🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-VA · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 17 sources retrieved model claude-sonnet-5 ·

United States – Virginia

US-VA schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 57 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
57Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force but enforcement rests solely with a general-purpose AG office lacking rulemaking power or a dedicated registration regime.

Primary frameworkVirginia Consumer Data Protection Act (VCDPA), Va. Code §§59.1-575 to 59.1-585
Traffic-light rationale — AmberComprehensive statute in force but enforcement rests solely with a general-purpose AG office lacking rulemaking power or a dedicated registration regime.

Sub-modules (5)

Regulator And AuthorityAmber

AG is the sole enforcer; no private right of action exists.

Claims (1):

  • The Virginia Attorney General's Office is the exclusive enforcer of the VCDPA and there is no private right of action for violations.

Act And InstrumentsGreen

VCDPA effective Jan 1 2023; amended by three 2022 bills ahead of effective date.

Claims (2):

  • The Virginia Consumer Data Protection Act (VCDPA) went into effect on January 1, 2023.
  • In 2022 the Virginia General Assembly enacted three amendment bills to the VCDPA that converted the right to delete data-broker-sourced personal data into a right to opt out of its processing, expanded the nonprofit exclusion to political organizations, and repealed the VCDPA Consumer Privacy Fund.

Material ScopeGreen

Covers VA-resident consumer personal data in individual/household context only.

Claims (1):

  • The VCDPA governs 'personal data' of natural persons who are Virginia residents acting only in an individual or household context, expressly excluding data about individuals acting in an employment or commercial context.

Territorial ScopeGreen

Dual-threshold applicability test based on consumer volume/sale-revenue, not turnover.

Claims (1):

  • The VCDPA applies to persons conducting business in Virginia or producing products/services targeted to Virginia residents that, during a calendar year, either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.

Regulator Registration And FilingAmber

No rulemaking authority or filing/registration regime exists under the Act.

Claims (1):

  • Unlike California's CCPA/CPRA, the VCDPA's final text does not grant the Attorney General rulemaking authority, and the statute imposes no controller registration or filing obligation with the Commonwealth.
Category narrative81 words

Virginia's data-protection regime is anchored in the Virginia Consumer Data Protection Act (VCDPA), Va. Code §§59.1-575 et seq., effective January 1, 2023, enforced exclusively by the Virginia Attorney General's Office with no dedicated privacy regulator, no rulemaking authority, and no controller-registration/filing obligation. The Act applies to entities conducting business in or targeting Virginia residents that meet a 100,000-consumer processing threshold or a 25,000-consumer-plus-50%-sale-revenue threshold. The statute has been amended multiple times (2022, 2026) via the General Assembly rather than agency rulemaking.

Sources and claims (6)
  1. ConfirmedVirginia Office of the Attorney GeneralThe Virginia Attorney General's Office is the exclusive enforcer of the VCDPA and there is no private right of action for violations.observed
  2. ConfirmedVirginia Office of the Attorney GeneralThe Virginia Consumer Data Protection Act (VCDPA) went into effect on January 1, 2023.observed
  3. ConfirmedIAPPIn 2022 the Virginia General Assembly enacted three amendment bills to the VCDPA that converted the right to delete data-broker-sourced personal data into a right to opt out of its processing, expanded the nonprofit exclusion to political organizations, and repealed the VCDPA Consumer Privacy Fund.observed
  4. ConfirmedIAPPThe VCDPA governs 'personal data' of natural persons who are Virginia residents acting only in an individual or household context, expressly excluding data about individuals acting in an employment or commercial context.observed
  5. ConfirmedOneTrust DataGuidanceThe VCDPA applies to persons conducting business in Virginia or producing products/services targeted to Virginia residents that, during a calendar year, either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.observed
  6. ConfirmedIAPPUnlike California's CCPA/CPRA, the VCDPA's final text does not grant the Attorney General rulemaking authority, and the statute imposes no controller registration or filing obligation with the Commonwealth.observed

#

Consent-for-sensitive-data regime is clear and Confirmed, but the Act lacks a GDPR-equivalent enumerated lawful-basis structure.

Primary frameworkVCDPA, Va. Code §§59.1-575 to 59.1-585
Traffic-light rationale — AmberConsent-for-sensitive-data regime is clear and Confirmed, but the Act lacks a GDPR-equivalent enumerated lawful-basis structure.

Sub-modules (4)

Lawful BasesAmber

No enumerated Article-6-style basis list; default-permitted processing plus opt-out rights substitute for a licensing model.

Claims (1):

  • The VCDPA does not enumerate GDPR Article-6-style lawful processing bases; general processing of non-sensitive personal data is permitted subject to purpose- and data-minimization limits, with consumers instead granted opt-out rights against targeted advertising, sale, and certain profiling.

Special CategoriesGreen

Sensitive-data list includes race/ethnicity, religion, health diagnosis, sexual orientation, immigration status, genetic/biometric ID data, known-child (<13) data, and (2026) precise geolocation data.

