Back to the hub

What must a Virginia VCDPA privacy notice include?

Virginia Code section 59.1-578(C) requires controllers to give consumers a reasonably accessible, clear, and meaningful privacy notice listing five items: the categories of personal data processed, the purpose of processing, how consumers exercise and appeal their rights, the categories shared with third parties, and the categories of those third parties.

Applies to: Controllers subject to the Virginia Consumer Data Protection Act, which must publish a privacy notice meeting Va. Code Section 59.1-578(C) and describe their consumer request methods in it.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Virginia's privacy notice rule is a five-item list in one subsection, with two further duties sitting just below it. Most notices written for California cover the list already. The parts that get missed are the appeal route and the ban on making people open an account.

The five items in Section 59.1-578(C)

Controllers shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes:

the categories of personal data processed by the controller; the purpose for processing personal data; how consumers may exercise their consumer rights pursuant to Section 59.1-577, including how a consumer may appeal a controller's decision with regard to the consumer's request; the categories of personal data that the controller shares with third parties, if any; and the categories of third parties, if any, with whom the controller shares personal data.

Item three is the one to check first. It asks for two things in one clause: how to make a request, and how to appeal a refusal. A notice that explains the request form but says nothing about appeals is incomplete, and the appeal process itself has a hard 60-day clock under Section 59.1-577(C), covered on our VCDPA response deadline page.

The opt-out disclosure in subsection D

Section 59.1-578(D) adds a duty that only applies to some controllers. If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose such processing, as well as the manner in which a consumer may exercise the right to opt out of such processing.

"Clearly and conspicuously" is doing work here. The disclosure that a category of sharing exists is not the same as telling people plainly that you sell data and where the switch is.

How people are allowed to reach you

Section 59.1-578(E) governs the request channel and is more prescriptive than it looks. A controller shall establish, and shall describe in a privacy notice, one or more secure and reliable means for consumers to submit a request to exercise their consumer rights. Those means shall take into account the ways in which consumers normally interact with the controller, the need for secure and reliable communication of such requests, and the ability of the controller to authenticate the identity of the consumer making the request.

Then the line that catches product teams: controllers shall not require a consumer to create a new account in order to exercise consumer rights, but may require a consumer to use an existing account. A privacy request flow gated behind a signup wall does not comply.

The duties the notice describes

A notice is only as good as the practices behind it, and Section 59.1-578(A) sets those: limit collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes; do not process for incompatible purposes without consent; maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data; do not process data in violation of anti-discrimination laws or discriminate against a consumer for exercising rights; do not process sensitive data without consent, or without COPPA-compliant handling for a known child; and do not sell or offer for sale precise geolocation data.

Section 59.1-578(B) adds that any contract term purporting to waive or limit consumer rights under Section 59.1-577 is contrary to public policy, void, and unenforceable. Your terms of service cannot contract around the notice.

Subsection F, added by the 2026 amendments, sets separate limits on processing personal data collected from a known child, including restrictions on targeted advertising, sale, and profiling, and a parental consent requirement tied to COPPA.

Next step

Virginia's list overlaps heavily with Texas and the other state laws, which means one well-built notice can usually satisfy several states at once. The free 2-minute Obligation Scan tells you which of them reach your business, and the Virginia VCDPA overview covers the applicability thresholds.

Compliance checklist

  • List the categories of personal data you process and the purpose for processing them, as Section 59.1-578(C)(1) and (2) require.
  • Explain how consumers exercise their rights under Section 59.1-577, including how to appeal a decision on a request; the appeal route is part of the notice, not an afterthought.
  • Name the categories of personal data you share with third parties and the categories of those third parties, if any.
  • Describe in the notice the secure and reliable request methods you offer under Section 59.1-578(E), chosen with regard to how consumers normally interact with you, and do not force account creation.
  • If you sell personal data or run targeted advertising, add the clear and conspicuous disclosure and opt-out mechanism required by Section 59.1-578(D).

Sources

Last verified: 2026-08-19

Informational, not legal advice.