Skip to content

Evidence request lists

Virginia CDPA

Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Enforcement

VIRGINIAVCDPA-6
AG Enforcement, Cure, Penalties

Per VCDPA: AG Enforcement Authority (59.1-584) + 30-day cure + penalties up to USD 7,500 per violation.

Artefacts an auditor will ask for
  • VA VCDPA evidence for VIRGINIAVCDPA-6
Where this commonly fails
  • DPIA + cure partial

Notice and DPIA

VIRGINIAVCDPA-4
Privacy Notice and DPIA

Per VCDPA: privacy notice + DPIA for higher-risk processing.

Artefacts an auditor will ask for
  • VA VCDPA evidence for VIRGINIAVCDPA-4
Where this commonly fails
  • DPIA + cure partial

Processor

VIRGINIAVCDPA-5
Processor Contracts and Vendor Management

Per VCDPA: processor contracts + vendor management.

Artefacts an auditor will ask for
  • VA VCDPA evidence for VIRGINIAVCDPA-5
Where this commonly fails
  • DPIA + cure partial

Rights

VIRGINIAVCDPA-2
Consumer Rights

Per VCDPA: consumer rights including access + correction + deletion + portability + opt-out of sale + targeted advertising + profiling.

Artefacts an auditor will ask for
  • VA VCDPA evidence for VIRGINIAVCDPA-2
Where this commonly fails
  • DPIA + cure partial

Scope

VIRGINIAVCDPA-1
Scope, Applicability, Definitions

Per Virginia VCDPA: Definitions (Section 59.1-575) + Applicability (Section 59.1-576) + thresholds.

Artefacts an auditor will ask for
  • VA VCDPA evidence for VIRGINIAVCDPA-1
Where this commonly fails
  • DPIA + cure partial

Sensitive

VIRGINIAVCDPA-3
Sensitive Data Consent and Children

Per VCDPA: Sensitive Data Consent + children's data per VCDPA + COPPA alignment.

Artefacts an auditor will ask for
  • VA VCDPA evidence for VIRGINIAVCDPA-3
Where this commonly fails
  • DPIA + cure partial

VCDPA 59.1-575 to 576: Definitions, Scope and Exemptions

VCDPA-59-1-575-DEF
Controller and Processor Definitions

A controller is the natural or legal person that determines the purpose and means of processing personal data. A processor is a person that processes personal data on behalf of a controller. Role assignment governs which obligations apply.

Artefacts an auditor will ask for
  • controller versus processor designation per data flow
  • RACI for joint controllers
  • vendor inventory tagged with role
  • intra group data sharing role memo
Where this commonly fails
  • controller treated as processor to avoid duties
  • no analysis of joint controller arrangements
  • ambiguous role in service provider chains
VCDPA-59-1-576
Applicability Threshold for Controllers

VCDPA applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.

Artefacts an auditor will ask for
  • Virginia resident count by year
  • personal data volume tracker
  • revenue analysis showing percentage from data sales
  • applicability memo signed by counsel
Where this commonly fails
  • no Virginia-specific volume tracking
  • thresholds not recalculated annually
  • sale of data not analyzed against 50 percent test
VCDPA-59-1-576-EXEMPT
Entity and Data Level Exemptions

VCDPA exempts certain entities including state agencies, financial institutions subject to GLBA, covered entities and business associates under HIPAA, nonprofit organizations and institutions of higher education. Data level exemptions include PHI under HIPAA, GLBA data, FCRA data, FERPA data and employment data.

Artefacts an auditor will ask for
  • entity exemption memo
  • data classification matrix flagging GLBA, HIPAA, FCRA, FERPA data
  • scope boundary documentation
  • employment data carve out
Where this commonly fails
  • over claiming GLBA exemption beyond regulated data
  • no documentation that nonprofit status applies
  • employment data not separated from consumer data

VCDPA 59.1-577: Consumer Rights

VCDPA-59-1-577-A1
Consumer Right to Confirm and Access Personal Data

A consumer has the right to confirm whether a controller is processing their personal data and to access that data. The controller must respond within 45 days of receipt of an authenticated request, extendable once by 45 additional days when reasonably necessary.

