Everything you need to know about VCDPA compliance, data security requirements, and secure data disposal.
The Virginia Consumer Data Protection Act (VCDPA) was the second comprehensive consumer privacy law in the United States, following California's lead, and became the first of a new wave of state privacy laws built on a somewhat different structural model than the CCPA — one that has since been echoed by numerous other states. Effective January 1, 2023, the VCDPA gives Virginia residents meaningful rights over their personal data while placing structured obligations on businesses.
Background
The VCDPA was signed into law in March 2021 and took effect January 1, 2023. Its passage marked a turning point in US privacy law: rather than following California's ballot-initiative-driven, business-focused disclosure model, Virginia adopted a framework closer in spirit to GDPR's controller/processor structure, which subsequent states such as Colorado, Connecticut, and Utah later used as a template for their own laws.
Who Must Comply
The VCDPA applies to entities that conduct business in Virginia or produce products or services targeted to Virginia residents, and that during a calendar year either:
- Control or process the personal data of at least 100,000 Virginia consumers, or
- Control or process the personal data of at least 25,000 Virginia consumers and derive over 50% of gross revenue from the sale of personal data
Certain entities are exempt, including state government bodies, financial institutions subject to the Gramm-Leach-Bliley Act, and covered entities or business associates governed by HIPAA.
Controller and Processor Roles
Like GDPR, the VCDPA distinguishes between "controllers" (entities that determine the purpose and means of processing personal data) and "processors" (entities that process personal data on behalf of a controller). This structure requires specific contractual terms between controllers and processors, including provisions on the nature and purpose of processing, duration, and the processor's obligations.
Consumer Rights
Virginia residents have the right to:
- Confirm whether a controller is processing their personal data and access that data
- Correct inaccuracies in their personal data
- Delete personal data provided by or obtained about the consumer
- Obtain a copy of their personal data in a portable format
- Opt out of the processing of their personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects
Sensitive Data Requirements
The VCDPA requires controllers to obtain a consumer's opt-in consent before processing "sensitive data," a category that includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify an individual, personal data collected from a known child, and precise geolocation data.
Data Protection Assessments
Controllers must conduct and document data protection assessments for processing activities that present a heightened risk of harm to consumers, including targeted advertising, the sale of personal data, processing of sensitive data, and profiling that presents reasonably foreseeable risks. These assessments must be made available to the Virginia Attorney General upon request in connection with an investigation.
Enforcement and Penalties
The VCDPA does not include a private right of action; enforcement authority rests exclusively with the Virginia Attorney General. Violations can result in civil penalties of up to $7,500 per violation, and the Attorney General can seek to recover reasonable expenses incurred in investigating and preparing a case. The law originally included a 30-day cure period allowing businesses to fix violations before enforcement, which was set to sunset after a defined period under the statute's terms.
Secure Data Deletion
Under the VCDPA's deletion right, controllers must permanently remove a consumer's personal data upon a valid request, not merely deactivate or logically mark it as deleted while leaving it recoverable. Combined with the law's general expectation of reasonable data security practices, this means Virginia-regulated businesses retiring servers, computers, or storage devices that processed consumer personal data should use standards-based, verifiable data erasure methods and retain destruction records to properly close out deletion requests and demonstrate compliance if the Attorney General's office opens an inquiry.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
The VCDPA established the structural template — controller/processor roles, opt-in consent for sensitive data, and mandatory risk assessments — that many subsequent US state privacy laws have followed. For businesses subject to the VCDPA, compliance means building GDPR-style governance processes alongside verifiable, secure data disposal practices at the end of the data lifecycle.
No comments yet. Be the first to comment.