Virginia privacy laws give residents enforceable rights over their personal data, set rules for how businesses must handle it, and separately govern data breaches, workplace monitoring, and the recording of conversations. The centerpiece is the Consumer Data Protection Act (VCDPA), which lets you see, correct, delete, and move the data companies hold about you and lets you opt out of certain uses like targeted advertising. Around it sit narrower statutes on breach notification, employer access to social media, and wiretapping, each with its own rules and penalties.
Your Rights Over Personal Data
If a covered business processes your personal data, you have five core rights under the VCDPA. You can confirm whether the business is processing your data and get a copy of it. You can ask for corrections to anything that is wrong. You can request deletion of data you provided or that the company collected from other sources. And you can obtain a portable copy in a commonly used digital format.1Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act
On top of those access-and-control rights, you can opt out of three specific uses: targeted advertising, the sale of your personal data to third parties, and profiling that produces legal or similarly significant effects in areas like credit, insurance, or employment.2Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act> Profiling that only personalizes a website’s look is not the same thing, so the opt-out reaches only automated decisions with real consequences for you.
How to Exercise Those Rights
You submit a request directly to the business. It has 45 days to respond. If the request is complex or the company is swamped with them, it can take another 45 days, but it must tell you about the delay and why. A denial has to come with a reason and instructions on how to appeal.1Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act
If your appeal is also denied, the business must give you a way to contact the Virginia Attorney General’s office to file a complaint. That is the escalation path built into the law: ask the business, appeal a denial, and if the appeal fails, take it to the AG.
Sensitive Data Requires Your Opt-In
Some categories of data get stronger treatment. A business cannot process what the VCDPA calls sensitive data unless you affirmatively opt in first. Sensitive data includes information revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify you, personal data from a known child, and precise geolocation.1Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act
The practical effect is a reversed default. For ordinary personal data like your name, email, or browsing history, the company can process it if it gives proper notice and you can opt out later. For sensitive data, it cannot process at all without your explicit permission upfront. A fitness app that wants your precise location or a health platform that logs a diagnosis needs your yes before it collects anything.
When the VCDPA Applies to a Business
These rights only kick in against businesses the law actually covers. The VCDPA reaches any company that does business in Virginia or targets its products and services to Virginia residents and meets one of two thresholds: it controls or processes personal data of at least 100,000 consumers during a calendar year, or it handles data of at least 25,000 consumers and earns more than 50 percent of its gross revenue from selling personal data.1Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act A small local business below both thresholds is not bound by the VCDPA’s consumer rights, though other Virginia laws may still apply to it.
Whole categories of organizations and data sit outside the law. Government bodies, nonprofits, and institutions of higher education are exempt. So is data already regulated under federal frameworks: health information covered by HIPAA, financial data under the Gramm-Leach-Bliley Act, and credit reporting data under the Fair Credit Reporting Act.1Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act A hospital’s patient records and a bank’s customer files are governed by those federal rules, not the VCDPA, even though both operate in Virginia.
Recording Conversations in Virginia
Virginia is a one-party consent state. Under Code of Virginia § 19.2-62, you can legally record any conversation you are part of, or any conversation where at least one participant has consented. This covers in-person conversations, phone calls, and electronic communications.3Virginia Code Commission. Code of Virginia 19.2-62 – Interception, Disclosure, Etc., of Wire, Electronic or Oral Communications Unlawful; Penalties; Exceptions
The line the statute draws is between participating and eavesdropping. Record a call you are on, fine. Plant a hidden device to capture a conversation you are not part of, without any participant’s consent, and that is a Class 6 felony.3Virginia Code Commission. Code of Virginia 19.2-62 – Interception, Disclosure, Etc., of Wire, Electronic or Oral Communications Unlawful; Penalties; Exceptions A Class 6 felony in Virginia carries one to five years in prison, or at the jury’s discretion, up to 12 months in jail and a fine of up to $2,500.
Privacy at Work
Under Code of Virginia § 40.1-28.7:5, a Virginia employer cannot require you or a job applicant to hand over usernames or passwords for personal social media accounts. It also cannot force you to add a supervisor or coworker to your contacts, change your privacy settings to grant employer access, or retaliate against you for saying no.
Company-owned devices and networks are a different world. Employers generally have broad authority to review emails, internet usage, and other activity on equipment they own and networks they run. The reasoning is that using corporate hardware or a corporate email system shrinks your reasonable expectation of privacy on those systems, and a written monitoring policy in an employee handbook shrinks it further. If your employer has told you in writing that it monitors company email, a court is unlikely to find you had a reasonable expectation of privacy in those messages.
At the federal level, the Electronic Communications Privacy Act bars employers from deliberately eavesdropping on purely personal conversations at work. It does not extend the same protection to business-related calls or to written electronic communications like email. The safer habit is to keep personal matters on personal devices and personal networks.
After a Data Breach
Separate from the VCDPA, Virginia’s breach notification law at Code of Virginia § 18.2-186.6 requires any individual or entity that owns or maintains personal information of Virginia residents to notify affected consumers and the Virginia Attorney General when an unauthorized person accesses unencrypted data in a way reasonably believed to cause identity theft or other fraud.4Office of the Attorney General of Virginia. Database Breach Notification Requirements The data types that trigger notification include Social Security numbers, driver’s license numbers, and financial account numbers combined with any required access codes.
Notification has to happen without unreasonable delay. The notice you receive should describe the incident, identify the types of information compromised, and explain steps you can take to protect yourself, like placing a credit freeze or monitoring accounts. The FTC advises that breach notices also tell recipients how the company will contact them going forward, so you can spot phishing attempts pretending to be follow-up.5Federal Trade Commission. Data Breach Response: A Guide for Business
How the VCDPA Is Enforced
Only the Virginia Attorney General can enforce the VCDPA. There is no private right of action, so you cannot sue a business directly under this law for a privacy violation. Before filing an enforcement action, the AG must give the business written notice of the alleged violation and a 30-day window to cure it.1Virginia Code Commission. Code of Virginia Title 59.1 Chapter 53 – Consumer Data Protection Act If the business fixes the problem within those 30 days and sends the AG a written statement of the corrective measures, the matter ends.
If the business does not cure the violation, the AG can seek injunctive relief and civil penalties of up to $7,500 per violation. For a company processing millions of records, violations that touch many people can add up quickly. Virginia’s cure period does not sunset, which makes the law more forgiving of businesses than some other state privacy statutes that have phased their cure periods out. For consumers, that is the reason to keep records of every request, denial, and appeal: the AG’s office is the ultimate lever, and a documented paper trail is what makes a complaint actionable.