close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Virginia Privacy Law

VA

Virginia (VCDPA)

Last updated

VCDPA Enacted, in effect

Who this affects: This page tracks Virginia’s VCDPA, which governs controllers and processors.

Who it applies to: Persons that do business in Virginia or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 1, 2023
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

VCDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Answer access, correction, deletion and opt-out requests within 45 days; extend once by 45 days only when reasonably necessary. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-577 “A controller shall respond to the consumer without undue delay, but in all cases within 45 days of receipt of the request” Read the statute VA-59.1-577 “The response period may be extended once by 45 additional days when reasonably necessary, taking into account the complexity and number of the consumer's requests, so long as the controller informs the consumer of any such extension within the initial 45-day response period, together with the reason for the extension.” Read the statute VA-59.1-577 “To confirm whether or not a controller is processing the consumer's personal data and to access such personal data” Read the statute VA-59.1-577 “To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data” Read the statute VA-59.1-577 “To delete personal data provided by or obtained about the consumer” Read the statute VA-59.1-577 “To opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.” Read the statute
  • Offer an appeal process for refused requests, answer appeals in writing within 60 days, and point denied appellants to the AG. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-577 “A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time” Read the statute VA-59.1-577 “Within 60 days of receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal” Read the statute VA-59.1-577 “If the appeal is denied, the controller shall also provide the consumer with an online mechanism, if available, or other method through which the consumer may contact the Attorney General to submit a complaint.” Read the statute
  • Sign a binding contract with each processor setting out instructions, purpose, data type, duration and both parties' obligations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-579 “A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.” Read the statute

Can't

  • Process sensitive data without the consumer's consent, or a known child's sensitive data other than in accordance with COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-578 “Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.)” Read the statute
  • Sell or offer for sale precise geolocation data, or require consumers to create a new account to exercise their rights. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-578 “Not sell or offer for sale precise geolocation data concerning a consumer” Read the statute VA-59.1-578 “Controllers shall not require a consumer to create a new account in order to exercise consumer rights pursuant to § 59.1-577” Read the statute
  • Process a known child's personal data for targeted advertising, sale or significant-decision profiling without parental consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-578 “no controller shall process any personal data collected from a known child: a. For the purposes of (i) targeted advertising, (ii) the sale of such personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer; b. Unless such processing is reasonably necessary to provide the online service, product, or feature; c. For any processing purpose other than the processing purpose that the controller disclosed at the time such controller collected such personal data or that is reasonably necessary for and compatible with such disclosed purpose; or d. For longer than is reasonably necessary to provide the online service, product, or feature.” Read the statute VA-59.1-578 “No controller shall engage in the activities described in subdivisions 1 or 2 unless the controller obtains consent from the child's parent or legal guardian” Read the statute

Should

  • Document data protection assessments for covered processing and child-directed services, ready to hand to the Attorney General. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-580 “A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data” Read the statute VA-59.1-580 “Each controller that offers any online service, product, or feature directed to consumers whom such controller has actual knowledge are children shall conduct a data protection assessment for such online service, product, or feature that addresses (i) the purpose of such online service, product, or feature; (ii) the categories of known children's personal data that such online service, product, or feature processes; and (iii) the purposes for which such controller processes known children's personal data with respect to such online service, product, or feature.” Read the statute VA-59.1-580 “the controller shall make the data protection assessment available to the Attorney General” Read the statute
  • Use your privacy notice to describe secure request channels and clearly disclose any sale or targeted ads and how to opt out. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-578 “A controller shall establish, and shall describe in a privacy notice, one or more secure and reliable means for consumers to submit a request to exercise their consumer rights under this chapter” Read the statute VA-59.1-578 “the controller shall clearly and conspicuously disclose such processing, as well as the manner in which a consumer may exercise the right to opt out of such processing” Read the statute VA-59.1-577 “To opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.” Read the statute
  • Track request counts per consumer, since responses must be free of charge up to twice annually for each consumer. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. VA-59.1-577 “Information provided in response to a consumer request shall be provided by a controller free of charge, up to twice annually per consumer” Read the statute