Claims (2):

  • VCDPA sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed for unique identification, and personal data collected from a known child under 13.
  • Senate Bill 338, enacted as Chapter 820 of the 2026 Acts of Assembly and signed 13 April 2026, amends the VCDPA to prohibit controllers from selling or offering to sell a consumer's precise geolocation data, entering into force 1 July 2026.

Pseudonymisation And AnonymisationGreen

De-identified/pseudonymized data are exempted from personal-data scope subject to safeguards.

Claims (1):

  • The VCDPA exempts de-identified and pseudonymized data from the definition of personal data and from consumer-rights obligations, provided the controller maintains technical and organizational controls preventing re-identification.
Category narrative60 words

The VCDPA does not use a GDPR Article-6-style enumerated lawful-basis model; general processing proceeds by default subject to purpose- and data-minimization limits, while affirmative opt-in consent is mandatory for a defined list of sensitive-data categories, expanded in 2026 to include precise geolocation data. De-identified and pseudonymized data fall outside the Act's personal-data definition and rights obligations where technical/organizational safeguards exist.

Sources and claims (5)
  1. ProbableIAPPThe VCDPA does not enumerate GDPR Article-6-style lawful processing bases; general processing of non-sensitive personal data is permitted subject to purpose- and data-minimization limits, with consumers instead granted opt-out rights against targeted advertising, sale, and certain profiling.observed
  2. ConfirmedVirginia Office of the Attorney GeneralControllers must obtain a consumer's affirmative consent prior to processing that consumer's sensitive data under the VCDPA.observed
  3. ConfirmedVirginia Office of the Attorney GeneralVCDPA sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed for unique identification, and personal data collected from a known child under 13.observed
  4. ConfirmedIAPPSenate Bill 338, enacted as Chapter 820 of the 2026 Acts of Assembly and signed 13 April 2026, amends the VCDPA to prohibit controllers from selling or offering to sell a consumer's precise geolocation data, entering into force 1 July 2026.observed
  5. ConfirmedIAPPThe VCDPA exempts de-identified and pseudonymized data from the definition of personal data and from consumer-rights obligations, provided the controller maintains technical and organizational controls preventing re-identification.observed

#

Rights framework is comprehensive, statutorily explicit, and well-documented by the regulator itself.

Primary frameworkVCDPA, Va. Code §59.1-577
Traffic-light rationale — GreenRights framework is comprehensive, statutorily explicit, and well-documented by the regulator itself.

Sub-modules (5)

Access RightGreen

Right to confirm and access processed personal data.

Claims (1):

  • Consumers have the right to confirm whether a controller is processing their personal data and to access that personal data.

Rectification And ErasureGreen

Correction and deletion rights, with a data-broker-specific opt-out substitute for deletion post-2022 amendment.

Claims (1):

  • Consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them; for data obtained from a source other than the consumer, the 2022 amendments deem a controller compliant by instead opting the consumer out of further processing of that data.

Restriction And ObjectionGreen

Opt-out rights for targeted advertising, sale, and significant-effect profiling.

Claims (1):

  • Consumers have the right to opt out of the processing of their personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.

Data PortabilityAmber

Consumers may obtain a copy of their personal data held by a controller.

Claims (1):

  • Consumers have the right to obtain a copy of their personal data held by a controller.

Deadlines And Response WindowsGreen

45-day response window, extendable once by 45 days; mandatory appeal process.

Claims (1):

  • A controller must respond to a consumer rights request within 45 days of receipt, with one 45-day extension available where reasonably necessary provided the consumer is notified within the initial response period; if a request is refused, the controller must offer an appeal process and inform the consumer of the right to complain to the Attorney General if the appeal is denied.
Category narrative34 words

The VCDPA grants Virginia consumers access, correction, deletion, opt-out (targeted advertising/sale/profiling), and portability-adjacent rights, with a 45-day (plus one 45-day extension) response window and a mandatory appeal mechanism escalating to AG complaint if denied.

Sources and claims (5)
  1. ConfirmedIAPPConsumers have the right to confirm whether a controller is processing their personal data and to access that personal data.observed
  2. ConfirmedIAPPConsumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them; for data obtained from a source other than the consumer, the 2022 amendments deem a controller compliant by instead opting the consumer out of further processing of that data.observed
  3. ConfirmedVirginia Office of the Attorney GeneralConsumers have the right to opt out of the processing of their personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.observed
  4. ProbableVirginia Office of the Attorney GeneralConsumers have the right to obtain a copy of their personal data held by a controller.observed
  5. ConfirmedIAPPA controller must respond to a consumer rights request within 45 days of receipt, with one 45-day extension available where reasonably necessary provided the consumer is notified within the initial response period; if a request is refused, the controller must offer an appeal process and inform the consumer of the right to complain to the Attorney General if the appeal is denied.observed

#

Core accountability tools (DPIA, processor contracts) are present and Confirmed, but structural gaps exist versus GDPR (no DPO, no distinct ROPA, no VCDPA-specific retention schedule).

