Skip to content

What You Need to Know About Virginia’s New Data Privacy Law

On Behalf of Berenzweig Leonard, LLP | December 2, 2022 | M&A and Corporate

The Virginia Consumer Data Protection Act (VCDPA) goes into effect on January 1, 2023 but covered entities should begin preparing now to work toward compliance. Below is an overview of the key aspects that businesses should be aware of.

Who does it apply to?

The VCDPA applies to entities that conduct business in Virginia or produce products or services that target Virginia residents and that either:

(i) Control or process personal data of at least 100,000 consumers during a calendar year.

(ii) Control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.

Exclusions. The VCDPA does not apply to certain entities, including the following:

  • Government entities
  • Financial institutions or data governed by the Gramm-Leach-Bliley Act (GLBA)
  • Higher education institutions
  • Nonprofits
  • Covered entities or business associates governed by HIPAA

Who and what type of data does it protect?

The VCDPA protects consumers and their personal data. “Consumers” are defined as Virginia residents acting in an individual or household context. “Personal data” is defined to mean information that is linked or reasonably linkable to an identified or identifiable individual but does not include data that is de-identified or publicly available.

It is important to note that businesses and employers are not considered consumers under the VCDPA, which means that the VCDPA does not apply to data that is collected in a business-to-business or employment context.

What does it do?

Consumer Rights. Under the VCDPA, consumers have the following rights:

  • Right to Know
  • Right to Access
  • Right to Correct
  • Right to Delete
  • Right to Data Portability
  • Right to Opt Out

Additionally, the VCDPA prohibits businesses from discriminating or retaliating against a consumer for exercising these rights.

Limited Collection. The VCDPA limits the collection and use of personal data to what is adequate, relevant, and reasonably necessary for the purpose for which the data is processed.

Security Measures and AssessmentsCovered businesses are required to establish, implement, and maintain “reasonable” security measures to protect consumers’ personal data. A business must consider its size, revenue, and the type of data it processes to determine what is reasonable.

Controllers must also conduct and document periodic data protection assessments for certain processing activities, including processing sensitive data, targeted advertising, selling of personal data, profiling, and other activities of heightened risk to consumers.

Privacy Notices. Covered businesses must provide consumers with an accessible, clear, and meaningful privacy notice that informs consumers of the following:

  • categories of personal data that will be processed;
  • purpose of the processing;
  • their consumer rights under the VCDPA and how to exercise those rights, including how to appeal adverse decisions;
  • categories of personal data shared with third parties, if any; and
  • categories of third parties, if any, with whom the personal data is shared.

Data Processing Agreements. Controllers are required to enter into agreements with their processors and the VCDPA provides specific terms that must be included. Processors must adhere to controllers’ instructions and assist the controller in meeting the obligations under the VCDPA.

Who enforces it?

The Virginia Attorney General has exclusive authority to enforce the VCDPA and may impose a civil penalty of up to $7,500 per violation. The VCDPA provides businesses a right to cure, which allows businesses to correct any violation within 30 days of receiving notice from the Virginia Attorney General. The VCDPA does not provide a private right of action to consumers.

What should employers do to prepare?

To begin preparing, covered entities should start by assessing their obligations under the VCDPA. Other actions that employers should take include:

  • Data mapping to inventory what data is being collected to ensure compliance
  • Review policies to ensure adequate safety measures are in place to protect personal data
  • Review all agreements with third parties and vendors

Berenzweig Leonard will continue to monitor updates and developments related to new and existing data privacy laws. Please contact us if you have questions or concerns about whether the VCDPA applies to your business.

Aleksey House is an Associate at Berenzweig Leonard, LLP. She can be reached at ahouse@berenzweiglaw.com.