Virginia Enacts Second Privacy Law in the Nation

Articles / Publications

On March 2, 2021, Virginia’s governor signed into law the Consumer Data Protection Act (“CDPA”). Virginia is the second state in the nation, after California, to enact a privacy law protecting the rights of individual consumers in Virginia to control their personal information. The CDPA goes into effect on January 1, 2023.

The CDPA does not apply to all businesses that serve or market to Virginia consumers. It applies to businesses that conduct business in Virginia or produce products or services that are targeted to Virginia residents, and that (a) during a calendar year, control or process personal data of at least 100,000 consumers or (b) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. CDPA § 59.1-572(A).

The CDPA shares a number of features with the California Consumer Privacy Act of 2018 (“CCPA”) and the California Privacy Rights and Enforcement Act of 2020 (“CPRA”), as well as the EU’s General Data Protection Regulation (“GDPR”), including providing consumers the general rights to:

  • Confirm whether a controller is processing a consumer’s personal data and to access such personal data;
  • Correct inaccuracies in the consumer’s personal data;
  • Delete personal data;
  • Obtain a copy of the consumer’s personal data in a portable form; and
  • Opt-out of further processing of personal data for the purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

CDPA § 59.1-573(A)(1)-(5).

Additionally, the CDPA is similar to GDPR in that it creates a class of sensitive personal data, which includes:

  • Personal data revealing racial or ethnic origin, religious belief, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status;
  • The processing of genetic or biometric data for the purpose of uniquely identifying a natural person;
  • The personal data collected from a known child; or
  • Precise geolocation data.

A business shall not process sensitive data concerning a consumer without the consumer’s consent. Also similar to GDPR, the CDPA requires data protection assessments of its processing activities involving personal data.

For more information on compliance with the CDPA or California’s privacy laws and GDPR, please contact Beth Shirley. Beth is a Partner in the firm’s Cybersecurity and Commercial Litigation practice groups.

Burr
Jump to Page

Contact Us

About Burr & Forman Cybersecurity & Data Privacy Law

Burr & Forman's experienced team helps clients navigate the complex cybersecurity and data privacy landscape with strategies designed to assess current risks, develop a corrective action plan, implement best practices, and provide immediate and appropriate responses to a cybersecurity breach.

We use cookies to improve your website experience, provide additional security, and remember you when you return to the website. This website does not respond to "Do Not Track" signals. By clicking "Accept," you agree to our use of cookies. To learn more about how we use cookies, please see our Privacy Policy.

Necessary Cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.


Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.