Primary frameworkVCDPA, Va. Code §59.1-576 to 59.1-580; breach notice under Va. Code §18.2-186.6
Traffic-light rationale — AmberCore accountability tools (DPIA, processor contracts) are present and Confirmed, but structural gaps exist versus GDPR (no DPO, no distinct ROPA, no VCDPA-specific retention schedule).

Sub-modules (7)

Accountability And DpiaGreen

Data protection assessments required for targeted advertising, sale, high-risk profiling, and sensitive-data processing.

Claims (1):

  • Controllers must conduct data protection assessments (DPIAs) for processing activities involving targeted advertising, the sale of personal data, profiling presenting a reasonably foreseeable risk of unfair/deceptive treatment or unlawful disparate impact, processing of sensitive data, or other processing presenting a heightened risk of harm to consumers.

Dpo RequirementsRed

No DPO-appointment obligation identified.

Claims (1):

  • The VCDPA contains no statutory requirement to appoint a Data Protection Officer or equivalent independent privacy role.

Ropa RequirementsRed

No stand-alone ROPA mandate distinct from the assessment requirement.

Claims (1):

  • The VCDPA does not impose a distinct Article-30-style comprehensive Records of Processing Activities obligation on controllers, though data protection assessments must document the processing context and controller-consumer relationship.

Joint Controller ArrangementsGreen

Mandatory data processing agreements govern processor relationships.

Claims (1):

  • Where a processor acts on a controller's behalf, the VCDPA requires a data processing agreement clearly setting out instructions for processing, the nature and purpose of processing, the type of data, duration of processing, and the rights and obligations of both parties, mirroring GDPR Article 28-style processor terms.

Security MeasuresAmber

General reasonable-security obligation applies.

Claims (1):

  • Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of personal data at issue.

Breach NotificationAmber

Breach notice governed by a separate Virginia statute outside the VCDPA, with a 1,000-person AG/CRA notification trigger.

Claims (1):

  • Virginia's personal information breach notification statute (Va. Code §18.2-186.6, outside the VCDPA itself) requires notification of a breach of unencrypted, unredacted personal information to affected residents and, where notice is given to more than 1,000 persons, to the Attorney General and nationwide consumer reporting agencies.

Retention And DisposalAmber

Data-minimization principle applies; no VCDPA-specific fixed retention/disposal schedule identified.

Claims (2):

  • The VCDPA's data-minimization principle limits collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes of processing.
  • No fixed statutory data-retention-period or disposal-schedule requirement beyond the general data-minimization principle was identified for controllers under the VCDPA.
Category narrative60 words

Controllers must conduct data protection assessments for higher-risk processing (targeted advertising, sale, certain profiling, sensitive data), and processor relationships must be governed by GDPR-Article-28-style data processing agreements. The Act contains no DPO-appointment mandate and no stand-alone ROPA obligation distinct from the assessment requirement. Breach notification is governed by a separate Virginia statute (Va. Code §18.2-186.6) rather than the VCDPA itself.

Sources and claims (8)
  1. ConfirmedIAPPControllers must conduct data protection assessments (DPIAs) for processing activities involving targeted advertising, the sale of personal data, profiling presenting a reasonably foreseeable risk of unfair/deceptive treatment or unlawful disparate impact, processing of sensitive data, or other processing presenting a heightened risk of harm to consumers.observed
  2. ProbableVirginia Office of the Attorney GeneralThe VCDPA contains no statutory requirement to appoint a Data Protection Officer or equivalent independent privacy role.observed
  3. ProbableOneTrust DataGuidanceThe VCDPA does not impose a distinct Article-30-style comprehensive Records of Processing Activities obligation on controllers, though data protection assessments must document the processing context and controller-consumer relationship.observed
  4. ConfirmedIAPPWhere a processor acts on a controller's behalf, the VCDPA requires a data processing agreement clearly setting out instructions for processing, the nature and purpose of processing, the type of data, duration of processing, and the rights and obligations of both parties, mirroring GDPR Article 28-style processor terms.observed
  5. ProbableVirginia Office of the Attorney GeneralControllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of personal data at issue.observed
  6. ConfirmedOneTrust DataGuidanceVirginia's personal information breach notification statute (Va. Code §18.2-186.6, outside the VCDPA itself) requires notification of a breach of unencrypted, unredacted personal information to affected residents and, where notice is given to more than 1,000 persons, to the Attorney General and nationwide consumer reporting agencies.observed
  7. ConfirmedIAPPThe VCDPA's data-minimization principle limits collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes of processing.observed
  8. UncertainIAPPNo fixed statutory data-retention-period or disposal-schedule requirement beyond the general data-minimization principle was identified for controllers under the VCDPA.observed

#

No comprehensive cross-border transfer or adequacy regime exists in this jurisdiction; only a generic processor-contract requirement applies.

Traffic-light rationale — RedNo comprehensive cross-border transfer or adequacy regime exists in this jurisdiction; only a generic processor-contract requirement applies.

Sub-modules (6)

Transfer MechanismsAmber

Only a processor-contract requirement functions as a de facto transfer control; no adequacy/SCC/BCR regime exists.

