West Virginia Privacy Law
West Virginia has not enacted a comprehensive consumer privacy law. Its breach-notification requirements live inside the Consumer Credit and Protection Act at article 46A-2A, which means a failure to notify is handled as an unfair or deceptive act under that Act rather than under a standalone data-security statute. The trigger is narrower than most: the statutory definition of a breach itself requires a reasonable belief that identity theft or other fraud has been or will be caused.
Sector-Specific Privacy Laws in West Virginia
West Virginia Consumer Credit and Protection Act (W. Va. Code ch. 46A)
The breach article sits inside chapter 46A, and W. Va. Code § 46A-2A-104(a) closes the circuit: except for licensed financial institutions, a failure to comply with the notice provisions “constitutes an unfair or deceptive act of practice in violation of section one hundred four, article six, chapter forty-six-a of this code, which may be enforced by the Attorney General pursuant to the enforcement provisions of this chapter.” Subsection (b) makes the Attorney General’s authority exclusive and limits civil penalties sharply, and subsection (c) reserves violations by a licensed financial institution to that institution’s primary functional regulator.
Student Data Accessibility, Transparency and Accountability Act — W. Va. Code § 18-2-5h
The section carries its own short title and governs the West Virginia Department of Education’s statewide longitudinal student data system. It defines the board as the West Virginia Board of Education, the department as the West Virginia Department of Education, and the student data system as that longitudinal system, and then sets out the definitions and duties that apply to student data held within it.
Compliance through existing procedures — W. Va. Code § 46A-2A-103
The article recognises three alternative routes to compliance. Subsection (a) deems an entity compliant where it maintains its own notification procedures as part of an information privacy or security policy that are consistent with the article’s timing requirements and it notifies West Virginia residents in accordance with them. Subsection (b) deems a financial institution compliant where it responds in accordance with the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice. Subsection (c) deems an entity compliant where it follows the rules, regulations, procedures or guidelines established by its primary or functional regulator.
Data Breach Notification in West Virginia
W. Va. Code § 46A-2A-101(1) builds a harm requirement into the definition itself: a “breach of the security of a system” is the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information held as part of a database regarding multiple individuals “and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state.” Section 46A-2A-102(a) carries the same condition into the notice duty. Subsection (b) extends the duty to encrypted information accessed in unencrypted form and to breaches involving a person with access to the encryption key. Subsection (d) prescribes the content of the notice: a description, to the extent possible, of the categories of information reasonably believed to have been accessed; a telephone number or website address from which the individual may learn what types of information the entity maintained about that individual and whether it maintained information about them at all; and the toll-free numbers and addresses for the major credit reporting agencies together with information on how to place a fraud alert or security freeze. Subsection (f) adds notice to the nationwide consumer reporting agencies where more than one thousand persons must be notified, and exempts entities subject to Title V of the Gramm-Leach-Bliley Act. Subsection (g) provides that the notice is not a debt communication under the Fair Debt Collection Practices Act. On penalties, § 46A-2A-104(b) gives the Attorney General exclusive authority to sue and bars any civil penalty “unless the court finds that the defendant has engaged in a course of repeated and willful violations,” capping any penalty at $150,000 per breach or per series of breaches of a similar nature discovered in a single investigation.
Residents must be notified without unreasonable delay, subject to law-enforcement delay and to measures needed to determine the scope of the breach and restore system integrity. No Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 persons are notified, unless the entity is subject to the Gramm-Leach-Bliley Act. Complaints are taken by the West Virginia Attorney General, which enforces the statute.
Recent Enforcement in West Virginia
Block, Inc. (Cash App) — $363,498.65 to West Virginia, 2026. The Attorney General announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, resolving allegations that Block misled consumers about the app’s safety, failed to protect users from fraud and did not provide the fraud protection it promised. The office states that Block’s sign-up process was fast and frictionless and required minimal identity verification, that Cash App offered no phone support for years so that users found fake customer-service numbers run by scammers, and that a promotion called Cash App Fridays, which encouraged users to post their $cashtag publicly, became a tool scammers used to steal login credentials. Under the settlement Block must maintain customer support able to resolve fraud complaints and lockouts, offer live support 24 hours a day with phone availability at least 13.5 hours a day and live chat at least 18 hours a day, stop misleading safety claims, discontinue marketing practices known to increase fraud, and investigate fraud claims and reimburse victims. Oregon and Texas led the investigation for the 46 participating states; West Virginia’s share is $363,498.65.
Pending Privacy Legislation
No comprehensive consumer-privacy statute has been enacted in West Virginia. Article 46A-2A applies, by its own terms in § 46A-2A-105, only to the discovery or notification of a breach occurring on or after the article’s effective date, and it has not been replaced by a broader consumer data-rights scheme.
Federal Privacy Laws That Apply in West Virginia
Federal privacy law applies in West Virginia by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, West Virginia obligations run through the state’s breach-notification statute and the West Virginia Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach West Virginia Businesses
With no comprehensive state statute, most privacy obligations on a West Virginia business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach West Virginia businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while West Virginia itself has none, and any business holding personal information about West Virginia residents is subject to the state’s breach-notification statute described above.
West Virginia Privacy Law FAQ
Does every data breach trigger notice in West Virginia?
Must West Virginia businesses notify the Attorney General after a breach?
What must a West Virginia breach notice contain?
What civil penalty can West Virginia impose for a notice failure?
Who enforces the article against a licensed financial institution?
Is a West Virginia breach notice a debt communication?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- W. Va. Code § 46A-2A-101 — Definitions statute
- W. Va. Code § 46A-2A-102 — Notice of breach of security of computerized personal information statute
- W. Va. Code § 46A-2A-103 — Procedures deemed in compliance statute
- W. Va. Code § 46A-2A-104 — Violations statute
- W. Va. Code § 18-2-5h — Student Data Accessibility, Transparency and Accountability Act statute
- West Virginia Attorney General — Multistate settlement with Block, Inc. over Cash App agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.