Melissa Krasnow | March 12, 2021
The Virginia Consumer Data Protection Act (VCDPA) will become effective on January 1, 2023. This article discusses VCDPA application and definitions, consumer rights, privacy notice requirements, controller and processor responsibilities, and controller-processor contracts.
The Virginia attorney general will have exclusive authority to enforce the provisions of the VCDPA.
The VCDPA applies to persons that do the following.
"Controller" means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing personal data.
"Processor" means a natural or legal entity that processes personal data on behalf of a controller.
"Process" or "processing" means any operation or set of operations performed on personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data.
"Consumer" means a natural person who is a Virginia resident acting only in an individual or household context and does not include a natural person acting in a commercial or employment context.
"Personal data" means any information that is linked or reasonably linkable to an identified or identifiable natural person and does not include de-identified data or publicly available information.
"Identified or identifiable natural person" means a person who can be readily identified, directly or indirectly.
"Sensitive data" means a category of personal data that includes the following.
"Child" means any natural person younger than 13 years of age.
"De-identified data" means data that cannot reasonably be linked to an identified or identifiable natural person or a device linked to such person.
"Pseudonymous data" means personal data that cannot be attributed to a specific natural person without the use of additional information, provided that such additional information is kept separately and is subject to appropriate technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
"Sale of personal data" means the exchange of personal data for monetary consideration by the controller to a third party and does not include the following.
"Third party" means a natural or legal person, public authority, agency, or body other than the consumer, controller, processor, or an affiliate of the processor or the controller.
"Profiling" means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person's economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
"Targeted advertising" means displaying advertisements to a consumer where the advertisement is selected based on personal data obtained from that consumer's activities over time and across nonaffiliated websites or online applications to predict such consumer's preferences or interests and does not include the following.
"Decisions that produce legal or similarly significant effects concerning a consumer" means a decision made by the controller that results in the provision or denial by the controller of financial and lending services, housing, insurance, education enrollment, criminal justice, employment opportunities, healthcare services, or access to basic necessities, such as food and water.
"Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data relating to the consumer and may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action.
A consumer may invoke consumer rights at any time by submitting a request to a controller specifying the consumer rights that the consumer wishes to invoke.
Subject to certain specified exceptions, a controller must comply with an authenticated consumer request to exercise the following rights.
A controller must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes all of the following.
A controller must clearly and conspicuously disclose any sale of personal data to third parties or processing of personal data for targeted advertising and the manner in which a consumer may exercise the right to opt out thereof.
A controller must establish, and shall describe in a privacy notice, one or more secure and reliable means for consumers to submit a request to exercise their consumer rights.
A controller must do the following.
A processor must adhere to the instructions of a controller and must assist the controller in meeting its VCDPA obligations, including the following.
A contract between a controller and a processor must do the following.
The contract also must require the processor to do the following.
Opinions expressed in Expert Commentary articles are those of the author and are not necessarily held by the author's employer or IRMI. Expert Commentary articles and other IRMI Online content do not purport to provide legal, accounting, or other professional advice or opinion. If such advice is needed, consult with your attorney, accountant, or other qualified adviser.