Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / VCDPA
VIRGINIA CDPA · OPT-IN FOR SENSITIVE DATA

Virginia made sensitive data opt-in.

The Virginia Consumer Data Protection Act requires covered controllers to obtain consent before processing sensitive data, provide consumer rights and appeals workflows, offer opt-outs from targeted advertising, qualifying data sales, and certain profiling, and document assessments for high-risk processing. Virginia also restricts the use of known children’s data and prohibits the sale of precise geolocation data. Captain Compliance helps make these requirements operational and documented.

Opt-in sensitive dataData protection assessmentsAG-only enforcement

GDPR’s structure, a US enforcement model.

$7,500
Per violation

The Virginia Attorney General has exclusive enforcement authority and may seek civil penalties of up to $7,500 for each violation that continues after the statutory cure process or violates a written assurance of cure.

Opt-in
Sensitive data

Processing sensitive data requires affirmative consent, unlike California’s opt-out model.

30 days
Cure process

Before suing, the AG must give 30 days’ written notice of alleged violations; a cure plus an express written assurance can stop the action. This cure right remains part of the current statute.

Assessments
Required for high-risk processing

Data protection assessments are required for targeted advertising, sales, profiling with legal effects, sensitive-data processing, and services directed to known children.

No PRA
AG only

The VCDPA creates no private right of action. Enforcement belongs exclusively to the Virginia Attorney General.

Duties
Beyond consent

Controllers must also limit collection to necessary data, avoid incompatible secondary use, maintain reasonable security, and avoid discriminating against consumers for exercising their rights. Controllers remain responsible for organization-wide governance.

Opt-in where it’s required, rights where they’re owed.

The VCDPA imposes duties around data minimization, compatible use, reasonable security, consent for sensitive data, non-discrimination, transparency, consumer rights, and assessments — not a GDPR-style lawful-basis test. We make each part operational.

C

Sensitive-data opt-in

Obtain a clear affirmative act reflecting the consumer’s freely given, specific, informed, and unambiguous consent before processing sensitive data. For personal data from a known child under 13, follow COPPA’s verifiable parental-consent requirements. Sensitive data includes racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship/immigration status, biometric or genetic data used to uniquely identify someone, known-child data, and precise geolocation (generally within about 1,750 feet, subject to statutory exclusions).

D

Consumer rights

Confirmation, access, correction, deletion, portability, and opt-outs from targeted advertising, qualifying data sales, and certain profiling — with authentication, appeals, and documented deadlines. Controllers generally respond within 45 days (one 45-day extension allowed with notice). Denials include appeal instructions; appeals get a written answer within 60 days, with a way to contact the Virginia AG if the appeal is denied. Responses are free up to twice yearly per consumer.

O

Purpose-specific opt-outs

Provide clear methods for consumers to opt out of targeted advertising, the sale of personal data for monetary consideration, and profiling in furtherance of decisions producing legal or similarly significant effects. “Sale” means an exchange for monetary consideration — it excludes processor disclosures, service-requested disclosures, affiliate transfers, certain consumer-directed disclosures, and merger or bankruptcy transfers. Virginia does not currently require honoring Global Privacy Control or another Universal Opt-Out Mechanism.

A

Data protection assessments

Document assessments for targeted advertising, personal-data sales, sensitive-data processing, qualifying profiling, and other processing presenting a heightened risk of harm, including services directed to known children. Assessments weigh benefits against risks, apply to processing created after January 1, 2023, may cover comparable processing operations, and are confidential and exempt from public-record inspection.

P

Processor agreements

Track controller-processor contracts documenting processing instructions, purpose, data types, duration, confidentiality, deletion or return, compliance information, assessments, and subcontractor flow-down obligations. Processors must follow controller instructions and assist with rights requests, security and breach duties, and assessment information.

N

Privacy notice

Generate and maintain clear, accessible notices covering data categories, processing purposes, third-party sharing, consumer rights, secure request methods, and appeal instructions, with clear disclosure and opt-out information when data is sold or used for targeted advertising. Consumers can’t be required to open a new account just to exercise their rights.

G

Precise-geolocation controls

Help identify, document, and govern technologies that collect or transmit precise geolocation data, and apply consent controls before that data is collected or otherwise processed. Virginia treats precise geolocation as sensitive data and separately prohibits selling or offering to sell it — consent to sensitive-data processing is never a substitute for a sale the statute prohibits.

K

Known-child data controls

Support COPPA-aligned parental consent, purpose limitation, retention controls, targeted-advertising restrictions, and assessments for online services directed to known children under 13. Precise geolocation from a known child may be collected only when reasonably necessary, for only the necessary period, with a visible collection indicator, and with verifiable parental consent.

One operating framework, state-specific execution.

Virginia helped establish a model later used by several state privacy laws, but the statutes are not identical. Their definitions of sale, sensitive data, opt-out signals, applicability thresholds, response requirements, and assessment rules differ. Captain Compliance centralizes consent, rights, notice, and assessment workflows while routing each request and preference according to the applicable state requirements. A Virginia assessment may support compliance elsewhere only when its scope and effect are reasonably comparable to the other jurisdiction’s requirements.

Book a VCDPA audit
Illustrative rollout · timing varies by controller
  • Day 1 — Targeted-advertising, qualifying-sale, and profiling opt-out methods configured
  • Week 1 — Sensitive-data and precise-geolocation consent workflows mapped
  • Week 2 — Consumer-rights, authentication, denial, appeal, and deadline workflows deployed
  • Week 3 — High-risk processing and known-child assessments documented
  • Ongoing — Privacy notices, processor terms, consent records, rights requests, and multi-state requirements monitored

What changes when the VCDPA program is on.

