Virginia CDPA
Virginia Consumer Data Protection Act
Virginia CDPA is a compliance framework from United States - Virginia with 12 domains and 35 controls that map to 138 other frameworks. The largest domains are VCDPA 59.1-578: Controller Duties (9 controls), VCDPA 59.1-577: Consumer Rights (8 controls), VCDPA 59.1-579 to 580: Data Protection Assessments and Processors (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Enforcement
| Code | Title |
|---|---|
| VIRGINIAVCDPA-6 | AG Enforcement, Cure, Penalties |
Notice and DPIA
| Code | Title |
|---|---|
| VIRGINIAVCDPA-4 | Privacy Notice and DPIA |
Processor
| Code | Title |
|---|---|
| VIRGINIAVCDPA-5 | Processor Contracts and Vendor Management |
Rights
| Code | Title |
|---|---|
| VIRGINIAVCDPA-2 | Consumer Rights |
Scope
| Code | Title |
|---|---|
| VIRGINIAVCDPA-1 | Scope, Applicability, Definitions |
Sensitive
| Code | Title |
|---|---|
| VIRGINIAVCDPA-3 | Sensitive Data Consent and Children |
VCDPA 59.1-575 to 576: Definitions, Scope and Exemptions
| Code | Title |
|---|---|
| VCDPA-59-1-575-DEF | Controller and Processor Definitions |
| VCDPA-59-1-576 | Applicability Threshold for Controllers |
| VCDPA-59-1-576-EXEMPT | Entity and Data Level Exemptions |
VCDPA 59.1-577: Consumer Rights
| Code | Title |
|---|---|
| VCDPA-59-1-577-A1 | Consumer Right to Confirm and Access Personal Data |
| VCDPA-59-1-577-A2 | Right to Correct Inaccurate Personal Data |
| VCDPA-59-1-577-A3 | Right to Delete Personal Data |
| VCDPA-59-1-577-A4 | Right to Data Portability |
| VCDPA-59-1-577-A5-PROFILE | Right to Opt Out of Profiling with Legal or Similarly Significant Effects |
| VCDPA-59-1-577-A5-SALE | Right to Opt Out of Sale of Personal Data |
| VCDPA-59-1-577-A5-TARGETED | Right to Opt Out of Targeted Advertising |
| VCDPA-59-1-577-AUTH-AGENT | Authorized Agent Requests |
VCDPA 59.1-578: Controller Duties
| Code | Title |
|---|---|
| VCDPA-59-1-578-APPEAL | Consumer Appeal Process |
| VCDPA-59-1-578-CHILD | Children Data Processing Alignment with COPPA |
| VCDPA-59-1-578-NONDISCRIM | Nondiscrimination for Rights Exercise |
| VCDPA-59-1-578-OPTOUT-DISCLOSURE | Disclosure of Sale and Targeted Advertising Activities |
| VCDPA-59-1-578-PRIVACYNOTICE | Privacy Notice Content Requirements |
| VCDPA-59-1-578-PURPOSELIMIT | Purpose Limitation and Data Minimization |
| VCDPA-59-1-578-RESPONSE | Response Timing and Authentication |
| VCDPA-59-1-578-SECURITY | Reasonable Data Security Practices |
| VCDPA-59-1-578-SENSITIVE-OPTIN | Sensitive Data Opt In Consent |
VCDPA 59.1-579 to 580: Data Protection Assessments and Processors
| Code | Title |
|---|---|
| VCDPA-59-1-579-DPA | Data Protection Assessment Requirement |
| VCDPA-59-1-579-PROCESSOR-CONTRACT | Processor Contract Required Elements |
| VCDPA-59-1-579-PROCESSOR-DUTIES | Processor Duties to Assist Controller |
| VCDPA-59-1-580-DPA-CONTENT | Data Protection Assessment Content and Confidentiality |
VCDPA 59.1-581 to 582: De-identified Data and Exceptions
| Code | Title |
|---|---|
| VCDPA-59-1-581-DEIDENT | Deidentified Data Standards |
| VCDPA-59-1-581-PSEUDONYMOUS | Pseudonymous Data Carve Out |
| VCDPA-59-1-582-RESEARCH | Research Data Exception |
VCDPA 59.1-583 to 584: Enforcement
| Code | Title |
|---|---|
| VCDPA-59-1-583-CURE-SUNSET | 30 Day Cure Period and 2025 Sunset |
| VCDPA-59-1-584-ENFORCEMENT | Attorney General Exclusive Enforcement |
Your Compliance Coverage
If you comply with Virginia CDPA, you already cover:
Barbados Data Protection Act 2019
11%
4 controls mapped
Compare →South Korea ISMS-P
11%
4 controls mapped
Compare →GDPR
11%
4 controls mapped
Compare →+ 135 more: Saudi Arabia PDPL (11%), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) (11%)
See all 138 mapped frameworks ↓Maps to 138 other frameworks
What is Virginia CDPA and who does it apply to?
Virginia CDPA is a compliance framework from United States - Virginia with 12 domains and 35 controls. Virginia Consumer Data Protection Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Virginia CDPA actually require?
Virginia CDPA has 35 controls organised across 12 domains. The largest domains are VCDPA 59.1-578: Controller Duties (9 controls), VCDPA 59.1-577: Consumer Rights (8 controls), VCDPA 59.1-579 to 580: Data Protection Assessments and Processors (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Virginia CDPA do I already cover?
Virginia CDPA maps to 138 other compliance frameworks. The top mapping partners are Barbados Data Protection Act 2019 (11% coverage), South Korea ISMS-P (11% coverage), GDPR (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Virginia CDPA?
Start your Virginia CDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Virginia CDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required