Artefacts an auditor will ask for
  • DSAR portal screenshots
  • identity verification procedure
  • 45 day response tracker
  • extension notification templates
  • fulfilment logs with timestamps
Where this commonly fails
  • no authentication step leading to identity fraud risk
  • response SLA exceeded without extension notice
  • access provided only via email without portable format
VCDPA-59-1-577-A2
Right to Correct Inaccurate Personal Data

Consumers have the right to correct inaccuracies in their personal data, taking into account the nature of the personal data and the purposes of processing.

Artefacts an auditor will ask for
  • self service correction UI
  • verification rules for sensitive corrections
  • downstream notification to processors and third parties
  • correction audit log
Where this commonly fails
  • corrections applied in CRM only without propagation to data warehouse
  • no documented criteria for refusing corrections
  • downstream recipients not notified
VCDPA-59-1-577-A3
Right to Delete Personal Data

Consumers may request deletion of personal data provided by or obtained about them. Unlike CCPA, VCDPA explicitly covers data obtained about the consumer from third parties as well as data the consumer provided.

Artefacts an auditor will ask for
  • deletion procedure across primary and backup systems
  • third party sourced data deletion path
  • exceptions log (legal hold, fraud detection, security)
  • processor deletion certificate
Where this commonly fails
  • deletion limited to user provided data only
  • backups not addressed in deletion procedure
  • exceptions invoked without documented basis
VCDPA-59-1-577-A4
Right to Data Portability

Where processing is carried out by automated means consumers may obtain a copy of the personal data they previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance.

Artefacts an auditor will ask for
  • machine readable export format (JSON, CSV)
  • portability scope limited to consumer provided data
  • API or download mechanism
  • format documentation for receiving controller
Where this commonly fails
  • PDF only export not machine readable
  • portability extended to inferences (not required)
  • no rate limit causing operational risk
VCDPA-59-1-577-A5-PROFILE
Right to Opt Out of Profiling with Legal or Similarly Significant Effects

Consumers may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, such as denial of financial services, housing, insurance, education, employment, healthcare or essential goods.

Artefacts an auditor will ask for
  • list of automated decision systems with significant effects
  • opt out workflow with human review fallback
  • model explainability documentation
  • decision impact assessment
Where this commonly fails
  • fraud and credit scoring not catalogued as profiling
  • no human review alternative offered
  • opt out not communicated at point of decision
VCDPA-59-1-577-A5-SALE
Right to Opt Out of Sale of Personal Data

Consumers may opt out of the sale of personal data. Sale is defined narrowly as the exchange of personal data for monetary consideration by the controller to a third party. Free transfers and exchanges for other valuable consideration are not sales under VCDPA, unlike CCPA.

Artefacts an auditor will ask for
  • sale versus disclosure analysis per data flow
  • opt out interface and link
  • ledger of monetary consideration transfers
  • vendor contract clauses prohibiting sale
Where this commonly fails
  • broad CCPA style sale interpretation applied creating false positives
  • no evidence that no sale occurs
  • opt out path not symmetric with sale path
VCDPA-59-1-577-A5-TARGETED
Right to Opt Out of Targeted Advertising

Consumers have the right to opt out of processing of personal data for purposes of targeted advertising, defined as displaying advertisements selected based on data obtained from the consumer's activities across nonaffiliated websites or applications to predict consumer preferences or interests.

Artefacts an auditor will ask for
  • clear opt out link or toggle
  • ad tech vendor list and contract flags
  • signal propagation to ad platforms
  • audit of pixel and SDK behavior post opt out
Where this commonly fails
  • opt out applies to first party only
  • pixels continue to fire after opt out
  • no honoring of Global Privacy Control (mandatory from 2025 in some VA AG guidance)
VCDPA-59-1-577-AUTH-AGENT
Authorized Agent Requests

A consumer may designate an authorized agent to exercise opt out rights on their behalf. The controller may deny a request from an agent that does not submit proof of authorization. VCDPA's agent rules are narrower than CCPA, applying primarily to opt out rights.

