VCDPA § 59.1-580

Data protection assessments

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
January 1, 2023
Last reviewed
September 2026
Framework
VCDPA

What it requires

Requires controllers to conduct and document data protection assessments for high-risk activities, including processing for targeted advertising, selling personal data, processing sensitive data, and profiling that poses a foreseeable risk of harm. Assessments must weigh processing benefits against consumer risks.

Statute text

A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data: 1. The processing of personal data for purposes of targeted advertising; 2. The sale of personal data; 3. The processing of personal data for purposes of profiling...

Virginia Consumer Data Protection Act, § 59.1-580Read the full section from Virginia Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit