Virginia CDPA
Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Enforcement
Per VCDPA: AG Enforcement Authority (59.1-584) + 30-day cure + penalties up to USD 7,500 per violation.
- VA VCDPA evidence for VIRGINIAVCDPA-6
- DPIA + cure partial
Notice and DPIA
Per VCDPA: privacy notice + DPIA for higher-risk processing.
- VA VCDPA evidence for VIRGINIAVCDPA-4
- DPIA + cure partial
Processor
Per VCDPA: processor contracts + vendor management.
- VA VCDPA evidence for VIRGINIAVCDPA-5
- DPIA + cure partial
Rights
Per VCDPA: consumer rights including access + correction + deletion + portability + opt-out of sale + targeted advertising + profiling.
- VA VCDPA evidence for VIRGINIAVCDPA-2
- DPIA + cure partial
Scope
Per Virginia VCDPA: Definitions (Section 59.1-575) + Applicability (Section 59.1-576) + thresholds.
- VA VCDPA evidence for VIRGINIAVCDPA-1
- DPIA + cure partial
Sensitive
Per VCDPA: Sensitive Data Consent + children's data per VCDPA + COPPA alignment.
- VA VCDPA evidence for VIRGINIAVCDPA-3
- DPIA + cure partial
VCDPA 59.1-575 to 576: Definitions, Scope and Exemptions
A controller is the natural or legal person that determines the purpose and means of processing personal data. A processor is a person that processes personal data on behalf of a controller. Role assignment governs which obligations apply.
- controller versus processor designation per data flow
- RACI for joint controllers
- vendor inventory tagged with role
- intra group data sharing role memo
- controller treated as processor to avoid duties
- no analysis of joint controller arrangements
- ambiguous role in service provider chains
VCDPA applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.
- Virginia resident count by year
- personal data volume tracker
- revenue analysis showing percentage from data sales
- applicability memo signed by counsel
- no Virginia-specific volume tracking
- thresholds not recalculated annually
- sale of data not analyzed against 50 percent test
VCDPA exempts certain entities including state agencies, financial institutions subject to GLBA, covered entities and business associates under HIPAA, nonprofit organizations and institutions of higher education. Data level exemptions include PHI under HIPAA, GLBA data, FCRA data, FERPA data and employment data.
- entity exemption memo
- data classification matrix flagging GLBA, HIPAA, FCRA, FERPA data
- scope boundary documentation
- employment data carve out
- over claiming GLBA exemption beyond regulated data
- no documentation that nonprofit status applies
- employment data not separated from consumer data
VCDPA 59.1-577: Consumer Rights
A consumer has the right to confirm whether a controller is processing their personal data and to access that data. The controller must respond within 45 days of receipt of an authenticated request, extendable once by 45 additional days when reasonably necessary.
- DSAR portal screenshots
- identity verification procedure
- 45 day response tracker
- extension notification templates
- fulfilment logs with timestamps
- no authentication step leading to identity fraud risk
- response SLA exceeded without extension notice
- access provided only via email without portable format
Consumers have the right to correct inaccuracies in their personal data, taking into account the nature of the personal data and the purposes of processing.
- self service correction UI
- verification rules for sensitive corrections
- downstream notification to processors and third parties
- correction audit log
- corrections applied in CRM only without propagation to data warehouse
- no documented criteria for refusing corrections
- downstream recipients not notified
Consumers may request deletion of personal data provided by or obtained about them. Unlike CCPA, VCDPA explicitly covers data obtained about the consumer from third parties as well as data the consumer provided.
- deletion procedure across primary and backup systems
- third party sourced data deletion path
- exceptions log (legal hold, fraud detection, security)
- processor deletion certificate
- deletion limited to user provided data only
- backups not addressed in deletion procedure
- exceptions invoked without documented basis
Where processing is carried out by automated means consumers may obtain a copy of the personal data they previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance.
- machine readable export format (JSON, CSV)
- portability scope limited to consumer provided data
- API or download mechanism
- format documentation for receiving controller
- PDF only export not machine readable
- portability extended to inferences (not required)
- no rate limit causing operational risk
Consumers may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, such as denial of financial services, housing, insurance, education, employment, healthcare or essential goods.
- list of automated decision systems with significant effects
- opt out workflow with human review fallback
- model explainability documentation
- decision impact assessment
- fraud and credit scoring not catalogued as profiling
- no human review alternative offered
- opt out not communicated at point of decision
Consumers may opt out of the sale of personal data. Sale is defined narrowly as the exchange of personal data for monetary consideration by the controller to a third party. Free transfers and exchanges for other valuable consideration are not sales under VCDPA, unlike CCPA.
