations, processors should understand the boundaries of their role and the terms governing disclosure of personal data to them, and confirm the specific processor obligations against the statutory text.
Legal and security professionals coordinating multi-state programs
Counsel and security teams supporting organizations operating across US states should treat the VCDPA as distinct from the CCPA/CPRA and from the EU or UK GDPR. Applicability thresholds, exemptions, rights procedures, retention, transfer mechanics, and enforcement are not covered here and must be verified against the Code of Virginia and current guidance from the Virginia Office of the Attorney General.

Inside VCDPA

Scope and applicability thresholds
The VCDPA applies to entities conducting business in Virginia or targeting Virginia residents that meet defined processing thresholds tied to the volume of consumers whose data is processed, with an alternative threshold that considers deriving revenue from the sale of personal data. Practitioners should confirm current thresholds against the statutory text rather than relying on figures from memory, as this summary does not restate specific numeric thresholds.
Controller and processor roles
The VCDPA distinguishes between controllers, who determine the purposes and means of processing, and processors, who process personal data on behalf of a controller. The controller bears primary accountability obligations, while the processor is bound by contractual duties and must assist the controller. This role distinction parallels but is not identical to controller/processor concepts under other regimes; obligations should be scoped to the VCDPA text.
Consumer rights
The VCDPA grants Virginia consumers a defined set of rights that generally include access, correction, deletion, portability, and the right to opt out of certain processing such as targeted advertising, the sale of personal data, and certain profiling. Rights are subject to statutory exceptions and verification requirements. This entry does not enumerate every exception or the precise mechanics of response timelines.
Sensitive data and consent
The VCDPA treats certain categories as sensitive data and generally requires opt-in consent before processing them. This differs from the treatment of ordinary personal data under the statute and from special category data definitions under the EU or UK GDPR. Consent under the VCDPA is one requirement among several and does not by itself establish overall compliance.
Data protection assessments
The VCDPA requires controllers to conduct data protection assessments for certain higher-risk processing activities, such as targeted advertising, sale of personal data, certain profiling, and processing of sensitive data. These assessments are triggered by specified activities rather than being universally mandatory for all processing, and they differ in scope and trigger from a data protection impact assessment under the GDPR.
Enforcement authority
Enforcement of the VCDPA rests with the Virginia Attorney General. This summary does not restate specific penalty amounts, cure period mechanics, or the presence or absence of a private right of action, as those details should be confirmed against the current statutory text.

Common questions

Answers to the questions practitioners most commonly ask about VCDPA.

Does the VCDPA work the same way as the CCPA/CPRA, so a California-ready program automatically covers Virginia?
No. The VCDPA and the California framework are distinct state laws and should not be treated as interchangeable. They use different terminology, defined roles, applicability thresholds, and consumer rights, and a program built to satisfy one does not automatically satisfy the other. In most cases, organizations must map each state's specific obligations separately rather than assuming a single control set is sufficient. This answer does not detail every point of divergence; consult the operative text of each statute and current guidance for a full comparison.
Is a consumer's consent under the VCDPA the same as a general lawful basis that authorizes any processing?
No. Consent should not be conflated with a blanket authorization for all processing. Under the VCDPA framing, consent is a specific, freely given, informed, and unambiguous agreement that is generally required for defined categories of processing, and other processing may be governed by different requirements. Consent is not a single mechanism that guarantees compliance; its validity depends on how it is obtained, scoped, and documented. This entry does not enumerate every processing activity that does or does not require consent.
How do we determine whether the VCDPA applies to our organization?
Applicability generally turns on statutory thresholds tied to doing business in or targeting Virginia residents and to the volume of consumers whose personal data is processed, sometimes combined with revenue derived from selling personal data. Because the precise thresholds and any exemptions are defined in the operative text, you should confirm current figures and exemption categories against the statute rather than relying on generalized descriptions. This answer does not state specific numeric thresholds and does not cover entity- or data-level exemptions in detail.
What is the difference between the controller and processor roles under the VCDPA, and who bears which obligations?
The VCDPA distinguishes between the party that determines the purposes and means of processing and the party that processes personal data on that party's behalf. In most cases, the controller bears the primary accountability obligations, such as responding to consumer rights requests and providing required disclosures, while the processor is generally bound to act on the controller's documented instructions and to assist the controller under a governing contract. Correctly classifying each party is essential because it drives who owes which duties. This answer does not enumerate every required contractual term or every allocated obligation.
When are we required to conduct a data protection assessment under the VCDPA, and is one always necessary?
A data protection assessment is not required for all processing. The VCDPA generally requires assessments for certain higher-risk processing activities defined in the statute, so the trigger is the nature of the processing rather than a universal mandate. Organizations should evaluate each activity against the statute's specified categories and maintain demonstrable documentation, since accountability generally requires evidence rather than stated intent. This answer does not list every triggering activity or prescribe the assessment's required contents.
How should we operationalize consumer rights requests under the VCDPA?
Practically, this typically involves establishing intake channels for the rights recognized under the statute, verifying the requester, routing requests to the controller as the accountable party, and coordinating with processors as needed under contract. Organizations generally need documented procedures and records to demonstrate timely and consistent handling, since compliance depends on implementation and evidence rather than a stated policy alone. This answer does not specify response timelines, appeal mechanics, or the full scope of each right, which should be confirmed against the operative text and current guidance.

Common misconceptions

The VCDPA is essentially the same as the CCPA/CPRA or the GDPR, so compliance with one satisfies the other.
The VCDPA is a distinct Virginia statute with its own applicability thresholds, defined terms, rights, and role definitions. While it shares conceptual similarities with other regimes, terminology and obligations differ, and controls or documentation prepared for one framework should not be assumed to satisfy another without mapping to the VCDPA text.
A data protection assessment must be performed for every processing activity under the VCDPA.
The VCDPA ties the assessment requirement to specified higher-risk activities such as targeted advertising, sale of personal data, certain profiling, and processing of sensitive data. Not all processing triggers the requirement, and the trigger and scope differ from a GDPR data protection impact assessment.
Obtaining consumer consent under the VCDPA guarantees lawful processing across the board.
Consent is required primarily for certain activities, notably the processing of sensitive data, and is one element among several statutory obligations. It does not by itself establish overall compliance, and controllers remain subject to other duties such as honoring consumer rights and conducting required assessments.

Best practices

Confirm applicability by assessing current statutory processing thresholds and revenue-from-sale criteria against your actual processing volumes, rather than relying on remembered figures.
Map your data flows to identify where you act as a controller versus a processor under the VCDPA, and ensure processor arrangements are supported by contracts reflecting the required duties and assistance obligations.
Inventory processing of sensitive data and implement an opt-in consent mechanism for those categories, documenting how consent is obtained and recorded.
Establish a process to identify triggering activities (targeted advertising, sale of personal data, certain profiling, sensitive data processing) and conduct and retain data protection assessments for them as demonstrable evidence of accountability.
Build verifiable consumer rights request workflows covering access, correction, deletion, portability, and opt-out, including identity verification and tracking of statutory response obligations.
Cross-reference VCDPA obligations against any parallel GDPR, UK GDPR, or CCPA/CPRA programs to reuse controls where genuinely applicable while documenting Virginia-specific requirements separately.