Law / United States / Virginia

Virginia

United States law applies in Virginia Virginia is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Virginia, described on this page below, applies here too.

11 of 14 named instruments researched to a stage, across four of the six areas of law we track: 9 in force, 1 enacted but not yet in force and 1 repealed, withdrawn or blocked. As of 14 September 2026.

When they take effect9 of 11 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 1 instrument (1 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 6 instruments (6 in force) 2024: 0 instruments 2025: 0 instruments 2026: 1 instrument (1 repealed, withdrawn or blocked) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (261 words)

Virginia's AI-specific findings sit in the criminal code rather than a horizontal AI act: Va. Code Ann. § 18.2-386.2 was amended by HB 2678 (2019), effective July 1, 2019, to extend the state's nonconsensual-image statute to a videographic or still image created, adapted, or modified to falsely depict an identifiable actual person (a deepfake), and §§ 18.2-374.1 and 18.2-374.1:1 define child pornography to reach a computer-generated depiction of an identifiable minor without requiring the depicted scene itself to have actually occurred.

Virginia's flagship horizontal measure, HB 2094 (2025), the High-Risk Artificial Intelligence Developer and Deployer Act, passed both chambers but was vetoed by the Governor on March 24, 2025 and the veto was sustained; no comparable measure has since been enacted.

A second 2025 measure, HB 2124 (signed as Chapter 398), would have extended defamation liability and created a new fraud offense for synthetic digital content, but its own text withholds effect from those provisions unless reenacted by the 2026 Session of the General Assembly, and the current Code of Virginia carries neither the amended defamation language nor the new section, so reenactment did not occur and those provisions have never taken effect.

A family of 2026 bills on synthetic media in campaign advertisements (including SB 141, which reached and failed at a conference committee) and a companion-chatbot bill (HB 635, referred to committee) did not advance either. Executive Order 30 (2024) and the 2026 Joint Commission on Technology and Science study directed by HB 797/SB 384 each bind only Virginia government bodies or study committees and are not catalogued here.

AI prohibited practices

Computer-Generated Child Sexual Abuse Material

Va. Code Ann. §§ 18.2-374.1, 18.2-374.1:1official codified text, Virginia Law (law.lis.virginia.gov)

In force. Binds public and private bodies.

What this law does

Virginia's child pornography statute defines an identifiable minor to include a person whose image as a minor was used in creating, adapting, or modifying a visual depiction, recognizable by face, likeness, or other distinguishing characteristic, and its own text states that for this purpose the minor depicted does not have to actually exist, reaching a computer-generated or AI-manipulated depiction built from an identifiable real minor's likeness on the same terms as an unaltered photograph.

Section 18.2-374.1 punishes producing, financing, or knowingly taking part in producing such material, with penalties graduated by the subject's age and the offender's age relative to the subject; section 18.2-374.1:1 separately punishes knowing possession, and reproduction, sale, distribution, or solicitation to gain entry into a trading group.

The statute's history note lists amendments through 2024, but does not isolate which amendment year first added the 'does not have to actually exist' clause, so no commencement date for that specific text is confirmed here even though the statute as a whole is unquestionably in force today.

What it requires

HB 2678 (2019), Deepfakes in Nonconsensual Image Dissemination

Va. Code Ann. § 18.2-386.2official codified text, Virginia Law (law.lis.virginia.gov)

In force since 1 July 2019. Binds public and private bodies.

What this law does

Any person who, with intent to coerce, harass, or intimidate, maliciously disseminates or sells a videographic or still image depicting another person nude, partially exposed, or (where not exposed) obscene, knowing or having reason to know they are not licensed or authorized to do so, is guilty of a Class 1 misdemeanor.

HB 2678 (2019), effective July 1, 2019, expanded 'another person' to include someone whose image was used in creating, adapting, or modifying a videographic or still image to depict an actual, recognizable person, reaching a falsely created or digitally manipulated (deepfake) image on the same terms as an unaltered photograph.

An internet, email, or other access-software provider is not liable under this section for content supplied by another person, and venue lies where the unlawful act occurs or where the image is produced, found, stored, or possessed.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (274 words)

Virginia has no dedicated biometric statute; the Virginia Consumer Data Protection Act (VCDPA) is Virginia's comprehensive consumer-privacy regime, codified at Va. Code Ann. sections 59.1-575 to 59.1-585 (Title 59.1, Chapter 53). Effective January 1, 2023, it requires opt-in consent for sensitive data and gives consumers access, correction, deletion, portability, and opt-out rights.

Genetic and biometric data collected to uniquely identify a person is one of VCDPA's enumerated sensitive-data categories, so biometric data itself is a heightened category here.

Within that category, VCDPA's biometric data definition separately carries a blanket exclusion for any data generated from a photograph, video, or audio recording, with no clawback for data generated to identify someone, so a faceprint or voiceprint extracted from a recording falls outside biometric data, and therefore outside sensitive data, entirely.

A separate chapter, Va. Code Ann. section 18.2-186.6, governs breach notification, and that chapter, unlike VCDPA itself, preserves an individual's right to recover direct economic damages for a violation of the notification duty. The VCDPA Attorney General has exclusive enforcement authority over the comprehensive act; there is no private right of action under VCDPA.