Claims (1):

  • The VCDPA contains no dedicated cross-border data-transfer mechanism (no adequacy-decision framework, SCCs, or BCR approval regime); the only transfer-relevant control is the mandatory controller-processor data processing agreement applicable regardless of the processor's location.

Adequacy ReceivedRed

Not applicable — VCDPA has no adequacy-recognition mechanism.

Adequacy GrantedRed

Not applicable — Virginia grants no state-level adequacy determinations to other regimes.

Sccs And BcrsRed

No VCDPA-specific SCC or BCR approval regime identified.

Transfer Impact AssessmentRed

No TIA-equivalent requirement identified at the state level.

Data LocalisationRed

No data-localisation mandate identified under the VCDPA.

Category narrative47 words

As a US state consumer-privacy statute, the VCDPA has no GDPR-style cross-border transfer or adequacy framework. The only transfer-relevant control is the mandatory controller-processor data processing agreement, which applies irrespective of processor location. No adequacy decisions, SCC/BCR regimes, transfer impact assessment requirements, or data-localisation mandates were identified.

Sources and claims (1)
  1. ProbableIAPPThe VCDPA contains no dedicated cross-border data-transfer mechanism (no adequacy-decision framework, SCCs, or BCR approval regime); the only transfer-relevant control is the mandatory controller-processor data processing agreement applicable regardless of the processor's location.observed

#

Sectoral carve-outs are clear and Confirmed for finance/health/credit/education, but coverage relies on displacement to federal sectoral statutes rather than an integrated overlay.

Primary frameworkVCDPA exemptions (Va. Code §59.1-576) plus federal GLBA/HIPAA/FCRA/FERPA and VA reproductive-health-data statute
Traffic-light rationale — AmberSectoral carve-outs are clear and Confirmed for finance/health/credit/education, but coverage relies on displacement to federal sectoral statutes rather than an integrated overlay.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA-regulated data/entities exempted from VCDPA scope.

Claims (1):

  • The VCDPA exempts information subject to the federal Gramm-Leach-Bliley Act (GLBA) and GLBA-regulated financial institutions' data-handling activities from its scope, leaving GLBA as the operative privacy framework for that data.

Health Sector OverlayAmber

HIPAA-covered data exempted; separate reproductive-health-data consent statute in force since July 2025.

Claims (2):

  • Protected health information governed by HIPAA and data held by HIPAA-covered entities/business associates is exempted from VCDPA scope, leaving HIPAA as the operative health-data framework.
  • A separate Virginia statute restricting the sharing of reproductive or sexual health data without consumer consent entered into effect July 1, 2025, supplementing the VCDPA's sensitive-data consent regime for this category of health information.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style statute identified for Virginia beyond general VCDPA opt-out rights.

Employment DataAmber

Employment/commercial-context data is excluded from the 'consumer' definition entirely.

Claims (1):

  • The VCDPA's definition of 'consumer' expressly excludes a natural person acting in an employment context, so employee and job-applicant personal data generally falls outside VCDPA obligations, unlike California's CPRA.

Credit And ScoringAmber

FCRA-regulated data exempted from VCDPA scope.

Claims (1):

  • Data regulated by the federal Fair Credit Reporting Act (FCRA) is exempted from VCDPA scope, leaving FCRA as the operative framework for consumer credit-reporting and scoring data.

EducationAmber

FERPA-regulated data and higher-education institutions exempted from VCDPA scope.

Claims (1):

  • Data governed by the federal Family Educational Rights and Privacy Act (FERPA) and Virginia's institutions of higher education are exempted from VCDPA scope.

InsuranceRed

No insurance-sector-specific overlay distinct from the general GLBA-type financial exemption was identified.

Category narrative57 words

The VCDPA carves out 14 categories of exempted data/entities, including information governed by GLBA, HIPAA, FCRA, the Driver's Privacy Protection Act, the Farm Credit Act, and FERPA, and excludes employment/commercial-context data entirely. A separate Virginia statute effective July 1, 2025 restricts sharing of reproductive/sexual health data without consent, supplementing the VCDPA's sensitive-data consent rules for that category.

Sources and claims (6)
  1. ConfirmedIAPPThe VCDPA exempts information subject to the federal Gramm-Leach-Bliley Act (GLBA) and GLBA-regulated financial institutions' data-handling activities from its scope, leaving GLBA as the operative privacy framework for that data.observed
  2. ConfirmedOneTrust DataGuidanceProtected health information governed by HIPAA and data held by HIPAA-covered entities/business associates is exempted from VCDPA scope, leaving HIPAA as the operative health-data framework.observed
  3. ProbableOneTrust DataGuidanceA separate Virginia statute restricting the sharing of reproductive or sexual health data without consumer consent entered into effect July 1, 2025, supplementing the VCDPA's sensitive-data consent regime for this category of health information.observed
  4. ConfirmedIAPPThe VCDPA's definition of 'consumer' expressly excludes a natural person acting in an employment context, so employee and job-applicant personal data generally falls outside VCDPA obligations, unlike California's CPRA.observed
  5. ConfirmedIAPPData regulated by the federal Fair Credit Reporting Act (FCRA) is exempted from VCDPA scope, leaving FCRA as the operative framework for consumer credit-reporting and scoring data.observed
  6. ConfirmedOneTrust DataGuidanceData governed by the federal Family Educational Rights and Privacy Act (FERPA) and Virginia's institutions of higher education are exempted from VCDPA scope.observed

#

Opt-out rights are Confirmed and functional, but the Act lacks GPC-signal recognition and dark-pattern prohibitions found in some peer states.

