Privacy Laws

What is VCDPA (Virginia Consumer Data Protection Act)?

The Virginia Consumer Data Protection Act (VCDPA) is Virginia's comprehensive privacy law, effective January 1, 2023, which grants Virginia residents rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, data sales, and profiling.

Virginia was the second US state to pass a comprehensive privacy law, and it chose a different template than California: rather than extending the CCPA, the VCDPA borrowed the GDPR's controller/processor vocabulary and a cleaner rights catalog. That Virginia model — not California's — became the chassis for most subsequent state laws, including Colorado's, Connecticut's, and Utah's.

It applies to businesses that control or process the personal data of at least 100,000 Virginia consumers in a calendar year, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data. Notably, there is no general revenue threshold — a large company with minimal Virginia data volume may be outside it. 'Consumer' covers individuals acting in a personal or household context, excluding employment and B2B data entirely.

Consumers may access, correct, delete, and obtain a portable copy of their data, and may opt out of targeted advertising, the sale of personal data (defined more narrowly than California's — exchange for monetary consideration), and profiling that produces legal or similarly significant effects. Processing sensitive data — including racial or ethnic origin, religion, health diagnoses, sexual orientation, citizenship or immigration status, genetic and biometric data, children's data, and precise geolocation — requires opt-in consent, a stricter approach than California's limit-use right. Controllers must also conduct data protection assessments for higher-risk processing.

Enforcement belongs exclusively to the Virginia Attorney General — there is no private right of action — with civil penalties up to $7,500 per violation and a permanent 30-day cure period that lets businesses fix noticed violations before penalties attach.

Why it matters for eCommerce

If your store touches 100,000 Virginians' data a year — achievable for a national DTC brand — the VCDPA applies. The practical deltas from California: opt-in consent before processing sensitive data, opt-out rights framed around 'targeted advertising' rather than 'sharing,' and a friendlier enforcement posture with a cure period. Most brands satisfy it with the same machinery built for CCPA plus a consent gate on sensitive categories.

Frequently asked questions

Who must comply with the VCDPA?
Businesses that control or process personal data of 100,000+ Virginia consumers annually, or 25,000+ consumers while deriving over half of gross revenue from selling personal data. Unlike the CCPA, there is no standalone revenue threshold.
Can Virginia consumers sue under the VCDPA?
No — enforcement is exclusive to the Virginia Attorney General, with civil penalties up to $7,500 per violation. Businesses also get a 30-day cure period after notice, which Virginia made permanent.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Scan against Virginia's law

← Back to all glossary terms