Virginia Consumer Data Protection Act (VCDPA)
The Virginia Consumer Data Protection Act (effective January 1, 2023) is a comprehensive consumer privacy law establishing rights for Virginia residents and obligations for businesses. It applies to persons conducting business in Virginia or producing products/services targeted to Virginia residents that control or process personal data of at least 100,000 consumers annually, or 25,000 consumers while deriving over 50% of gross revenue from sale of personal data.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Consumer Rights (§59.1-577)
| Code | Title |
|---|---|
| VCDPA-3 | Right to Access |
| VCDPA-4 | Right to Correct, Delete, and Port |
| VCDPA-5 | Right to Opt Out |
Controller Responsibilities (§59.1-578)
| Code | Title |
|---|---|
| VCDPA-6 | Data Minimization |
| VCDPA-7 | Privacy Notice |
| VCDPA-8 | Security Measures |
Data Protection Assessments (§59.1-580)
| Code | Title |
|---|---|
| VCDPA-10 | Sensitive Data Consent |
| VCDPA-9 | Assessment Requirements |
Definitions and Applicability (§59.1-575–576)
| Code | Title |
|---|---|
| VCDPA-1 | Definitions (§59.1-575) |
| VCDPA-2 | Applicability (§59.1-576) |
Enforcement (§59.1-584–585)
| Code | Title |
|---|---|
| VCDPA-11 | AG Enforcement Authority (§59.1-584) |
| VCDPA-12 | Penalties |
Maps to 509 other frameworks
Frequently Asked Questions
What is Virginia Consumer Data Protection Act (VCDPA)?
Virginia Consumer Data Protection Act (VCDPA) is a compliance framework from United States — Virginia with 5 domains and 12 controls. The Virginia Consumer Data Protection Act (effective January 1, 2023) is a comprehensive consumer privacy law establishing rights for Virginia residents and obligations for businesses. It applies to persons conducting business in Virginia or producing products/services targeted to Virginia residents that control or process personal data of at least 100,000 consumers annually, or 25,000 consumers while deriving over 50% of gross revenue from sale of personal data. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Virginia Consumer Data Protection Act (VCDPA) have?
Virginia Consumer Data Protection Act (VCDPA) has 12 controls organised across 5 domains. The largest domains are Consumer Rights (§59.1-577) (3 controls), Controller Responsibilities (§59.1-578) (3 controls), Data Protection Assessments (§59.1-580) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Virginia Consumer Data Protection Act (VCDPA) map to?
Virginia Consumer Data Protection Act (VCDPA) maps to 509 other compliance frameworks. The top mapping partners are ILO Nursing Personnel Convention C149 (1977) (33% coverage), EU Anti-Money Laundering Directive (AMLD6 / Directive 2018/1673) (33% coverage), ISO 8000 — Data Quality (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Virginia Consumer Data Protection Act (VCDPA) compliance?
Start your Virginia Consumer Data Protection Act (VCDPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Virginia Consumer Data Protection Act (VCDPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 12 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required