VCDPA § 59.1-578

Data controller responsibilities; transparency

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
July 1, 2026
Last reviewed
September 2026
Framework
VCDPA

What it requires

Requires data controllers to practice data minimization, implement reasonable data security, and obtain opt-in consent for sensitive data. Since July 1, 2026, SB 338 (2026 Acts of Assembly ch. 820) also bars a controller from selling or offering for sale a consumer's precise geolocation data, and consent does not lift that ban. Mandates a clear and accessible privacy notice disclosing categories of data processed, processing purposes, sharing with third parties, and instructions for exercising rights.

Statute text

A controller shall: 1. Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; [...] 5. Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.); and 6. Not sell or offer for sale precise geolocation data concerning a consumer. [...] Controllers shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: [...]

Virginia Consumer Data Protection Act, § 59.1-578Read the full section from Virginia Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit