How long does a business have to respond to a VCDPA request?
Virginia Code section 59.1-577(B)(1) gives a controller 45 days from receipt to respond to an authenticated consumer request, extendable once by another 45 days if the controller tells the consumer why within the first 45. Appeals get a separate 60-day written answer under section 59.1-577(C), which must explain the decision.
Applies to: Controllers subject to the Virginia Consumer Data Protection Act that receive consumer requests to access, correct, delete, obtain a copy of, or opt out of the processing of personal data.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanVirginia runs two clocks, and teams that only build for the first one fail the second. Forty-five days to answer a request. Sixty days to answer an appeal of that answer. They are different deadlines with different content requirements.
The 45-day clock
Section 59.1-577(B)(1): a controller shall respond to the consumer without undue delay, but in all cases within 45 days of receipt of the request. The response period may be extended once by 45 additional days when reasonably necessary, taking into account the complexity and number of the consumer's requests, so long as the controller informs the consumer of any such extension within the initial 45-day response period, together with the reason for the extension.
Three details decide whether a workflow complies. The clock runs from receipt, not from the point you finish authenticating. The extension is available once, not repeatedly. And it is conditional: notice of the extension, with a reason, has to reach the consumer inside the original 45 days. An extension taken silently on day 44 is not an extension.
Declining a request is still a response
Section 59.1-577(B)(2): if a controller declines to take action, it shall inform the consumer without undue delay, and in all cases within 45 days of receipt, of the justification for declining and instructions for how to appeal the decision.
So a refusal carries two extra payloads: why, and what to do next. Silence is not a lawful denial.
The appeal, and its 60 days
Section 59.1-577(C) requires a controller to establish a process for a consumer to appeal a refusal, within a reasonable period after the consumer receives the decision. The appeal process shall be conspicuously available and similar to the process for submitting requests.
Within 60 days of receipt of an appeal, the controller shall inform the consumer in writing of any action taken or not taken, including a written explanation of the reasons for the decision. If the appeal is denied, the controller shall also provide the consumer with an online mechanism, if available, or another method through which the consumer may contact the Attorney General to submit a complaint.
That last clause is unusual and easy to miss. A denied appeal has to hand the consumer a route to the regulator.
Which requests start the clock
Section 59.1-577(A) lists five rights a controller must honor on an authenticated request: to confirm whether the controller is processing the consumer's personal data and to access it; to correct inaccuracies, taking into account the nature of the data and the purposes of processing; to delete personal data provided by or obtained about the consumer; to obtain a copy in a portable and, to the extent technically feasible, readily usable format that allows transmission to another controller without hindrance, where processing is carried out by automated means; and to opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.
A known child's parent or legal guardian may invoke those rights on the child's behalf.
Cost, verification, and third-party data
Three provisions shape the edges. Section 59.1-577(B)(3): responses are free up to twice annually per consumer; for manifestly unfounded, excessive, or repetitive requests the controller may charge a reasonable administrative fee or decline, but bears the burden of demonstrating that character. Section 59.1-577(B)(4): where the controller cannot authenticate the request using commercially reasonable efforts, it need not comply and may request more information.
Section 59.1-577(B)(5) handles data you did not get from the consumer. A controller that obtained personal data from another source is deemed compliant with a deletion request by either retaining a record of the deletion request and the minimum data necessary to keep the consumer's data deleted, using it for nothing else, or opting the consumer out of processing for any non-exempt purpose.
Next step
The response windows differ across states, and running one calendar per law is how deadlines get missed. The free 2-minute Obligation Scan tells you which state privacy laws apply to your business and the request deadlines each one sets. The Virginia VCDPA overview covers applicability, and the privacy notice requirements page covers what you must publish about these processes.
Compliance checklist
- Start a 45-day clock on receipt of each authenticated request, not on the date you finish verifying the person.
- If you need the extension, tell the consumer within the initial 45-day window and give the reason; the extension is not automatic and cannot be taken twice.
- When you decline a request, send the justification and the appeal instructions within 45 days, as Section 59.1-577(B)(2) requires.
- Run a conspicuous appeal process similar to your request process, and answer appeals in writing within 60 days with the reasons for the decision.
- If you deny an appeal, give the consumer an online mechanism, if available, or another method to contact the Attorney General to submit a complaint.
Sources
- Va. Code Section 59.1-577 (personal data rights; consumers), Virginia Law, Code of Virginia
- Va. Code Chapter 53, Consumer Data Protection Act, Virginia Law
Last verified: 2026-08-19
Informational, not legal advice.