Virginia Privacy Law
Virginia wrote the template that most comprehensive state privacy laws now follow — controller and processor roles, opt-in consent for sensitive data, assessments for higher-risk processing, exclusive Attorney General enforcement — and has since moved away from it in ways worth noting. Section 59.1-577.1, in force since January 1, 2026, caps a minor’s use of a social media platform at one hour per day per service unless a parent consents otherwise, a substantive design mandate the original 2021 statute contained nothing like. Virginia’s breach statute sits in the criminal code rather than the commercial one, counts passport and military identification numbers as personal information, caps the Attorney General’s penalty at $150,000 per breach, and preserves an individual’s claim for direct economic damages. And the state’s first privacy settlement was recovered not under the VCDPA at all but under its 2023 Genetic Data Privacy chapter.
The Virginia Consumer Data Protection Act (VCDPA)
Chapter 53 of title 59.1 runs from § 59.1-575 through § 59.1-584. Section 59.1-576 applies it to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and that either control or process the personal data of at least 100,000 consumers during a calendar year, or control or process the data of at least 25,000 consumers while deriving over fifty percent of gross revenue from the sale of personal data. It exempts, as entities, Virginia public bodies, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofit organisations, and institutions of higher education — the nonprofit and higher-education carve-outs being entity-level rather than data-level, which is narrower than the approach several later states took. Section 59.1-578(A)(5) bars processing sensitive data without consent, and subsection (F) bars processing a known child’s data for targeted advertising, sale, or profiling producing legal or similarly significant effects, and requires a signal that remains available to the child for the entire duration of any precise geolocation collection. Section 59.1-577.1, added by chapter 703 of the 2025 Acts of Assembly, is the newest and most demanding piece: for any user younger than sixteen, a social media platform must limit use to one hour per day per service or application, must allow a parent to give verifiable consent to raise or lower that limit, must use commercially reasonable methods such as a neutral age screen to determine whether a user is a minor, and may not use the information collected for age determination for anything other than age determination and the provision of age-appropriate experiences.
| Effective date | January 1, 2023 |
|---|---|
| Citation | Va. Code § 59.1-575 et seq. (tit. 59.1, ch. 53) |
| Enforced by | Virginia Attorney General |
| Maximum penalty | Up to $7,500 per violation under Va. Code § 59.1-584, plus reasonable investigation expenses and attorney fees |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days |
Who Must Comply
The VCDPA reaches a business that controls or processes the personal data of at least 100,000 Virginia consumers during a calendar year, or controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.
Section 59.1-584 states not only that the Attorney General has exclusive enforcement authority but that nothing in the chapter “shall be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter or under any other law” — language aimed at derivative claims, not merely at direct ones. Penalties, expenses and fees are paid into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund rather than the general fund
Consumer Rights Under the VCDPA
Residents of Virginia can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Virginia
Genetic Data Privacy (Va. Code tit. 59.1, ch. 56)
Chapter 56, enacted by chapter 526 of the 2023 Acts of Assembly, regulates direct-to-consumer genetic testing companies independently of the VCDPA. Section 59.1-597 requires such a company to implement and maintain reasonable security procedures and practices to protect a consumer’s genetic data against unauthorized access, destruction, use, modification or disclosure, and to establish procedures through which a consumer may access that data, delete it, and revoke consent. The chapter carries its own consent architecture separate from the VCDPA’s, and it is the provision on which Virginia recovered its first privacy settlement — the Attorney General cited § 59.1-597(1) by name in the July 2026 23andMe matter.
