Back to the hub

Who is exempt from Virginia's Consumer Data Protection Act?

Virginia Code Section 59.1-576(B) exempts five kinds of entity from the Consumer Data Protection Act: state and local government bodies, financial institutions or GLBA data, HIPAA covered entities and business associates, nonprofit organizations, and institutions of higher education. Subsection (C) separately exempts fourteen categories of data.

Applies to: Businesses that meet the Virginia Consumer Data Protection Act thresholds in Section 59.1-576(A) and need to know whether an entity-level or data-level exemption takes them, or part of their data, outside the law.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Virginia's Consumer Data Protection Act does two different things in one section, and reading them as one list is how businesses get the answer wrong. Section 59.1-576(B) removes whole organizations from the chapter. Section 59.1-576(C) removes particular categories of data from a business that is otherwise covered. The first ends the analysis. The second only narrows it.

The five entity exemptions

Section 59.1-576(B) says the chapter shall not apply to any:

  1. body, authority, board, bureau, commission, district or agency of the Commonwealth or of any political subdivision of the Commonwealth;
  2. financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act;
  3. covered entity or business associate governed by the privacy, security and breach notification rules issued by the U.S. Department of Health and Human Services at 45 C.F.R. Parts 160 and 164, and the HITECH Act;
  4. nonprofit organization;
  5. institution of higher education.

If one of those describes your organization, the chapter does not reach you at all. Not your marketing data, not your website analytics, not your customer records.

The second one is drafted with an "or" that does real work. It exempts a financial institution or data subject to GLBA Title V. So a business that is not a bank can still put GLBA-regulated data outside the chapter, and a bank is outside it regardless of what data is in question.

The fourteen data exemptions

Section 59.1-576(C) is the other half. It exempts information and data rather than organizations, and it runs to fourteen numbered categories. The health-related ones dominate the list: protected health information under HIPAA, health records for purposes of Title 32.1, patient identifying information under 42 U.S.C. 290dd-2, identifiable private information from human subjects research, information created for the Health Care Quality Improvement Act, patient safety work product, de-identified health data, and intermingled data held by a covered entity or business associate.

Then the federal statutes: FCRA consumer report data, but only to the extent the activity is regulated by and authorized under the Fair Credit Reporting Act; personal data handled in compliance with the Driver's Privacy Protection Act; personal data regulated by FERPA; and personal data handled in compliance with the Farm Credit Act.

The employment carve-out most SaaS businesses rely on

Section 59.1-576(C)(14) is the one that matters to a company with no health or credit data at all. It exempts data processed or maintained in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor or third party, to the extent the data is collected and used within the context of that role. It also covers emergency contact information used for emergency contact purposes, and data retained to administer benefits for someone related to that individual.

So your HR system is outside the Virginia chapter. Your customer database is not. California is the outlier that brought employee and B2B data inside its law; Virginia, Texas, Iowa, Indiana and Nebraska all keep it out.

What this does not exempt you from

Section 59.1-576(D) adds one deeming rule rather than an exemption: a controller or processor that complies with the verifiable parental consent requirements of the Children's Online Privacy Protection Act is treated as compliant with any obligation to obtain parental consent under the chapter. That is a safe harbor for a specific duty, not a way out of the chapter.

And an exemption in Virginia is a Virginia answer. Iowa conditions its HIPAA exemption on persons "subject to and comply with" the federal rules, which is a higher bar than Virginia's "governed by". Colorado has no general nonprofit exemption at all. A business selling into a dozen states has a dozen versions of this question, which is the practical reason to run the applicability test per state rather than once.

Compliance checklist

  • Confirm first that you actually meet a threshold in Section 59.1-576(A), because an exemption question only matters once the 100,000 consumer or 25,000-plus-50-percent-of-revenue test is met.
  • Check the five entity exemptions in Section 59.1-576(B) before the data ones, since an entity exemption removes you from the chapter completely and makes the rest of the analysis unnecessary.
  • If you are a financial institution, note that Section 59.1-576(B)(ii) exempts the institution or GLBA Title V data, so the carve-out can be read at either level.
  • Work through the fourteen data exemptions in Section 59.1-576(C) for anything you process that is regulated elsewhere, including FCRA consumer report data, DPPA driver data, FERPA education records and Farm Credit Act data.
  • Treat employee and applicant data as outside the chapter under Section 59.1-576(C)(14), which covers data processed in the course of applying to, being employed by, or acting as an agent or independent contractor of a controller.
  • Do not assume a Virginia exemption carries to other states, because Iowa conditions its HIPAA exemption on actually complying and Colorado has no general nonprofit exemption.

Sources

Last verified: 2026-09-04

Informational, not legal advice.