VCDPA: An introduction
What is VCDPA?
The Virginia Consumer Data Protection Act (VCDPA) operates based on the consumer right to opt-out of having personal data processed for the purposes of targeted advertising, profiling for decisions that could affect the consumer in a legal or similarly significant way and/or sale. It also requires companies and organizations to obtain the prior consent from end-users if they collect or process sensitive personal data, which we will take a deeper look at below.
This is similar to the EU’s General Data Protection Regulation (GDPR) that has been in effect since 2018.
From January 1, 2023, websites, companies, and organizations who conduct business in Virginia or produce products or services targeted to Virginia residents and control or process personal data of 100,000 or more consumers during a calendar year, or control or process personal data of 25,000 or more consumers and derive over 50 percent of their gross revenue from the sale of that personal data must comply with the VCDPA’s requirements.
What is personal data under VCDPA?
The VCDPA defines “personal data” as any information that is linked or reasonably linkable to an identified or identifiable natural person (de-identified data or publicly available information is exempt). The VCDPA also distinguishes between “personal data” and “sensitive personal data”, the latter includes data from users under the age of 13, health and biometric data, geolocation data and data about racial or ethnic origin, religious beliefs, political convictions, and sexual orientation.
Who is required to comply with the VCDPA?
The VCDPA applies to companies or for-profit organizations doing business in Virginia or that produces products and services for Virginia residents. If you have a for-profit company located outside of Virginia but you have users from inside Virginia (e.g. by offering online services that Virginia residents use), you are also required to be compliant with the VCDPA.
How to be compliant with Virginia law?
Users must have the option to opt out of personal data being used for so-called targeted advertising.
Targeted advertising is when websites and companies use personal data to tailor marketing campaigns to the users, and is defined in the VCDPA as advertising that is “selected based on personal data obtained from a consumer’s activities over time and across nonaffiliated websites or online applications to predict such consumer’s preferences or interests.”
In other words, under the Virginia Consumer Data Protection Act (VCDPA), users inside Virginia must be enabled to opt out of cookies and trackers on websites that collect personal data for the purpose of targeted advertising.
This is usually done through a consent management platform (CMP) that automatically detects cookies and controls them based on the consent state of users, as they navigate a consent banner (also known as a ‘cookie banner’) on the website they visit.
VCDPA: A Cookiebot checklist
The checklist is not intended as legal advice - if in doubt, seek advice from a trusted legal source or your Data Protection Authority.
Step 1: Add your domain
- Log into the Cookiebot Manager and navigate to the Domains tab.
- Enter the domain name (excluding https://-part, for example: domain.com)
Step 2: Configure your banner type
Virginia Law has the following requirement for the cookie banner:
- It must show an opt-out option (decline cookies)
Any GDPR compliant banner might also be compliant with VCDPA. If you only need to set up a cookie banner according to the VCDPA regulations, you can follow these settings:
- Navigate to the "Dialog" pane
- Select any banner type that includes a “decline” or “reject all” button
- In case of sensitive data: If you are using the banner type “multilevel” or “inline multilevel”, make sure you do not have any of the category checkboxes pre-ticked.
Geo location settings (optional)
If you wish to only display a banner to visitors in Virginia, you can do so by configuring "Distribution" at the bottom of the page:
Step 3: Get your scripts
- Navigate to the "Your scripts" pane
- Follow the instructions to insert your banner and cookie declaration on your website.
If you intend to implement Cookiebot CMP by other means than manually adding the script(s) to your template, please refer to our implementation section in the Help Center.