Artefacts an auditor will ask for
  • authorized agent verification procedure
  • proof of authorization template
  • limit agent rights to opt out
  • logs distinguishing direct versus agent requests
Where this commonly fails
  • agent allowed to submit access and deletion requests (not required by VCDPA)
  • no consumer confirmation step for agent
  • blanket trust of GPC as authorized agent

VCDPA 59.1-578: Controller Duties

VCDPA-59-1-578-APPEAL
Consumer Appeal Process

Controllers must establish a process for consumers to appeal refusal to take action on a request. Within 60 days of receipt of an appeal the controller must inform the consumer in writing of any action taken or not taken, with a written explanation. If the appeal is denied the controller must provide a means to submit a complaint to the Attorney General.

Artefacts an auditor will ask for
  • appeal intake form
  • 60 day response tracker
  • denial template with AG complaint link
  • appeal decisions log
Where this commonly fails
  • no separate appeal channel (re-using same DSAR queue)
  • AG complaint link missing from denial notice
  • appeals not tracked separately from initial requests
VCDPA-59-1-578-CHILD
Children Data Processing Alignment with COPPA

Personal data of a known child is sensitive data requiring opt in consent. Processing of sensitive data concerning a known child must be done in accordance with the federal Children's Online Privacy Protection Act (COPPA). A known child is a consumer under 13 years of age.

Artefacts an auditor will ask for
  • age gate logic
  • COPPA verifiable parental consent records
  • child specific privacy notice
  • no targeted advertising to known children policy
Where this commonly fails
  • age gate easily bypassed
  • COPPA consent method weak (email only)
  • no marketing suppression for under 13
VCDPA-59-1-578-NONDISCRIM
Nondiscrimination for Rights Exercise

Controllers must not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers. Controllers may not discriminate against a consumer for exercising any rights, including denying goods or services, charging different prices or providing a different level of quality, except where the offer is related to the consumer's voluntary participation in a bona fide loyalty, rewards, premium features or discount program.

Artefacts an auditor will ask for
  • nondiscrimination policy
  • loyalty program design memo justifying value exchange
  • audit of pricing or service tiers post opt out
  • fairness review of automated systems
Where this commonly fails
  • service degraded after opt out of targeted ads
  • loyalty program treated as blanket consent override
  • no review of disparate impact
VCDPA-59-1-578-OPTOUT-DISCLOSURE
Disclosure of Sale and Targeted Advertising Activities

If a controller sells personal data to third parties or processes personal data for targeted advertising the controller must clearly and conspicuously disclose this processing and the manner in which a consumer may exercise the right to opt out.

Artefacts an auditor will ask for
  • homepage or footer opt out link
  • ad tech disclosure block in privacy notice
  • screenshots of opt out journey
  • annual link visibility audit
Where this commonly fails
  • opt out link buried in privacy notice footer
  • disclosure absent from app stores or mobile UI
  • no disclosure where sale occurs via SDK
VCDPA-59-1-578-PRIVACYNOTICE
Privacy Notice Content Requirements

Controllers must provide consumers with a reasonably accessible, clear and meaningful privacy notice that includes categories of personal data processed, purposes of processing, how consumers may exercise their rights and appeal, categories of personal data shared with third parties, categories of third parties with whom data is shared and one or more methods to submit requests.

Artefacts an auditor will ask for
  • VCDPA aligned privacy notice
  • section mapping to statutory requirements
  • review log with versioning
  • accessibility (WCAG, translation) review
Where this commonly fails
  • generic GDPR notice without Virginia rights section
  • missing third party category disclosure
  • no appeal process described
VCDPA-59-1-578-PURPOSELIMIT
Purpose Limitation and Data Minimization

Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes. Controllers may not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes unless the consumer's consent is obtained.