Insurance Data Security Act (Va. Code tit. 38.2, ch. 6, art. 2)
Article 2 of chapter 6 of title 38.2 puts insurance licensees on a reporting clock far shorter than the general breach statute’s. Section 38.2-625 requires notice to the State Corporation Commission as promptly as possible and in no event later than three business days from determining that a cybersecurity event has occurred, where the licensee is a domestic insurer or a producer whose home state is the Commonwealth and the event meets the Commission’s criteria, or where the licensee reasonably believes the nonpublic information involved is that of 250 or more Virginia consumers and notice is required under federal or another state’s law. The notice carries thirteen specified items, among them the date of the event and how it was discovered, a description of the information exposed and any third-party involvement, the identity of the source, the number of Virginia consumers affected, the remediation underway, and a copy of the licensee’s consumer privacy policy.
Virginia Consumer Protection Act (Va. Code § 59.1-196 et seq.)
The VCPA is Virginia’s unfair-practices statute, and § 59.1-200 enumerates the prohibited practices rather than relying only on a general standard. Subdivision (A)(85) is the one that matters most for privacy: it makes it a prohibited practice to obtain, disclose, sell or disseminate any personally identifiable reproductive or sexual health information without the consumer’s consent, exempting information covered by the Gramm-Leach-Bliley Act. Subdivision (A)(35) addresses using a consumer’s Social Security number as an account number where the consumer has asked in writing that it not be, and subdivision (A)(14) is the catch-all reaching any other deception, fraud, false pretense, false promise or misrepresentation in a consumer transaction — the provision under which a gap between a stated privacy practice and an actual one is pleaded.
Data Breach Notification in Virginia
Virginia’s breach statute is § 18.2-186.6, sitting in the crimes title rather than in the trade and commerce title where the VCDPA lives. Its definition of personal information is narrower than most and includes two elements many states omit: an individual’s first name or first initial and last name in combination with, and linked to, an unencrypted and unredacted Social Security number, driver’s licence or state identification number, financial account number with any required security code, passport number, or military identification number. A “breach of the security of the system” is the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises security or confidentiality and that causes, or the entity reasonably believes has caused or will cause, identity theft or another fraud. Notice to residents and to the Attorney General is due without unreasonable delay after discovery, and may be delayed to determine the scope of the breach or where law enforcement advises that notice would impede an investigation. The Attorney General and the nationwide consumer reporting agencies are notified where more than 1,000 persons are being notified at one time. Substitute notice becomes available where the cost of notice would exceed $50,000 or more than 100,000 residents are affected — both figures well below the $250,000 and 500,000 thresholds common elsewhere. The Attorney General may impose a civil penalty not to exceed $150,000 per breach, or per series of similar breaches discovered in a single investigation. The section closes by providing that nothing in it limits an individual from recovering direct economic damages from a violation, which is a narrower opening than a general private right of action but is not nothing.
Residents must be notified without unreasonable delay after discovery, subject to delay for law enforcement and for determining the scope of the breach. Notify the Attorney General and the nationwide consumer reporting agencies without unreasonable delay where more than 1,000 persons are notified at one time. Complaints are taken by the Virginia Attorney General, which enforces the statute.
How the VCDPA Is Enforced
Exclusive authority, a 30-day cure, and a dedicated fund. Section 59.1-584 gives the Attorney General exclusive authority to enforce the VCDPA. Before an action, the office provides written notice identifying the alleged violations; if the controller or processor cures within thirty days and provides written confirmation, no action proceeds. Where violations continue after the cure period, or an express written statement of cure is breached, the office may seek up to $7,500 per violation. It may also recover reasonable expenses incurred in investigating and preparing the case, including attorney fees. Penalties, expenses and fees are paid into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund.
The office states how it will approach the social media provision. In its February 16, 2026 announcement on § 59.1-577.1 the office described the sequence it intends to follow: communicate evidence of non-compliance directly to companies, provide thirty days to remedy the violation, and, where violations continue, pursue civil penalties of up to $7,500 per violation together with injunctive relief. The same announcement recorded that the office had moved to dismiss the suit NetChoice brought against the provision.
