Virginia privacy laws: What marketers need to know about the VCDPA
Marketers need more than a legal summary of the Virginia Consumer Data Protection Act. Here's what VCDPA means for your ad targeting and measurement strategy.
Linnea Zielinski · 10 min read
Lending someone your car keys is usually a pretty low-stakes decision. You trust them to drive it, maybe run an errand, and bring it back. But you'd probably want a heads up before they let three other people take it for a spin too. That's roughly the deal with personal data these days. Consumers are fine handing some of it over, but they want to know where it's going next, and Virginia just made that expectation part of the law.
For marketing teams, how you build your audiences, what personal data you're allowed to act on, and how much you can trust your platform-reported numbers all depend on staying ahead of Virginia privacy laws, especially as more states pass their own versions.
Key takeaways
- The Virginia Consumer Data Protection Act (VCDPA) applies to businesses that process the personal data of at least 100,000 Virginia residents a year, or at least 25,000 residents if they also get more than half their gross revenue from selling personal data.
- Virginia residents can access, correct, delete, and request a portable copy of their personal data, plus opt out of targeted advertising, the sale of personal data, and certain profiling.
- Sensitive data, including racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, and biometric or genetic data, requires opt-in consent before a business can process it.
- Businesses have to conduct data protection assessments before engaging in higher-risk data processing, like targeted advertising, selling personal data, or processing sensitive data.
- Virginia's revenue-percentage threshold, more than 50% of gross revenue from selling personal data, is meaningfully different from how Colorado's privacy law sets its lower consumer threshold, which matters if you're trying to figure out whether your business even qualifies.
- As more states pass their own data privacy laws, a compliance and targeting strategy built for just one state won't hold up for long.
What is the Virginia Consumer Data Protection Act?
The Virginia Consumer Data Protection Act took effect on January 1, 2023, and it applies to any business, whether structured as a natural person, a natural or legal entity, or a larger organization, that conducts business in Virginia, or that produces products or services targeted to Virginia residents, and meets one of two thresholds:
- The business is likely to process personal data of at least 100,000 consumers in a calendar year.
- The business is likely to process personal data of at least 25,000 consumers while also deriving more than 50% of gross revenue from selling personal data.
That second threshold is different from how some other states handle the same idea. Colorado's privacy law, for example, uses a lower bar: any revenue or discount tied to selling personal data, without a specific percentage requirement, once you cross the 25,000-consumer mark. Virginia's 50%-of-gross-revenue requirement means a business would need to be substantially built around selling personal data, not just occasionally doing it, before that lower threshold applies. If your business is likely to process a meaningful amount of personal data but selling it isn't a major revenue driver, you may fall under the Consumer Data Protection Act only through the 100,000-consumer threshold instead.
A handful of business types and specific data uses are exempt outright, including entities regulated under federal laws like the Gramm-Leach-Bliley Act (financial and lending services), the Fair Credit Reporting Act, and HIPAA, along with certain human subjects research conducted pursuant to established human research protections and personal data covered under the Federal Farm Credit Act. Local government records and content published through widely distributed media, like news reporting, also generally fall outside the law's scope.
Consumer rights under the Virginia Consumer Data Protection Act
Virginia residents get a specific set of rights over their own personal data, and businesses need a documented process for handling consumer's requests when they come in. Here's what the law grants:
- Access: Consumers can confirm whether a business is processing their personal data and access it.
- Correction: Consumers can correct inaccuracies in their personal data.
- Deletion: Consumers can delete personal data a business collected about them or obtained from another source.
- Portability: Consumers can request a copy of their personal data in a readily usable format they can transmit elsewhere.
- Opt-out: Consumers can opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects.
Businesses generally have 45 days to respond to a verified request, with a possible 45-day extension for more complex cases. If you process personal data at any real scale, it's worth having a clear, documented process for how each of these consumer's requests actually gets fulfilled, since a consumer can ask whether you process personal data about them at all before asking you to act on it. Personal data processed for one purpose can't simply be repurposed without checking whether that use is still covered by your original privacy notice.
