Back to the hub

Does Virginia's VCDPA apply to your business?

Virginia's Consumer Data Protection Act applies to any business that sells to or targets Virginia residents and, in a calendar year, controls or processes personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over half its gross revenue from selling personal data. It took effect January 1, 2023.

Applies to: Businesses that operate in Virginia or target Virginia residents and control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Virginia was the second state, after California, to pass a comprehensive privacy law, and its numbers became the template that Colorado, Connecticut, and others copied. If your business touches Virginia residents' data at any real scale, the question is not where you are based. It is how many Virginians you reach.

Who the VCDPA covers

The Consumer Data Protection Act applies to a person that conducts business in Virginia, or produces products or services targeted to Virginia residents, and meets one of two data thresholds in a calendar year. Location alone does not decide it. A company headquartered in another state, or another country, is covered if it handles enough Virginia consumers' data. "Consumer" here means a Virginia resident acting in an individual or household context, not someone acting in a commercial or employment role, so your B2B contacts and your own staff records sit outside the count.

What are the two thresholds?

You are covered if, during a calendar year, you either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and derive over 50 percent of your gross revenue from the sale of personal data. The second branch targets data brokers and businesses built on selling data: a smaller audience still triggers the law when the sale of personal data is central to how you earn. For most SaaS companies without a data-sale business model, the 100,000-consumer line is the one that matters.

Who is exempt?

Virginia exempts whole categories of organization rather than making each one prove it. Bodies of the Commonwealth, financial institutions and data governed by the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofit organizations, and institutions of higher education fall outside the chapter. On top of those entity exemptions, specific data is carved out where it is already regulated by federal law, including protected health information under HIPAA, consumer-report data under the Fair Credit Reporting Act, and education records under FERPA.

How Virginia compares

Virginia's 100,000-consumer line, and its 25,000-plus-data-sale branch, sit close to the Colorado Privacy Act and the Connecticut Data Privacy Act. It works very differently from the Texas TDPSA, which drops numeric thresholds and asks instead whether you are a small business under a federal definition. A company below Virginia's counts can still be caught in Texas, so clearing one state tells you little about the next. The US state privacy laws hub lays the tests side by side.

Next step

Counting how many Virginia consumers you actually control or process, and keeping employee and B2B records out of that count, is where most teams get stuck. The free 2-minute Obligation Scan runs Virginia's thresholds against your data and tells you plainly whether the VCDPA applies, then lists the notice, consumer-rights, and assessment duties that follow if it does.

Compliance checklist

  • Estimate how many Virginia residents' personal data you control or process in a calendar year.
  • Separate consumer data from employee and business-to-business data, which the VCDPA does not count.
  • Check whether over 50 percent of your gross revenue comes from selling personal data, which lowers the threshold to 25,000 consumers.
  • Confirm you are not within an exempt category, such as a GLBA financial institution, HIPAA covered entity, nonprofit, or higher-education institution.
  • If covered, publish a compliant privacy notice, honor consumer rights requests, and run data protection assessments for high-risk processing.

Sources

Last verified: 2026-07-21

Informational, not legal advice.