These are the highlights we judge most important, not everything VCDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Virginia Consumer Data Protection Act

VCDPA (SB 1392) is Virginia’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
2021 Va. Acts Sp. Sess. I, ch. 35 (HB 2307; identical companion of SB 1392, ch. 36) (uncodified enactment clauses) Archived excerpt — the text we read …r 1, 2021. 3. That any reference to federal law or statute in this act shall be deemed to include any accompanying rules or regulations or exemptions thereto. Further, this enactment is declaratory of existing law. 4. That the provisions of the first and third enactments of this act shall become effective on January 1, 2023. Archived from source — captured 2026-08-14 · snapshot 1fc9cc46 Verify at the source
Effective
January 1, 2023
2021 Va. Acts Sp. Sess. I, ch. 35 (HB 2307; identical companion of SB 1392, ch. 36) (uncodified enactment clauses) Archived excerpt — the text we read …2021. 3. That any reference to federal law or statute in this act shall be deemed to include any accompanying rules or regulations or exemptions thereto. Further, this enactment is declaratory of existing law. 4. That the provisions of the first and third enactments of this act shall become effective on January 1, 2023. Archived from source — captured 2026-08-14 · snapshot 1fc9cc46 Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Signed
March 2, 2021
2021 Va. Acts Sp. Sess. I, ch. 35 (HB 2307; identical companion of SB 1392, ch. 36) (approval line) Archived excerpt — the text we read …nt version CHAPTER 35 An Act to amend the Code of Virginia by adding in Title 59.1 a chapter numbered 52, consisting of sections numbered 59.1-571 through 59.1-581, relating to Consumer Data Protection Act. [H 2307] Approved March 2, 2021 Be it enacted by the General Assembly of Virginia: 1. That the Code of Virginia is amended by adding in Title 59.1 a chapter numbered 52, consisting of sections numbered 59.1-571 through 59.1-581, as follows: CHAPTER… Archived from source — captured 2026-08-14 · snapshot 1fc9cc46 Verify at the source

Corroborated by Legislative record

Enforced by
Attorney General
Archived excerpt — the text we read § 59.1-584. Enforcement; civil penalty; expenses. A. The Attorney General shall have exclusive authority to enforce the provisions of this chapter. B. Prior to initiating any action under this chapter, the Attorney General shall provide a controller or processor 30 days' written notice identifying the specific provisions of this chapter the Attorney General allege… Archived from source — captured 2026-08-14 · snapshot 4481f6ec Verify at the source
Maximum penalty per violation
$7,500
Enforced only by the AG after the 30-day cure period; the AG may also recover fees and seek an injunction. “may seek an injunction to restrain any violations of this chapter and civil penalties of up to $7,500 for each violation under this chapter” View the statute
Right to cure
30 days
The cure requires a written statement to the AG that violations are cured and will not recur. Archived excerpt — the text we read § 59.1-584. Enforcement; civil penalty; expenses. A. The Attorney General shall have exclusive authority to enforce the provisions of this chapter. B. Prior to initiating any action under this chapter, the Attorney General shall provide a controller or processor 30 days' written notice identifying the specific provisions of this chapter the Attorney General alleges have been or are being violated. If within the 30-day period the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action shall be initiated against the controller or processor. C. If a controller or processor continues to violate this chapter following the cure period in subsection B or breaches an express written statement provided to the Attorney General under that subsection, the Attorney … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …, and Enforcement Revolving Trust Fund. D. The Attorney General may recover reasonable expenses incurred in investigating and preparing the case, including attorney fees, in any action initiated under this chapter. E. Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter or under any other law. 2021, Sp. Sess. I, cc. 35, 36; 2022, cc. 451, 452. Archived from source — captured 2026-08-14 · snapshot 4481f6ec Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Universal opt-out signal
Not required

Corroborated by Privacy-law tracker

Who it applies to

Persons that do business in Virginia or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data