- sale versus disclosure analysis per data flow
- opt out interface and link
- ledger of monetary consideration transfers
- vendor contract clauses prohibiting sale
- broad CCPA style sale interpretation applied creating false positives
- no evidence that no sale occurs
- opt out path not symmetric with sale path
Consumers have the right to opt out of processing of personal data for purposes of targeted advertising, defined as displaying advertisements selected based on data obtained from the consumer's activities across nonaffiliated websites or applications to predict consumer preferences or interests.
- clear opt out link or toggle
- ad tech vendor list and contract flags
- signal propagation to ad platforms
- audit of pixel and SDK behavior post opt out
- opt out applies to first party only
- pixels continue to fire after opt out
- no honoring of Global Privacy Control (mandatory from 2025 in some VA AG guidance)
A consumer may designate an authorized agent to exercise opt out rights on their behalf. The controller may deny a request from an agent that does not submit proof of authorization. VCDPA's agent rules are narrower than CCPA, applying primarily to opt out rights.
- authorized agent verification procedure
- proof of authorization template
- limit agent rights to opt out
- logs distinguishing direct versus agent requests
- agent allowed to submit access and deletion requests (not required by VCDPA)
- no consumer confirmation step for agent
- blanket trust of GPC as authorized agent
VCDPA 59.1-578: Controller Duties
Controllers must establish a process for consumers to appeal refusal to take action on a request. Within 60 days of receipt of an appeal the controller must inform the consumer in writing of any action taken or not taken, with a written explanation. If the appeal is denied the controller must provide a means to submit a complaint to the Attorney General.
- appeal intake form
- 60 day response tracker
- denial template with AG complaint link
- appeal decisions log
- no separate appeal channel (re-using same DSAR queue)
- AG complaint link missing from denial notice
- appeals not tracked separately from initial requests
Personal data of a known child is sensitive data requiring opt in consent. Processing of sensitive data concerning a known child must be done in accordance with the federal Children's Online Privacy Protection Act (COPPA). A known child is a consumer under 13 years of age.
- age gate logic
- COPPA verifiable parental consent records
- child specific privacy notice
- no targeted advertising to known children policy
- age gate easily bypassed
- COPPA consent method weak (email only)
- no marketing suppression for under 13
Controllers must not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers. Controllers may not discriminate against a consumer for exercising any rights, including denying goods or services, charging different prices or providing a different level of quality, except where the offer is related to the consumer's voluntary participation in a bona fide loyalty, rewards, premium features or discount program.
- nondiscrimination policy
- loyalty program design memo justifying value exchange
- audit of pricing or service tiers post opt out
- fairness review of automated systems
- service degraded after opt out of targeted ads
- loyalty program treated as blanket consent override
- no review of disparate impact
If a controller sells personal data to third parties or processes personal data for targeted advertising the controller must clearly and conspicuously disclose this processing and the manner in which a consumer may exercise the right to opt out.
- homepage or footer opt out link
- ad tech disclosure block in privacy notice
- screenshots of opt out journey
- annual link visibility audit
- opt out link buried in privacy notice footer
- disclosure absent from app stores or mobile UI
- no disclosure where sale occurs via SDK
Controllers must provide consumers with a reasonably accessible, clear and meaningful privacy notice that includes categories of personal data processed, purposes of processing, how consumers may exercise their rights and appeal, categories of personal data shared with third parties, categories of third parties with whom data is shared and one or more methods to submit requests.
- VCDPA aligned privacy notice
- section mapping to statutory requirements
- review log with versioning
- accessibility (WCAG, translation) review
- generic GDPR notice without Virginia rights section
- missing third party category disclosure
- no appeal process described
Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes. Controllers may not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes unless the consumer's consent is obtained.
- data inventory with purposes per field
- minimization review at product design
- secondary use consent workflow
- purpose compatibility analysis
- data captured for analytics later used for advertising without consent
- free text fields capture sensitive data
- retention not aligned to purpose
Controllers must respond to consumer requests within 45 days of receipt. The period may be extended once by 45 additional days when reasonably necessary with notice to the consumer. Information must be provided free of charge up to twice annually. Controllers must use commercially reasonable efforts to authenticate the request.
- request ticketing system with SLA clock
- authentication procedures by request type
- extension notification template
- fee policy for excessive or repetitive requests
- fee charged on first or second annual request (not allowed)
- extension applied without notification
- authentication so burdensome it deters legitimate requests
Controllers must establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data. The practices must be appropriate to the volume and nature of the personal data at issue.
- written information security program (WISP)
- control framework mapping (ISO 27001, NIST CSF)
- encryption at rest and in transit
- access control review logs
- incident response runbook
- security program not scaled to data volume
- no encryption for legacy systems holding personal data
- vendor security oversight missing
Controllers must not process sensitive data without obtaining the consumer's freely given, specific, informed and unambiguous consent (opt in). Sensitive data of a known child must be processed in accordance with COPPA. Sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data for unique identification, data of a known child and precise geolocation.