What the Virginia Consumer Data Protection Act requires of businesses
Beyond consumer rights, the Consumer Data Protection Act puts a handful of operational requirements directly on businesses:
- You need to practice data minimization, meaning you only collect personal data that's reasonably necessary for the purpose disclosed in a meaningful privacy notice.
- You need to maintain reasonable administrative, technical, and physical data security practices to protect the personal data you hold.
- You need a data processing agreement in place with any processor that helps it process personal data on its behalf, spelling out the processor's data processing procedures and limits on how such data can be used.
For higher-risk data processing, like targeted advertising, selling personal data, or profiling that carries a reasonably foreseeable risk of harm, businesses have to conduct data protection assessments before they start. Think of a data protection assessment as weighing the benefits of a given use of personal data against the risk to the consumer, or natural person, whose personal data is at stake. Virginia's Attorney General can request to see these data protection assessments as part of an investigation, so they're worth documenting properly and keeping current as your data processing changes. A qualified and independent assessor isn't required by the statute itself, but many businesses bring one in anyway to help document data protection assessments consistently across their marketing and data teams.
Sensitive data needs opt-in consent
A specific set of categories require a consumer's clear affirmative act signifying consent before a business can process them at all, not just an opt-out option. That list includes:
- Racial or ethnic origin and religious beliefs
- Sexual orientation and citizenship or immigration status
- A physical health diagnosis or mental health condition
- Genetic or biometric data used to identify a natural person
- Precise geolocation data
- Personal data collected from a known child
If your marketing touches any of these sensitive data categories, even by inference rather than direct collection, you need opt-in consent before you process sensitive data or otherwise process personal data belonging to one of these groups at all. Personal data revealing racial or ethnic origin, health status, or similar categories carries this higher bar even when the business never intended to treat it as sensitive, and it applies the same way regardless of whether the natural person in question realizes their information falls into one of these categories.
What counts as a "sale" or "targeted advertising" under the Consumer Data Protection Act
Both terms are defined more broadly than a lot of marketing teams assume, which is exactly where compliance risk tends to hide.
A sale of personal data under the Consumer Data Protection Act means a controller shares personal data with a third party for monetary consideration. That's a narrower definition than some other states use, since Virginia's law is specifically tied to money changing hands rather than any form of valuable consideration. Still, that covers more standard ad tech than many teams assume, particularly arrangements where a platform pays for, or pays out based on, personal data it receives.
Targeted advertising covers ads displayed to a consumer based on personal data obtained from that consumer's activities over time and across non-affiliated websites or apps, used to predict personal aspects related to their preferences or interests. Ads based only on the consumer's current search query, or on the context of the page they're currently viewing, generally fall outside that definition.
How the Consumer Data Protection Act affects your ad targeting and audience building
A few practical shifts follow from those definitions:
- Know which data exchanges actually count as a sale. Since Virginia ties "sale" to monetary consideration, review your ad tech and data processing agreements to confirm whether money is actually changing hands when a vendor helps you process personal data, not just whether it has data access.
- Expect gradual audience shrinkage. As more Virginia residents exercise their opt-out rights for targeted advertising, some prospecting and retargeting pools will shrink over time.
- Watch how vendors classify personal data collected. If a vendor is matching your customer list against a platform's user base, confirm how that exchange is being classified under your data processing agreement.
- Be careful with inference. If your targeting logic predicts personal aspects related to sensitive categories, like health or lifestyle interests, from behavior that looks unrelated, that inference can trigger the opt-in consent requirement.
- Know your context. The Consumer Data Protection Act governs personal data collected in a commercial or employment context, or in an individual or household context, but personal data processed strictly within an employment context, like employment records, is generally handled under separate rules.
None of this takes targeted advertising off the table in Virginia. It means the personal data behind your audiences needs a clearer paper trail. Data protection assessments generally need to be updated whenever the underlying data processing changes in a meaningful way, whether that's a new use of personal data collected in an individual or household context or a shift in how a vendor is set up to process personal data on your behalf.
