Virginia Privacy Law (VCDPA): Compliance Guide
Virginia was the second state to pass a comprehensive privacy law, and the Virginia Consumer Data Protection Act — effective January 1, 2023 — became the template that most later states copied. Its formula of opt-out rights, a sensitive-data opt-in, 100,000/25,000 thresholds, and Attorney General enforcement now defines the mainstream of US privacy law. If you understand the VCDPA, you understand the baseline that fifteen other states started from.
- Effective
- January 1, 2023
- GPC / universal opt-out
- Not required
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Virginia Consumer Data Protection Act (VCDPA)
Applicability
Who must comply with the VCDPA
The Virginia Consumer Data Protection Act applies to businesses that meet the following criteria:
- Conducts business in Virginia or produces products or services targeted to Virginia residents, and:
- Controls or processes the personal data of 100,000 or more Virginia consumers, or
- Controls or processes the personal data of 25,000 or more Virginia consumers and derives 50% or more of gross revenue from the sale of personal data
Consumer rights
What Virginia consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to obtain a portable copy of personal data
- Right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions with legal effects
Opt-out mechanics
Virginia opt-out & GPC requirements
Like every US state privacy law, the VCDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Virginia is “Your Privacy Choices”.
Global Privacy Control: Not required
The VCDPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link is the required mechanism.
Enforcement
VCDPA penalties & enforcement
- Up to $7,500 per violation
Cure period: 30-day cure period, available until December 31, 2025.
State quirks
What makes Virginia different
Virginia's importance is structural: it wrote the template. The opt-out framework with opt-in for sensitive data, the 100,000-consumer threshold with a 50%-of-revenue trigger at 25,000, data protection assessments for high-risk processing — all of it was copied state after state. Virginia itself keeps evolving in unusual directions: a 2026 amendment limits social media use for under-16s to one hour per day unless a parent extends it. Its 30-day cure period sunset December 31, 2025, leaving $7,500-per-violation exposure with no grace window.
Opt-in for sensitive data
Processing sensitive personal data requires explicit consumer consent — an opt-in standard most states reserve for narrower cases.
Data protection assessments
Required for high-risk processing activities.
Minors and social media (2026)
A 2026 amendment limits social media use for minors under 16 to one hour per day unless a parent extends it — a product-level duty that goes well beyond consent mechanics.
Automation
How ConsentKit handles Virginia
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Virginia visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Virginia visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Virginia does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Virginia the opt-out link remains the visitor's control.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Virginia visitor makes a choice.
For Virginia's sensitive-data opt-in, ConsentKit's per-category consent records give you an audit trail; the “Your Privacy Choices” link handles the sale and advertising opt-outs.
FAQ
Virginia VCDPA FAQ
Does the VCDPA apply to my business?
It applies if you conduct business in Virginia or target products or services to Virginia residents, and either control or process the personal data of 100,000 or more Virginia consumers, or 25,000 or more while deriving 50% or more of gross revenue from selling personal data.
Is Global Privacy Control required in Virginia?
No. Despite inspiring many later laws, the VCDPA itself has no universal opt-out signal requirement — the “Your Privacy Choices” opt-out link is the required mechanism.
What changed for minors in Virginia in 2026?
A 2026 amendment limits social media use for minors under 16 to one hour per day unless a parent extends it — an unusual, product-level duty that goes well beyond consent mechanics and requires platforms to build time limits into the product itself.
What are the penalties and cure period under the VCDPA?
Up to $7,500 per violation. The 30-day cure period was available only until December 31, 2025 — violations now carry full exposure once enforcement begins.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the VCDPA.
Comply with Virginia's VCDPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.