Back to Blog

Virginia's Privacy Law Applies Differently Than California's — Here's the Real Difference

July 29, 2026 2 min readBy Regulens Team

If you've already checked your store against California's privacy law, it's tempting to assume Virginia works the same way, just with different numbers. It doesn't. Virginia's Consumer Data Protection Act has no revenue threshold at all, and that single difference changes how you need to think about it.

Who VCDPA Actually Applies To

The Virginia Consumer Data Protection Act applies to businesses that control or process personal data for 100,000 or more Virginia consumers in a calendar year, or that control or process data for 25,000 or more Virginia consumers while deriving over 50% of gross revenue from the sale of personal data.

Notice what's missing from that sentence: any dollar figure tied to your total business revenue. A store doing $500,000 a year and a store doing $50 million a year face the exact same test under VCDPA. What matters is how many Virginia residents' data you're processing, not how much money you're making overall.

The Six Rights Virginia Grants

Virginia consumers can confirm whether their data is being processed and access it, correct inaccurate data, request deletion, obtain a portable copy of their data, and opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects.

If any of that sounds familiar, it should. Virginia's law was one of the earlier comprehensive privacy statutes, and much of the newer wave of state privacy laws, including Kentucky's and Indiana's, borrowed heavily from its structure.

Sensitive Data Needs Opt-In Consent

If your store collects sensitive categories of information, health data, precise geolocation, biometric identifiers, and similar categories, Virginia requires affirmative opt-in consent before you process it. This is a meaningfully higher bar than a simple opt-out link. The consumer has to say yes first.

Enforcement

The Virginia Attorney General holds exclusive enforcement authority. There is no private right of action, meaning individual consumers cannot sue your business directly under this law. Businesses get a 30-day cure period to fix a violation before facing enforcement action.

Why This Matters for Multi-State Sellers

If your store already tracks California exposure carefully but treats every other state as an afterthought, Virginia is exactly the kind of gap that slips through. A mid-sized store well under California's $25 million CCPA revenue threshold could still have real Virginia exposure purely based on Virginia consumer volume, something a revenue-only mental model would never catch.

Check Your Virginia Exposure

All information in this article is sourced from the Virginia Consumer Data Protection Act (Va. Code Ann. § 59.1-575 et seq.) and the Virginia Attorney General's published compliance guidance. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.

Regulens tracks Virginia as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.

Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.

Check your store's Virginia privacy readiness at getregulens.com

Check your store's readiness score — free.

Takes 3 minutes. Not legal advice.

Further Reading