A 2026 amendment (S.B. 338) banned the sale of precise geolocation data, and separate minors' social-media provisions (section 59.1-577.1) are under a federal preliminary injunction: NetChoice v. Jones, No. 1:25-cv-2067 (PTG/LRV) (E.D. Va.), granted around February 27, 2026, with the Attorney General's appeal docketed at the Fourth Circuit on March 3, 2026.

Section 59.1-577.1 is not catalogued here as its own instrument: neither the provision's text nor the appeal's current posture is verified against the court docket, and the citation above rests on the court's own memorandum opinion and secondary reporting.

Breach notification

Breach of personal information notification

Va. Code Ann. § 18.2-186.6official Virginia statute text, Title 18.2 Chapter 6, Code of Virginia

Commencement not set. Binds public and private bodies.

What this law does

An individual or entity that owns or licenses computerized data including personal information must disclose a breach of the security of the system to the Office of the Attorney General and any affected Virginia resident without unreasonable delay following discovery.

'Personal information' here (a Social Security, driver's license or state ID, passport, or military ID number, or a financial account number with an access code, each combined with a name) is narrower than VCDPA's 'personal data' and excludes information obtained from publicly available government records.

Unlike VCDPA, which bars a private plaintiff outright, this breach-notification chapter expressly preserves an individual's right to recover direct economic damages for a violation of the notification duty. This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Comprehensive regime

Virginia Consumer Data Protection Act (VCDPA), general applicability and controller/processor duties

Va. Code Ann. §§ 59.1-575, 59.1-576, 59.1-578, 59.1-579official Virginia statute text, Title 59.1 Chapter 53, Code of Virginia

In force since 1 January 2023. Binds private bodies.

What this law does

VCDPA governs private-sector processing of Virginia residents' personal data. Enacted in the 2021 Special Session I (cc. 35, 36), effective January 1, 2023. Controllers need a lawful basis for processing outside disclosed purposes and opt-in consent for sensitive data; controller duties are allocated at section 59.1-578 and processor duties, including a required data-processing contract, at section 59.1-579.

A 2026 amendment (S.B. 338, Ch. 820) added a ban on the sale of precise geolocation data, effective July 1, 2026 and already reflected in the codified text.

What it requires

Data subject rights

Virginia Consumer Data Protection Act, consumer rights

Va. Code Ann. § 59.1-577official Virginia statute text, Title 59.1 Chapter 53, Code of Virginia

In force since 1 January 2023. Binds private bodies.

What this law does

VCDPA gives a Virginia consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects, exercisable against the controller.

A controller must respond without undue delay and within 45 days of receipt, with one 45-day extension available, and must answer an appeal of a denial within 60 days, with an option to escalate to the Attorney General.

What it requires

Enforcement supervision

Virginia Consumer Data Protection Act, Attorney General enforcement

Va. Code Ann. §§ 59.1-583, 59.1-584official Virginia statute text, Title 59.1 Chapter 53, Code of Virginia

In force since 1 January 2023. Binds private bodies.

What this law does

The Virginia Attorney General has exclusive authority to enforce VCDPA. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated; this cure right carries no sunset date in the text, unlike several peer states'. The Attorney General may seek an injunction and civil penalties of up to $7,500 per violation. The chapter creates no private right of action.

What it requires

Sensitive categories

Virginia Consumer Data Protection Act, sensitive data and biometric data definitions

Va. Code Ann. § 59.1-575official Virginia statute text, Title 59.1 Chapter 53, Code of Virginia

In force since 1 January 2023. Binds private bodies.

What this law does

VCDPA classifies the processing of genetic or biometric data to uniquely identify a person, along with racial or ethnic origin, religious belief, a mental or physical health diagnosis, sexual orientation, citizenship or immigration status, precise geolocation, and a known child's data, as sensitive data requiring prior opt-in consent.

'Biometric data' means data from automatic measurement of an individual's biological characteristics used to identify them, such as a fingerprint, voiceprint, or eye retina or iris pattern, but the definition carries a blanket, unconditional exclusion for a photograph, video or audio recording, or data generated from either, with no clawback for data generated to identify someone.

A faceprint or voiceprint extracted from a recording for identification purposes therefore falls outside both biometric data and sensitive data under this Act.

What it requires

Scraping law2 instruments, 2 in force

Research summary (165 words)

Virginia diverges from the federal baseline in two ways: its computer trespass statute is narrower than a bare without-authorization test, since it also requires malicious intent or intentionally deceptive means; and the Virginia Consumer Data Protection Act (VCDPA), the first comprehensive state privacy law in the country, was reported amended in 2026 to flatly ban the sale of precise geolocation data rather than merely requiring consent.

Copyright, text-and-data-mining, and database rights are federal only; Virginia adds nothing there. VCDPA's current codification runs from section 59.1-575 (Chapter 53's own definitions section) to section 59.1-584 (its enforcement section); section 59.1-571, sometimes cited as its start, is now the Humane and Toxin-Free Cosmetics Act's definitions section, and section 59.1-585 is a repealed placeholder.

