Comprehensive statute in force but enforcement rests solely with a general-purpose AG office lacking rulemaking power or a dedicated registration regime.
Primary frameworkVirginia Consumer Data Protection Act (VCDPA), Va. Code §§59.1-575 to 59.1-585
Traffic-light rationale — AmberComprehensive statute in force but enforcement rests solely with a general-purpose AG office lacking rulemaking power or a dedicated registration regime.
Sub-modules (5)
Regulator And AuthorityAmber
AG is the sole enforcer; no private right of action exists.
Claims (1):
The Virginia Attorney General's Office is the exclusive enforcer of the VCDPA and there is no private right of action for violations.
Act And InstrumentsGreen
VCDPA effective Jan 1 2023; amended by three 2022 bills ahead of effective date.
Claims (2):
The Virginia Consumer Data Protection Act (VCDPA) went into effect on January 1, 2023.
In 2022 the Virginia General Assembly enacted three amendment bills to the VCDPA that converted the right to delete data-broker-sourced personal data into a right to opt out of its processing, expanded the nonprofit exclusion to political organizations, and repealed the VCDPA Consumer Privacy Fund.
Material ScopeGreen
Covers VA-resident consumer personal data in individual/household context only.
Claims (1):
The VCDPA governs 'personal data' of natural persons who are Virginia residents acting only in an individual or household context, expressly excluding data about individuals acting in an employment or commercial context.
Territorial ScopeGreen
Dual-threshold applicability test based on consumer volume/sale-revenue, not turnover.
Claims (1):
The VCDPA applies to persons conducting business in Virginia or producing products/services targeted to Virginia residents that, during a calendar year, either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.
Regulator Registration And FilingAmber
No rulemaking authority or filing/registration regime exists under the Act.
Claims (1):
Unlike California's CCPA/CPRA, the VCDPA's final text does not grant the Attorney General rulemaking authority, and the statute imposes no controller registration or filing obligation with the Commonwealth.
Category narrative81 words
Virginia's data-protection regime is anchored in the Virginia Consumer Data Protection Act (VCDPA), Va. Code §§59.1-575 et seq., effective January 1, 2023, enforced exclusively by the Virginia Attorney General's Office with no dedicated privacy regulator, no rulemaking authority, and no controller-registration/filing obligation. The Act applies to entities conducting business in or targeting Virginia residents that meet a 100,000-consumer processing threshold or a 25,000-consumer-plus-50%-sale-revenue threshold. The statute has been amended multiple times (2022, 2026) via the General Assembly rather than agency rulemaking.
Sources and claims (6)
ConfirmedVirginia Office of the Attorney General — The Virginia Attorney General's Office is the exclusive enforcer of the VCDPA and there is no private right of action for violations.observed
ConfirmedIAPP — In 2022 the Virginia General Assembly enacted three amendment bills to the VCDPA that converted the right to delete data-broker-sourced personal data into a right to opt out of its processing, expanded the nonprofit exclusion to political organizations, and repealed the VCDPA Consumer Privacy Fund.observed
ConfirmedIAPP — The VCDPA governs 'personal data' of natural persons who are Virginia residents acting only in an individual or household context, expressly excluding data about individuals acting in an employment or commercial context.observed
ConfirmedOneTrust DataGuidance — The VCDPA applies to persons conducting business in Virginia or producing products/services targeted to Virginia residents that, during a calendar year, either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.observed
ConfirmedIAPP — Unlike California's CCPA/CPRA, the VCDPA's final text does not grant the Attorney General rulemaking authority, and the statute imposes no controller registration or filing obligation with the Commonwealth.observed
Traffic-light rationale — AmberConsent-for-sensitive-data regime is clear and Confirmed, but the Act lacks a GDPR-equivalent enumerated lawful-basis structure.
Sub-modules (4)
Lawful BasesAmber
No enumerated Article-6-style basis list; default-permitted processing plus opt-out rights substitute for a licensing model.
Claims (1):
The VCDPA does not enumerate GDPR Article-6-style lawful processing bases; general processing of non-sensitive personal data is permitted subject to purpose- and data-minimization limits, with consumers instead granted opt-out rights against targeted advertising, sale, and certain profiling.
Consent ThresholdsGreen
Affirmative consent required before processing sensitive data.
Claims (1):
Controllers must obtain a consumer's affirmative consent prior to processing that consumer's sensitive data under the VCDPA.
Special CategoriesGreen
Sensitive-data list includes race/ethnicity, religion, health diagnosis, sexual orientation, immigration status, genetic/biometric ID data, known-child (<13) data, and (2026) precise geolocation data.
Claims (2):
VCDPA sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed for unique identification, and personal data collected from a known child under 13.
Senate Bill 338, enacted as Chapter 820 of the 2026 Acts of Assembly and signed 13 April 2026, amends the VCDPA to prohibit controllers from selling or offering to sell a consumer's precise geolocation data, entering into force 1 July 2026.
Pseudonymisation And AnonymisationGreen
De-identified/pseudonymized data are exempted from personal-data scope subject to safeguards.
Claims (1):
The VCDPA exempts de-identified and pseudonymized data from the definition of personal data and from consumer-rights obligations, provided the controller maintains technical and organizational controls preventing re-identification.
Category narrative60 words
The VCDPA does not use a GDPR Article-6-style enumerated lawful-basis model; general processing proceeds by default subject to purpose- and data-minimization limits, while affirmative opt-in consent is mandatory for a defined list of sensitive-data categories, expanded in 2026 to include precise geolocation data. De-identified and pseudonymized data fall outside the Act's personal-data definition and rights obligations where technical/organizational safeguards exist.
Sources and claims (5)
ProbableIAPP — The VCDPA does not enumerate GDPR Article-6-style lawful processing bases; general processing of non-sensitive personal data is permitted subject to purpose- and data-minimization limits, with consumers instead granted opt-out rights against targeted advertising, sale, and certain profiling.observed
ConfirmedVirginia Office of the Attorney General — Controllers must obtain a consumer's affirmative consent prior to processing that consumer's sensitive data under the VCDPA.observed
ConfirmedVirginia Office of the Attorney General — VCDPA sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed for unique identification, and personal data collected from a known child under 13.observed
ConfirmedIAPP — Senate Bill 338, enacted as Chapter 820 of the 2026 Acts of Assembly and signed 13 April 2026, amends the VCDPA to prohibit controllers from selling or offering to sell a consumer's precise geolocation data, entering into force 1 July 2026.observed
ConfirmedIAPP — The VCDPA exempts de-identified and pseudonymized data from the definition of personal data and from consumer-rights obligations, provided the controller maintains technical and organizational controls preventing re-identification.observed
Traffic-light rationale — GreenRights framework is comprehensive, statutorily explicit, and well-documented by the regulator itself.
Sub-modules (5)
Access RightGreen
Right to confirm and access processed personal data.
Claims (1):
Consumers have the right to confirm whether a controller is processing their personal data and to access that personal data.
Rectification And ErasureGreen
Correction and deletion rights, with a data-broker-specific opt-out substitute for deletion post-2022 amendment.
Claims (1):
Consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them; for data obtained from a source other than the consumer, the 2022 amendments deem a controller compliant by instead opting the consumer out of further processing of that data.
Restriction And ObjectionGreen
Opt-out rights for targeted advertising, sale, and significant-effect profiling.
Claims (1):
Consumers have the right to opt out of the processing of their personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.
Data PortabilityAmber
Consumers may obtain a copy of their personal data held by a controller.
Claims (1):
Consumers have the right to obtain a copy of their personal data held by a controller.
Deadlines And Response WindowsGreen
45-day response window, extendable once by 45 days; mandatory appeal process.
Claims (1):
A controller must respond to a consumer rights request within 45 days of receipt, with one 45-day extension available where reasonably necessary provided the consumer is notified within the initial response period; if a request is refused, the controller must offer an appeal process and inform the consumer of the right to complain to the Attorney General if the appeal is denied.
Category narrative34 words
The VCDPA grants Virginia consumers access, correction, deletion, opt-out (targeted advertising/sale/profiling), and portability-adjacent rights, with a 45-day (plus one 45-day extension) response window and a mandatory appeal mechanism escalating to AG complaint if denied.
Sources and claims (5)
ConfirmedIAPP — Consumers have the right to confirm whether a controller is processing their personal data and to access that personal data.observed
ConfirmedIAPP — Consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them; for data obtained from a source other than the consumer, the 2022 amendments deem a controller compliant by instead opting the consumer out of further processing of that data.observed
ConfirmedVirginia Office of the Attorney General — Consumers have the right to opt out of the processing of their personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.observed
ConfirmedIAPP — A controller must respond to a consumer rights request within 45 days of receipt, with one 45-day extension available where reasonably necessary provided the consumer is notified within the initial response period; if a request is refused, the controller must offer an appeal process and inform the consumer of the right to complain to the Attorney General if the appeal is denied.observed
Core accountability tools (DPIA, processor contracts) are present and Confirmed, but structural gaps exist versus GDPR (no DPO, no distinct ROPA, no VCDPA-specific retention schedule).
Primary frameworkVCDPA, Va. Code §59.1-576 to 59.1-580; breach notice under Va. Code §18.2-186.6
Traffic-light rationale — AmberCore accountability tools (DPIA, processor contracts) are present and Confirmed, but structural gaps exist versus GDPR (no DPO, no distinct ROPA, no VCDPA-specific retention schedule).
Sub-modules (7)
Accountability And DpiaGreen
Data protection assessments required for targeted advertising, sale, high-risk profiling, and sensitive-data processing.
Claims (1):
Controllers must conduct data protection assessments (DPIAs) for processing activities involving targeted advertising, the sale of personal data, profiling presenting a reasonably foreseeable risk of unfair/deceptive treatment or unlawful disparate impact, processing of sensitive data, or other processing presenting a heightened risk of harm to consumers.
Dpo RequirementsRed
No DPO-appointment obligation identified.
Claims (1):
The VCDPA contains no statutory requirement to appoint a Data Protection Officer or equivalent independent privacy role.
Ropa RequirementsRed
No stand-alone ROPA mandate distinct from the assessment requirement.
Claims (1):
The VCDPA does not impose a distinct Article-30-style comprehensive Records of Processing Activities obligation on controllers, though data protection assessments must document the processing context and controller-consumer relationship.
Joint Controller ArrangementsGreen
Mandatory data processing agreements govern processor relationships.
Claims (1):
Where a processor acts on a controller's behalf, the VCDPA requires a data processing agreement clearly setting out instructions for processing, the nature and purpose of processing, the type of data, duration of processing, and the rights and obligations of both parties, mirroring GDPR Article 28-style processor terms.
Security MeasuresAmber
General reasonable-security obligation applies.
Claims (1):
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of personal data at issue.
Breach NotificationAmber
Breach notice governed by a separate Virginia statute outside the VCDPA, with a 1,000-person AG/CRA notification trigger.
Claims (1):
Virginia's personal information breach notification statute (Va. Code §18.2-186.6, outside the VCDPA itself) requires notification of a breach of unencrypted, unredacted personal information to affected residents and, where notice is given to more than 1,000 persons, to the Attorney General and nationwide consumer reporting agencies.
Retention And DisposalAmber
Data-minimization principle applies; no VCDPA-specific fixed retention/disposal schedule identified.
Claims (2):
The VCDPA's data-minimization principle limits collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes of processing.
No fixed statutory data-retention-period or disposal-schedule requirement beyond the general data-minimization principle was identified for controllers under the VCDPA.
Category narrative60 words
Controllers must conduct data protection assessments for higher-risk processing (targeted advertising, sale, certain profiling, sensitive data), and processor relationships must be governed by GDPR-Article-28-style data processing agreements. The Act contains no DPO-appointment mandate and no stand-alone ROPA obligation distinct from the assessment requirement. Breach notification is governed by a separate Virginia statute (Va. Code §18.2-186.6) rather than the VCDPA itself.
Sources and claims (8)
ConfirmedIAPP — Controllers must conduct data protection assessments (DPIAs) for processing activities involving targeted advertising, the sale of personal data, profiling presenting a reasonably foreseeable risk of unfair/deceptive treatment or unlawful disparate impact, processing of sensitive data, or other processing presenting a heightened risk of harm to consumers.observed
ProbableVirginia Office of the Attorney General — The VCDPA contains no statutory requirement to appoint a Data Protection Officer or equivalent independent privacy role.observed
ProbableOneTrust DataGuidance — The VCDPA does not impose a distinct Article-30-style comprehensive Records of Processing Activities obligation on controllers, though data protection assessments must document the processing context and controller-consumer relationship.observed
ConfirmedIAPP — Where a processor acts on a controller's behalf, the VCDPA requires a data processing agreement clearly setting out instructions for processing, the nature and purpose of processing, the type of data, duration of processing, and the rights and obligations of both parties, mirroring GDPR Article 28-style processor terms.observed
ProbableVirginia Office of the Attorney General — Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of personal data at issue.observed
ConfirmedOneTrust DataGuidance — Virginia's personal information breach notification statute (Va. Code §18.2-186.6, outside the VCDPA itself) requires notification of a breach of unencrypted, unredacted personal information to affected residents and, where notice is given to more than 1,000 persons, to the Attorney General and nationwide consumer reporting agencies.observed
ConfirmedIAPP — The VCDPA's data-minimization principle limits collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes of processing.observed
UncertainIAPP — No fixed statutory data-retention-period or disposal-schedule requirement beyond the general data-minimization principle was identified for controllers under the VCDPA.observed
Traffic-light rationale — RedNo comprehensive cross-border transfer or adequacy regime exists in this jurisdiction; only a generic processor-contract requirement applies.
Sub-modules (6)
Transfer MechanismsAmber
Only a processor-contract requirement functions as a de facto transfer control; no adequacy/SCC/BCR regime exists.
Claims (1):
The VCDPA contains no dedicated cross-border data-transfer mechanism (no adequacy-decision framework, SCCs, or BCR approval regime); the only transfer-relevant control is the mandatory controller-processor data processing agreement applicable regardless of the processor's location.
Adequacy ReceivedRed
Not applicable — VCDPA has no adequacy-recognition mechanism.
Adequacy GrantedRed
Not applicable — Virginia grants no state-level adequacy determinations to other regimes.
Sccs And BcrsRed
No VCDPA-specific SCC or BCR approval regime identified.
Transfer Impact AssessmentRed
No TIA-equivalent requirement identified at the state level.
Data LocalisationRed
No data-localisation mandate identified under the VCDPA.
Category narrative47 words
As a US state consumer-privacy statute, the VCDPA has no GDPR-style cross-border transfer or adequacy framework. The only transfer-relevant control is the mandatory controller-processor data processing agreement, which applies irrespective of processor location. No adequacy decisions, SCC/BCR regimes, transfer impact assessment requirements, or data-localisation mandates were identified.
Sources and claims (1)
ProbableIAPP — The VCDPA contains no dedicated cross-border data-transfer mechanism (no adequacy-decision framework, SCCs, or BCR approval regime); the only transfer-relevant control is the mandatory controller-processor data processing agreement applicable regardless of the processor's location.observed
Sectoral carve-outs are clear and Confirmed for finance/health/credit/education, but coverage relies on displacement to federal sectoral statutes rather than an integrated overlay.
Primary frameworkVCDPA exemptions (Va. Code §59.1-576) plus federal GLBA/HIPAA/FCRA/FERPA and VA reproductive-health-data statute
Traffic-light rationale — AmberSectoral carve-outs are clear and Confirmed for finance/health/credit/education, but coverage relies on displacement to federal sectoral statutes rather than an integrated overlay.
Sub-modules (7)
Financial Sector OverlayAmber
GLBA-regulated data/entities exempted from VCDPA scope.
Claims (1):
The VCDPA exempts information subject to the federal Gramm-Leach-Bliley Act (GLBA) and GLBA-regulated financial institutions' data-handling activities from its scope, leaving GLBA as the operative privacy framework for that data.
Health Sector OverlayAmber
HIPAA-covered data exempted; separate reproductive-health-data consent statute in force since July 2025.
Claims (2):
Protected health information governed by HIPAA and data held by HIPAA-covered entities/business associates is exempted from VCDPA scope, leaving HIPAA as the operative health-data framework.
A separate Virginia statute restricting the sharing of reproductive or sexual health data without consumer consent entered into effect July 1, 2025, supplementing the VCDPA's sensitive-data consent regime for this category of health information.
Telecoms And EprivacyRed
No dedicated telecoms/ePrivacy-style statute identified for Virginia beyond general VCDPA opt-out rights.
Employment DataAmber
Employment/commercial-context data is excluded from the 'consumer' definition entirely.
Claims (1):
The VCDPA's definition of 'consumer' expressly excludes a natural person acting in an employment context, so employee and job-applicant personal data generally falls outside VCDPA obligations, unlike California's CPRA.
Credit And ScoringAmber
FCRA-regulated data exempted from VCDPA scope.
Claims (1):
Data regulated by the federal Fair Credit Reporting Act (FCRA) is exempted from VCDPA scope, leaving FCRA as the operative framework for consumer credit-reporting and scoring data.
EducationAmber
FERPA-regulated data and higher-education institutions exempted from VCDPA scope.
Claims (1):
Data governed by the federal Family Educational Rights and Privacy Act (FERPA) and Virginia's institutions of higher education are exempted from VCDPA scope.
InsuranceRed
No insurance-sector-specific overlay distinct from the general GLBA-type financial exemption was identified.
Category narrative57 words
The VCDPA carves out 14 categories of exempted data/entities, including information governed by GLBA, HIPAA, FCRA, the Driver's Privacy Protection Act, the Farm Credit Act, and FERPA, and excludes employment/commercial-context data entirely. A separate Virginia statute effective July 1, 2025 restricts sharing of reproductive/sexual health data without consent, supplementing the VCDPA's sensitive-data consent rules for that category.
Sources and claims (6)
ConfirmedIAPP — The VCDPA exempts information subject to the federal Gramm-Leach-Bliley Act (GLBA) and GLBA-regulated financial institutions' data-handling activities from its scope, leaving GLBA as the operative privacy framework for that data.observed
ConfirmedOneTrust DataGuidance — Protected health information governed by HIPAA and data held by HIPAA-covered entities/business associates is exempted from VCDPA scope, leaving HIPAA as the operative health-data framework.observed
ProbableOneTrust DataGuidance — A separate Virginia statute restricting the sharing of reproductive or sexual health data without consumer consent entered into effect July 1, 2025, supplementing the VCDPA's sensitive-data consent regime for this category of health information.observed
ConfirmedIAPP — The VCDPA's definition of 'consumer' expressly excludes a natural person acting in an employment context, so employee and job-applicant personal data generally falls outside VCDPA obligations, unlike California's CPRA.observed
ConfirmedIAPP — Data regulated by the federal Fair Credit Reporting Act (FCRA) is exempted from VCDPA scope, leaving FCRA as the operative framework for consumer credit-reporting and scoring data.observed
ConfirmedOneTrust DataGuidance — Data governed by the federal Family Educational Rights and Privacy Act (FERPA) and Virginia's institutions of higher education are exempted from VCDPA scope.observed
Traffic-light rationale — AmberOpt-out rights are Confirmed and functional, but the Act lacks GPC-signal recognition and dark-pattern prohibitions found in some peer states.
