Artifact GuideUSCalifornia vs Virginia

CPRA vs Virginia VCDPA

California and Virginia share several privacy-program controls, but their scope tests, sale definitions, sensitive-data rules, assessments, and enforcement routes differ.

Apply each law to the same entity, consumer, purpose, data category, recipient, and system before deciding what evidence can be reused.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
20

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The CCPA as amended by the CPRA and the core (VCDPA) took effect on January 1, 2023. Virginia has since amended the VCDPA, including by adding rules for known children's data and social media services used by minors. They remain separate state laws: California regulates qualifying businesses and defined recipient roles, while Virginia regulates qualifying controllers and processors. Coverage or compliance under one law does not establish coverage or compliance under the other.

Side-by-side comparison

CPRA vs Virginia VCDPA

Apply every row to the same entity and processing activity. Keep separate conclusions where definitions, exemptions, or duties diverge.

Review all sources
First framework
California CCPA as amended by CPRA

California regulates qualifying businesses and defined recipients under its own sale, sharing, rights, sensitive-information, and enforcement rules.

Second framework
Virginia VCDPA

Virginia regulates qualifying controllers and processors and has separate consent, appeal, assessment, contract, and Attorney General enforcement rules.

Comparison row 1

Scope thresholds

California CCPA as amended by CPRA

A qualifying for-profit entity doing business in California is a business if it meets a statutory route: annual gross revenue above the adjusted threshold; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Other affiliate, joint-venture, and voluntary-certification routes can apply.

Virginia VCDPA

The VCDPA covers a person conducting business in Virginia or producing products or services targeted to Virginia residents if it controls or processes personal data of at least 100,000 consumers in a calendar year, or at least 25,000 consumers and derives more than 50% of gross revenue from selling personal data.

Operational implication

Virginia has no standalone gross-revenue route. California's volume route includes households and buying, selling, or sharing, while Virginia's count is tied to Virginia consumers and controlling or processing personal data.

Comparison row 2

Consumers and exemptions

California CCPA as amended by CPRA

California's consumer definition is tied to California residency and is not restricted to a personal or household context. California includes multiple activity- and data-specific exemptions, including provisions involving regulated health and financial information.

Virginia VCDPA

A Virginia consumer is a Virginia resident acting only in an individual or household context, not an employment or commercial context. Virginia also exempts listed entities, including state bodies, financial institutions or data subject to the GLBA, HIPAA-covered entities and business associates, and nonprofit organizations.

Operational implication

A Virginia entity exemption may remove the entity from the VCDPA while a narrower California data exemption leaves other California processing in scope.

Comparison row 3

Consumer rights and appeals

California CCPA as amended by CPRA

California provides rights to know or access, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and receive non-discriminatory treatment. California's detailed response and verification rules vary by request.

Virginia VCDPA

Virginia provides confirmation and access, correction, deletion, portability, and opt-outs from targeted advertising, sale, and specified profiling. A controller must provide a conspicuous appeal process and explain how a denied appeal can be taken to the Attorney General.

Operational implication

A common request portal needs state-specific request types, exceptions, authentication steps, response text, and a Virginia appeal branch.

Comparison row 4

Sale, sharing, advertising, and profiling

California CCPA as amended by CPRA

California sale includes specified disclosures for monetary or other valuable consideration. Sharing separately covers cross-context behavioral advertising whether or not consideration is exchanged. California's current automated-decisionmaking duties must be assessed under the applicable regulations and triggers.

Virginia VCDPA

Virginia sale is an exchange of personal data for monetary consideration, subject to listed exclusions. Consumers can also opt out of targeted advertising and profiling used to further decisions that produce legal or similarly significant effects.

Operational implication

A transfer can fall outside Virginia sale yet remain Virginia targeted advertising, California sharing, or California sale. Record each classification separately.

Comparison row 5

Sensitive data and consent

California CCPA as amended by CPRA

California defines sensitive personal information and provides a right to limit uses and disclosures outside specified permitted purposes. The right is not a general requirement to obtain consent before every sensitive-information use. California separately requires affirmative authorization before selling or sharing the personal information of a consumer the business knows is under 16, with parental or guardian authorization for a consumer under 13.

Virginia VCDPA

Virginia prohibits processing sensitive data without the consumer's consent. For a known child's sensitive data, the controller must comply with COPPA. Virginia also prohibits selling or offering to sell precise geolocation data and now imposes additional conditions on specified processing of known children's personal data and on social media platforms used by minors.

Operational implication

Use separate state rules for sensitive data and age-related processing. Record the consumer's age or knowledge trigger, the activity, the required consent or authorization, the decision right, and any service-specific condition under each law.

