Virginia Data Privacy Rights: VCDPA Guide for Data Broker Opt-Outs (2026)
Virginia CDPA guide covering consumer rights, controller duties, deletion requests, appeal routes, and how residents can address broker-held data.
Virginia's Consumer Data Protection Act (VCDPA) took effect on January 1, 2023. The current Code of Virginia, Chapter 53 provides rights and controller duties subject to scope thresholds, exemptions, authentication, and request-specific rules. This guide explains how those rules may relate to broker-held data; it is not legal advice.
Source review boundary (August 26, 2026): The Virginia-law statements below use the current chapter text, dated August 25, 2026. The comparison table is an orientation aid: California, Texas, and Colorado rights and appeal rules have their own current statutes and regulations, and should not be inferred from Virginia's wording or from a provider's having a Virginia profile.
Key Takeaways
- VCDPA coverage is conditional. The current statute uses volume and revenue thresholds and lists exemptions; a provider's having a Virginia profile does not by itself prove coverage.
- An authenticated covered request has a response period. The statute provides up to 45 days and permits one additional 45-day extension when the statutory conditions and notice requirements are met.
- A declined request has an appeal route. The controller must establish an appeal process, and the statute gives it up to 60 days to explain the appeal result.
- Sensitive-data rules are category- and purpose-specific. Review the current statute rather than applying a generic rule to every broker.
- Precise geolocation data has an outright sale ban, not just consent. Since July 1, 2026, Va. Code § 59.1-578 bars selling a consumer's precise geolocation data regardless of consent; that is broader than the opt-in framework applied to other sensitive categories.
- A legal citation does not guarantee a faster response or deletion. Use the provider's current route, preserve evidence, and distinguish request, response, source change, and search indexing.
What the Virginia Consumer Data Protection Act Covers
The VCDPA applies to businesses that:
- Control or process personal data of at least 100,000 Virginia consumers per year, OR
- Control or process personal data of at least 25,000 Virginia consumers AND derive over 50% of gross revenue from selling personal data
The statute applies to covered persons that conduct business in Virginia or target products or services to Virginia residents, subject to the statutory thresholds and exemptions. A company's headquarters is only one fact.
Exercise your statutory data deletion rights
Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.
Core Consumer Rights Under VCDPA
Right to Access: Virginia residents can request confirmation of whether a company processes their personal data and access to that data.
Right to Correct: You can request correction of inaccurate personal data.
Right to Delete: You can request deletion of personal data you provided or that was collected about you through your activities.
Right to Data Portability: You can request a copy of your personal data in a portable, commonly used format.
Right to Opt Out of Sale: You can opt out of the sale of your personal data to third parties.
Right to Opt Out of Targeted Advertising: You can opt out of targeted advertising based on your personal data.
Right to Opt Out of Profiling: For profiling that produces legal or similarly significant effects, opt-out rights apply.
What Makes Virginia's Law Distinctive
Appeals mechanism: VCDPA requires businesses to establish an internal appeals process for denied consumer requests. If a data broker denies your deletion request, you can formally appeal within the company. If the appeal is also denied, you can file a complaint with the Virginia Attorney General.
Sensitive data opt-in: VCDPA requires businesses to obtain opt-in consent before processing sensitive categories of personal data. Sensitive categories include:
- Racial/ethnic origin
- Religious beliefs
- Mental or physical health
- Sexual orientation
- Citizenship or immigration status
- Genetic data
- Biometric data used for identification
- Children's data (under 13)
- Precise geolocation data
Geolocation-sale ban (effective July 1, 2026): SB 338 (2026) moved precise geolocation data beyond opt-in consent. Va. Code § 59.1-578 now bars a controller or processor from selling, or offering to sell, a consumer's precise geolocation data outright; consent no longer makes that specific sale lawful. "Sale" keeps VCDPA's narrower definition — an exchange for monetary consideration — so review the current statute for what other geolocation processing remains consent-based.
No private right of action: Like Texas, Virginia's VCDPA has no private right of action, enforcement is exclusively through the AG's office.
Deidentification boundary: VCDPA defines de-identified data as data that cannot reasonably be linked to an identified or identifiable natural person, or to a device linked to that person. Controllers possessing de-identified data still have statutory obligations for that data, so deidentification is not simply removing every visible identifier or a blanket exemption from the chapter.
How to Exercise VCDPA Rights Against Data Brokers
Step 1: Identify covered data brokers
Use the catalog as a research lead, not proof of coverage. For each provider, confirm the legal entity, processing purpose, current notice, thresholds, exemptions, and authentication requirements.
