What VCDPA actually requires
Virginia's comprehensive consumer privacy law, the second US state law of its kind after California. The VCDPA gives Virginia residents rights over their personal data and requires controllers to honour opt-out signals for targeted advertising, the sale of personal data, and certain profiling. Enforcement sits with the Virginia Attorney General.
Key requirements
- Provide a clear privacy notice covering the categories of data processed
- Honour consumer opt-outs of targeted advertising, sale of data, and certain profiling
- Respect Global Privacy Control browser signals
- Respond to access, correction, deletion and portability requests within 45 days
- Conduct data protection assessments for high-risk processing
- Sign processing agreements with vendors that handle personal data
At a glance
Full name
Virginia Consumer Data Protection Act
Region
Virginia, USA
Status
In force since January 2023
Who it affects
Businesses that control or process personal data of 100,000+ Virginia residents in a year, OR 25,000+ residents while deriving over 50% of revenue from selling personal data.
Penalties
Civil penalties up to USD 7,500 per violation, plus the AG's reasonable costs of enforcement. There is currently a 30-day right to cure violations.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