Sub-modules (6)
Cookies And TrackersAmber
No dedicated cookie-consent regime; tracking for targeted advertising addressed via opt-out right.
Claims (1):
The VCDPA does not impose a dedicated cookie-consent regime; tracking for targeted advertising is instead addressed through the Act's opt-out right rather than an ePrivacy-style prior-consent-for-cookies rule.
Dark PatternsRed
No VCDPA-specific dark-patterns prohibition identified.
Claims (1):
No VCDPA-specific statutory prohibition on 'dark patterns' in consent interfaces was identified, in contrast to California's CPRA.
Opt Out SignalsRed
Universal opt-out mechanism was discussed but not enacted in the VCDPA.
Claims (1):
During the VCDPA implementation work group, stakeholders discussed—but the enacted VCDPA text did not adopt—a Colorado-style universal opt-out mechanism (e.g., Global Privacy Control) requirement; no such signal-recognition mandate was identified in the current statute.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific provisions identified.
Cross Context AdvertisingAmber
Narrower 'sale' (monetary-only) and 'targeted advertising' constructs versus CPRA's sale/share dichotomy.
Claims (1):
The VCDPA's opt-out right covers 'sale' of personal data (defined narrowly as exchange for monetary consideration) and 'targeted advertising' across non-affiliated sites and applications, a narrower construct than CPRA's 'sale'/'share' dichotomy.
Direct MarketingRed
No dedicated direct-marketing consent/suppression statute distinct from the targeted-advertising opt-out was identified.
Category narrative61 words
The VCDPA regulates commercial data use primarily through opt-out rights covering targeted advertising, the narrowly-defined monetary 'sale' of personal data, and significant-effect profiling, rather than a prior-consent cookie regime. No universal opt-out signal (e.g., Global Privacy Control) mandate or dark-patterns-specific prohibition was located in the enacted statute, though a GPC-style mechanism was discussed and rejected during the 2022 implementation work group.
Sources and claims (4)
ProbableVirginia Office of the Attorney General — The VCDPA does not impose a dedicated cookie-consent regime; tracking for targeted advertising is instead addressed through the Act's opt-out right rather than an ePrivacy-style prior-consent-for-cookies rule.observed
ProbableIAPP — During the VCDPA implementation work group, stakeholders discussed—but the enacted VCDPA text did not adopt—a Colorado-style universal opt-out mechanism (e.g., Global Privacy Control) requirement; no such signal-recognition mandate was identified in the current statute.observed
UncertainIAPP — No VCDPA-specific statutory prohibition on 'dark patterns' in consent interfaces was identified, in contrast to California's CPRA.observed
ConfirmedIAPP — The VCDPA's opt-out right covers 'sale' of personal data (defined narrowly as exchange for monetary consideration) and 'targeted advertising' across non-affiliated sites and applications, a narrower construct than CPRA's 'sale'/'share' dichotomy.observed
Core profiling opt-out and biometric/genetic consent rules are Confirmed, but the flagship cross-sectoral AI risk-assessment bill was vetoed and several adjacent AI bills remain unverified.
Primary frameworkVCDPA sensitive-data/profiling provisions; no in-force cross-sectoral AI statute (HB2094 vetoed)
Traffic-light rationale — AmberCore profiling opt-out and biometric/genetic consent rules are Confirmed, but the flagship cross-sectoral AI risk-assessment bill was vetoed and several adjacent AI bills remain unverified.
Sub-modules (6)
Profiling RestrictionsGreen
Opt-out right for significant-effect profiling; DPIA required for high-risk profiling.
Claims (1):
Consumers have the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects on the consumer, and controllers must conduct a data protection assessment for such profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact.
Automated Decision Making TransparencyAmber
No explicit ADM-explanation right distinct from privacy-notice/opt-out provisions.
Claims (1):
The VCDPA does not include a GDPR Article 22-style express right to obtain an explanation of automated-decision logic; transparency is addressed indirectly through the privacy-notice and opt-out-right provisions.
Ai Risk AssessmentsAmber
Cross-sectoral High-Risk AI Act vetoed; narrower criminal-justice AI oversight bill and an unverified AI impact-assessment/advisory-commission measure reported.
Claims (3):
Virginia's Governor vetoed House Bill 2094, the High-Risk Artificial Intelligence Developer and Deployer Act, which would have imposed risk-disclosure and algorithmic-discrimination-prevention duties on developers and deployers of high-risk AI systems, leaving Virginia without a comprehensive cross-sectoral AI risk-assessment statute as of the veto.
A Virginia AI-related enactment (distinct from the vetoed High-Risk AI Developer and Deployer Act) is reported by an aggregator to mandate AI impact assessments and establish an AI advisory commission; the specific bill number and full compliance scope were not independently verified against primary legislative text.
Virginia's House Bill 1642 restricts sole reliance on artificial intelligence in criminal-justice decision-making, requiring human oversight of AI-informed determinations.
