Privacy
Virginia Consumer Data Protection Act
The law applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and that, during a calendar year, control or process personal data of at least 100,000 consumers. It also applies to persons that control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. It does not apply to state agencies and political subdivisions, financial institutions or data subject to the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofit organizations, or institutions of higher education.
What the website needs
- A covered controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purposes of processing, how consumers can exercise their rights and appeal a decision, the categories of personal data shared with third parties, and the categories of third parties that receive personal data.
- A controller that sells personal data or processes it for targeted advertising must clearly and conspicuously disclose that processing and explain how a consumer can opt out of it.
- A controller must establish one or more secure and reliable means for consumers to submit rights requests, must describe those means in the privacy notice, and may not require a consumer to create a new account to make a request.
- A controller may not process a consumer's sensitive data without the consumer's consent, and data about a known child must be processed in accordance with the federal Children's Online Privacy Protection Act.


