Virginia Consumer Data Protection Act (Va. Code 59.1-575 et seq.)
Below is what the official text of Virginia Consumer Data Protection Act (Va. Code 59.1-575 et seq.) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Virginia and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Virginia: Not triggered by these answers.
- A US business with no users in Virginia: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Protects consumers' personal data and binds persons who conduct business in Virginia or target Virginia residents and meet the volume thresholds.Official wordingThis chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that | law.lis.virginia.gov read 2026-10-06 |
| When it applies to a business | Applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and that, during a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data. Conditions to check: Excluded entities (59.1-576(B)): Commonwealth and local government bodies; financial institutions or data subject to Title V of the Gramm-Leach-Bliley Act; HIPAA covered entities and business associates; nonprofit organizations; institutions of higher education. Many categories of data are also exempt (59.1-576(C)), e.g. HIPAA protected health information, FERPA data, FCRA-regulated credit data, employment-context data. 'Conduct business in the Commonwealth' and 'targeted to residents' are not defined in the quote; we test whether you have users there, which is only a proxy. The definition of 'consumer' (59.1-575) was not read. Official wordingthat conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. | law.lis.virginia.gov read 2026-10-06 |
| In force from | 2023-01-01 2021 Acts of Assembly Sp. Sess. I ch. 35, 4th enactment: the first and third enactments become effective January 1, 2023 (later amendments, e.g. 2022, 2024, 2026, are in the live Code). Official wording4. That the provisions of the first and third enactments of this act shall become effective on January 1, 2023. | legacylis.virginia.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text read does not say whether a data protection officer or privacy officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here