Privacy Policy in Virginia
The Virginia Consumer Data Protection Act (Va. Code § 59.1-575 et seq., effective January 1, 2023) requires controllers of Virginia consumers' personal data to publish a privacy notice disclosing categories of personal data processed, purposes of processing, categories shared with third parties, consumer rights, and an appeal mechanism for denied rights requests.
Last reviewed against current law: 2026-05-14
How Virginia law treats privacy policy
The VCDPA applies to businesses that (1) conduct business in Virginia or produce products/services targeted to Virginia residents, and (2) either control or process the personal data of 100,000+ Virginia consumers in a calendar year, or control or process the personal data of 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.
The privacy notice must include the categories of personal data processed, the purpose of processing, how consumers may exercise their rights and appeal a denial, the categories of personal data shared with third parties, and the categories of third parties with whom personal data is shared. Sensitive data (defined to include racial origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship status, genetic or biometric data, geolocation, and data from a known child) requires opt-in consent.
VCDPA rights include access, correction, deletion, portability, and opt-out of sale, targeted advertising, and certain profiling decisions. The Virginia Attorney General has exclusive enforcement authority — there is no private right of action — and may seek up to $7,500 per violation plus injunctive relief.
Primary sources
Frequently asked questions — Virginia
When does the VCDPA apply to my business?▾
When you process personal data of 100,000+ Virginia consumers per year, or process 25,000+ Virginia consumers and derive over 50% of revenue from selling personal data. Smaller businesses processing data on Virginia residents are outside the law's scope.
Does the VCDPA require opt-in for sensitive data?▾
Yes. Sensitive data — including biometric, genetic, geolocation, health, and children's data — requires opt-in consent rather than the opt-out model that governs most other processing.
Can consumers sue under the VCDPA?▾
No. Enforcement is exclusive to the Virginia Attorney General, with penalties up to $7,500 per violation plus actual damages and injunctive relief.