What the Virginia Consumer Data Protection Act means for your marketing measurement
There's no single comprehensive federal law governing personal data privacy yet, so state and federal laws are setting the pace piece by piece, with Virginia's law as one of the more influential early examples other states have modeled their own versions after.
Click-based, user-level attribution depends on the exact kind of cross-site personal data processing these laws restrict. As more consumers exercise their opt-out rights, the personal data feeding platform-reported conversions gets less complete. Measurement approaches that work at an aggregated, statistical level rather than tracking an identifiable natural person don't carry that same exposure, since they aren't built on the personal data these laws regulate in the first place. That's one of the reasons why marketing mix modeling has become a bigger part of the measurement conversation as more states pass privacy laws of their own.
Virginia isn't the only state you need to track
If your brand markets nationally, Virginia is one piece of a larger patchwork. States including California, with the California Consumer Privacy Act, and Colorado, with its own privacy law, have each written their own version of comprehensive data protection legislation, and the details don't line up. Virginia's revenue-percentage threshold versus Colorado's simpler revenue-tied threshold is a good example of how "does this law apply to us" can have a different answer state by state, even when the underlying consumer rights look similar on the surface.
The practical takeaway for marketers is that a state-by-state compliance and targeting strategy doesn't scale. If your approach is built around any single state's specific thresholds, you'll always be catching up to whatever the next state passes.
Where Prescient comes in
As more states pass laws like Virginia's, the personal data marketers have relied on for targeting and measurement keeps getting harder to collect and less complete once you have it. Prescient's marketing mix modeling doesn't depend on the kind of individually identifiable personal data these laws restrict. Instead, it works with your aggregated spend and performance data to show you what's actually driving revenue across your marketing mix.
That means your measurement doesn't break every time a new state passes a privacy law or redefines what counts as a sale. If you want to see how that works, book a demo and our team of experts will walk you through it.
FAQs
Does the Virginia Consumer Data Protection Act apply to businesses outside Virginia?
Yes. The Consumer Data Protection Act applies based on whether a business conducts business in Virginia, or produces products or services targeted to Virginia residents, not where the business itself is headquartered. A company based anywhere can fall under the law if it meets the consumer thresholds and reaches Virginia residents.
What's the difference between the Virginia Consumer Data Protection Act and other state privacy laws, like Colorado's CPA?
Both laws give consumers similar rights, like access, correction, deletion, and opt-out of targeted advertising and the sale of personal data, but the thresholds differ. Virginia requires more than 50% of gross revenue from selling personal data to trigger its lower consumer threshold, while Colorado's law ties that lower threshold to any revenue or discount from selling personal data, without a percentage requirement.
What happens if a business doesn't comply with the Virginia Consumer Data Protection Act?
Virginia's Attorney General can investigate and bring enforcement actions, with civil penalties of up to $7,500 per violation. Businesses get a 30-day cure period to fix a violation before facing formal enforcement, though that cure period isn't guaranteed to last indefinitely as the law continues to be enforced.
Is it legal to record a sales call or webinar in Virginia without telling the other person?
This falls under a completely different Virginia law than the Consumer Data Protection Act: the state's wiretapping statute, Virginia Code § 19.2-62. Virginia is a one-party consent state, meaning it's generally legal to record a conversation you're part of, like a sales call, without telling the other person, as long as you consent to the recording yourself. That said, if a call includes someone in a two-party consent state, that state's stricter rule can still apply, so it's worth getting explicit consent whenever a call crosses state lines.
The Halo
Exclusive insights, every week.
Subscribe to The Halo for sharper marketing thinking.
You're subscribed to The Halo!
Quick question (optional): How familiar are you with MMM?
Thanks for sharing! Enjoy The Halo.
Keep reading
View all
Understanding how Colorado privacy laws change your marketing measurement
Read articleWhat is a tracking pixel audit (and how do you run one)?
Read articlePixels vs. cookies: What they are, how they differ, and what's changing
Read articleIs pixel tracking considered selling personal data? Sometimes.
Read article
What California's data privacy law means for your marketing data
Read article
What is privacy-preserving ad measurement?
Read article