Unlock unlimited alerts, exports & API access — RuleWatch Pro at $29/mo

Regulation dossier

Virginia, United States

Virginia Data Breach Notification Law

CybersecurityAmended

A focused view of the rule, its enforcement posture, and the timeline teams should keep in their operating plan.

Plain-English summary

What this regulation means

Built for operators

Virginia requires entities and state agencies that suffer qualifying breaches involving personal information to notify affected residents and, in many cases, the Attorney General. It affects businesses and public bodies that own or license personal information and sets timelines, notice content expectations, and substitute-notice rules.

Reading guide

Use the timeline below to see how the rule progressed from enactment to current obligations.

Related regulations surface adjacent requirements in the same jurisdiction or policy lane.

Timeline

Regulatory lifecycle

Sequence: Original Effective -> Amendment Effective -> Amendment Effective
  1. 1

    Jul 1, 2008

    Original Effective

    Virginia's original data breach notification duties became effective for covered personal information.

  2. 2

    Jul 1, 2019

    Amendment Effective

    Virginia amendments expanded breach-notice coverage and Attorney General notification obligations.

  3. 3

    Jul 1, 2020

    Amendment Effective

    Virginia updated the breach notification statute again as part of later personal-information amendments.

Pro feature

📊 Stay ahead of this regulation

Get email alerts when this regulation changes and export records to CSV for your compliance workflow — available with RuleWatch Pro.

  • →Email alerts when this regulation is updated or enforced
  • →Export to CSV or JSON for compliance reporting
  • →API access to integrate regulation tracking into your workflows
See what's included

Subscribe for regulation alerts

Get alerts for this regulation →

Free weekly digest for compliance professionals following material legal changes.

No spam. Professional updates only.

Free to join. Unsubscribe anytime.

Related regulations

What else belongs on the watchlist

Pulled from the same jurisdiction or category so teams can compare adjacent obligations quickly.

Virginia, United States

Virginia Artificial Intelligence-Based Tools

AI RegulationIn Effect

Virginia now requires human decision-makers to remain responsible for major criminal justice decisions even when AI-based tools generate recommendations or predictions. It affects judicial officers and other criminal-justice decision-makers by limiting AI to an assistive role and preserving opportunities to challenge AI outputs.

Effective
Jul 1, 2025
View detail

Virginia, United States

Virginia Consumer Data Protection Act

PrivacyIn Effect

Virginia gives consumers rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising, sale, and certain profiling. It applies to controllers and processors that meet statutory thresholds and requires privacy notices, data protection assessments, and contracts with processors. Sensitive data processing generally needs consumer consent.

Effective
Jan 1, 2023
View detail

Texas, United States

Texas Cybersecurity Program

CybersecurityIn Effect

Texas gives certain businesses a safe harbor from exemplary damages after a breach if they implemented and maintained a qualifying cybersecurity program. It affects Texas businesses that handle sensitive personal information and pushes them toward recognized cybersecurity frameworks and scaled security controls.

Effective
Sep 1, 2025
View detail