| Scope thresholds | A qualifying for-profit entity doing business in California is a business if it meets a statutory route: annual gross revenue above the adjusted threshold; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Other affiliate, joint-venture, and voluntary-certification routes can apply. | The VCDPA covers a person conducting business in Virginia or producing products or services targeted to Virginia residents if it controls or processes personal data of at least 100,000 consumers in a calendar year, or at least 25,000 consumers and derives more than 50% of gross revenue from selling personal data. | Virginia has no standalone gross-revenue route. California's volume route includes households and buying, selling, or sharing, while Virginia's count is tied to Virginia consumers and controlling or processing personal data. |
|---|
| Consumers and exemptions | California's consumer definition is tied to California residency and is not restricted to a personal or household context. California includes multiple activity- and data-specific exemptions, including provisions involving regulated health and financial information. | A Virginia consumer is a Virginia resident acting only in an individual or household context, not an employment or commercial context. Virginia also exempts listed entities, including state bodies, financial institutions or data subject to the GLBA, HIPAA-covered entities and business associates, and nonprofit organizations. | A Virginia entity exemption may remove the entity from the VCDPA while a narrower California data exemption leaves other California processing in scope. |
|---|
| Consumer rights and appeals | California provides rights to know or access, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and receive non-discriminatory treatment. California's detailed response and verification rules vary by request. | Virginia provides confirmation and access, correction, deletion, portability, and opt-outs from targeted advertising, sale, and specified profiling. A controller must provide a conspicuous appeal process and explain how a denied appeal can be taken to the Attorney General. | A common request portal needs state-specific request types, exceptions, authentication steps, response text, and a Virginia appeal branch. |
|---|
| Sale, sharing, advertising, and profiling | California sale includes specified disclosures for monetary or other valuable consideration. Sharing separately covers cross-context behavioral advertising whether or not consideration is exchanged. California's current automated-decisionmaking duties must be assessed under the applicable regulations and triggers. | Virginia sale is an exchange of personal data for monetary consideration, subject to listed exclusions. Consumers can also opt out of targeted advertising and profiling used to further decisions that produce legal or similarly significant effects. | A transfer can fall outside Virginia sale yet remain Virginia targeted advertising, California sharing, or California sale. Record each classification separately. |
|---|
| Sensitive data and consent | California defines sensitive personal information and provides a right to limit uses and disclosures outside specified permitted purposes. The right is not a general requirement to obtain consent before every sensitive-information use. California separately requires affirmative authorization before selling or sharing the personal information of a consumer the business knows is under 16, with parental or guardian authorization for a consumer under 13. | Virginia prohibits processing sensitive data without the consumer's consent. For a known child's sensitive data, the controller must comply with COPPA. Virginia also prohibits selling or offering to sell precise geolocation data and now imposes additional conditions on specified processing of known children's personal data and on social media platforms used by minors. | Use separate state rules for sensitive data and age-related processing. Record the consumer's age or knowledge trigger, the activity, the required consent or authorization, the decision right, and any service-specific condition under each law. |
|---|
| Processor contracts and assessments | California requires role-specific terms for service providers, contractors, and third parties. California risk assessments apply under separate regulatory triggers and cannot be presumed identical to another state's assessment. | Virginia controller-processor contracts must cover instructions, nature and purpose, data type, duration, rights and duties, confidentiality, deletion or return, assessment support, audits, and subcontractors. Controllers must assess targeted advertising, sale, sensitive data, specified profiling, and other processing that presents a heightened risk of harm. The assessment requirement applies to processing created or generated after January 1, 2023. | A shared contract or assessment can reuse processing facts, but it must satisfy each state's role, trigger, content, and timing rules. |
|---|
| Enforcement and cure | The California Privacy Protection Agency can bring administrative actions, and the California Attorney General can bring civil actions. California has a limited private cause of action for specified security incidents, not for every CCPA violation. | The Virginia Attorney General has exclusive VCDPA enforcement authority. Before bringing an action, the Attorney General must give 30 days' written notice; if the controller or processor cures the alleged violation within that period and gives the required written statement, no action is initiated for that notice. | Do not import Virginia's cure process into a California response plan or describe either law as creating a general consumer right to sue for every violation. |
|---|