Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress does not determine whether the Virginia Consumer Data Protection Act (VCDPA) applies to your site. Applicability depends on the legal operator, whether the business conducts business in Virginia or targets Virginians, the amount and type of personal data processed, revenue from selling personal data, and available exemptions. Check that scope first, then map the site’s data flows and build the required notice, rights, vendor, security, and assessment processes.

Does the VCDPA apply to my WordPress site?

The VCDPA applies to a covered person that conducts business in Virginia or produces products or services targeted to Virginia residents and meets one of the statutory processing thresholds. The relevant subject is usually the business or other legal operator, not the WordPress installation itself. Review the current Virginia Code § 59.1-576 before making a final determination.

Threshold test

Route into scope What the statute says
General volume threshold Control or process personal data of at least 100,000 consumers during a calendar year.
Lower volume plus data-sale revenue Control or process personal data of at least 25,000 consumers during a calendar year and derive more than 50% of gross revenue from the sale of personal data.
Virginia connection Conduct business in the Commonwealth or produce products or services targeted to Virginia residents.

These are legal applicability criteria, not estimates of how many WordPress sites are covered. Count the Virginia consumers whose data the organization actually controls or processes, define the calendar year used, and document how the figures were calculated. A site that appears small in page views can still have substantial account, subscriber, customer, or prospect records; conversely, traffic alone does not establish that a threshold is met.

Exemptions are fact-specific

Section 59.1-576 includes entity-level exemptions for categories such as government bodies, certain financial institutions and related data, HIPAA-covered entities and business associates, nonprofits, and institutions of higher education. It also contains exemptions for particular data or processing. An organization may therefore have exempt data alongside nonexempt data. Do not treat “small business,” “uses WordPress,” or “has no Virginia office” as an automatic exemption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A practical scope decision

  1. Identify the legal entity or person operating the site and any related companies that determine processing purposes.
  2. Record products, services, advertising, or content that are offered to or intentionally targeted at Virginia residents.
  3. Estimate the number of Virginia consumers whose personal data is controlled or processed in the calendar year.
  4. If using the 25,000-consumer route, calculate the percentage of gross revenue derived from selling personal data and retain the accounting basis.
  5. Check each potentially applicable entity and data exemption with qualified counsel.

Map what your WordPress installation actually collects

Once scope is plausible, make a data inventory. The statute requires collection to be adequate, relevant, and reasonably necessary for disclosed purposes; compatible processing; a clear privacy notice; and secure, reliable ways to exercise rights. A WordPress-specific inventory is an implementation method inferred from those duties, not a checklist written into the statute. See § 59.1-578.

Inventory first-party collection

  • User registration, login, password-reset, and profile fields
  • Comments, reviews, forum posts, and moderation records
  • Contact, quote, support, newsletter, event, and download forms
  • Checkout, shipping, billing, order, subscription, and refund records
  • Site-search terms, uploaded files, and messages sent through WordPress

Inventory automated and connected collection

  • Hosting, server logs, security tools, backups, and error monitoring
  • Analytics, pixels, advertising tags, retargeting tools, and audience platforms
  • Video, map, social, payment, chat, CAPTCHA, font, and other embedded services
  • Email, customer relationship management, help-desk, fulfillment, and marketing integrations

For every source, record the data categories, purpose, retention, recipients, transfer or access method, and the person or vendor responsible. Follow the data beyond WordPress: a form submission may be copied into email, a CRM, analytics, backups, and a support platform.

Write a privacy notice from the real data map

Information the notice must cover

The notice must be reasonably accessible, clear, and meaningful. It should describe:

  • Categories of personal data processed
  • Purposes for processing each relevant category
  • Consumer rights and how to appeal a denied request
  • Categories of personal data shared with third parties and categories of those third parties
  • Secure and reliable methods for submitting requests

Do not copy generic WordPress boilerplate and assume it is accurate. Reconcile the notice with active plugins, tag-manager rules, forms, checkout settings, embedded content, and vendor contracts. If a purpose changes, determine whether the new processing is compatible with the disclosed purpose or whether consent is required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sensitive data and cookies

Sensitive data generally requires consent under the current statute, with a special rule for known children and the federal Children’s Online Privacy Protection Act (COPPA). Determine whether any form, account, membership, advertising, or support workflow collects sensitive data and document how consent is obtained and withdrawn.