Biometric RegimeAmber
Biometric data for unique ID is VCDPA sensitive data requiring consent; a further 2026 biometric-consent bill (HB654) is unverified as to final enactment.
Claims (2):
Biometric data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent.
House Bill 654 (2026 session), which would mandate consent for processing biometric data and add COPPA-aligned children's-data provisions, was reported in a legislative-tracking timeline; its final enactment status and effective date were not independently confirmed against a primary legislative record.
Genetic DataGreen
Genetic data for unique ID is VCDPA sensitive data; separate genetic-testing-privacy statute imposes express-consent duties on DTC genetic testing companies.
Claims (1):
Genetic data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent, and a separate Virginia genetic-testing-privacy statute requires direct-to-consumer genetic testing companies to obtain express consent for collection, use, and disclosure of genetic data, with rights to revoke consent and require destruction of biological samples within 30 days.
State Surveillance CarveoutsAmber
Standard government/nonprofit entity-level exemptions apply; no bespoke surveillance carve-out framework identified.
Claims (1):
The VCDPA contains standard exemptions for state and local government entities, but no comprehensive national-security or state-surveillance carve-out framework specific to the Act was identified beyond its general government-and-nonprofit entity-level exemptions.
Category narrative88 words
The VCDPA grants an opt-out right against solely-automated profiling with legal or similarly significant effects and requires a data protection assessment for high-risk profiling, but lacks a GDPR Article 22-style explanation right. Virginia's Governor vetoed the cross-sectoral High-Risk Artificial Intelligence Developer and Deployer Act (HB2094), leaving no comprehensive AI risk-assessment statute, although narrower AI-adjacent bills (criminal-justice human-oversight, and an aggregator-reported AI impact-assessment/advisory-commission measure) have advanced with unconfirmed final scope. Biometric and genetic data for unique identification are VCDPA sensitive-data categories requiring consent, reinforced by a separate genetic-testing-privacy statute.
Sources and claims (9)
ConfirmedIAPP — Consumers have the right to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects on the consumer, and controllers must conduct a data protection assessment for such profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact.observed
ProbableVirginia Office of the Attorney General — The VCDPA does not include a GDPR Article 22-style express right to obtain an explanation of automated-decision logic; transparency is addressed indirectly through the privacy-notice and opt-out-right provisions.observed
ConfirmedIAPP — Virginia's Governor vetoed House Bill 2094, the High-Risk Artificial Intelligence Developer and Deployer Act, which would have imposed risk-disclosure and algorithmic-discrimination-prevention duties on developers and deployers of high-risk AI systems, leaving Virginia without a comprehensive cross-sectoral AI risk-assessment statute as of the veto.observed
UncertainOneTrust DataGuidance — A Virginia AI-related enactment (distinct from the vetoed High-Risk AI Developer and Deployer Act) is reported by an aggregator to mandate AI impact assessments and establish an AI advisory commission; the specific bill number and full compliance scope were not independently verified against primary legislative text.observed
ProbableOneTrust DataGuidance — Virginia's House Bill 1642 restricts sole reliance on artificial intelligence in criminal-justice decision-making, requiring human oversight of AI-informed determinations.observed
ConfirmedVirginia Office of the Attorney General — Biometric data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent.observed
ProbableOneTrust DataGuidance — House Bill 654 (2026 session), which would mandate consent for processing biometric data and add COPPA-aligned children's-data provisions, was reported in a legislative-tracking timeline; its final enactment status and effective date were not independently confirmed against a primary legislative record.observed
ConfirmedVirginia General Assembly (hosted via DataGuidance) — Genetic data processed for the purpose of uniquely identifying a natural person is classified as VCDPA sensitive data requiring prior consumer consent, and a separate Virginia genetic-testing-privacy statute requires direct-to-consumer genetic testing companies to obtain express consent for collection, use, and disclosure of genetic data, with rights to revoke consent and require destruction of biological samples within 30 days.observed
ProbableOneTrust DataGuidance — The VCDPA contains standard exemptions for state and local government entities, but no comprehensive national-security or state-surveillance carve-out framework specific to the Act was identified beyond its general government-and-nonprofit entity-level exemptions.observed
Strong and Confirmed 2026 minors'-social-media protections are counterbalanced by active constitutional litigation and several unverified adjacent bills.
Primary frameworkVCDPA sensitive-data provisions plus 2026 minors'-social-media amendment (SB854)
Traffic-light rationale — AmberStrong and Confirmed 2026 minors'-social-media protections are counterbalanced by active constitutional litigation and several unverified adjacent bills.
Sub-modules (5)
Age VerificationGreen
Commercially-reasonable age-screening required to identify users under 16 on social media platforms.
Claims (1):
Effective January 1, 2026, Virginia law requires social media platforms to use commercially reasonable methods, such as a neutral age-screening mechanism, to determine whether a user is a minor younger than 16.
