Virginia — Comprehensive Law

Virginia Privacy Law

Virginia wrote the template that most comprehensive state privacy laws now follow — controller and processor roles, opt-in consent for sensitive data, assessments for higher-risk processing, exclusive Attorney General enforcement — and has since moved away from it in ways worth noting. Section 59.1-577.1, in force since January 1, 2026, caps a minor’s use of a social media platform at one hour per day per service unless a parent consents otherwise, a substantive design mandate the original 2021 statute contained nothing like. Virginia’s breach statute sits in the criminal code rather than the commercial one, counts passport and military identification numbers as personal information, caps the Attorney General’s penalty at $150,000 per breach, and preserves an individual’s claim for direct economic damages. And the state’s first privacy settlement was recovered not under the VCDPA at all but under its 2023 Genetic Data Privacy chapter.

The Virginia Consumer Data Protection Act (VCDPA)

Chapter 53 of title 59.1 runs from § 59.1-575 through § 59.1-584. Section 59.1-576 applies it to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and that either control or process the personal data of at least 100,000 consumers during a calendar year, or control or process the data of at least 25,000 consumers while deriving over fifty percent of gross revenue from the sale of personal data. It exempts, as entities, Virginia public bodies, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofit organisations, and institutions of higher education — the nonprofit and higher-education carve-outs being entity-level rather than data-level, which is narrower than the approach several later states took. Section 59.1-578(A)(5) bars processing sensitive data without consent, and subsection (F) bars processing a known child’s data for targeted advertising, sale, or profiling producing legal or similarly significant effects, and requires a signal that remains available to the child for the entire duration of any precise geolocation collection. Section 59.1-577.1, added by chapter 703 of the 2025 Acts of Assembly, is the newest and most demanding piece: for any user younger than sixteen, a social media platform must limit use to one hour per day per service or application, must allow a parent to give verifiable consent to raise or lower that limit, must use commercially reasonable methods such as a neutral age screen to determine whether a user is a minor, and may not use the information collected for age determination for anything other than age determination and the provision of age-appropriate experiences.

Effective dateJanuary 1, 2023
CitationVa. Code § 59.1-575 et seq. (tit. 59.1, ch. 53)
Enforced byVirginia Attorney General
Maximum penaltyUp to $7,500 per violation under Va. Code § 59.1-584, plus reasonable investigation expenses and attorney fees
Private right of actionNo, enforcement by the state only
Right to cure30 days

Who Must Comply

The VCDPA reaches a business that controls or processes the personal data of at least 100,000 Virginia consumers during a calendar year, or controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.

Section 59.1-584 states not only that the Attorney General has exclusive enforcement authority but that nothing in the chapter “shall be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter or under any other law” — language aimed at derivative claims, not merely at direct ones. Penalties, expenses and fees are paid into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund rather than the general fund

Consumer Rights Under the VCDPA

Residents of Virginia can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Virginia

Genetic Data Privacy (Va. Code tit. 59.1, ch. 56)

Chapter 56, enacted by chapter 526 of the 2023 Acts of Assembly, regulates direct-to-consumer genetic testing companies independently of the VCDPA. Section 59.1-597 requires such a company to implement and maintain reasonable security procedures and practices to protect a consumer’s genetic data against unauthorized access, destruction, use, modification or disclosure, and to establish procedures through which a consumer may access that data, delete it, and revoke consent. The chapter carries its own consent architecture separate from the VCDPA’s, and it is the provision on which Virginia recovered its first privacy settlement — the Attorney General cited § 59.1-597(1) by name in the July 2026 23andMe matter.

Insurance Data Security Act (Va. Code tit. 38.2, ch. 6, art. 2)

Article 2 of chapter 6 of title 38.2 puts insurance licensees on a reporting clock far shorter than the general breach statute’s. Section 38.2-625 requires notice to the State Corporation Commission as promptly as possible and in no event later than three business days from determining that a cybersecurity event has occurred, where the licensee is a domestic insurer or a producer whose home state is the Commonwealth and the event meets the Commission’s criteria, or where the licensee reasonably believes the nonpublic information involved is that of 250 or more Virginia consumers and notice is required under federal or another state’s law. The notice carries thirteen specified items, among them the date of the event and how it was discovered, a description of the information exposed and any third-party involvement, the identity of the source, the number of Virginia consumers affected, the remediation underway, and a copy of the licensee’s consumer privacy policy.

Virginia Consumer Protection Act (Va. Code § 59.1-196 et seq.)

The VCPA is Virginia’s unfair-practices statute, and § 59.1-200 enumerates the prohibited practices rather than relying only on a general standard. Subdivision (A)(85) is the one that matters most for privacy: it makes it a prohibited practice to obtain, disclose, sell or disseminate any personally identifiable reproductive or sexual health information without the consumer’s consent, exempting information covered by the Gramm-Leach-Bliley Act. Subdivision (A)(35) addresses using a consumer’s Social Security number as an account number where the consumer has asked in writing that it not be, and subdivision (A)(14) is the catch-all reaching any other deception, fraud, false pretense, false promise or misrepresentation in a consumer transaction — the provision under which a gap between a stated privacy practice and an actual one is pleaded.

