VCDPA § 59.1-578
Data controller responsibilities; transparency
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- July 1, 2026
- Last reviewed
- September 2026
- Framework
- VCDPA
What it requires
Requires data controllers to practice data minimization, implement reasonable data security, and obtain opt-in consent for sensitive data. Since July 1, 2026, SB 338 (2026 Acts of Assembly ch. 820) also bars a controller from selling or offering for sale a consumer's precise geolocation data, and consent does not lift that ban. Mandates a clear and accessible privacy notice disclosing categories of data processed, processing purposes, sharing with third parties, and instructions for exercising rights.
Statute text
A controller shall: 1. Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; [...] 5. Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.); and 6. Not sell or offer for sale precise geolocation data concerning a consumer. [...] Controllers shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: [...]
Virginia Consumer Data Protection Act, § 59.1-578Read the full section from Virginia Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.