Solutions / By Regulation

Virginia CDPA compliance, simplified.

Stand up consent, sensitive data opt-ins, DPIAs, and consumer rights workflows tailored to Virginia's CDPA — and reuse them across every other US state law.

VA CDPA at a glance
$7,500
max civil penalty per violation
100K
VA consumers triggers applicability
45 days
to respond to a consumer rights request
30 days
right-to-cure notice from the AG

What is VA CDPA?

Overview

The VA CDPA, effective January 1, 2023, was the second comprehensive US state privacy law. It applies to entities that conduct business in Virginia and meet specific thresholds, granting consumers rights to access, correct, delete, port, and opt out of targeted advertising, sale of personal data, and certain profiling. The Virginia Attorney General has exclusive enforcement authority.

Who must comply

Typical applicability thresholds

  • Process PI of 100,000+ VA consumers in a year, or
  • Process PI of 25,000+ VA consumers and derive 50%+ of revenue from sale of PI
  • Excludes governmental bodies, GLBA & HIPAA-covered entities, and non-profits
  • B2B and employee data are largely out of scope

Key requirements

What VA CDPA expects from your organization.

Consumer rights

Provide rights to access, correct, delete, obtain a portable copy, and opt out of targeted ads, sale, and profiling with legal/significant effects.

Opt-in for sensitive data

Obtain consent before processing sensitive data including racial/ethnic origin, religion, health, sexual orientation, citizenship, biometric, precise geo, and children's data.

Data Protection Assessments

Conduct DPAs for targeted advertising, sale of PI, sensitive data processing, profiling with risk of harm, and other heightened-risk activities.

Privacy notice

Publish a clear notice describing categories processed, purposes, sharing, and how consumers may exercise their rights and appeal denials.

Contracts with processors

Bind processors with contracts specifying instructions, confidentiality, security, sub-processors, and audit rights.

Appeals process

Establish an appeals mechanism for consumers whose rights requests are denied, with response within 60 days.

Penalties & enforcement

What's at stake

The Virginia AG has exclusive enforcement authority. Civil penalties of up to $7,500 per violation, plus attorney's fees and investigative costs. Businesses receive a 30-day right to cure before enforcement action — but only if cure is possible.

How Clarip helps

Operationalize VA CDPA on one platform.

Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for VA CDPA.

Consent & opt-out

  • Sensitive data opt-in flows
  • Targeted ad / sale opt-out
  • Universal opt-out signal handling

Consumer rights

  • Self-service VA rights portal
  • Identity verification
  • Built-in appeals workflow

Data mapping

  • Auto-classify sensitive data
  • ROPA tailored to CDPA
  • Processor inventory & contracts

Data Protection Assessments

  • CDPA DPA templates
  • Risk balancing & mitigation
  • Versioned, audit-ready evidence

Notice & policy

  • Privacy notice generator
  • Change tracking & approvals
  • Multi-state policy harmonization

Multi-state reuse

  • Map controls across CCPA, CO, CT, UT
  • One DSR engine for all states
  • Single ROPA, many regulators
FAQ

VA CDPA compliance, answered.

Quick answers to the questions privacy, legal, and engineering teams most often ask about VA CDPA.

The VA CDPA took effect on January 1, 2023, making Virginia the second US state with a comprehensive consumer privacy law after California.

Persons that conduct business in Virginia or produce products/services targeted to Virginia residents, and that during a calendar year either: (1) control or process personal data of 100,000+ Virginia consumers, or (2) control or process personal data of 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.

No. The CDPA defines 'consumer' as a Virginia resident acting in an individual or household context, explicitly excluding individuals acting in a commercial or employment context.

Sensitive data includes racial/ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship/immigration status, genetic or biometric data processed to identify a person, precise geolocation, and personal data of a known child. Processing requires opt-in consent.

No. The Virginia Attorney General has exclusive enforcement authority. There is no private right of action for consumers.

Clarip provides sensitive data opt-in flows, a Virginia-specific consumer rights portal with built-in appeals, automated Data Protection Assessment workflows, processor contract management, and a unified data map you can reuse across every other US state privacy law.

Get VA CDPA-ready with Clarip.

Book a 30-minute walkthrough and a custom gap assessment against VA CDPArequirements — mapped to the systems and vendors you already use.