VCDPA § 59.1-576

Scope; exemptions

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
January 1, 2023
Last reviewed
September 2026
Framework
VCDPA

What it requires

Establishes applicability thresholds for businesses targeting Virginia residents, requiring compliance for entities processing data of 100,000+ consumers, or 25,000+ consumers if over 50% of gross revenue comes from selling personal data. Provides exemptions for government entities, HIPAA-covered entities, GLBA financial institutions, and nonprofits.

Statute text

This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.

Virginia Consumer Data Protection Act, § 59.1-576Read the full section from Virginia Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit