Hand drawing digital document with shield icon

Does the Virginia Consumer Data Protection Act Apply to My Business? A Virginia Business Law Attorney’s Plain-English Threshold Test

Most Virginia companies that ask a Virginia business law attorney about the Consumer Data Protection Act discover they are not covered by it, and the reason is arithmetic rather than legal interpretation. The VCDPA, Va. Code ยง 59.1-575 and following, took effect January 1, 2023. Its thresholds sit high, its definition of a consumer is narrower than most people assume, and its exemptions remove entire categories of business regardless of size.

What are the two thresholds that trigger the VCDPA?

The law applies to a person that conducts business in Virginia, or produces products or services targeted to Virginia residents, and that during a calendar year either controls or processes personal data of at least 100,000 consumers, or controls or processes personal data of at least 25,000 consumers while deriving more than half of gross revenue from the sale of personal data.

Two features of that test get overlooked. The count includes data you merely process on someone else’s behalf, so a service provider can cross the line on client data it does not own. And the 100,000 figure counts Virginia residents only, not total customers, so a national e-commerce brand can have a large customer base and still fall well short.

Who counts as a consumer, and who does not?

A consumer under the VCDPA is a natural person who is a Virginia resident acting only in an individual or household context. The statute expressly excludes people acting in a commercial or employment context.

That exclusion does more work than any other provision in the law. Employees, job applicants, contractors, and business contacts do not count toward the thresholds, and their data is not subject to the statute’s consumer rights. A staffing firm with 60,000 candidate records and a B2B distributor with 40,000 purchasing-agent contacts are both looking at numbers that carry no weight here. California takes the opposite approach and covers employment and business-to-business data, which is why compliance advice written for the CCPA misleads Virginia companies so often.

Which businesses are exempt no matter their size?

The VCDPA exempts several categories of organization at the entity level, meaning the exemption covers all of the entity’s data rather than only the regulated portion. Financial institutions and data subject to the Gramm-Leach-Bliley Act, covered entities and business associates under HIPAA, nonprofits, institutions of higher education, and state bodies and political subdivisions all sit outside the statute.

Separate data-level exemptions cover information governed by other federal regimes, including protected health information, consumer report data under the Fair Credit Reporting Act, student records under FERPA, and driver’s license data under the Driver’s Privacy Protection Act. A community bank, a medical practice, and a charitable foundation can generally stop reading. A fintech that is not itself a financial institution usually cannot.

What does the sale of personal data mean in Virginia?

Virginia defines the sale of personal data as the exchange of personal data for monetary consideration by the controller to a third party. That is narrower than the definition in California, Colorado, and several other states, which reach exchanges for other valuable consideration as well.

The distinction matters mainly for the second threshold. A company that shares data with advertising partners without receiving money for it may not be selling personal data in Virginia, even though the same arrangement counts as a sale elsewhere. Document that analysis if you rely on it, because these arrangements are rarely as simple as the contracts describe.

What do you actually have to do if you are covered?

Covered controllers owe consumers a defined set of rights on a fixed timeline. Consumers may access, correct, delete, and obtain a portable copy of their personal data, and may opt out of targeted advertising, the sale of personal data, and profiling used in decisions producing legal or similarly significant effects.

Responses are due within 45 days of receipt, extendable once by another 45 days with notice to the consumer. Controllers must also run an internal appeal process for denied requests, respond to an appeal within 60 days, and tell the consumer how to complain to the Attorney General if the appeal fails.

Other obligations sit behind the scenes. Processing sensitive data, which includes precise geolocation, health diagnoses, biometric and genetic data, religious beliefs, sexual orientation, immigration status, and the data of a known child, requires opt-in consent. Data protection assessments are required for targeted advertising, sales of personal data, certain profiling, sensitive data, and processing that presents a heightened risk of harm. Contracts with processors must contain specified terms, which is why larger customers keep pushing data processing agreements down to their vendors.

What happens if you get this wrong?

Enforcement rests exclusively with the Virginia Attorney General, and there is no private right of action, so the risk is a regulatory inquiry rather than a class action. The Attorney General must give written notice of an alleged violation and allow 30 days to cure before filing suit. Penalties run up to $7,500 per violation, and the office may also recover reasonable expenses of investigating and preparing the case, including attorney fees.

Virginia’s cure period has no sunset date, unlike equivalent provisions in some other state privacy laws that expired after an initial grace period. That favors any company that responds promptly to a notice.

What does a Virginia business law attorney check if you are under the threshold?

Falling outside the VCDPA settles one question and leaves several open. Virginia’s breach notification statute applies regardless of company size. Customers subject to the GDPR or California law routinely require contractual privacy and security commitments from vendors who are not themselves regulated. Several states have since passed privacy laws with lower or no volume thresholds, so a growing company can become regulated in Texas or Nebraska long before Virginia’s numbers come into view.

Run the threshold test with real numbers, confirm whether an entity-level exemption covers you, and document the conclusion so it can be defended later. A Virginia business law attorney can work through that analysis alongside your vendor contracts and privacy notice, and identify which obligations reach you by agreement even when the statute does not. Reach out through the firm’s website to schedule a review of your data practices.