VCDPA · Opt-out model

Virginia Privacy Law (VCDPA): Compliance Guide

Virginia was the second state to pass a comprehensive privacy law, and the Virginia Consumer Data Protection Act — effective January 1, 2023 — became the template that most later states copied. Its formula of opt-out rights, a sensitive-data opt-in, 100,000/25,000 thresholds, and Attorney General enforcement now defines the mainstream of US privacy law. If you understand the VCDPA, you understand the baseline that fifteen other states started from.

Effective
January 1, 2023
GPC / universal opt-out
Not required
Required link text
Your Privacy Choices
Handle VCDPA compliance free

Last reviewed July 19, 2026 · Virginia Consumer Data Protection Act (VCDPA)

Applicability

Who must comply with the VCDPA

The Virginia Consumer Data Protection Act applies to businesses that meet the following criteria:

  • Conducts business in Virginia or produces products or services targeted to Virginia residents, and:
  • Controls or processes the personal data of 100,000 or more Virginia consumers, or
  • Controls or processes the personal data of 25,000 or more Virginia consumers and derives 50% or more of gross revenue from the sale of personal data

Consumer rights

What Virginia consumers can demand

  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to obtain a portable copy of personal data
  • Right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions with legal effects

Opt-out mechanics

Virginia opt-out & GPC requirements

Like every US state privacy law, the VCDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Virginia is Your Privacy Choices.

Global Privacy Control: Not required

The VCDPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link is the required mechanism.

Enforcement

VCDPA penalties & enforcement

  • Up to $7,500 per violation

Cure period: 30-day cure period, available until December 31, 2025.

State quirks

What makes Virginia different

Virginia's importance is structural: it wrote the template. The opt-out framework with opt-in for sensitive data, the 100,000-consumer threshold with a 50%-of-revenue trigger at 25,000, data protection assessments for high-risk processing — all of it was copied state after state. Virginia itself keeps evolving in unusual directions: a 2026 amendment limits social media use for under-16s to one hour per day unless a parent extends it. Its 30-day cure period sunset December 31, 2025, leaving $7,500-per-violation exposure with no grace window.

Opt-in for sensitive data

Processing sensitive personal data requires explicit consumer consent — an opt-in standard most states reserve for narrower cases.

Data protection assessments

Required for high-risk processing activities.

Minors and social media (2026)

A 2026 amendment limits social media use for minors under 16 to one hour per day unless a parent extends it — a product-level duty that goes well beyond consent mechanics.

Automation

How ConsentKit handles Virginia

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Virginia visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Virginia visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Virginia does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Virginia the opt-out link remains the visitor's control.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Virginia visitor makes a choice.

For Virginia's sensitive-data opt-in, ConsentKit's per-category consent records give you an audit trail; the “Your Privacy Choices” link handles the sale and advertising opt-outs.

FAQ

Virginia VCDPA FAQ

Does the VCDPA apply to my business?

It applies if you conduct business in Virginia or target products or services to Virginia residents, and either control or process the personal data of 100,000 or more Virginia consumers, or 25,000 or more while deriving 50% or more of gross revenue from selling personal data.

Is Global Privacy Control required in Virginia?

No. Despite inspiring many later laws, the VCDPA itself has no universal opt-out signal requirement — the “Your Privacy Choices” opt-out link is the required mechanism.

What changed for minors in Virginia in 2026?

A 2026 amendment limits social media use for minors under 16 to one hour per day unless a parent extends it — an unusual, product-level duty that goes well beyond consent mechanics and requires platforms to build time limits into the product itself.

What are the penalties and cure period under the VCDPA?

Up to $7,500 per violation. The 30-day cure period was available only until December 31, 2025 — violations now carry full exposure once enforcement begins.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the VCDPA.

Comply with Virginia's VCDPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.