Data Breach Notification in Virginia

Virginia’s breach statute is § 18.2-186.6, sitting in the crimes title rather than in the trade and commerce title where the VCDPA lives. Its definition of personal information is narrower than most and includes two elements many states omit: an individual’s first name or first initial and last name in combination with, and linked to, an unencrypted and unredacted Social Security number, driver’s licence or state identification number, financial account number with any required security code, passport number, or military identification number. A “breach of the security of the system” is the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises security or confidentiality and that causes, or the entity reasonably believes has caused or will cause, identity theft or another fraud. Notice to residents and to the Attorney General is due without unreasonable delay after discovery, and may be delayed to determine the scope of the breach or where law enforcement advises that notice would impede an investigation. The Attorney General and the nationwide consumer reporting agencies are notified where more than 1,000 persons are being notified at one time. Substitute notice becomes available where the cost of notice would exceed $50,000 or more than 100,000 residents are affected — both figures well below the $250,000 and 500,000 thresholds common elsewhere. The Attorney General may impose a civil penalty not to exceed $150,000 per breach, or per series of similar breaches discovered in a single investigation. The section closes by providing that nothing in it limits an individual from recovering direct economic damages from a violation, which is a narrower opening than a general private right of action but is not nothing.

Residents must be notified without unreasonable delay after discovery, subject to delay for law enforcement and for determining the scope of the breach. Notify the Attorney General and the nationwide consumer reporting agencies without unreasonable delay where more than 1,000 persons are notified at one time. Complaints are taken by the Virginia Attorney General, which enforces the statute.

How the VCDPA Is Enforced

Exclusive authority, a 30-day cure, and a dedicated fund. Section 59.1-584 gives the Attorney General exclusive authority to enforce the VCDPA. Before an action, the office provides written notice identifying the alleged violations; if the controller or processor cures within thirty days and provides written confirmation, no action proceeds. Where violations continue after the cure period, or an express written statement of cure is breached, the office may seek up to $7,500 per violation. It may also recover reasonable expenses incurred in investigating and preparing the case, including attorney fees. Penalties, expenses and fees are paid into the Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund.

The office states how it will approach the social media provision. In its February 16, 2026 announcement on § 59.1-577.1 the office described the sequence it intends to follow: communicate evidence of non-compliance directly to companies, provide thirty days to remedy the violation, and, where violations continue, pursue civil penalties of up to $7,500 per violation together with injunctive relief. The same announcement recorded that the office had moved to dismiss the suit NetChoice brought against the provision.

Recent Enforcement in Virginia

23andMe — $662,649 to Virginia, the first recovery under the Genetic Data Privacy law. On July 20, 2026 the Attorney General announced a settlement with the bankruptcy trustee of 23andMe, joined by a coalition of forty-two attorneys general, resolving claims arising from the October 2023 breach. Virginia’s share is $662,649 on behalf of 170,495 affected Virginians. The states’ allowed claims totalled $150 million, of which recovery is limited to $18 million payable immediately from available bankruptcy funds. The release identifies the statutory basis as Va. Code § 59.1-597(1) and states that this is Virginia’s first settlement as it relates to the new Genetic Data Privacy law. The alleged security failures were: failing to employ safeguards against credential stuffing attacks including comparing passwords against blocklists; failing to implement appropriate rate limiting or intrusion prevention; failing to implement logging and monitoring or other tools likely to detect a breach; failing to appropriately investigate or address unusual login patterns; failing to remediate known vulnerabilities; and failing to properly review and test design features.

NetChoice challenge to § 59.1-577.1 — motion to dismiss filed February 16, 2026. On February 16, 2026 the Attorney General announced that the office intends to fully enforce the social media provisions of the Consumer Data Protection Act that took effect January 1, 2026, and that it had filed a motion to dismiss the lawsuit NetChoice brought challenging the law on behalf of its member platforms. The provision at issue limits a minor’s use of a social media platform to one hour per day per service or application for users younger than sixteen. The office stated it will communicate evidence of non-compliance directly to companies and provide thirty days to remedy before seeking civil penalties of up to $7,500 per violation and injunctive relief.

Pending Privacy Legislation

Virginia’s recent privacy activity has been amendment and litigation rather than new frameworks. Chapter 703 of the 2025 Acts of Assembly added § 59.1-577.1, the social media time limit for users under sixteen, which took effect January 1, 2026 and is the subject of a NetChoice challenge the Attorney General moved to dismiss on February 16, 2026. The Genetic Data Privacy chapter at title 59.1, chapter 56 was enacted as chapter 526 of the 2023 Acts of Assembly and produced the Commonwealth’s first privacy settlement in July 2026. Section 59.1-585 of the VCDPA has been repealed. Nothing enacted since 2021 has altered the chapter’s core applicability thresholds of 100,000 consumers, or 25,000 consumers with over fifty percent of gross revenue from the sale of personal data.