What the law gives consumers

  • Right to access A known child's parent or legal guardian may invoke these rights on the child's behalf (59.1-577(A)). Archived excerpt — the text we read …uardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the known child. A controller shall comply with an authenticated consumer request to exercise the right: 1. To confirm whether or not a controller is processing the consumer's personal data and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to correct Archived excerpt — the text we read … child. A controller shall comply with an authenticated consumer request to exercise the right: 1. To confirm whether or not a controller is processing the consumer's personal data and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent tech… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to delete For data obtained from another source, the controller may keep a record of the deletion request and minimal data to keep it deleted, or opt the consumer out of non-exempt processing (59.1-577(B)(5)). Archived excerpt — the text we read … and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to tran… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to data portability (limited) Only data the consumer previously provided, and only where the processing is carried out by automated means. Archived excerpt — the text we read …nsumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5. To opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly signifi… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …table and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5. To opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. B. Except as otherwise provided in this chapter, a controller shall comply with a request by a consumer to exercise the consumer rights authorized pursuant to subsection A as follows: 1. A controller shall respond to … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …table and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5. To opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. B. Except as otherwise provided in this chapter, a controller shall comply with a request by a consumer to exercise the consumer rights authorized pursuant to subsection A as follows: 1. A controller shall respond to … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …table and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5. To opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. B. Except as otherwise provided in this chapter, a controller shall comply with a request by a consumer to exercise the consumer rights authorized pursuant to subsection A as follows: 1. A controller shall respond to … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read … consumer has exercised his right to opt out pursuant to § 59.1-577 or the offer is related to a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program; 5. Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.); and 6. Not… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right to appeal Archived excerpt — the text we read … other purpose pursuant to the provisions of this chapter or (ii) opting the consumer out of the processing of such personal data for any purpose except for those exempted pursuant to the provisions of this chapter. C. A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision pursuant to subdivision B 2. The appeal process shall be conspicuously available and similar to the process for submitting requests to initiate action pursuant to subsection A. Within 60 days of receipt of an appeal, a … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Right against discrimination Archived excerpt — the text we read …curity practices shall be appropriate to the volume and nature of the personal data at issue; 4. Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer. However, nothing in this subdivision shall be construed to require a controller to provide a product or service that requires the persona… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …, and Enforcement Revolving Trust Fund. D. The Attorney General may recover reasonable expenses incurred in investigating and preparing the case, including attorney fees, in any action initiated under this chapter. E. Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter or under any other law. 2021, Sp. Sess. I, cc. 35, 36; 2022, cc. 451, 452. Archived from source — captured 2026-08-14 · snapshot 4481f6ec Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …ive action. "Consumer" means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context. "Controller" means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing personal data. "Covered entity" means the same as the term is established by HIPAA. "Decisions that produce legal or similarly significant effects concerning a consumer" means a decision made by the controller that results in the pr… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Processors Archived excerpt — the text we read …r set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. "Processor" means a natural or legal entity that processes personal data on behalf of a controller. "Profiling" means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person's economic situation, health, pers… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source

Exemptions

  • State and local government agencies Archived excerpt — the text we read …of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. B. This chapter shall not apply to any (i) body, authority, board, bureau, commission, district, or agency of the Commonwealth or of any political subdivision of the Commonwealth; (ii) financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.); (iii) covered entity or business associate governed by the privacy, security, and breach notificat… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • GLBA: financial institutions and data subject to Title V Entity- and data-level Archived excerpt — the text we read …e from the sale of personal data. B. This chapter shall not apply to any (i) body, authority, board, bureau, commission, district, or agency of the Commonwealth or of any political subdivision of the Commonwealth; (ii) financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.); (iii) covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant t… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • HIPAA covered entities and business associates Archived excerpt — the text we read … district, or agency of the Commonwealth or of any political subdivision of the Commonwealth; (ii) financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.); (iii) covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the Health Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Nonprofit organizations Archived excerpt — the text we read … rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the Health Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1. Protected health information under HIPAA; 2. Health records for purposes of Title 32.1; 3. Patient ident… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Institutions of higher education Archived excerpt — the text we read …tment of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the Health Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1. Protected health information under HIPAA; 2. Health records for purposes of Title 32.1; 3. Patient identifying information for purposes of 42 U.… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Protected health information under HIPAA Archived excerpt — the text we read …alth Information Technology for Economic and Clinical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1. Protected health information under HIPAA; 2. Health records for purposes of Title 32.1; 3. Patient identifying information for purposes of 42 U.S.C. § 290dd-2; 4. Identifiable private information for purposes of the federal policy for the protection of huma… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Health records under Title 32.1 Archived excerpt — the text we read …linical Health Act (P.L. 111-5); (iv) nonprofit organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1. Protected health information under HIPAA; 2. Health records for purposes of Title 32.1; 3. Patient identifying information for purposes of 42 U.S.C. § 290dd-2; 4. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; identifiabl… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Patient identifying information under 42 U.S.C. 290dd-2 Archived excerpt — the text we read … organization; or (v) institution of higher education. C. The following information and data is exempt from this chapter: 1. Protected health information under HIPAA; 2. Health records for purposes of Title 32.1; 3. Patient identifying information for purposes of 42 U.S.C. § 290dd-2; 4. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; identifiable private information that is otherwise information collected as part of … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Human subjects research information Archived excerpt — the text we read …information and data is exempt from this chapter: 1. Protected health information under HIPAA; 2. Health records for purposes of Title 32.1; 3. Patient identifying information for purposes of 42 U.S.C. § 290dd-2; 4. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by The International Council for Harmonisation of Tec… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read …nder 21 C.F.R. Parts 6, 50, and 56, or personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in accordance with applicable law; 5. Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. § 11101 et seq.); 6. Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act (42 U.S.C. § 299b-21 et seq.); 7. Information derived from any of the health care-related information listed in th… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Patient Safety and Quality Improvement Act work product Archived excerpt — the text we read …this chapter, or other research conducted in accordance with applicable law; 5. Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. § 11101 et seq.); 6. Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act (42 U.S.C. § 299b-21 et seq.); 7. Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; 8. Information origi… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • De-identified health-related information Archived excerpt — the text we read … federal Health Care Quality Improvement Act of 1986 (42 U.S.C. § 11101 et seq.); 6. Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act (42 U.S.C. § 299b-21 et seq.); 7. Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; 8. Information originating from, and intermingled to be indistinguishable with, or information treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Information intermingled with exempt health information When maintained by a HIPAA covered entity/business associate or a 42 U.S.C. § 290dd-2 program/qualified service organization. Archived excerpt — the text we read … 299b-21 et seq.); 7. Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; 8. Information originating from, and intermingled to be indistinguishable with, or information treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business associate as defined by HIPAA or a program or a qualified service organization as defined by 42 U.S.C. § 290dd-2; 9. Information used only for public health activities and purposes as authorized by HIPAA; 10. The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • HIPAA public health activities information Archived excerpt — the text we read …manner as information exempt under this subsection that is maintained by a covered entity or business associate as defined by HIPAA or a program or a qualified service organization as defined by 42 U.S.C. § 290dd-2; 9. Information used only for public health activities and purposes as authorized by HIPAA; 10. The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …business associate as defined by HIPAA or a program or a qualified service organization as defined by 42 U.S.C. § 290dd-2; 9. Information used only for public health activities and purposes as authorized by HIPAA; 10. The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency or furnisher that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.); 11. Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. § 2721 et seq.); 12. Personal data regulated by the federal Family Educatio… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …ion for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.); 11. Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. § 2721 et seq.); 12. Personal data regulated by the federal Family Educational Rights and Privacy Act (20 U.S.C. § 1232g et seq.); 13. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …l Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.); 11. Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. § 2721 et seq.); 12. Personal data regulated by the federal Family Educational Rights and Privacy Act (20 U.S.C. § 1232g et seq.); 13. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act (12 U.S.C. § 2001 et seq.); and 14. Data processed or maintained (i) in the course of an individual applying t… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read … in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. § 2721 et seq.); 12. Personal data regulated by the federal Family Educational Rights and Privacy Act (20 U.S.C. § 1232g et seq.); 13. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act (12 U.S.C. § 2001 et seq.); and 14. Data processed or maintained (i) in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Employment data Archived excerpt — the text we read …d Privacy Act (20 U.S.C. § 1232g et seq.); 13. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act (12 U.S.C. § 2001 et seq.); and 14. Data processed or maintained (i) in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; (ii) as the emergency contact information of an individual under this chapter used for emergency contact purposes; or (iii) that is necessary to retain to administer benefits for another individual relating to the indi… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Emergency contact information Archived excerpt — the text we read …an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; (ii) as the emergency contact information of an individual under this chapter used for emergency contact purposes; or (iii) that is necessary to retain to administer benefits for another individual relating to the individual under clause (i) and used for the purposes of administering those benefits. D. Controllers and processors t… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Benefits administration data Archived excerpt — the text we read …third party, to the extent that the data is collected and used within the context of that role; (ii) as the emergency contact information of an individual under this chapter used for emergency contact purposes; or (iii) that is necessary to retain to administer benefits for another individual relating to the individual under clause (i) and used for the purposes of administering those benefits. D. Controllers and processors that comply with the verifiable parental consent requirements of the Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.) shall be deemed compliant with any obligation to o… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Human subjects research data Human subjects research data under ICH good clinical practice guidelines or 21 C.F.R. Parts 6, 50 and 56. Archived excerpt — the text we read … Title 32.1; 3. Patient identifying information for purposes of 42 U.S.C. § 290dd-2; 4. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use; the protection of human subjects under 21 C.F.R. Parts 6, 50, and 56, or personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in accordance with applicable law; 5. Information and documents created … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Personal data used or shared in research conducted under this chapter or other applicable law Archived excerpt — the text we read …od clinical practice guidelines issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use; the protection of human subjects under 21 C.F.R. Parts 6, 50, and 56, or personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in accordance with applicable law; 5. Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. § 11101 et seq.); 6. Patient safety work product for purposes of the federal Patient Safety and … Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Evidentiary privilege (compliance would violate a Virginia evidentiary privilege) Archived excerpt — the text we read …roller or are otherwise compatible with processing data in furtherance of the provision of a product or service specifically requested by a consumer or the performance of a contract to which the consumer is a party. C. The obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with this chapter would violate an evidentiary privilege under the laws of the Commonwealth. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of the Commonwealth as p… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read …ation imposed on controllers and processors that adversely affects the rights or freedoms of any persons, such as exercising the right of free speech pursuant to the First Amendment to the United States Constitution, or applies to the processing of personal data by a person in the course of a purely personal or household activity. F. Personal data processed by a controller pursuant to this section shall not be processed for any purpose other than those expressly listed in this section unless otherwise allowed by this chapter. Personal data proc… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …ations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with this chapter would violate an evidentiary privilege under the laws of the Commonwealth. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of the Commonwealth as part of a privileged communication. D. A controller or processor that discloses personal data to a third-party controller or processor, in compliance with the requirements of this chapter, is not in violation of this chapter if the third-party controller… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source
  • Rights and freedoms of others, including free speech Archived excerpt — the text we read …ntroller or processor in compliance with the requirements of this chapter is likewise not in violation of this chapter for the transgressions of the controller or processor from which it receives such personal data. E. Nothing in this chapter shall be construed as an obligation imposed on controllers and processors that adversely affects the rights or freedoms of any persons, such as exercising the right of free speech pursuant to the First Amendment to the United States Constitution, or applies to the processing of personal data by a person in the course of a purely personal or household activity. F. Personal data processed by a controller pursuant to this section shall not be processed for any pu… Archived from source — captured 2026-09-22 · snapshot 95a1401e Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

VCDPA milestones

Drag the handle or use ← → to step through the milestones. The marker shows where today falls.

Done Upcoming Today
You are here
Completed January 1, 2026

Social media platform duties toward minors took effect (59.1-577.1)

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026