Primary frameworkVCDPA, Va. Code §59.1-577
Traffic-light rationale — AmberOpt-out rights are Confirmed and functional, but the Act lacks GPC-signal recognition and dark-pattern prohibitions found in some peer states.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie-consent regime; tracking for targeted advertising addressed via opt-out right.

Claims (1):

  • The VCDPA does not impose a dedicated cookie-consent regime; tracking for targeted advertising is instead addressed through the Act's opt-out right rather than an ePrivacy-style prior-consent-for-cookies rule.

Dark PatternsRed

No VCDPA-specific dark-patterns prohibition identified.

Claims (1):

  • No VCDPA-specific statutory prohibition on 'dark patterns' in consent interfaces was identified, in contrast to California's CPRA.

Opt Out SignalsRed

Universal opt-out mechanism was discussed but not enacted in the VCDPA.

Claims (1):

  • During the VCDPA implementation work group, stakeholders discussed—but the enacted VCDPA text did not adopt—a Colorado-style universal opt-out mechanism (e.g., Global Privacy Control) requirement; no such signal-recognition mandate was identified in the current statute.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific provisions identified.

Cross Context AdvertisingAmber

Narrower 'sale' (monetary-only) and 'targeted advertising' constructs versus CPRA's sale/share dichotomy.

Claims (1):

  • The VCDPA's opt-out right covers 'sale' of personal data (defined narrowly as exchange for monetary consideration) and 'targeted advertising' across non-affiliated sites and applications, a narrower construct than CPRA's 'sale'/'share' dichotomy.

Direct MarketingRed

No dedicated direct-marketing consent/suppression statute distinct from the targeted-advertising opt-out was identified.

Category narrative61 words

The VCDPA regulates commercial data use primarily through opt-out rights covering targeted advertising, the narrowly-defined monetary 'sale' of personal data, and significant-effect profiling, rather than a prior-consent cookie regime. No universal opt-out signal (e.g., Global Privacy Control) mandate or dark-patterns-specific prohibition was located in the enacted statute, though a GPC-style mechanism was discussed and rejected during the 2022 implementation work group.

Sources and claims (4)
  1. ProbableVirginia Office of the Attorney GeneralThe VCDPA does not impose a dedicated cookie-consent regime; tracking for targeted advertising is instead addressed through the Act's opt-out right rather than an ePrivacy-style prior-consent-for-cookies rule.observed
  2. ProbableIAPPDuring the VCDPA implementation work group, stakeholders discussed—but the enacted VCDPA text did not adopt—a Colorado-style universal opt-out mechanism (e.g., Global Privacy Control) requirement; no such signal-recognition mandate was identified in the current statute.observed
  3. UncertainIAPPNo VCDPA-specific statutory prohibition on 'dark patterns' in consent interfaces was identified, in contrast to California's CPRA.observed
  4. ConfirmedIAPPThe VCDPA's opt-out right covers 'sale' of personal data (defined narrowly as exchange for monetary consideration) and 'targeted advertising' across non-affiliated sites and applications, a narrower construct than CPRA's 'sale'/'share' dichotomy.observed

#

Core profiling opt-out and biometric/genetic consent rules are Confirmed, but the flagship cross-sectoral AI risk-assessment bill was vetoed and several adjacent AI bills remain unverified.

Primary frameworkVCDPA sensitive-data/profiling provisions; no in-force cross-sectoral AI statute (HB2094 vetoed)
Traffic-light rationale — AmberCore profiling opt-out and biometric/genetic consent rules are Confirmed, but the flagship cross-sectoral AI risk-assessment bill was vetoed and several adjacent AI bills remain unverified.

Sub-modules (6)

Profiling RestrictionsGreen

Opt-out right for significant-effect profiling; DPIA required for high-risk profiling.

Claims (1):

  • Consumers have the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects on the consumer, and controllers must conduct a data protection assessment for such profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact.

Automated Decision Making TransparencyAmber

No explicit ADM-explanation right distinct from privacy-notice/opt-out provisions.

Claims (1):

  • The VCDPA does not include a GDPR Article 22-style express right to obtain an explanation of automated-decision logic; transparency is addressed indirectly through the privacy-notice and opt-out-right provisions.

Ai Risk AssessmentsAmber

Cross-sectoral High-Risk AI Act vetoed; narrower criminal-justice AI oversight bill and an unverified AI impact-assessment/advisory-commission measure reported.

Claims (3):

  • Virginia's Governor vetoed House Bill 2094, the High-Risk Artificial Intelligence Developer and Deployer Act, which would have imposed risk-disclosure and algorithmic-discrimination-prevention duties on developers and deployers of high-risk AI systems, leaving Virginia without a comprehensive cross-sectoral AI risk-assessment statute as of the veto.
  • A Virginia AI-related enactment (distinct from the vetoed High-Risk AI Developer and Deployer Act) is reported by an aggregator to mandate AI impact assessments and establish an AI advisory commission; the specific bill number and full compliance scope were not independently verified against primary legislative text.
  • Virginia's House Bill 1642 restricts sole reliance on artificial intelligence in criminal-justice decision-making, requiring human oversight of AI-informed determinations.

Biometric RegimeAmber

Biometric data for unique ID is VCDPA sensitive data requiring consent; a further 2026 biometric-consent bill (HB654) is unverified as to final enactment.

Claims (2):

  • Biometric data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent.
  • House Bill 654 (2026 session), which would mandate consent for processing biometric data and add COPPA-aligned children's-data provisions, was reported in a legislative-tracking timeline; its final enactment status and effective date were not independently confirmed against a primary legislative record.

Genetic DataGreen

Genetic data for unique ID is VCDPA sensitive data; separate genetic-testing-privacy statute imposes express-consent duties on DTC genetic testing companies.

Claims (1):

  • Genetic data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent, and a separate Virginia genetic-testing-privacy statute requires direct-to-consumer genetic testing companies to obtain express consent for collection, use, and disclosure of genetic data, with rights to revoke consent and require destruction of biological samples within 30 days.

State Surveillance CarveoutsAmber

Standard government/nonprofit entity-level exemptions apply; no bespoke surveillance carve-out framework identified.

Claims (1):

  • The VCDPA contains standard exemptions for state and local government entities, but no comprehensive national-security or state-surveillance carve-out framework specific to the Act was identified beyond its general government-and-nonprofit entity-level exemptions.
Category narrative88 words

The VCDPA grants an opt-out right against solely-automated profiling with legal or similarly significant effects and requires a data protection assessment for high-risk profiling, but lacks a GDPR Article 22-style explanation right. Virginia's Governor vetoed the cross-sectoral High-Risk Artificial Intelligence Developer and Deployer Act (HB2094), leaving no comprehensive AI risk-assessment statute, although narrower AI-adjacent bills (criminal-justice human-oversight, and an aggregator-reported AI impact-assessment/advisory-commission measure) have advanced with unconfirmed final scope. Biometric and genetic data for unique identification are VCDPA sensitive-data categories requiring consent, reinforced by a separate genetic-testing-privacy statute.

Sources and claims (9)
  1. ConfirmedIAPPConsumers have the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects on the consumer, and controllers must conduct a data protection assessment for such profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact.observed
  2. ProbableVirginia Office of the Attorney GeneralThe VCDPA does not include a GDPR Article 22-style express right to obtain an explanation of automated-decision logic; transparency is addressed indirectly through the privacy-notice and opt-out-right provisions.observed
  3. ConfirmedIAPPVirginia's Governor vetoed House Bill 2094, the High-Risk Artificial Intelligence Developer and Deployer Act, which would have imposed risk-disclosure and algorithmic-discrimination-prevention duties on developers and deployers of high-risk AI systems, leaving Virginia without a comprehensive cross-sectoral AI risk-assessment statute as of the veto.observed
  4. UncertainOneTrust DataGuidanceA Virginia AI-related enactment (distinct from the vetoed High-Risk AI Developer and Deployer Act) is reported by an aggregator to mandate AI impact assessments and establish an AI advisory commission; the specific bill number and full compliance scope were not independently verified against primary legislative text.observed
  5. ProbableOneTrust DataGuidanceVirginia's House Bill 1642 restricts sole reliance on artificial intelligence in criminal-justice decision-making, requiring human oversight of AI-informed determinations.observed
  6. ConfirmedVirginia Office of the Attorney GeneralBiometric data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent.observed
  7. ProbableOneTrust DataGuidanceHouse Bill 654 (2026 session), which would mandate consent for processing biometric data and add COPPA-aligned children's-data provisions, was reported in a legislative-tracking timeline; its final enactment status and effective date were not independently confirmed against a primary legislative record.observed
  8. ConfirmedVirginia General Assembly (hosted via DataGuidance)Genetic data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent, and a separate Virginia genetic-testing-privacy statute requires direct-to-consumer genetic testing companies to obtain express consent for collection, use, and disclosure of genetic data, with rights to revoke consent and require destruction of biological samples within 30 days.observed
  9. ProbableOneTrust DataGuidanceThe VCDPA contains standard exemptions for state and local government entities, but no comprehensive national-security or state-surveillance carve-out framework specific to the Act was identified beyond its general government-and-nonprofit entity-level exemptions.observed

#

Strong and Confirmed 2026 minors'-social-media protections are counterbalanced by active constitutional litigation and several unverified adjacent bills.

