Add your website and identify cookies, pixels, trackers and third-party scripts that may collect or transmit personal data.
Get Your Website Ready for Virginia CDPA Compliance
Build clearer website privacy controls under the Virginia Consumer Data Protection Act (VCDPA). Okito helps you identify tracking technologies, configure consent and opt-out choices, and keep visitor preference records organised in one platform.
Build a Clearer Virginia CDPA Compliance Process
Identify Website Technologies
Scan your website for cookies, pixels, tags and third-party scripts. Okito helps you organise detected technologies by category, purpose and provider.
Configure Privacy Choices
Set up consent and opt-out controls that reflect how personal data is used. Manage choices for sensitive data, targeted advertising and relevant processing purposes.
Keep Settings and Records Organised
Bring detected technologies, consent activity and visitor preferences into one dashboard. Review your configuration as vendors and website integrations change.
Key Privacy Controls Under the Virginia CDPA
Obtain Consent for Sensitive Data
The Virginia CDPA requires consumer consent before sensitive data is processed. The consent request should clearly explain the relevant data and purpose so the consumer can make an informed choice.
Present clear information before requesting consent.
Use a specific and affirmative action to record the decision.
Connect the choice with the relevant technologies or processing purposes.
Sensitive data includes specified information about health, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status. It also includes precise geolocation, personal data collected from a known child, and genetic or biometric data processed to uniquely identify an individual.
Okito helps you configure granular consent choices and apply recorded preferences to relevant website technologies.
Keep Privacy Notices Clear and Accessible
A Virginia CDPA privacy notice should explain what personal data is processed, why it is used and which categories of third parties receive it. It must also tell consumers how to exercise their rights and appeal a refused request.
Describe the categories and purposes of personal data processing.
Explain how consumers can access, correct, delete or obtain a portable copy of their data.
Provide clear instructions for submitting requests and appealing decisions.
Where personal data is sold or processed for targeted advertising, the notice should clearly disclose the activity and explain how consumers can opt out.
Okito’s technology inventory helps your team compare website activity with the information presented in your privacy disclosures.
Manage Consumer Opt-Out Choices
Virginia consumers may opt out of personal data processing for targeted advertising, the sale of personal data and profiling used for decisions with legal or similarly significant effects.
Give consumers an accessible way to communicate applicable opt-out choices.
Apply their preferences to the relevant configured advertising and tracking services.
Allow visitors to revisit and change their website privacy settings.
Not every disclosure of personal data is a sale under the Virginia CDPA. The law generally defines a sale as an exchange of personal data for monetary consideration and provides specific exclusions.
Okito supports the preference and opt-out layer of the broader consumer rights process by keeping website choices and related settings in one place.
Support Assessments and Ongoing Accountability
The Virginia CDPA requires controllers to conduct and document data protection assessments for specified activities involving increased privacy risks.
Assess processing for targeted advertising, personal data sales and qualifying profiling activities.
Review sensitive data processing and other activities presenting a heightened risk of harm.
Weigh the benefits of the processing against potential risks and available safeguards.
Controllers must also maintain reasonable administrative, technical and physical security practices appropriate to the volume and nature of the personal data they process.
Okito’s technology inventory, provider details and preference records can provide useful input for internal reviews. The controller remains responsible for completing and documenting the required assessment.
Put Your Virginia CDPA Privacy Controls in Place
Frequently Asked Questions CDPA Compliance
The Virginia Consumer Data Protection Act, commonly called the Virginia CDPA or VCDPA, is Virginia’s comprehensive consumer privacy law. It was signed on March 2, 2021, and took effect on January 1, 2023.
The law gives Virginia consumers rights over their personal data and places transparency, security, consent and assessment obligations on covered controllers and processors.
The Virginia CDPA covers organisations that conduct business in Virginia or target Virginia residents and meet either of these annual thresholds:
Process personal data belonging to at least 100,000 consumers.
Process personal data belonging to at least 25,000 consumers and derive more than 50% of gross revenue from personal data sales.
It regulates privacy notices, consumer requests, sensitive data consent, targeted advertising, personal data sales, qualifying profiling, data security and controller–processor responsibilities.
Employment and commercial contexts are excluded, and certain organisations and regulated data are exempt.
Personal data is information linked or reasonably linkable to an identified or identifiable person. Depending on how it is used, this may include names, contact details, account information, online identifiers, cookie IDs, device identifiers, browsing activity and location data.
The definition does not include de-identified data or publicly available information as defined by the Virginia CDPA.
The Virginia Attorney General has exclusive authority to enforce the Virginia CDPA. Before initiating an enforcement action, the Attorney General must issue written notice and allow the controller or processor 30 days to cure the alleged violation.
If the violation continues or the organisation breaches its written cure statement, the Attorney General may seek an injunction and a civil penalty of up to $7,500 per violation, as well as reasonable investigation expenses and attorney fees. The Act does not provide a private right of action.
The Virginia CDPA does not expressly require every website to display a cookie consent banner or obtain consent for every cookie.
A consent or preference interface may be appropriate when website technologies process sensitive data or support targeted advertising, personal data sales or qualifying profiling.
Sensitive data processing requires consent, while the other specified activities are generally subject to consumer opt-out rights. The website’s privacy controls should reflect its actual technologies and processing purposes.
Virginia consumers may opt out of personal data processing for:
Targeted advertising based on activity across nonaffiliated websites or applications.
The sale of personal data for monetary consideration.
Profiling used to support decisions producing legal or similarly significant effects.
These rights do not apply to every advertisement, data disclosure or automated process. Controllers must determine whether their actual processing activities fall within the statutory definitions and clearly explain applicable opt-out methods.
Sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status. It also includes precise geolocation, personal data collected from a known child, and genetic or biometric data processed to uniquely identify a person.
Controllers must obtain consent before processing sensitive data. Data belonging to a known child must be processed in accordance with federal COPPA parental consent requirements. Virginia law also prohibits the sale or offer for sale of precise geolocation data.
Yes. Controllers must conduct and document data protection assessments for:
Targeted advertising.
The sale of personal data.
Profiling presenting a reasonably foreseeable risk of specified harm.
Sensitive data processing.
Other processing activities presenting a heightened risk of harm.
The assessment must weigh the benefits of processing against risks to consumers and consider available safeguards. Technology inventories and consent records may support the review, but the controller remains responsible for the assessment.
A controller must generally respond to an authenticated consumer request within 45 days. The period may be extended once by another 45 days when reasonably necessary because of the complexity or number of requests, provided the consumer is informed during the initial period.
Responses are generally free up to twice annually. If a request is refused, the controller must explain the reason and provide an appeal process. The appeal must be answered in writing within 60 days.
The Virginia CDPA and California CCPA both give consumers rights over their personal data, but their scope and requirements differ. The VCDPA generally uses specific data-processing thresholds and requires consent before sensitive data processing, while the CCPA uses broader applicability criteria and gives
California consumers additional rights, including the right to opt out of the sale or sharing of personal information and the right to limit certain uses of sensitive personal information. The VCDPA is enforced by the Virginia Attorney General and does not provide a private right of action, while the CCPA allows limited private lawsuits for certain data breaches.
Türkçe
English