WordPress does not determine whether the Virginia Consumer Data Protection Act (VCDPA) applies to your site. Applicability depends on the legal operator, whether the business conducts business in Virginia or targets Virginians, the amount and type of personal data processed, revenue from selling personal data, and available exemptions. Check that scope first, then map the site’s data flows and build the required notice, rights, vendor, security, and assessment processes.
Does the VCDPA apply to my WordPress site?
The VCDPA applies to a covered person that conducts business in Virginia or produces products or services targeted to Virginia residents and meets one of the statutory processing thresholds. The relevant subject is usually the business or other legal operator, not the WordPress installation itself. Review the current Virginia Code § 59.1-576 before making a final determination.
Threshold test
| Route into scope | What the statute says |
|---|---|
| General volume threshold | Control or process personal data of at least 100,000 consumers during a calendar year. |
| Lower volume plus data-sale revenue | Control or process personal data of at least 25,000 consumers during a calendar year and derive more than 50% of gross revenue from the sale of personal data. |
| Virginia connection | Conduct business in the Commonwealth or produce products or services targeted to Virginia residents. |
These are legal applicability criteria, not estimates of how many WordPress sites are covered. Count the Virginia consumers whose data the organization actually controls or processes, define the calendar year used, and document how the figures were calculated. A site that appears small in page views can still have substantial account, subscriber, customer, or prospect records; conversely, traffic alone does not establish that a threshold is met.
Exemptions are fact-specific
Section 59.1-576 includes entity-level exemptions for categories such as government bodies, certain financial institutions and related data, HIPAA-covered entities and business associates, nonprofits, and institutions of higher education. It also contains exemptions for particular data or processing. An organization may therefore have exempt data alongside nonexempt data. Do not treat “small business,” “uses WordPress,” or “has no Virginia office” as an automatic exemption.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
A practical scope decision
- Identify the legal entity or person operating the site and any related companies that determine processing purposes.
- Record products, services, advertising, or content that are offered to or intentionally targeted at Virginia residents.
- Estimate the number of Virginia consumers whose personal data is controlled or processed in the calendar year.
- If using the 25,000-consumer route, calculate the percentage of gross revenue derived from selling personal data and retain the accounting basis.
- Check each potentially applicable entity and data exemption with qualified counsel.
Map what your WordPress installation actually collects
Once scope is plausible, make a data inventory. The statute requires collection to be adequate, relevant, and reasonably necessary for disclosed purposes; compatible processing; a clear privacy notice; and secure, reliable ways to exercise rights. A WordPress-specific inventory is an implementation method inferred from those duties, not a checklist written into the statute. See § 59.1-578.
Inventory first-party collection
- User registration, login, password-reset, and profile fields
- Comments, reviews, forum posts, and moderation records
- Contact, quote, support, newsletter, event, and download forms
- Checkout, shipping, billing, order, subscription, and refund records
- Site-search terms, uploaded files, and messages sent through WordPress
Inventory automated and connected collection
- Hosting, server logs, security tools, backups, and error monitoring
- Analytics, pixels, advertising tags, retargeting tools, and audience platforms
- Video, map, social, payment, chat, CAPTCHA, font, and other embedded services
- Email, customer relationship management, help-desk, fulfillment, and marketing integrations
For every source, record the data categories, purpose, retention, recipients, transfer or access method, and the person or vendor responsible. Follow the data beyond WordPress: a form submission may be copied into email, a CRM, analytics, backups, and a support platform.
Write a privacy notice from the real data map
Information the notice must cover
The notice must be reasonably accessible, clear, and meaningful. It should describe:
Rank #2
- Categories of personal data processed
- Purposes for processing each relevant category
- Consumer rights and how to appeal a denied request
- Categories of personal data shared with third parties and categories of those third parties
- Secure and reliable methods for submitting requests
Do not copy generic WordPress boilerplate and assume it is accurate. Reconcile the notice with active plugins, tag-manager rules, forms, checkout settings, embedded content, and vendor contracts. If a purpose changes, determine whether the new processing is compatible with the disclosed purpose or whether consent is required.
Recommended Free Tools
Sensitive data and cookies
Sensitive data generally requires consent under the current statute, with a special rule for known children and the federal Children’s Online Privacy Protection Act (COPPA). Determine whether any form, account, membership, advertising, or support workflow collects sensitive data and document how consent is obtained and withdrawn.
The current Code page should control cookie and disclosure decisions. Do not import cookie-banner requirements from a 2024 bill or describe a banner as universally mandated by the VCDPA. A banner or consent tool is useful only if its configured behavior matches the site’s actual tags, embeds, purposes, and opt-out signals.
