DSAR Requirements in Virginia (VCDPA)

Virginia DSAR requirements: consumer rights, response deadlines, identity verification, and penalties under the VCDPA.

Last updated: 2026-02-08

Consumer Rights That Trigger DSARs

Virginia consumers can submit requests to:

  • Access all personal data you hold about them
  • Correct inaccurate personal data
  • Delete personal data you collected
  • Port their data in a portable, machine-readable format
  • Opt out of the sale of personal data
  • Opt out of targeted advertising
  • Opt out of profiling that produces legal or similarly significant effects

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Consult a qualified attorney for guidance specific to your business.

Response Deadline

45 days from receipt. You can extend by an additional 45 days if reasonably necessary — but you must notify the consumer of the extension and the reason within the initial 45-day window.

Identity Verification

Required before fulfilling any request. The VCDPA does not prescribe a specific verification method.

Appeal Process

If you deny a request, you must inform the consumer of their right to appeal. If the appeal is also denied, you must provide information on how to file a complaint with the Virginia Attorney General.

Penalties

  • $7,500 per violation
  • 30-day cure period — the Attorney General must give you written notice and 30 days to fix the violation before pursuing enforcement
  • No private right of action — only the Attorney General can enforce

Enforced by the Virginia Attorney General.

DSAR-Specific Exemptions

You may decline or limit a request when the data is needed to:

  • Comply with a legal obligation
  • Detect security incidents or protect against fraud
  • Complete a transaction the consumer requested

Sensitive data (racial/ethnic origin, religious beliefs, health data, sexual orientation, biometric data, children's data, geolocation) requires opt-in consent before processing.

Who This Applies To

Businesses that process personal data of 100K+ Virginia consumers or 25K+ consumers with 50%+ revenue from data sales.

For the full Virginia privacy law guide, see boringgovernance.com.

Related Guides