State Guide
Virginia Privacy & Data Security Laws
Every statute below can apply to a business handling Virginia residents' data, depending on your revenue, the number of Virginia consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies to entities controlling/processing data of 100,000+ Virginia consumers, or 25,000+ if 50%+ of revenue comes from selling personal data. SB 338 (signed Apr 13, 2026, effective Jul 1, 2026) replaced the VCDPA's prior consent-based treatment of precise geolocation with an outright ban on selling or offering to sell it — consent no longer cures the sale. "Precise geolocation" means a location identified within a 1,750-foot radius. Virginia joined Maryland and Oregon as the states banning these sales outright; Connecticut follows on Oct 1, 2026.
Data Security & Breach Notification · 1
Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.