Federal Privacy Laws That Apply in Virginia

Federal privacy law applies in Virginia by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The VCDPA sits alongside those rules rather than displacing them: the Virginia Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Virginia Consumer Protection Act (Va. Code § 59.1-196 et seq.), which the Virginia Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Virginia Privacy Law FAQ

How long may a minor use a social media platform in Virginia?
One hour per day, per service or application, by default. Section 59.1-577.1, enacted as chapter 703 of the 2025 Acts of Assembly and in force since January 1, 2026, defines a minor as any natural person younger than sixteen and requires a social media platform to limit that user’s daily use to one hour per service, while allowing a parent to give verifiable parental consent to increase or decrease the limit. Operators use commercially reasonable methods, such as a neutral age screen mechanism, to determine whether a user is a minor, and information collected for age determination may not be used for any purpose other than age determination and providing age-appropriate experiences.
Does Virginia’s breach law count a passport number as personal information?
Yes, and a military identification number as well. Section 18.2-186.6 lists five data elements that, unencrypted and unredacted and linked to a name, make information “personal information”: Social Security number, driver’s licence or state identification number, financial account number with any required security code, passport number, and military identification number. The passport and military elements are absent from most state breach statutes, and Virginia’s list is otherwise short — it does not reach medical information, health insurance identifiers or biometric data, which several neighbouring states include.
What is the maximum penalty for a breach-notification failure in Virginia?
$150,000, and the cap attaches to the breach rather than to each affected person. Section 18.2-186.6 provides that the Attorney General may impose a civil penalty not to exceed $150,000 per breach of the security of the system, or per series of breaches of a similar nature that are discovered in a single investigation. That is a different structure from the VCDPA, where § 59.1-584 sets $7,500 per violation with no aggregate cap.
Can a Virginian sue over a breach or a VCDPA violation?
The two statutes answer differently. Section 59.1-584 forecloses private VCDPA claims in unusually broad terms, providing that nothing in the chapter shall be construed as providing the basis for, or being subject to, a private right of action for violations of the chapter or under any other law. Section 18.2-186.6, by contrast, closes with a saving clause: nothing in the section limits an individual from recovering direct economic damages from a violation of it. That preserves a claim measured by economic loss rather than creating a statutory damages remedy.
Which entities fall outside the VCDPA entirely?
Section 59.1-576 exempts five categories at the entity level: any body, authority, board, bureau, commission, district or agency of the Commonwealth or a political subdivision; a financial institution or data subject to Title V of the Gramm-Leach-Bliley Act; a HIPAA covered entity or business associate; a nonprofit organisation; and an institution of higher education. Because the nonprofit and higher-education exemptions run to the entity rather than to particular data, a Virginia nonprofit sits outside the chapter for all of its processing. Data-level exemptions cover HIPAA protected health information, health records under title 32.1, patient identifying information, de-identified information, credit reporting data, driver’s licence information, educational records, farm credit data, and data collected in an employment or job-applicant context.
How quickly must a Virginia insurance licensee report a cybersecurity event?
Three business days, under Va. Code § 38.2-625, running from the determination that a cybersecurity event occurred rather than from discovery of an incident. The duty is triggered where the licensee is a domestic insurance company or a producer whose home state is the Commonwealth and the event meets the State Corporation Commission’s requirements, or where the licensee reasonably believes that nonpublic information of 250 or more Virginia consumers is involved and notice is required under federal or another state’s law. The notice carries thirteen items, including a copy of the licensee’s consumer privacy policy.
Is reproductive health information specially protected in Virginia?
Yes, through the consumer protection statute rather than the privacy one. Section 59.1-200(A)(85) makes it a prohibited practice under the Virginia Consumer Protection Act to obtain, disclose, sell or disseminate any personally identifiable reproductive or sexual health information without the consumer’s consent, with an exemption for information covered by the Gramm-Leach-Bliley Act. Placing the rule in § 59.1-200 rather than in the VCDPA matters because the VCDPA’s applicability thresholds and entity exemptions do not gate it.
Has Virginia actually enforced its privacy statutes?
Yes, though the first recovery came under the genetic data chapter rather than the VCDPA. On July 20, 2026 the Attorney General announced a multistate settlement of bankruptcy claims against 23andMe over the 2023 genetic data breach, with Virginia receiving $662,649 on behalf of 170,495 affected Virginians; the release cites Va. Code § 59.1-597(1) and states that this is Virginia’s first settlement relating to the new Genetic Data Privacy law. Separately, on February 16, 2026 the office announced that it intends to fully enforce § 59.1-577.1 and moved to dismiss a NetChoice suit challenging it, stating that it will communicate evidence of non-compliance directly to companies and allow thirty days to remedy before seeking civil penalties of up to $7,500 per violation and injunctive relief.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.