Virginia's Privacy Law Applies Differently Than California's — Here's the Real Difference
If you've already checked your store against California's privacy law, it's tempting to assume Virginia works the same way, just with different numbers. It doesn't. Virginia's Consumer Data Protection Act has no revenue threshold at all, and that single difference changes how you need to think about it.
Who VCDPA Actually Applies To
The Virginia Consumer Data Protection Act applies to businesses that control or process personal data for 100,000 or more Virginia consumers in a calendar year, or that control or process data for 25,000 or more Virginia consumers while deriving over 50% of gross revenue from the sale of personal data.
Notice what's missing from that sentence: any dollar figure tied to your total business revenue. A store doing $500,000 a year and a store doing $50 million a year face the exact same test under VCDPA. What matters is how many Virginia residents' data you're processing, not how much money you're making overall.
The Six Rights Virginia Grants
Virginia consumers can confirm whether their data is being processed and access it, correct inaccurate data, request deletion, obtain a portable copy of their data, and opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects.
If any of that sounds familiar, it should. Virginia's law was one of the earlier comprehensive privacy statutes, and much of the newer wave of state privacy laws, including Kentucky's and Indiana's, borrowed heavily from its structure.
Sensitive Data Needs Opt-In Consent
If your store collects sensitive categories of information, health data, precise geolocation, biometric identifiers, and similar categories, Virginia requires affirmative opt-in consent before you process it. This is a meaningfully higher bar than a simple opt-out link. The consumer has to say yes first.
Enforcement
The Virginia Attorney General holds exclusive enforcement authority. There is no private right of action, meaning individual consumers cannot sue your business directly under this law. Businesses get a 30-day cure period to fix a violation before facing enforcement action.
Why This Matters for Multi-State Sellers
If your store already tracks California exposure carefully but treats every other state as an afterthought, Virginia is exactly the kind of gap that slips through. A mid-sized store well under California's $25 million CCPA revenue threshold could still have real Virginia exposure purely based on Virginia consumer volume, something a revenue-only mental model would never catch.
Check Your Virginia Exposure
All information in this article is sourced from the Virginia Consumer Data Protection Act (Va. Code Ann. § 59.1-575 et seq.) and the Virginia Attorney General's published compliance guidance. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Virginia as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Check your store's Virginia privacy readiness at getregulens.com
Further Reading
Tennessee's Privacy Law Has an Escape Hatch No Other State Offers
Tennessee lets businesses build a legal defense into their compliance program itself. Here's how TIPA's threshold works, and the one framework that can protect you even if something goes wrong.
Minnesota's Privacy Law Gives Consumers a Right No Other State Grants
Minnesota lets consumers ask exactly which companies you sold their data to, by name. Most state privacy laws only require a general disclosure. Here's what that actually means for a Shopify store.