Handle Virginia consumer rights on a deadline
A covered controller must provide authenticated methods for requests to confirm processing and access personal data, correct inaccuracies, delete personal data provided by or obtained about a consumer, obtain a portable copy of data the consumer provided where processing is automated, and opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. The rights and timing rules are in § 59.1-577.
| Requirement | Operational meaning for a WordPress operator | Statutory timing or limit |
|---|---|---|
| Initial response | Verify identity proportionately, search WordPress and connected systems, and provide the required response or explain a denial. | Generally within 45 days. |
| Extension | Use only when reasonably necessary and explain it during the initial response period. | One extension of up to 45 additional days. |
| Appeal | Provide an appeal route when a request is denied and send the outcome with reasons. | Respond within 60 days. |
| Contact after denied appeal | Include a way for the consumer to contact the Virginia Attorney General when the appeal remains denied. | Required with a denied appeal. |
| Fees | Provide information without charge unless the statute’s rules for manifestly unfounded, excessive, or repetitive requests apply. | Free up to twice annually per consumer, subject to statutory rules. |
Build a repeatable request workflow
- Publish a dedicated privacy-request channel, such as a protected form or monitored email address, and explain available rights.
- Authenticate the requester using information proportionate to the risk; do not collect unnecessary identity documents.
- Log the received date, request type, identity-verification result, applicable deadline, and assigned owner.
- Search WordPress databases, media, orders, comments, backups where practical, and every relevant vendor or integration.
- Apply lawful exceptions, make the correction, deletion, export, or opt-out change, and record what was done.
- Respond in the required period. If denying any part, state the reason and provide appeal instructions.
- Track appeals separately, coordinate any vendor changes, and retain an audit record of the outcome.
The statute does not require a particular WordPress plugin, form layout, or ticketing product. The operator remains responsible for accurate searches, authentication, coordination, and deadline control.
Classify vendors and review processor contracts
WordPress labels do not determine whether a provider is a processor, third party, or another role. Classify each relationship from the actual data flow and the parties’ decisions about purposes and means. Hosting, analytics, email, forms, advertising, payment, commerce, security, and embedded-service providers may have different roles in the same installation.
Processor contract essentials
Under § 59.1-579, a processor acts on the controller’s instructions. A binding contract should specify:
Rank #4
- Documented processing instructions, nature and purpose, data types, and duration
- The parties’ rights and obligations
- Confidentiality requirements for people handling the data
- Assistance with consumer-rights requests, security and breach duties, assessments, and reasonable compliance inquiries
- Deletion or return of personal data when services end, unless law requires retention
Maintain a vendor register linking each provider to the data categories it receives, the contract or terms governing it, retention settings, subprocessors where known, and a practical route for fulfilling a consumer request.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Determine whether a data protection assessment is required
Documented data protection assessments are required for processing created or generated after January 1, 2023, when it involves targeted advertising, sale of personal data, specified high-risk profiling, sensitive data, or another activity presenting a heightened risk of harm. The current assessment provisions appear in § 59.1-580.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What an assessment should examine
- Direct and indirect benefits to the controller, consumer, other stakeholders, and the public
- Risks to consumer rights and the likelihood and severity of foreseeable harm
- Safeguards, de-identification, data minimization, access controls, and retention limits
- Consumer expectations, the processing context, and the relationship between the parties
A single assessment may cover comparable operations. Keep the assessment confidential and available if the Attorney General requests it. The statutory requirement is not retroactive to every historical activity, but new or materially changed processing should be screened before launch.
Best Value
What a WordPress compliance tool can—and cannot—prove
A consent, privacy, security, or rights-request plugin may help display notices, record choices, route requests, or change tags. It cannot decide whether the organization meets the VCDPA threshold, identify every data flow, negotiate processor terms, perform a legally sufficient assessment, or guarantee that a configuration behaves correctly.
Before relying on any tool, test the actual site in logged-in and logged-out states and document:
- Which scripts, pixels, embeds, and cookies load before and after a choice
- Whether an opt-out reaches each advertising, sale, or profiling vendor
- Whether request records are authenticated, timestamped, searchable, and exportable
- Whether deletion, correction, and suppression actions propagate to connected systems
- Whether the notice matches the categories, purposes, recipients, and retention actually observed
No WordPress-specific setup or product, by itself, is evidence of compliance. Evidence comes from the operator’s scope analysis, data inventory, notice, contracts, rights records, security measures, assessments, and tested configurations.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesKeep the program current
Virginia Code pages used for this guide showed updates in 2026, and statutory language can change. Recheck the live official sections—especially scope, rights, controller duties, processor duties, and assessments—when launching a new data use or revising the program. For a business-specific applicability, exemption, contract, or interpretation question, obtain advice from a qualified privacy lawyer.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