Step 2: Submit deletion requests
Use the current provider privacy route. If the facts fit VCDPA, a written request can identify the statute without implying that it overrides authentication, exemptions, or the provider's current scope:
"Pursuant to the Virginia Consumer Data Protection Act (Va. Code § 59.1-577), I am requesting review and deletion of the personal data within the scope of this request. Please confirm the request type, verification needed, applicable exceptions, and response route."
Step 3: If denied, invoke the appeal process
VCDPA requires a covered controller to establish an appeal mechanism. If your request is denied, request the current appeal instructions, preserve the denial and dates, and review the Virginia Attorney General route if the appeal remains unresolved.
Step 4: File AG complaints for non-compliance
If a covered controller does not respond within the applicable period or does not provide the required appeal route, preserve the evidence and review the Virginia Attorney General complaint route and current Code of Virginia.
Safety-sensitive residents
Public address exposure can create different risks for federal employees, contractors, journalists, advocates, survivors, and other safety-sensitive people. The VCDPA does not itself decide an individual's threat level. If a request could expose additional information, consult the relevant employer, agency, advocate, or qualified lawyer before interacting with a provider.
VCDPA Compared to Other State Laws
| Feature | Virginia VCDPA | California CCPA | Texas TDPSA | Colorado CPA |
|---|---|---|---|---|
| Effective date | Jan 1, 2023 | Jan 1, 2020 | Jul 1, 2024 | Jul 1, 2023 |
| Right to delete | Yes | Yes | Yes | Yes |
| Right to correct | Yes | Yes | Yes | Yes |
| Opt out of sale | Yes | Yes | Yes | Yes |
| Sensitive data | Opt-in consent | Enhanced | Opt-in consent | Opt-in consent |
| Appeals required | Yes | Limited (ADMT) | Yes | Yes |
| Private right of action | No | Limited | No | No |
| Enforcement | AG | CPPA / AG | AG | AG / DAs |
Virginia's appeal mechanism is statutory. Appeal requirements and enforcement authorities vary by state, so review the current law for the jurisdiction and request type rather than treating this table as a complete comparison.
Practical Data Broker Opt-Out Steps for Virginia Residents
Submit requests to sources that show a matching record or relevant field. VCDPA can provide deletion rights for covered businesses when it applies to the request. For an unresolved request, preserve the correspondence, use the controller's appeal process, and review the Virginia AG's current guidance before escalating.
OfflistMe's catalog can help you review listed providers, prepare broker-specific request drafts, and reach the listed opt-out method in one session. You review and send each request yourself; provider coverage, verification, and outcomes remain outside OfflistMe's control. Start here.
Frequently Asked Questions
Does Virginia VCDPA apply to all companies processing my data, including small businesses?
VCDPA has size thresholds (100,000 consumers/year or 25,000 consumers plus more than 50% of gross revenue from selling personal data), along with exemptions. Do not assume that a named broker exceeds the thresholds without current entity and activity evidence.
Can I use VCDPA rights even if the data broker is not based in Virginia?
A company's location is not the only test. Review Va. Code § 59.1-576 for scope, thresholds, exemptions, controller role, and the provider's relationship to Virginia consumers.
What is the timeline for Virginia data brokers to respond to deletion requests?
The current statute provides up to 45 days after receipt of an authenticated request, with one possible additional 45-day extension when the controller gives the required notice and reason. This is a response period, not a guaranteed deletion result.
I filed a VCDPA deletion request and it was denied. What do I do?
Request the controller's appeal process, preserve the denial and dates, and follow the current instructions. The statute provides up to 60 days for the controller to explain an appeal result. If the appeal is denied or the process is not provided, review the current Virginia Attorney General complaint route.
Primary references and review boundary
- Virginia Code, Chapter 53: scope, definitions, rights, response periods, appeals, and enforcement.
- Virginia Attorney General Consumer Protection: current complaint and consumer-protection starting point.
- California Privacy Protection Agency CCPA FAQ and current CCPA regulations: California rights, exceptions, and limited ADMT appeal context.
- Texas Business & Commerce Code, Chapter 541: Texas rights, response, and appeal provisions.
- Colorado Attorney General: Colorado Privacy Act: Colorado rights, response, and enforcement overview.
These references support the bounded legal summaries above; they do not determine whether a named provider is covered, whether a request is authenticated or accepted, or whether deletion will occur.
Related Guides
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Related Data Broker Removal Guides
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