Primary frameworkVCDPA sensitive-data provisions plus 2026 minors'-social-media amendment (SB854)
Traffic-light rationale — AmberStrong and Confirmed 2026 minors'-social-media protections are counterbalanced by active constitutional litigation and several unverified adjacent bills.

Sub-modules (5)

Age VerificationGreen

Commercially-reasonable age-screening required to identify users under 16 on social media platforms.

Claims (1):

  • Effective January 1, 2026, Virginia law requires social media platforms to use commercially reasonable methods, such as a neutral age-screening mechanism, to determine whether a user is a minor younger than 16.

Minor Profiling BansGreen

Known-child (<13) data is VCDPA sensitive data requiring consent.

Claims (1):

  • Personal data collected from a known child under 13 is classified as VCDPA sensitive data requiring consent before processing.

Education SettingsAmber

Higher-education institutions are VCDPA-exempt; FERPA is the operative framework.

Claims (1):

  • Virginia's institutions of higher education are entity-level exempt from the VCDPA, leaving federal FERPA as the operative privacy framework for most student education records in education settings.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated)-specific data protection provision identified in Virginia's data-protection framework.

Category narrative81 words

Virginia has rapidly expanded children's-data protections: known-child (<13) data is VCDPA sensitive data requiring consent; a 2026 amendment (effective January 1, 2026) requires social-media platforms to age-screen users and cap minors' (<16) daily use at one hour absent verifiable parental consent to adjust the limit, currently being enforced by AG Jay Jones against a First Amendment/Commerce Clause challenge from NetChoice. Additional parental-access and parental-consent bills (HB1593, SB232) have advanced with some effective-date uncertainty. No dependent-adult (elderly/incapacitated)-specific data protection provision was identified.

Sources and claims (6)
  1. ConfirmedVirginia Office of the Attorney GeneralEffective January 1, 2026, Virginia law requires social media platforms to use commercially reasonable methods, such as a neutral age-screening mechanism, to determine whether a user is a minor younger than 16.observed
  2. ConfirmedVirginia Office of the Attorney GeneralUnder the same 2026 provision, social media platforms must limit a minor's use of the platform to one hour per day, per service or application, unless a parent provides verifiable consent to increase or decrease that daily limit.observed
  3. ConfirmedVirginia Office of the Attorney GeneralNetChoice has sued the Virginia Attorney General alleging the minors'-social-media-use provisions (Senate Bill 854) violate the First Amendment and the Commerce Clause; the Attorney General's office has filed a motion to dismiss and announced its intent to fully enforce the law.observed
  4. UncertainOneTrust DataGuidanceVirginia's House Bill 1593 grants parents access to a minor's records unless access is restricted by a court or due to potential harm to the minor.observed
  5. ConfirmedVirginia Office of the Attorney GeneralPersonal data collected from a known child under 13 is classified as VCDPA sensitive data requiring consent before processing.observed
  6. ConfirmedOneTrust DataGuidanceVirginia's institutions of higher education are entity-level exempt from the VCDPA, leaving federal FERPA as the operative privacy framework for most student education records in education settings.observed

#

Enforcement powers and penalty caps are Confirmed and modest relative to peer states, redress avenues are narrow (no PRA/class action), and several 2026-session bills' final status remains unverified.

Primary frameworkVCDPA enforcement provisions, Va. Code §59.1-584
Traffic-light rationale — AmberEnforcement powers and penalty caps are Confirmed and modest relative to peer states, redress avenues are narrow (no PRA/class action), and several 2026-session bills' final status remains unverified.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Civil penalties up to $7,500/violation after failed 30-day cure, plus injunctive relief.

Claims (1):

  • The Attorney General may seek civil penalties of up to $7,500 per violation of the VCDPA where a controller or processor fails to cure a notified violation within 30 days, plus injunctive relief, with penalties and attorney fees deposited into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund since the 2022 amendments.

Enforcement Activity IndexAmber

AG announced full enforcement of minors'-social-media provisions in February 2026, filing a motion to dismiss NetChoice's suit.

Claims (1):

  • In February 2026, Attorney General Jay Jones announced his office's intent to fully enforce the VCDPA's new minors'-social-media-use-limitation provisions and filed a motion to dismiss NetChoice's challenge to the law.

Regulator Funding And CapacityAmber

OAG has historically flagged insufficient dedicated enforcement funding for VCDPA implementation.

Claims (1):

  • During the VCDPA work group process, the Office of the Attorney General noted that the self-funding dynamic of the (now-repealed) Consumer Privacy Fund was not feasible because no funds were available to support enforcement at the initial implementation stage.

Collective Redress And Class ActionsRed

Class-action enforcement of VCDPA violations is precluded.

Claims (1):

  • The VCDPA precludes class-action enforcement of its provisions.

Private Right Of ActionRed

No private right of action exists; enforcement is AG-exclusive.

Claims (1):

  • The VCDPA does not grant consumers a private right of action; enforcement is exclusively vested in the Attorney General.

Recent Developments 180DAmber

SB338 geolocation-sale ban (enacted April 2026, in force July 2026) and AG minors'-social-media enforcement announcement (February 2026); several additional 2026-session bills remain unverified as to final status.

Claims (2):

  • Within the 180 days preceding this run, Virginia enacted Senate Bill 338 (signed 13 April 2026, in force 1 July 2026) banning the sale of precise geolocation data, and Attorney General Jay Jones announced (February 2026) enforcement of the new minors' social-media time-limit provisions amid ongoing NetChoice litigation.
  • Additional 2026-session Virginia bills affecting the VCDPA framework include Senate Bill 232 (verified parental consent for minors' online agreements and expanded parental rights), Senate Bill 85 (interoperability interfaces for social-media/AI data sharing), Senate Bill 245 (social-media/AI regulations addressing minor protection and algorithmic discrimination), and Senate Bill 615 (restrictions on online device-based pricing practices); the enactment status of each was not independently confirmed against primary legislative records at the time of this research.
Category narrative62 words

Enforcement is vested exclusively in the Virginia Attorney General with a 30-day cure period, penalties up to $7,500 per violation plus injunctive relief, and no private right of action or class-action mechanism. Recent enforcement activity centers on the AG's February 2026 announcement to fully enforce the minors'-social-media-use provisions against NetChoice's constitutional challenge, alongside the April 2026 enactment of the precise-geolocation-data sale ban.

Sources and claims (7)
  1. ConfirmedVirginia Office of the Attorney GeneralThe Attorney General may seek civil penalties of up to $7,500 per violation of the VCDPA where a controller or processor fails to cure a notified violation within 30 days, plus injunctive relief, with penalties and attorney fees deposited into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund since the 2022 amendments.observed
  2. ConfirmedVirginia Office of the Attorney GeneralIn February 2026, Attorney General Jay Jones announced his office's intent to fully enforce the VCDPA's new minors'-social-media-use-limitation provisions and filed a motion to dismiss NetChoice's challenge to the law.observed
  3. ProbableIAPPDuring the VCDPA work group process, the Office of the Attorney General noted that the self-funding dynamic of the (now-repealed) Consumer Privacy Fund was not feasible because no funds were available to support enforcement at the initial implementation stage.observed
  4. ConfirmedIAPPThe VCDPA precludes class-action enforcement of its provisions.observed
  5. ConfirmedVirginia Office of the Attorney GeneralThe VCDPA does not grant consumers a private right of action; enforcement is exclusively vested in the Attorney General.observed
  6. ConfirmedIAPPWithin the 180 days preceding this run, Virginia enacted Senate Bill 338 (signed 13 April 2026, in force 1 July 2026) banning the sale of precise geolocation data, and Attorney General Jay Jones announced (February 2026) enforcement of the new minors' social-media time-limit provisions amid ongoing NetChoice litigation.observed
  7. UncertainOneTrust DataGuidanceAdditional 2026-session Virginia bills affecting the VCDPA framework include Senate Bill 232 (verified parental consent for minors' online agreements and expanded parental rights), Senate Bill 85 (interoperability interfaces for social-media/AI data sharing), Senate Bill 245 (social-media/AI regulations addressing minor protection and algorithmic discrimination), and Senate Bill 615 (restrictions on online device-based pricing practices); the enactment status of each was not independently confirmed against primary legislative records at the time of this research.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Virginia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 57 claim(s), 17 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with at least one Tier-1 (OAG primary/press-release) or Tier-2 (IAPP) anchor. regulator_and_framework, data_subject_rights, lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, children_and_vulnerable_groups, and enforcement_and_redress each rest on multiple T1/T2 sources including two direct Virginia OAG publications (SRC-VA-001, SRC-VA-004) and OAG enforcement press releases (SRC-VA-003). cross_border_and_adequacy is a legitimate 'no comprehensive regime' finding (red traffic light, absent_field_provenance) since VCDPA has no GDPR-style transfer/adequacy apparatus. adtech_and_commercial_privacy and algorithmic_biometric_and_surveillance_governance rely more heavily on T2/T3 secondary aggregator sources (IAPP, DataGuidance) for several 2026-session bills (HB654, HB1593, HB1642, SB232/85/245/615) whose final enactment status and effective dates could not be independently confirmed against primary Virginia legislative records (LIS) within this run's retrieval allowlist.

Unresolved questions (6):

  • Final enactment status and effective date of House Bill 654 (2026, biometric-data consent).
  • Final enactment status and effective date of House Bill 1593 (2026, parental records access).
  • Final enactment status and effective date of House Bill 1642 (2026, AI in criminal-justice decisions).
  • Bill number, primary text, and enactment status of the aggregator-reported Virginia AI impact-assessment/advisory-commission measure.
  • Enactment status of Senate Bills 232, 85, 245, and 615 (2026 session).
  • Whether Virginia's VCDPA cure period is subject to any legislatively-set sunset (as occurred in some peer states) — no sunset provision was located in sources reviewed.

Escalate to primary-source review: yes