Without a program
  • Sensitive data processed without affirmative consent
  • Targeted-advertising, sale, and profiling opt-outs missing or difficult to use
  • No appeal process for denied rights requests
  • No assessments for sensitive or other high-risk processing
  • Precise-geolocation collection and transfers not mapped
  • Processor terms inconsistent across vendors
  • Known-child data lacks parental-consent and purpose controls
With Captain Compliance
  • Affirmative sensitive-data consent documented
  • Purpose-specific opt-out methods clearly available
  • 45-day request and 60-day appeal workflows tracked
  • Assessments completed and stored for covered high-risk processing
  • Precise-geolocation technologies identified and governed
  • Required processor terms tracked by vendor
  • Known-child consent, purpose, retention, and assessment workflows supported

VCDPA, answered plainly.

How is Virginia different from California?+
Virginia generally requires opt-in consent before processing sensitive data, while California primarily provides rights to limit certain uses and disclosures of sensitive personal information. Virginia defines “sale” more narrowly as an exchange for monetary consideration, uses applicability thresholds based on consumer volume and revenue from data sales, exempts nonprofits, and gives the Attorney General exclusive enforcement authority. Unlike California, Virginia does not currently require recognition of Global Privacy Control or another universal opt-out signal.
What counts as a data protection assessment?+
A documented evaluation of the risks of certain processing — targeted advertising, sale, profiling with legal or similarly significant effects, sensitive-data processing, and services directed to known children — weighed against its benefits. We provide the template, route high-risk processing into it, and store the result. Assessments are confidential and exempt from public-record inspection, though the Attorney General may request them by civil investigative demand.
Who enforces the VCDPA?+
The Virginia Attorney General has exclusive enforcement authority. Before bringing an action, the Attorney General must provide 30 days’ written notice identifying the alleged violations. If the controller or processor cures the violations within that period and provides the required written assurance that they have been cured and will not recur, no action may be initiated. Uncured violations, or a breach of that written assurance, may result in an injunction, civil penalties of up to $7,500 per violation, investigation expenses, and attorney fees. The VCDPA does not create a private right of action.
Are we in scope?+
The VCDPA generally applies if your organization conducts business in Virginia or targets products or services to Virginia residents and either controls or processes the personal data of at least 100,000 Virginia consumers during a calendar year, or controls or processes the personal data of at least 25,000 Virginia consumers and derives more than 50% of gross revenue from selling personal data. “Consumers” are Virginia residents acting in an individual or household context, not employment or business-to-business contexts. Broad entity-level exemptions include Virginia government bodies, qualifying financial institutions or GLBA-regulated data, HIPAA covered entities and business associates, nonprofit organizations, and institutions of higher education; other data-specific exemptions may also apply.
Does Virginia require Global Privacy Control?+
No. The VCDPA gives consumers rights to opt out of targeted advertising, the sale of personal data, and certain profiling, but it does not currently require controllers to recognize Global Privacy Control or another Universal Opt-Out Mechanism. Captain Compliance may recognize GPC as part of a broader multi-state implementation, but that capability should not be described as a Virginia-specific mandate.
How long do we have to answer a consumer appeal?+
A controller must respond to an appeal in writing within 60 days. The response must explain any action taken or not taken and the reasons for the decision. If the appeal is denied, the controller must provide an online mechanism, if available, or another method through which the consumer can contact the Virginia Attorney General.
Can we sell precise geolocation data after obtaining consent?+
The VCDPA treats precise geolocation as sensitive data, requiring consent for its processing. The statute also separately states that a controller may not sell or offer to sell a consumer’s precise geolocation data. Consent to process the data should not be presented as permission to conduct a sale the statute prohibits.
Does Virginia require assessments for children’s online services?+
Yes. A controller offering an online service, product, or feature directed to consumers it actually knows are children must conduct a data protection assessment addressing the service’s purpose, the categories of known children’s personal data processed, and the purposes for that processing.
Does the VCDPA have a right to cure?+
Yes. Before bringing an enforcement action, the Virginia Attorney General must provide 30 days’ written notice identifying the alleged violations. If the controller or processor cures them within that period and provides an express written assurance that they have been cured and will not recur, the Attorney General may not initiate the action.
Is Virginia’s social-media provision for minors currently in effect?+
Virginia Code § 59.1-577.1 contains special requirements for covered social-media platforms involving users under 16, including age determination and a default one-hour daily limit subject to parental adjustment. On February 27, 2026, a federal district court entered a preliminary injunction blocking enforcement of that provision in NetChoice v. Jones. Virginia appealed to the U.S. Court of Appeals for the Fourth Circuit, and the litigation remained pending as of August 2026. This provision is not an active Captain Compliance feature or a presently enforceable general VCDPA obligation while the injunction remains in place; affected platforms should monitor the litigation and obtain current legal advice. Read the preliminary-injunction opinion, NetChoice v. Jones.
Where can I find the official VCDPA statute?+
Code of Virginia — complete Consumer Data Protection Act, scope and exemptions (§ 59.1-576), consumer rights and appeals (§ 59.1-577), controller duties and transparency (§ 59.1-578), controller-processor responsibilities (§ 59.1-579), data protection assessments (§ 59.1-580), and enforcement and civil penalties (§ 59.1-584). This page provides general information and does not constitute legal advice; applicability and compliance requirements depend on an organization’s data practices, business model, exemptions, and circumstances.

Make Virginia’s opt-in model operational.

Consent where it’s required, rights where they’re owed, assessments on file. Start free.

Start free See pricing