Comparison row 6

Processor contracts and assessments

California CCPA as amended by CPRA

California requires role-specific terms for service providers, contractors, and third parties. California risk assessments apply under separate regulatory triggers and cannot be presumed identical to another state's assessment.

Virginia VCDPA

Virginia controller-processor contracts must cover instructions, nature and purpose, data type, duration, rights and duties, confidentiality, deletion or return, assessment support, audits, and subcontractors. Controllers must assess targeted advertising, sale, sensitive data, specified profiling, and other processing that presents a heightened risk of harm. The assessment requirement applies to processing created or generated after January 1, 2023.

Operational implication

A shared contract or assessment can reuse processing facts, but it must satisfy each state's role, trigger, content, and timing rules.

Comparison row 7

Enforcement and cure

California CCPA as amended by CPRA

The California Privacy Protection Agency can bring administrative actions, and the California Attorney General can bring civil actions. California has a limited private cause of action for specified security incidents, not for every CCPA violation.

Virginia VCDPA

The Virginia Attorney General has exclusive VCDPA enforcement authority. Before bringing an action, the Attorney General must give 30 days' written notice; if the controller or processor cures the alleged violation within that period and gives the required written statement, no action is initiated for that notice.

Operational implication

Do not import Virginia's cure process into a California response plan or describe either law as creating a general consumer right to sue for every violation.

Practical decision rule

How to use the California-Virginia comparison

  • Make separate scope and exemption findings before assigning a shared control.
  • Reuse inventories, vendors, request infrastructure, and assessment facts only after mapping both legal definitions.
  • Keep state-specific branches for appeals, sensitive-data consent, sale and advertising, recipient contracts, assessments, cure, and enforcement.
Section 1

What should a California-Virginia comparison decide?

First decide scope. California has a for-profit business test with three main threshold routes. Virginia applies to a person doing business in Virginia or targeting Virginia residents if it controls or processes personal data of at least 100,000 Virginia consumers in a calendar year, or at least 25,000 consumers while deriving more than 50% of gross revenue from personal-data sales.

Then classify the same processing under both laws. Virginia's consumer definition excludes employment and commercial contexts, its sale definition requires monetary consideration, and its sensitive-data rule requires consent. California uses broader sale and separate sharing concepts and gives consumers a conditional right to limit certain sensitive-personal-information uses.

  • Calculate each state's threshold with its own consumer, household, revenue, sale, and sharing definitions.
  • Record whether an entity-level or data-level exemption applies and why; the exemption structures are different.
  • Classify each recipient as a California service provider, contractor, or third party and as a Virginia processor or third party.
  • Separate sale, sharing, targeted advertising, profiling, sensitive data, and child-data decisions.
  • Identify which request, consent, opt-out, appeal, contract, assessment, or enforcement branch the processing triggers.
Section 2

How should a shared privacy program branch by state?

Reuse the facts, not the legal conclusion. One data inventory, rights portal, vendor register, consent service, and assessment library can support both states, but the workflow must apply the correct definitions and exceptions before closing either requirement.

Virginia requires an appeal process after a controller refuses a consumer request and gives the Attorney General exclusive enforcement authority with a statutory 30-day notice-and-cure process. California does not use that Virginia appeal or cure structure and has both CPPA administrative enforcement and Attorney General civil enforcement.

  • Rights workflow: support access, correction, deletion, portability, and relevant opt-outs, then add Virginia's appeal and complaint route.
  • Advertising workflow: test California sale and sharing separately from Virginia sale and targeted advertising.
  • Sensitive-data workflow: obtain Virginia consent where required; for California, determine whether the use triggers the right to limit.
  • Contract workflow: use a common processing schedule but add the terms required for the recipient's role in each state.
  • Assessment workflow: apply Virginia's listed data-protection-assessment triggers, including targeted advertising, sale, sensitive data, specified profiling, and other heightened-risk processing.
  • Evidence: retain the state finding, request or signal, consumer response, downstream action, exception, test result, owner, and review date.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Subdivision (c) establishes the affirmative-authorization rules for sale or sharing when the business knows the consumer is under 16.
law.lis.virginia.gov
Referenced sections
  • Section 59.1-577 establishes Virginia rights, response procedures, appeals, and the Attorney General complaint route.
law.lis.virginia.gov
Referenced sections
  • Virginia permits one assessment for comparable processing and recognizes assessments under other laws when scope and effect are reasonably comparable.
law.lis.virginia.gov
Referenced sections
  • Section 59.1-584 gives the Attorney General exclusive authority and states the 30-day notice-and-cure procedure.
law.lis.virginia.gov
Referenced sections
  • These sections specify processor contracts, assessment triggers, required analysis, regulator access, reuse, and the January 1, 2023 non-retroactivity rule.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.