Artefacts an auditor will ask for
  • data inventory with purposes per field
  • minimization review at product design
  • secondary use consent workflow
  • purpose compatibility analysis
Where this commonly fails
  • data captured for analytics later used for advertising without consent
  • free text fields capture sensitive data
  • retention not aligned to purpose
VCDPA-59-1-578-RESPONSE
Response Timing and Authentication

Controllers must respond to consumer requests within 45 days of receipt. The period may be extended once by 45 additional days when reasonably necessary with notice to the consumer. Information must be provided free of charge up to twice annually. Controllers must use commercially reasonable efforts to authenticate the request.

Artefacts an auditor will ask for
  • request ticketing system with SLA clock
  • authentication procedures by request type
  • extension notification template
  • fee policy for excessive or repetitive requests
Where this commonly fails
  • fee charged on first or second annual request (not allowed)
  • extension applied without notification
  • authentication so burdensome it deters legitimate requests
VCDPA-59-1-578-SECURITY
Reasonable Data Security Practices

Controllers must establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data. The practices must be appropriate to the volume and nature of the personal data at issue.

Artefacts an auditor will ask for
  • written information security program (WISP)
  • control framework mapping (ISO 27001, NIST CSF)
  • encryption at rest and in transit
  • access control review logs
  • incident response runbook
Where this commonly fails
  • security program not scaled to data volume
  • no encryption for legacy systems holding personal data
  • vendor security oversight missing
VCDPA-59-1-578-SENSITIVE-OPTIN
Sensitive Data Opt In Consent

Controllers must not process sensitive data without obtaining the consumer's freely given, specific, informed and unambiguous consent (opt in). Sensitive data of a known child must be processed in accordance with COPPA. Sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data for unique identification, data of a known child and precise geolocation.

Artefacts an auditor will ask for
  • sensitive data classification matrix
  • opt in consent UI per category
  • COPPA verifiable parental consent records
  • biometric identifier processing register
Where this commonly fails
  • sensitive data processed under legitimate interest argument (not permitted)
  • geolocation captured without precise versus approximate distinction
  • no separate consent for biometric identifiers

VCDPA 59.1-579 to 580: Data Protection Assessments and Processors

VCDPA-59-1-579-DPA
Data Protection Assessment Requirement

Controllers must conduct and document a data protection assessment of each of the following processing activities: processing for purposes of targeted advertising, sale of personal data, processing for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or financial, physical or reputational injury, processing of sensitive data and any processing activities involving personal data that present a heightened risk of harm.

Artefacts an auditor will ask for
  • DPA template covering statutory triggers
  • register of activities requiring DPA
  • completed DPAs with sign off
  • annual review cycle
Where this commonly fails
  • DPAs done only for sensitive data not targeted ads or profiling
  • no risk weighing of benefits versus harms
  • DPAs not refreshed when processing changes
VCDPA-59-1-579-PROCESSOR-CONTRACT
Processor Contract Required Elements

Processing by a processor must be governed by a contract between the controller and the processor that sets out instructions for processing, nature and purpose of processing, type of data, duration of processing, rights and obligations of both parties, confidentiality duty, deletion or return of data at end of provision, audit cooperation and use of subcontractors only with controller authorization under a written contract that flows down the obligations.

Artefacts an auditor will ask for
  • VCDPA aligned data processing addendum
  • subprocessor authorization log
  • flow down evidence in subprocessor contracts
  • audit right exercise procedure
Where this commonly fails
  • GDPR DPA used without Virginia specific terms
  • subprocessor authorization not tracked
  • no deletion certificate at termination
VCDPA-59-1-579-PROCESSOR-DUTIES
Processor Duties to Assist Controller

A processor must adhere to the controller's instructions and assist the controller in meeting obligations including responding to consumer rights requests, implementing reasonable security and conducting data protection assessments. A determination of whether a person is acting as a controller or processor is fact specific.

Artefacts an auditor will ask for
  • processor playbook for rights requests
  • DPA assistance procedure
  • security assistance documentation
  • role fact pattern analysis per vendor
Where this commonly fails
  • processor cannot operationally support deletion requests
  • no formal channel for controller assistance requests
  • processor acts as controller in some flows without recognition
VCDPA-59-1-580-DPA-CONTENT
Data Protection Assessment Content and Confidentiality

DPAs must identify and weigh the benefits that may flow from the processing to the controller, consumer, other stakeholders and the public against the potential risks to the rights of the consumer, as mitigated by safeguards. The Attorney General may request a DPA pursuant to a civil investigative demand and the DPA is confidential and not subject to FOIA disclosure.

Artefacts an auditor will ask for
  • DPA section structure with benefit-risk balancing
  • safeguard mitigation table
  • AG response procedure with legal review
  • confidentiality labeling
Where this commonly fails
  • DPAs too generic to demonstrate balancing
  • no safeguard mapping per risk
  • AG response procedure not tested

VCDPA 59.1-581 to 582: De-identified Data and Exceptions

VCDPA-59-1-581-DEIDENT
Deidentified Data Standards

Deidentified data is data that cannot reasonably be linked to an identified or identifiable natural person or device. A controller that uses deidentified data must take reasonable measures to ensure the data cannot be associated with a natural person, publicly commit to maintain and use the data only in deidentified fashion and contractually obligate any recipients to comply with VCDPA.

Artefacts an auditor will ask for
  • deidentification methodology document (k-anonymity, suppression, hashing)
  • public commitment in privacy notice or trust page
  • recipient contracts prohibiting reidentification
  • reidentification risk assessment
Where this commonly fails
  • pseudonymous data treated as deidentified
  • no public commitment
  • recipients not contractually bound
VCDPA-59-1-581-PSEUDONYMOUS
Pseudonymous Data Carve Out

The obligations of consumer rights (access, correction, deletion, portability, opt out) do not apply to pseudonymous data when the controller is able to demonstrate that information necessary to identify the consumer is kept separately and subject to effective technical and organizational controls preventing the controller from accessing the information.

Artefacts an auditor will ask for
  • pseudonymization architecture diagram
  • key management documentation
  • access control matrix showing controller cannot reverse
  • audit log of access attempts
Where this commonly fails
  • pseudonymization done with reversible keys held by same team
  • no documented separation of identification info
  • carve out claimed for hashed but linkable data
VCDPA-59-1-582-RESEARCH
Research Data Exception

VCDPA does not restrict a controller's ability to engage in public or peer reviewed scientific or statistical research in the public interest that adheres to applicable ethics review board and human subject protection standards.

Artefacts an auditor will ask for
  • IRB or equivalent ethics approval
  • research protocol documentation
  • anonymization or safeguards for research data
  • peer review or publication record
Where this commonly fails
  • commercial product analytics labelled as research
  • no IRB equivalent oversight
  • research data combined with marketing data

VCDPA 59.1-583 to 584: Enforcement

VCDPA-59-1-583-CURE-SUNSET
30 Day Cure Period and 2025 Sunset

Prior to initiating an action the AG was required to provide a controller or processor 30 days written notice identifying specific violations. If the violation was cured and a written statement provided that no further violations would occur no action could be initiated. This cure period sunset on 1 January 2025 and is no longer available.

Artefacts an auditor will ask for
  • any AG cure notice received with response
  • compliance gap remediation evidence post 2025
  • elevated compliance posture documentation
  • tabletop exercise for AG enforcement
Where this commonly fails
  • reliance on cure period in operating model
  • no procedure for immediate AG action post 2025
  • missed gap identification before cure sunset
VCDPA-59-1-584-ENFORCEMENT
Attorney General Exclusive Enforcement

The Attorney General has exclusive authority to enforce VCDPA. There is no private right of action. The AG may seek injunctive relief and civil penalties of up to USD 7,500 for each violation, plus reasonable expenses including attorney fees.

Artefacts an auditor will ask for
  • AG inquiry response runbook
  • violation log with remediation status
  • penalty exposure analysis per processing activity
  • external counsel retainer
Where this commonly fails
  • no internal escalation path for AG correspondence
  • no violation log distinct from incident log
  • penalty exposure assumed at single occurrence rather than per consumer
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Virginia CDPA framework page.