- sensitive data classification matrix
- opt in consent UI per category
- COPPA verifiable parental consent records
- biometric identifier processing register
- sensitive data processed under legitimate interest argument (not permitted)
- geolocation captured without precise versus approximate distinction
- no separate consent for biometric identifiers
VCDPA 59.1-579 to 580: Data Protection Assessments and Processors
Controllers must conduct and document a data protection assessment of each of the following processing activities: processing for purposes of targeted advertising, sale of personal data, processing for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or financial, physical or reputational injury, processing of sensitive data and any processing activities involving personal data that present a heightened risk of harm.
- DPA template covering statutory triggers
- register of activities requiring DPA
- completed DPAs with sign off
- annual review cycle
- DPAs done only for sensitive data not targeted ads or profiling
- no risk weighing of benefits versus harms
- DPAs not refreshed when processing changes
Processing by a processor must be governed by a contract between the controller and the processor that sets out instructions for processing, nature and purpose of processing, type of data, duration of processing, rights and obligations of both parties, confidentiality duty, deletion or return of data at end of provision, audit cooperation and use of subcontractors only with controller authorization under a written contract that flows down the obligations.
- VCDPA aligned data processing addendum
- subprocessor authorization log
- flow down evidence in subprocessor contracts
- audit right exercise procedure
- GDPR DPA used without Virginia specific terms
- subprocessor authorization not tracked
- no deletion certificate at termination
A processor must adhere to the controller's instructions and assist the controller in meeting obligations including responding to consumer rights requests, implementing reasonable security and conducting data protection assessments. A determination of whether a person is acting as a controller or processor is fact specific.
- processor playbook for rights requests
- DPA assistance procedure
- security assistance documentation
- role fact pattern analysis per vendor
- processor cannot operationally support deletion requests
- no formal channel for controller assistance requests
- processor acts as controller in some flows without recognition
DPAs must identify and weigh the benefits that may flow from the processing to the controller, consumer, other stakeholders and the public against the potential risks to the rights of the consumer, as mitigated by safeguards. The Attorney General may request a DPA pursuant to a civil investigative demand and the DPA is confidential and not subject to FOIA disclosure.
- DPA section structure with benefit-risk balancing
- safeguard mitigation table
- AG response procedure with legal review
- confidentiality labeling
- DPAs too generic to demonstrate balancing
- no safeguard mapping per risk
- AG response procedure not tested
VCDPA 59.1-581 to 582: De-identified Data and Exceptions
Deidentified data is data that cannot reasonably be linked to an identified or identifiable natural person or device. A controller that uses deidentified data must take reasonable measures to ensure the data cannot be associated with a natural person, publicly commit to maintain and use the data only in deidentified fashion and contractually obligate any recipients to comply with VCDPA.
- deidentification methodology document (k-anonymity, suppression, hashing)
- public commitment in privacy notice or trust page
- recipient contracts prohibiting reidentification
- reidentification risk assessment
- pseudonymous data treated as deidentified
- no public commitment
- recipients not contractually bound
The obligations of consumer rights (access, correction, deletion, portability, opt out) do not apply to pseudonymous data when the controller is able to demonstrate that information necessary to identify the consumer is kept separately and subject to effective technical and organizational controls preventing the controller from accessing the information.
- pseudonymization architecture diagram
- key management documentation
- access control matrix showing controller cannot reverse
- audit log of access attempts
- pseudonymization done with reversible keys held by same team
- no documented separation of identification info
- carve out claimed for hashed but linkable data
VCDPA does not restrict a controller's ability to engage in public or peer reviewed scientific or statistical research in the public interest that adheres to applicable ethics review board and human subject protection standards.
- IRB or equivalent ethics approval
- research protocol documentation
- anonymization or safeguards for research data
- peer review or publication record
- commercial product analytics labelled as research
- no IRB equivalent oversight
- research data combined with marketing data
VCDPA 59.1-583 to 584: Enforcement
Prior to initiating an action the AG was required to provide a controller or processor 30 days written notice identifying specific violations. If the violation was cured and a written statement provided that no further violations would occur no action could be initiated. This cure period sunset on 1 January 2025 and is no longer available.
- any AG cure notice received with response
- compliance gap remediation evidence post 2025
- elevated compliance posture documentation
- tabletop exercise for AG enforcement
- reliance on cure period in operating model
- no procedure for immediate AG action post 2025
- missed gap identification before cure sunset
The Attorney General has exclusive authority to enforce VCDPA. There is no private right of action. The AG may seek injunctive relief and civil penalties of up to USD 7,500 for each violation, plus reasonable expenses including attorney fees.
- AG inquiry response runbook
- violation log with remediation status
- penalty exposure analysis per processing activity
- external counsel retainer
- no internal escalation path for AG correspondence
- no violation log distinct from incident log
- penalty exposure assumed at single occurrence rather than per consumer
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Virginia CDPA framework page.