ToS enforceability rests on ordinary Virginia contract law, expressly preserved by the computer trespass statute's own text; Virginia's Consumer Protection Act and common-law trespass to chattels are available in principle for unfair competition, untested against scraping specifically. robots.txt carries no independent legal weight in Virginia.

Computer misuse

Virginia Computer Trespass, malicious intent or deceptive means requirement

Va. Code Ann. § 18.2-152.4official text, Virginia Law (law.lis.virginia.gov)

In force since 1 July 1984. Binds public and private bodies.

What this law does

Section 18.2-152.4(A) makes it unlawful for any person, with malicious intent or through intentionally deceptive means and without authority, to remove, disable, alter, damage, or otherwise interfere with computer data, programs, software, or operation.

Unlike a bare without-authorization standard (the Computer Fraud and Abuse Act (CFAA)'s, and most peer states' own statutes), this section requires malicious intent or intentionally deceptive means in addition to lack of authority, so ordinary unauthenticated, non-deceptive, non-malicious automated access to a public page that performs none of the listed disruptive acts does not fit the statute's elements at all, regardless of authorization; this makes Virginia's statute narrower and more scraping-favorable on its face than a pure authorization test, though no Virginia case law was found applying it to a scraping or automated-collection fact pattern specifically.

Subsection (C) expressly states the statute is not to be construed to interfere with or prohibit terms or conditions in a contract or license related to computers or computer services, preserving ordinary contract law as the separate track for ToS enforcement; no Virginia case addresses browsewrap versus clickwrap for a scraping dispute specifically.

What it requires

Personal data

Virginia Consumer Data Protection Act (VCDPA)

Va. Code Ann. §§ 59.1-575 to 59.1-584official text, Virginia Law (law.lis.virginia.gov)

In force since 1 January 2023. Binds private bodies.

What this law does

VCDPA, the first comprehensive state consumer privacy law in the country, defines personal data to exclude de-identified data and publicly available information, meaning information lawfully made available through government records, or that a business has a reasonable basis to believe is lawfully made available to the general public through widely distributed media, by the consumer, or by a person to whom the consumer has disclosed the information, unless the consumer has restricted it to a specific audience; this reaches most scraped public personal data outside VCDPA's coverage at the definitional level.

Enforcement is by the Attorney General exclusively; the Act expressly states that nothing in it shall be construed as providing the basis for, or be subject to, a private right of action. This Act is sometimes cited as sections 59.1-571 to 59.1-585, which is wrong: section 59.1-571 is currently the definitions section of the unrelated Humane and Toxin-Free Cosmetics Act (Title 59.1, Chapter 52), and section 59.1-585 is a repealed placeholder.

VCDPA's actual current codification, confirmed directly against the official Virginia Law site, runs from section 59.1-575 (Chapter 53's own definitions section) to section 59.1-584 (its enforcement section).

In 2026, the General Assembly passed and Governor Spanberger signed SB 338 (signed April 13, 2026, effective July 1, 2026, per contemporaneous legal commentary), replacing VCDPA's prior consent-based treatment of precise geolocation as sensitive data with an outright ban on selling a consumer's precise geolocation data; the enrolled text of SB 338 is not reproduced in the official code copy cited here, so its effective date and exact mechanism rest on that commentary.

What it requires

Age gating law2 instruments, 1 in force, 1 repealed, withdrawn or blocked

Research summary (140 words)

Virginia has required age verification for websites where a substantial portion of content is material harmful to minors since July 1, 2023, a law that predates and survived the 2025 U.S. Supreme Court ruling in Free Speech Coalition v. Paxton upholding similar state laws.

A 2025 law requiring social media platforms to screen for minors under 16 and cap their daily use at one hour was set to take effect January 1, 2026, but a federal court granted NetChoice a preliminary injunction in February 2026, and the state's appeal is pending at the Fourth Circuit. An App Store Accountability Act (SB 237, HB 757) was introduced in the 2026 General Assembly session but did not complete passage; HB 757 was continued to the next session in committee in February 2026. Virginia has not enacted a standalone age appropriate design code.

Adult content age verification (AV)

SB 1515 (2023), civil liability for Internet publication of material harmful to minors

Va. Code § 8.01-40.5 (2023 Va. Acts c. 811)official Code of Virginia text

In force since 1 July 2023. Binds private bodies.

What this law does

Commercial entities that knowingly publish or distribute material harmful to minors on websites containing a substantial portion (more than one third) of such material must verify that visitors are at least 18 years old using a commercially available age verification database or another commercially reasonable method.

Note and primary source

Social media and minors

SB 854 (2025), social media platforms; responsibilities and prohibitions related to minors

Va. Code § 59.1-577.1 (2025 Va. Acts c. 703)official Code of Virginia text and federal court memorandum opinion

Enjoined: enforcement paused by a court, effective 1 January 2026. Binds private bodies.

What this law does

Amends the Virginia Consumer Data Protection Act to require social media platforms to use commercially reasonable methods, such as a neutral age screen, to determine whether a user is under 16, and to limit such minors to one hour of daily use per platform unless a parent gives verifiable consent to change the limit.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.