VCDPA § 59.1-580
Data protection assessments
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- January 1, 2023
- Last reviewed
- September 2026
- Framework
- VCDPA
What it requires
Requires controllers to conduct and document data protection assessments for high-risk activities, including processing for targeted advertising, selling personal data, processing sensitive data, and profiling that poses a foreseeable risk of harm. Assessments must weigh processing benefits against consumer risks.
Statute text
A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data: 1. The processing of personal data for purposes of targeted advertising; 2. The sale of personal data; 3. The processing of personal data for purposes of profiling...
Virginia Consumer Data Protection Act, § 59.1-580Read the full section from Virginia Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.