Parental ConsentAmber
One-hour daily social-media cap for minors absent verifiable parental consent to adjust; active NetChoice litigation; HB1593 parental-records-access bill (date unconfirmed).
Claims (3):
Under the same 2026 provision, social media platforms must limit a minor's use of the platform to one hour per day, per service or application, unless a parent provides verifiable consent to increase or decrease that daily limit.
NetChoice has sued the Virginia Attorney General alleging the minors'-social-media-use provisions (Senate Bill 854) violate the First Amendment and the Commerce Clause; the Attorney General's office has filed a motion to dismiss and announced its intent to fully enforce the law.
Virginia's House Bill 1593 grants parents access to a minor's records unless access is restricted by a court or due to potential harm to the minor.
Minor Profiling BansGreen
Known-child (<13) data is VCDPA sensitive data requiring consent.
Claims (1):
Personal data collected from a known child under 13 is classified as VCDPA sensitive data requiring consent before processing.
Education SettingsAmber
Higher-education institutions are VCDPA-exempt; FERPA is the operative framework.
Claims (1):
Virginia's institutions of higher education are entity-level exempt from the VCDPA, leaving federal FERPA as the operative privacy framework for most student education records in education settings.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated)-specific data protection provision identified in Virginia's data-protection framework.
Category narrative81 words
Virginia has rapidly expanded children's-data protections: known-child (<13) data is VCDPA sensitive data requiring consent; a 2026 amendment (effective January 1, 2026) requires social-media platforms to age-screen users and cap minors' (<16) daily use at one hour absent verifiable parental consent to adjust the limit, currently being enforced by AG Jay Jones against a First Amendment/Commerce Clause challenge from NetChoice. Additional parental-access and parental-consent bills (HB1593, SB232) have advanced with some effective-date uncertainty. No dependent-adult (elderly/incapacitated)-specific data protection provision was identified.
Sources and claims (6)
ConfirmedVirginia Office of the Attorney General — Effective January 1, 2026, Virginia law requires social media platforms to use commercially reasonable methods, such as a neutral age-screening mechanism, to determine whether a user is a minor younger than 16.observed
ConfirmedVirginia Office of the Attorney General — Under the same 2026 provision, social media platforms must limit a minor's use of the platform to one hour per day, per service or application, unless a parent provides verifiable consent to increase or decrease that daily limit.observed
ConfirmedVirginia Office of the Attorney General — NetChoice has sued the Virginia Attorney General alleging the minors'-social-media-use provisions (Senate Bill 854) violate the First Amendment and the Commerce Clause; the Attorney General's office has filed a motion to dismiss and announced its intent to fully enforce the law.observed
UncertainOneTrust DataGuidance — Virginia's House Bill 1593 grants parents access to a minor's records unless access is restricted by a court or due to potential harm to the minor.observed
ConfirmedVirginia Office of the Attorney General — Personal data collected from a known child under 13 is classified as VCDPA sensitive data requiring consent before processing.observed
ConfirmedOneTrust DataGuidance — Virginia's institutions of higher education are entity-level exempt from the VCDPA, leaving federal FERPA as the operative privacy framework for most student education records in education settings.observed
Enforcement powers and penalty caps are Confirmed and modest relative to peer states, redress avenues are narrow (no PRA/class action), and several 2026-session bills' final status remains unverified.
Traffic-light rationale — AmberEnforcement powers and penalty caps are Confirmed and modest relative to peer states, redress avenues are narrow (no PRA/class action), and several 2026-session bills' final status remains unverified.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
Civil penalties up to $7,500/violation after failed 30-day cure, plus injunctive relief.
Claims (1):
The Attorney General may seek civil penalties of up to $7,500 per violation of the VCDPA where a controller or processor fails to cure a notified violation within 30 days, plus injunctive relief, with penalties and attorney fees deposited into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund since the 2022 amendments.
Enforcement Activity IndexAmber
AG announced full enforcement of minors'-social-media provisions in February 2026, filing a motion to dismiss NetChoice's suit.
Claims (1):
In February 2026, Attorney General Jay Jones announced his office's intent to fully enforce the VCDPA's new minors'-social-media-use-limitation provisions and filed a motion to dismiss NetChoice's challenge to the law.
Regulator Funding And CapacityAmber
OAG has historically flagged insufficient dedicated enforcement funding for VCDPA implementation.
Claims (1):
During the VCDPA work group process, the Office of the Attorney General noted that the self-funding dynamic of the (now-repealed) Consumer Privacy Fund was not feasible because no funds were available to support enforcement at the initial implementation stage.
Collective Redress And Class ActionsRed
Class-action enforcement of VCDPA violations is precluded.
Claims (1):
The VCDPA precludes class-action enforcement of its provisions.
Private Right Of ActionRed
No private right of action exists; enforcement is AG-exclusive.
Claims (1):
The VCDPA does not grant consumers a private right of action; enforcement is exclusively vested in the Attorney General.
