West Virginia

West Virginia Privacy Law

West Virginia has not enacted a comprehensive consumer privacy law. Its breach-notification requirements live inside the Consumer Credit and Protection Act at article 46A-2A, which means a failure to notify is handled as an unfair or deceptive act under that Act rather than under a standalone data-security statute. The trigger is narrower than most: the statutory definition of a breach itself requires a reasonable belief that identity theft or other fraud has been or will be caused.

Sector-Specific Privacy Laws in West Virginia

West Virginia Consumer Credit and Protection Act (W. Va. Code ch. 46A)

The breach article sits inside chapter 46A, and W. Va. Code § 46A-2A-104(a) closes the circuit: except for licensed financial institutions, a failure to comply with the notice provisions “constitutes an unfair or deceptive act of practice in violation of section one hundred four, article six, chapter forty-six-a of this code, which may be enforced by the Attorney General pursuant to the enforcement provisions of this chapter.” Subsection (b) makes the Attorney General’s authority exclusive and limits civil penalties sharply, and subsection (c) reserves violations by a licensed financial institution to that institution’s primary functional regulator.

Student Data Accessibility, Transparency and Accountability Act — W. Va. Code § 18-2-5h

The section carries its own short title and governs the West Virginia Department of Education’s statewide longitudinal student data system. It defines the board as the West Virginia Board of Education, the department as the West Virginia Department of Education, and the student data system as that longitudinal system, and then sets out the definitions and duties that apply to student data held within it.

Compliance through existing procedures — W. Va. Code § 46A-2A-103

The article recognises three alternative routes to compliance. Subsection (a) deems an entity compliant where it maintains its own notification procedures as part of an information privacy or security policy that are consistent with the article’s timing requirements and it notifies West Virginia residents in accordance with them. Subsection (b) deems a financial institution compliant where it responds in accordance with the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice. Subsection (c) deems an entity compliant where it follows the rules, regulations, procedures or guidelines established by its primary or functional regulator.

Data Breach Notification in West Virginia

W. Va. Code § 46A-2A-101(1) builds a harm requirement into the definition itself: a “breach of the security of a system” is the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information held as part of a database regarding multiple individuals “and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state.” Section 46A-2A-102(a) carries the same condition into the notice duty. Subsection (b) extends the duty to encrypted information accessed in unencrypted form and to breaches involving a person with access to the encryption key. Subsection (d) prescribes the content of the notice: a description, to the extent possible, of the categories of information reasonably believed to have been accessed; a telephone number or website address from which the individual may learn what types of information the entity maintained about that individual and whether it maintained information about them at all; and the toll-free numbers and addresses for the major credit reporting agencies together with information on how to place a fraud alert or security freeze. Subsection (f) adds notice to the nationwide consumer reporting agencies where more than one thousand persons must be notified, and exempts entities subject to Title V of the Gramm-Leach-Bliley Act. Subsection (g) provides that the notice is not a debt communication under the Fair Debt Collection Practices Act. On penalties, § 46A-2A-104(b) gives the Attorney General exclusive authority to sue and bars any civil penalty “unless the court finds that the defendant has engaged in a course of repeated and willful violations,” capping any penalty at $150,000 per breach or per series of breaches of a similar nature discovered in a single investigation.

Residents must be notified without unreasonable delay, subject to law-enforcement delay and to measures needed to determine the scope of the breach and restore system integrity. No Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 persons are notified, unless the entity is subject to the Gramm-Leach-Bliley Act. Complaints are taken by the West Virginia Attorney General, which enforces the statute.

Recent Enforcement in West Virginia

Block, Inc. (Cash App) — $363,498.65 to West Virginia, 2026. The Attorney General announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, resolving allegations that Block misled consumers about the app’s safety, failed to protect users from fraud and did not provide the fraud protection it promised. The office states that Block’s sign-up process was fast and frictionless and required minimal identity verification, that Cash App offered no phone support for years so that users found fake customer-service numbers run by scammers, and that a promotion called Cash App Fridays, which encouraged users to post their $cashtag publicly, became a tool scammers used to steal login credentials. Under the settlement Block must maintain customer support able to resolve fraud complaints and lockouts, offer live support 24 hours a day with phone availability at least 13.5 hours a day and live chat at least 18 hours a day, stop misleading safety claims, discontinue marketing practices known to increase fraud, and investigate fraud claims and reimburse victims. Oregon and Texas led the investigation for the 46 participating states; West Virginia’s share is $363,498.65.

Pending Privacy Legislation

No comprehensive consumer-privacy statute has been enacted in West Virginia. Article 46A-2A applies, by its own terms in § 46A-2A-105, only to the discovery or notification of a breach occurring on or after the article’s effective date, and it has not been replaced by a broader consumer data-rights scheme.

Federal Privacy Laws That Apply in West Virginia

Federal privacy law applies in West Virginia by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

Outside those federal sectors, West Virginia obligations run through the state’s breach-notification statute and the West Virginia Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.

Industry Rules That Reach West Virginia Businesses

With no comprehensive state statute, most privacy obligations on a West Virginia business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach West Virginia businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while West Virginia itself has none, and any business holding personal information about West Virginia residents is subject to the state’s breach-notification statute described above.

West Virginia Privacy Law FAQ

Does every data breach trigger notice in West Virginia?
No, and the limit is built into the definition rather than added as an exception. W. Va. Code § 46A-2A-101(1) defines a breach of the security of a system as unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information “and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state.” Section 46A-2A-102(a) repeats that condition in the notice duty.
Must West Virginia businesses notify the Attorney General after a breach?
Article 46A-2A contains no Attorney General notification threshold. The only third-party notice it requires is in § 46A-2A-102(f): where more than one thousand persons must be notified, the entity must also notify all consumer reporting agencies that compile and maintain files on a nationwide basis, as defined by 15 U.S.C. § 1681a(p), of the timing, distribution and content of the notices. That subsection does not apply to entities subject to Title V of the Gramm-Leach-Bliley Act.
What must a West Virginia breach notice contain?
W. Va. Code § 46A-2A-102(d) lists three items. First, to the extent possible, a description of the categories of information reasonably believed to have been accessed or acquired, including Social Security numbers, driver’s licence or state identification numbers and financial data. Second, a telephone number or website address the individual may use to learn what types of information the entity maintained about that individual, and whether it maintained information about them at all. Third, the toll-free contact telephone numbers and addresses for the major credit reporting agencies and information on how to place a fraud alert or security freeze.
What civil penalty can West Virginia impose for a notice failure?
W. Va. Code § 46A-2A-104(b) sets two conditions. No civil penalty may be assessed “unless the court finds that the defendant has engaged in a course of repeated and willful violations of this article,” and no civil penalty may exceed $150,000 per breach of security of the system, or per series of breaches of a similar nature that are discovered in a single investigation. The same subsection gives the Attorney General exclusive authority to bring the action.
Who enforces the article against a licensed financial institution?
W. Va. Code § 46A-2A-104(c) provides that a violation of the article by a licensed financial institution “shall be enforceable exclusively by the financial institution’s primary functional regulator.” That carve-out sits alongside § 46A-2A-103(b), which deems a financial institution in compliance where it responds in accordance with the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice.
Is a West Virginia breach notice a debt communication?
W. Va. Code § 46A-2A-102(g) answers this directly: the notice required by the section “shall not be considered a debt communication as defined by the Fair Debt Collection Practice Act in 15 U.S.C. §1692a.” The provision matters because the breach article sits inside the Consumer Credit and Protection Act, where debt-collection rules also live.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.