When does the Virginia VCDPA require a data protection assessment?
Under Virginia Code section 59.1-580, a controller must conduct and document a data protection assessment for five activities: targeted advertising, the sale of personal data, profiling that presents a reasonably foreseeable risk of listed harms, processing sensitive data, and any processing presenting a heightened risk of harm to consumers.
Applies to: Controllers subject to the Virginia Consumer Data Protection Act that run targeted advertising, sell personal data, profile consumers, process sensitive data, or offer online services directed to known children.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Virginia does not ask every controller to write assessments for everything. It names five processing activities and says: for these, do the work and write it down. If your business runs ads, sells data, profiles people, or touches sensitive data, at least one of the five is almost certainly yours.
The five triggers in Section 59.1-580(A)
A controller must conduct and document a data protection assessment of each of the following: processing personal data for purposes of targeted advertising; the sale of personal data; processing for purposes of profiling, where the profiling presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact on consumers, financial, physical, or reputational injury, a physical or other intrusion on solitude or seclusion or private affairs that would be offensive to a reasonable person, or other substantial injury; the processing of sensitive data; and any processing activities involving personal data that present a heightened risk of harm to consumers.
Note the asymmetry. Targeted advertising, sale, and sensitive data trigger the duty flatly. Profiling only triggers it where the listed risks are reasonably foreseeable. The final catch-all is deliberately open, and it is the one worth documenting your reasoning on either way.
Services directed to children
Section 59.1-580(B) adds a separate requirement. A controller that offers an online service, product, or feature directed to consumers it has actual knowledge are children must conduct an assessment for that service. The assessment has to address the purpose of the service, the categories of known children's personal data it processes, and the purposes for which the controller processes that data.
What the assessment has to weigh
Section 59.1-580(C) sets the substance. The assessment identifies and weighs the benefits that may flow, directly and indirectly, from the processing to the controller, the consumer, other stakeholders, and the public, against the potential risks to the rights of the consumer, as mitigated by safeguards the controller can employ. The use of de-identified data, the reasonable expectations of consumers, the context of the processing, and the relationship between controller and consumer all get factored in.
This is a balancing exercise, not a checklist, which is why the document matters as much as the conclusion. If you reach the answer that the processing is justified, the assessment is the record of how.
Who can ask to see it
Section 59.1-580(D) gives the Attorney General the right to request an assessment relevant to an investigation, through a civil investigative demand, and the controller must make it available. The Attorney General may evaluate it for compliance with the responsibilities in Section 59.1-578. Assessments are confidential and exempt from public inspection and copying under the Virginia Freedom of Information Act, and handing one over in response to that request does not waive attorney-client privilege or work product protection.
Reusing work you have already done
Two provisions save effort. Section 59.1-580(E) lets a single assessment address a comparable set of processing operations that include similar activities. Section 59.1-580(F) lets assessments conducted for compliance with other laws or regulations satisfy this section, provided they have a reasonably comparable scope and effect. If you already run GDPR Article 35 data protection impact assessments, that work is a realistic starting point rather than a parallel project.
Section 59.1-580(G) sets the boundary in time: the requirements apply to processing activities created or generated after January 1, 2023, and are not retroactive.
Next step
If you are not sure whether the VCDPA applies to you or which of your processing activities cross the assessment line, the free 2-minute Obligation Scan checks which state privacy laws reach your business and lists the documentation each one expects. The Virginia VCDPA overview covers the applicability thresholds, and the US state privacy laws hub compares assessment duties across states.
Compliance checklist
- Map your processing against the five triggers in Section 59.1-580(A) and record which activities require an assessment.
- Run a separate assessment under Section 59.1-580(B) for any online service, product, or feature directed to consumers you have actual knowledge are children.
- Weigh benefits to the controller, consumer, other stakeholders, and the public against risks to the consumer, as Section 59.1-580(C) requires, factoring in de-identification, consumer expectations, and the context of the relationship.
- Use a single assessment to cover a comparable set of processing operations where the activities are similar, which Section 59.1-580(E) permits.
- Reuse assessments prepared for other laws where they have a reasonably comparable scope and effect, as Section 59.1-580(F) allows.
Sources
- Va. Code Section 59.1-580 (data protection assessments), Virginia Law, Code of Virginia
- Va. Code Chapter 53, Consumer Data Protection Act, Virginia Law
Last verified: 2026-08-14
Informational, not legal advice.