Recent Enforcement in Virginia
23andMe — $662,649 to Virginia, the first recovery under the Genetic Data Privacy law. On July 20, 2026 the Attorney General announced a settlement with the bankruptcy trustee of 23andMe, joined by a coalition of forty-two attorneys general, resolving claims arising from the October 2023 breach. Virginia’s share is $662,649 on behalf of 170,495 affected Virginians. The states’ allowed claims totalled $150 million, of which recovery is limited to $18 million payable immediately from available bankruptcy funds. The release identifies the statutory basis as Va. Code § 59.1-597(1) and states that this is Virginia’s first settlement as it relates to the new Genetic Data Privacy law. The alleged security failures were: failing to employ safeguards against credential stuffing attacks including comparing passwords against blocklists; failing to implement appropriate rate limiting or intrusion prevention; failing to implement logging and monitoring or other tools likely to detect a breach; failing to appropriately investigate or address unusual login patterns; failing to remediate known vulnerabilities; and failing to properly review and test design features.
NetChoice challenge to § 59.1-577.1 — motion to dismiss filed February 16, 2026. On February 16, 2026 the Attorney General announced that the office intends to fully enforce the social media provisions of the Consumer Data Protection Act that took effect January 1, 2026, and that it had filed a motion to dismiss the lawsuit NetChoice brought challenging the law on behalf of its member platforms. The provision at issue limits a minor’s use of a social media platform to one hour per day per service or application for users younger than sixteen. The office stated it will communicate evidence of non-compliance directly to companies and provide thirty days to remedy before seeking civil penalties of up to $7,500 per violation and injunctive relief.
Pending Privacy Legislation
Virginia’s recent privacy activity has been amendment and litigation rather than new frameworks. Chapter 703 of the 2025 Acts of Assembly added § 59.1-577.1, the social media time limit for users under sixteen, which took effect January 1, 2026 and is the subject of a NetChoice challenge the Attorney General moved to dismiss on February 16, 2026. The Genetic Data Privacy chapter at title 59.1, chapter 56 was enacted as chapter 526 of the 2023 Acts of Assembly and produced the Commonwealth’s first privacy settlement in July 2026. Section 59.1-585 of the VCDPA has been repealed. Nothing enacted since 2021 has altered the chapter’s core applicability thresholds of 100,000 consumers, or 25,000 consumers with over fifty percent of gross revenue from the sale of personal data.
Federal Privacy Laws That Apply in Virginia
Federal privacy law applies in Virginia by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The VCDPA sits alongside those rules rather than displacing them: the Virginia Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Virginia Consumer Protection Act (Va. Code § 59.1-196 et seq.), which the Virginia Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Virginia Privacy Law FAQ
How long may a minor use a social media platform in Virginia?
Does Virginia’s breach law count a passport number as personal information?
What is the maximum penalty for a breach-notification failure in Virginia?
Can a Virginian sue over a breach or a VCDPA violation?
Which entities fall outside the VCDPA entirely?
How quickly must a Virginia insurance licensee report a cybersecurity event?
Is reproductive health information specially protected in Virginia?
Has Virginia actually enforced its privacy statutes?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Va. Code § 59.1-576 — Scope; exemptions statute
- Va. Code § 59.1-577.1 — Social media platforms; responsibilities and prohibitions related to minors statute
- Va. Code § 59.1-578 — Data controller responsibilities; transparency statute
- Va. Code § 59.1-584 — Enforcement; civil penalty; expenses statute
- Va. Code § 18.2-186.6 — Breach of personal information notification statute
- Va. Code § 59.1-200 — Prohibited practices (Virginia Consumer Protection Act) statute
- Va. Code § 59.1-597 — Genetic Data Privacy; duties of genetic testing companies statute
- Va. Code § 38.2-625 — Notification of a cybersecurity event (Insurance Data Security Act) statute
- Virginia Attorney General — multistate settlement of bankruptcy claims against 23andMe agency
- Virginia Attorney General — enforcement of the social media provisions and the NetChoice motion agency
- Virginia Attorney General — Virginians’ data privacy rights under the CDPA agency guidance
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.