Recent Developments 180DAmber
SB338 geolocation-sale ban (enacted April 2026, in force July 2026) and AG minors'-social-media enforcement announcement (February 2026); several additional 2026-session bills remain unverified as to final status.
Claims (2):
Within the 180 days preceding this run, Virginia enacted Senate Bill 338 (signed 13 April 2026, in force 1 July 2026) banning the sale of precise geolocation data, and Attorney General Jay Jones announced (February 2026) enforcement of the new minors' social-media time-limit provisions amid ongoing NetChoice litigation.
Additional 2026-session Virginia bills affecting the VCDPA framework include Senate Bill 232 (verified parental consent for minors' online agreements and expanded parental rights), Senate Bill 85 (interoperability interfaces for social-media/AI data sharing), Senate Bill 245 (social-media/AI regulations addressing minor protection and algorithmic discrimination), and Senate Bill 615 (restrictions on online device-based pricing practices); the enactment status of each was not independently confirmed against primary legislative records at the time of this research.
Category narrative62 words
Enforcement is vested exclusively in the Virginia Attorney General with a 30-day cure period, penalties up to $7,500 per violation plus injunctive relief, and no private right of action or class-action mechanism. Recent enforcement activity centers on the AG's February 2026 announcement to fully enforce the minors'-social-media-use provisions against NetChoice's constitutional challenge, alongside the April 2026 enactment of the precise-geolocation-data sale ban.
Sources and claims (7)
ConfirmedVirginia Office of the Attorney General — The Attorney General may seek civil penalties of up to $7,500 per violation of the VCDPA where a controller or processor fails to cure a notified violation within 30 days, plus injunctive relief, with penalties and attorney fees deposited into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund since the 2022 amendments.observed
ConfirmedVirginia Office of the Attorney General — In February 2026, Attorney General Jay Jones announced his office's intent to fully enforce the VCDPA's new minors'-social-media-use-limitation provisions and filed a motion to dismiss NetChoice's challenge to the law.observed
ProbableIAPP — During the VCDPA work group process, the Office of the Attorney General noted that the self-funding dynamic of the (now-repealed) Consumer Privacy Fund was not feasible because no funds were available to support enforcement at the initial implementation stage.observed
ConfirmedIAPP — The VCDPA precludes class-action enforcement of its provisions.observed
ConfirmedVirginia Office of the Attorney General — The VCDPA does not grant consumers a private right of action; enforcement is exclusively vested in the Attorney General.observed
ConfirmedIAPP — Within the 180 days preceding this run, Virginia enacted Senate Bill 338 (signed 13 April 2026, in force 1 July 2026) banning the sale of precise geolocation data, and Attorney General Jay Jones announced (February 2026) enforcement of the new minors' social-media time-limit provisions amid ongoing NetChoice litigation.observed
UncertainOneTrust DataGuidance — Additional 2026-session Virginia bills affecting the VCDPA framework include Senate Bill 232 (verified parental consent for minors' online agreements and expanded parental rights), Senate Bill 85 (interoperability interfaces for social-media/AI data sharing), Senate Bill 245 (social-media/AI regulations addressing minor protection and algorithmic discrimination), and Senate Bill 615 (restrictions on online device-based pricing practices); the enactment status of each was not independently confirmed against primary legislative records at the time of this research.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Virginia
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 57 claim(s), 17 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
All 10 modules populated with at least one Tier-1 (OAG primary/press-release) or Tier-2 (IAPP) anchor. regulator_and_framework, data_subject_rights, lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, children_and_vulnerable_groups, and enforcement_and_redress each rest on multiple T1/T2 sources including two direct Virginia OAG publications (SRC-VA-001, SRC-VA-004) and OAG enforcement press releases (SRC-VA-003). cross_border_and_adequacy is a legitimate 'no comprehensive regime' finding (red traffic light, absent_field_provenance) since VCDPA has no GDPR-style transfer/adequacy apparatus. adtech_and_commercial_privacy and algorithmic_biometric_and_surveillance_governance rely more heavily on T2/T3 secondary aggregator sources (IAPP, DataGuidance) for several 2026-session bills (HB654, HB1593, HB1642, SB232/85/245/615) whose final enactment status and effective dates could not be independently confirmed against primary Virginia legislative records (LIS) within this run's retrieval allowlist.
Unresolved questions (6):
Final enactment status and effective date of House Bill 654 (2026, biometric-data consent).
Final enactment status and effective date of House Bill 1593 (2026, parental records access).
Final enactment status and effective date of House Bill 1642 (2026, AI in criminal-justice decisions).
Bill number, primary text, and enactment status of the aggregator-reported Virginia AI impact-assessment/advisory-commission measure.
Enactment status of Senate Bills 232, 85, 245, and 615 (2026 session).
Whether Virginia's VCDPA cure period is subject to any legislatively-set sunset (as occurred in some peer states) — no sunset provision was located in sources reviewed.