Loading
Home / Get Your Website Ready for Virginia CDPA Compliance

Get Your Website Ready for Virginia CDPA Compliance

Build clearer website privacy controls under the Virginia Consumer Data Protection Act (VCDPA). Okito helps you identify tracking technologies, configure consent and opt-out choices, and keep visitor preference records organised in one platform.

Get Started
Powering we provide the latest solutions for website privacy compliance
garcia.png
suaryapi.png
blackstate.png
gulbenergen.png
reportage.png
sulax.png (1)
barbertrade.png
naksanyapi.png
byonhotels.png
atlastek.png
nexonya.png
uiduk.png
endemik.png
yediiklim.png
scotty.png
pehlivan.png
mintek.png
ader.png

Build a Clearer Virginia CDPA Compliance Process

Identify Website Technologies

Scan your website for cookies, pixels, tags and third-party scripts. Okito helps you organise detected technologies by category, purpose and provider.

Identify Website Technologies

Configure Privacy Choices

Set up consent and opt-out controls that reflect how personal data is used. Manage choices for sensitive data, targeted advertising and relevant processing purposes.

Configure Privacy Choices

Keep Settings and Records Organised

Bring detected technologies, consent activity and visitor preferences into one dashboard. Review your configuration as vendors and website integrations change.

Keep Settings and Records Organised

Key Privacy Controls Under the Virginia CDPA

Obtain Consent for Sensitive Data

The Virginia CDPA requires consumer consent before sensitive data is processed. The consent request should clearly explain the relevant data and purpose so the consumer can make an informed choice.

  • Present clear information before requesting consent.

  • Use a specific and affirmative action to record the decision.

  • Connect the choice with the relevant technologies or processing purposes.

Sensitive data includes specified information about health, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status. It also includes precise geolocation, personal data collected from a known child, and genetic or biometric data processed to uniquely identify an individual.

Okito helps you configure granular consent choices and apply recorded preferences to relevant website technologies.

Keep Privacy Notices Clear and Accessible

A Virginia CDPA privacy notice should explain what personal data is processed, why it is used and which categories of third parties receive it. It must also tell consumers how to exercise their rights and appeal a refused request.

  • Describe the categories and purposes of personal data processing.

  • Explain how consumers can access, correct, delete or obtain a portable copy of their data.

  • Provide clear instructions for submitting requests and appealing decisions.

Where personal data is sold or processed for targeted advertising, the notice should clearly disclose the activity and explain how consumers can opt out.

Okito’s technology inventory helps your team compare website activity with the information presented in your privacy disclosures.

Manage Consumer Opt-Out Choices

Virginia consumers may opt out of personal data processing for targeted advertising, the sale of personal data and profiling used for decisions with legal or similarly significant effects.

  • Give consumers an accessible way to communicate applicable opt-out choices.

  • Apply their preferences to the relevant configured advertising and tracking services.

  • Allow visitors to revisit and change their website privacy settings.

Not every disclosure of personal data is a sale under the Virginia CDPA. The law generally defines a sale as an exchange of personal data for monetary consideration and provides specific exclusions.

Okito supports the preference and opt-out layer of the broader consumer rights process by keeping website choices and related settings in one place.

Support Assessments and Ongoing Accountability

The Virginia CDPA requires controllers to conduct and document data protection assessments for specified activities involving increased privacy risks.

  • Assess processing for targeted advertising, personal data sales and qualifying profiling activities.

  • Review sensitive data processing and other activities presenting a heightened risk of harm.

  • Weigh the benefits of the processing against potential risks and available safeguards.

Controllers must also maintain reasonable administrative, technical and physical security practices appropriate to the volume and nature of the personal data they process.

Okito’s technology inventory, provider details and preference records can provide useful input for internal reviews. The controller remains responsible for completing and documenting the required assessment.

Put Your Virginia CDPA Privacy Controls in Place

1

Scan

Add your website and identify cookies, pixels, trackers and third-party scripts that may collect or transmit personal data.

2

Configure

Organise detected technologies and configure consent or opt-out choices based on their purposes and your privacy requirements.

3

Review

Publish your privacy controls, maintain preference records and review the configuration when your website technologies or vendors change.

Please use an email address that is not associated with an existing Okito account.

What Does CDPA Mean in Virginia?

CDPA stands for the Consumer Data Protection Act. In the context of this page, it refers to the Virginia Consumer Data Protection Act, commonly abbreviated as VCDPA. The law was signed on March 2, 2021, and took effect on January 1, 2023.

The Virginia CDPA regulates how covered controllers and processors handle the personal data of Virginia consumers. It gives individuals rights over their data and requires covered organisations to provide clear privacy notices, minimise unnecessary data collection, protect personal data and obtain consent before processing sensitive data.

It is not solely a cookie law and does not require consent for every processing activity. For websites, its most relevant requirements include transparency, sensitive data consent and opt-out choices for targeted advertising, personal data sales and certain profiling activities.

Who Does the Virginia CDPA Apply To?

The Virginia CDPA applies to organisations that conduct business in Virginia or offer products and services targeted to Virginia residents and meet at least one of the following thresholds during a calendar year:

  • Control or process personal data belonging to at least 100,000 consumers.

  • Control or process personal data belonging to at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.

A “consumer” is a Virginia resident acting in an individual or household context. Individuals acting in an employment or commercial context are not included when calculating these thresholds.

The Act also contains organisation- and data-level exemptions. These include certain Virginia public bodies, nonprofit organisations, higher education institutions, financial institutions or data covered by the Gramm-Leach-Bliley Act, and HIPAA-regulated covered entities and business associates. Whether the Virginia CDPA applies therefore depends on both the organisation and the specific data-processing activity.

