Skip to main content

Data Protection Map

Virginia

Consumer Data Privacy Law

Consumer Data Privacy and Online Monitoring

Available at: https://law.lis.virginia.gov/vacodefull/title59.1/chapter53/

Data Breach Requirements: Va. Code Ann. § 18.2-186.6.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

The term “personal information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a Virginia resident, when the data elements are neither encrypted nor redacted:

  1. Social Security number;
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license number;
  3. Financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial accounts;
  4. Passport number; or
  5. Military identification number.

Security Breach Definition

The term “breach of the security of the system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any Virginia resident.


Good Faith Exception

Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure.


Risk of Harm Analysis

If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any Virginia resident, an individual or entity that owns or licenses computerized data that includes personal information shall disclose the breach.


An individual or entity shall disclose the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form, or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such a breach has caused or will cause identity theft or other fraud to any Virginia resident.


Notification Timeline

The breach notification shall be provided without unreasonable delay, provided a notification may be reasonably delayed to allow the individual or entity to determine the scope of the breach of the security of the system and restore the reasonable integrity of the system.


Security and Investigation Exceptions

The breach notification may be delayed if, after the individual or entity notifies a law-enforcement agency, the law-enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation, or homeland or national security. Notice shall be made without unreasonable delay after the law-enforcement agency determines that the notification will no longer impede the investigation or jeopardize national or homeland security.


Notification Content Requirements

A breach notification shall include a description of the following:
(1) The incident in general terms;
(2) The type of personal information that was subject to the unauthorized access and acquisition;
(3) The general acts of the individual or entity to protect the personal information from further unauthorized access;
(4) A telephone number that the person may call for further information and assistance, if one exists; and
(5) Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.


Delivery Methods

A breach notice may be provided by one of the following methods:

  1. Written notice to the last known postal address in the records of the individual or entity;
  2. Telephone notice;
  3. Electronic notice; or
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000, the affected class of Virginia residents to be notified exceeds 100,000 residents, or the individual or the entity does not have sufficient contact information or consent to provide notice as described in subdivisions 1, 2, or 3 of this definition.

Substitute Notice

Substitute notice consists of all of the following:
a. Email notice if the individual or the entity has email addresses for the members of the affected class of residents;
b. Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; and
c. Notice to major statewide media.


Notice to Government Agencies

A breach notification shall be provided to the Office of the Attorney General and any affected resident of the commonwealth without unreasonable delay.


In the event an individual or entity provides notice to more than 1,000 persons at one time, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General of the timing, distribution, and content of the notice.


As part of the notification, the Virginia Attorney General’s Office requests the following information from the individual or entity making the notification:

  1. A cover letter on official letterhead to the Virginia Attorney General’s Office as notification of the breach; 2. Approximate date of the incident to include how the breach was discovered; 3. Cause of breach; 4. Number of Virginia residents affected by the breach; 5. The steps taken to remedy the breach; 6. If an organization’s employees’ tax identification numbers and amount of tax withheld are breached, the Federal Employer Identification Number (FEIN) of the organization; and 7. A sample of the notification made to the affected parties, to include any possible offers of free credit monitoring.

Consumer Reporting Agencies

In the event an individual or entity provides notice to more than 1,000 persons at one time, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General and all consumer reporting agencies of the timing, distribution, and content of the notice.


Preemption and Compliance

An entity that is subject to Title V of the Gramm-Leach-Bliley Act and maintains procedures for notification of a breach of the security of the system in accordance with the provision of that act and any rules, regulations, or guidelines promulgated thereto shall be deemed to be in compliance with this law.


An entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the entity’s primary or functional state or federal regulator shall be in compliance with this law.


Data Processor Obligations

An individual or entity that maintains computerized data that includes personal information that the individual or entity does not own or license shall notify the owner or licensee of the information of any breach of the security of the system without unreasonable delay following discovery of the breach of the security of the system, if the personal information was accessed and acquired by an unauthorized person or the individual or entity reasonably believes the personal information was accessed and acquired by an unauthorized person.


Other Information

Nothing in this law shall apply to an individual or entity regulated by the State Corporation Commission’s Bureau of Insurance.


The provisions of this section shall not apply to criminal intelligence systems subject to the restrictions of 28 C.F.R. Part 23 that are maintained by law enforcement agencies of the commonwealth and the organized Criminal Gang File of the Virginia Criminal Information Network (VCIN), established pursuant to Chapter 2 (§ 52-12 et seq.) of Title 52.


Notwithstanding any other provision of this section, any employer or payroll service provider that owns or licenses computerized data relating to income tax withheld pursuant to Article 16 (§ 58.1-460 et seq.) of Chapter 3 of Title 58.1 shall notify the Office of the Attorney General without unreasonable delay after the discovery or notification of unauthorized access and acquisition of unencrypted and unredacted computerized data containing a taxpayer identification number in combination with the income tax withheld for that taxpayer that compromises the confidentiality of such data and that creates a reasonable belief that an unencrypted and unredacted version of such information was accessed and acquired by an unauthorized person, and causes, or the employer or payroll provider reasonably believes has caused or will cause, identity theft or other fraud. With respect to employers, this subsection applies only to information regarding the employer’s employees, and does not apply to information regarding the employer’s customers or other non-employees. Such employer or payroll service provider shall provide the Office of the Attorney General with the name and federal employer identification number of the employer as defined in § 58.1-460 that may be affected by the compromise in confidentiality. Upon receipt of such notice, the Office of the Attorney General shall notify the Department of Taxation of the compromise in confidentiality. The notification required under this subsection that does not otherwise require notification under this section shall not be subject to any other notification, requirement, exemption, or penalty contained in this section.


Data Disposal and Security: See the Virginia Consumer Data Protection Act (Appendix 5).