What Consumer Rights Does the CDPA Provide?

The Virginia CDPA gives consumers specific rights over personal data processed by a covered controller. Subject to authentication and applicable legal exceptions, consumers have the right to:

  • Confirm whether their personal data is being processed and access that data.

  • Correct inaccuracies in their personal data.

  • Delete personal data provided by or obtained about them.

  • Obtain certain data they previously provided in a portable and readily usable format.

  • Opt out of targeted advertising, the sale of personal data and qualifying profiling activities.

Controllers must generally respond to an authenticated consumer request within 45 days. This period may be extended once by an additional 45 days when reasonably necessary because of the complexity or number of requests, provided the consumer is informed within the initial response period.

If a request is refused, the consumer must be given an accessible appeal process. The controller must respond to the appeal within 60 days and, if it is denied, explain how the consumer can contact the Virginia Attorney General. Consumers must not be unlawfully discriminated against for exercising their CDPA rights.

What Are the Penalties for Virginia CDPA Non-Compliance?

The Virginia Attorney General has exclusive authority to enforce the Virginia CDPA. The Act does not give consumers a private right of action, so an individual cannot bring a lawsuit solely on the basis that the CDPA was violated.

Before initiating an enforcement action, the Attorney General must provide the controller or processor with written notice identifying the alleged violation. The organisation then has 30 days to cure the violation and provide an express written statement confirming that it has been corrected and will not recur.

If the violation continues after the cure period, or the organisation later breaches its written statement, the Attorney General may seek an injunction and a civil penalty of up to $7,500 for each violation. The Attorney General may also recover reasonable investigation expenses and attorney fees.

The maximum penalty is not automatically imposed in every case; enforcement and the amount sought depend on the facts and circumstances of the violation.

FAQ

Frequently Asked Questions CDPA Compliance

The Virginia Consumer Data Protection Act, commonly called the Virginia CDPA or VCDPA, is Virginia’s comprehensive consumer privacy law. It was signed on March 2, 2021, and took effect on January 1, 2023.

The law gives Virginia consumers rights over their personal data and places transparency, security, consent and assessment obligations on covered controllers and processors.

The Virginia CDPA covers organisations that conduct business in Virginia or target Virginia residents and meet either of these annual thresholds:

  • Process personal data belonging to at least 100,000 consumers.

  • Process personal data belonging to at least 25,000 consumers and derive more than 50% of gross revenue from personal data sales.

It regulates privacy notices, consumer requests, sensitive data consent, targeted advertising, personal data sales, qualifying profiling, data security and controller–processor responsibilities.

Employment and commercial contexts are excluded, and certain organisations and regulated data are exempt.

Personal data is information linked or reasonably linkable to an identified or identifiable person. Depending on how it is used, this may include names, contact details, account information, online identifiers, cookie IDs, device identifiers, browsing activity and location data.

The definition does not include de-identified data or publicly available information as defined by the Virginia CDPA.

The Virginia Attorney General has exclusive authority to enforce the Virginia CDPA. Before initiating an enforcement action, the Attorney General must issue written notice and allow the controller or processor 30 days to cure the alleged violation.

If the violation continues or the organisation breaches its written cure statement, the Attorney General may seek an injunction and a civil penalty of up to $7,500 per violation, as well as reasonable investigation expenses and attorney fees. The Act does not provide a private right of action.

The Virginia CDPA does not expressly require every website to display a cookie consent banner or obtain consent for every cookie.

A consent or preference interface may be appropriate when website technologies process sensitive data or support targeted advertising, personal data sales or qualifying profiling.

Sensitive data processing requires consent, while the other specified activities are generally subject to consumer opt-out rights. The website’s privacy controls should reflect its actual technologies and processing purposes.

Virginia consumers may opt out of personal data processing for:

  • Targeted advertising based on activity across nonaffiliated websites or applications.

  • The sale of personal data for monetary consideration.

  • Profiling used to support decisions producing legal or similarly significant effects.

These rights do not apply to every advertisement, data disclosure or automated process. Controllers must determine whether their actual processing activities fall within the statutory definitions and clearly explain applicable opt-out methods.

Sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status. It also includes precise geolocation, personal data collected from a known child, and genetic or biometric data processed to uniquely identify a person.

Controllers must obtain consent before processing sensitive data. Data belonging to a known child must be processed in accordance with federal COPPA parental consent requirements. Virginia law also prohibits the sale or offer for sale of precise geolocation data.

Yes. Controllers must conduct and document data protection assessments for:

  • Targeted advertising.

  • The sale of personal data.

  • Profiling presenting a reasonably foreseeable risk of specified harm.

  • Sensitive data processing.

  • Other processing activities presenting a heightened risk of harm.

The assessment must weigh the benefits of processing against risks to consumers and consider available safeguards. Technology inventories and consent records may support the review, but the controller remains responsible for the assessment.

A controller must generally respond to an authenticated consumer request within 45 days. The period may be extended once by another 45 days when reasonably necessary because of the complexity or number of requests, provided the consumer is informed during the initial period.

Responses are generally free up to twice annually. If a request is refused, the controller must explain the reason and provide an appeal process. The appeal must be answered in writing within 60 days.

The Virginia CDPA and California CCPA both give consumers rights over their personal data, but their scope and requirements differ. The VCDPA generally uses specific data-processing thresholds and requires consent before sensitive data processing, while the CCPA uses broader applicability criteria and gives

California consumers additional rights, including the right to opt out of the sale or sharing of personal information and the right to limit certain uses of sensitive personal information. The VCDPA is enforced by the Virginia Attorney General and does not provide a private right of action, while the CCPA allows limited private lawsuits for certain data breaches.