The current Code page should control cookie and disclosure decisions. Do not import cookie-banner requirements from a 2024 bill or describe a banner as universally mandated by the VCDPA. A banner or consent tool is useful only if its configured behavior matches the site’s actual tags, embeds, purposes, and opt-out signals.

Handle Virginia consumer rights on a deadline

A covered controller must provide authenticated methods for requests to confirm processing and access personal data, correct inaccuracies, delete personal data provided by or obtained about a consumer, obtain a portable copy of data the consumer provided where processing is automated, and opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. The rights and timing rules are in § 59.1-577.

Requirement Operational meaning for a WordPress operator Statutory timing or limit
Initial response Verify identity proportionately, search WordPress and connected systems, and provide the required response or explain a denial. Generally within 45 days.
Extension Use only when reasonably necessary and explain it during the initial response period. One extension of up to 45 additional days.
Appeal Provide an appeal route when a request is denied and send the outcome with reasons. Respond within 60 days.
Contact after denied appeal Include a way for the consumer to contact the Virginia Attorney General when the appeal remains denied. Required with a denied appeal.
Fees Provide information without charge unless the statute’s rules for manifestly unfounded, excessive, or repetitive requests apply. Free up to twice annually per consumer, subject to statutory rules.

Build a repeatable request workflow

  1. Publish a dedicated privacy-request channel, such as a protected form or monitored email address, and explain available rights.
  2. Authenticate the requester using information proportionate to the risk; do not collect unnecessary identity documents.
  3. Log the received date, request type, identity-verification result, applicable deadline, and assigned owner.
  4. Search WordPress databases, media, orders, comments, backups where practical, and every relevant vendor or integration.
  5. Apply lawful exceptions, make the correction, deletion, export, or opt-out change, and record what was done.
  6. Respond in the required period. If denying any part, state the reason and provide appeal instructions.
  7. Track appeals separately, coordinate any vendor changes, and retain an audit record of the outcome.

The statute does not require a particular WordPress plugin, form layout, or ticketing product. The operator remains responsible for accurate searches, authentication, coordination, and deadline control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Classify vendors and review processor contracts

WordPress labels do not determine whether a provider is a processor, third party, or another role. Classify each relationship from the actual data flow and the parties’ decisions about purposes and means. Hosting, analytics, email, forms, advertising, payment, commerce, security, and embedded-service providers may have different roles in the same installation.

Processor contract essentials

Under § 59.1-579, a processor acts on the controller’s instructions. A binding contract should specify:

  • Documented processing instructions, nature and purpose, data types, and duration
  • The parties’ rights and obligations
  • Confidentiality requirements for people handling the data
  • Assistance with consumer-rights requests, security and breach duties, assessments, and reasonable compliance inquiries
  • Deletion or return of personal data when services end, unless law requires retention

Maintain a vendor register linking each provider to the data categories it receives, the contract or terms governing it, retention settings, subprocessors where known, and a practical route for fulfilling a consumer request.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Determine whether a data protection assessment is required

Documented data protection assessments are required for processing created or generated after January 1, 2023, when it involves targeted advertising, sale of personal data, specified high-risk profiling, sensitive data, or another activity presenting a heightened risk of harm. The current assessment provisions appear in § 59.1-580.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an assessment should examine

  • Direct and indirect benefits to the controller, consumer, other stakeholders, and the public
  • Risks to consumer rights and the likelihood and severity of foreseeable harm
  • Safeguards, de-identification, data minimization, access controls, and retention limits
  • Consumer expectations, the processing context, and the relationship between the parties

A single assessment may cover comparable operations. Keep the assessment confidential and available if the Attorney General requests it. The statutory requirement is not retroactive to every historical activity, but new or materially changed processing should be screened before launch.

What a WordPress compliance tool can—and cannot—prove

A consent, privacy, security, or rights-request plugin may help display notices, record choices, route requests, or change tags. It cannot decide whether the organization meets the VCDPA threshold, identify every data flow, negotiate processor terms, perform a legally sufficient assessment, or guarantee that a configuration behaves correctly.

Before relying on any tool, test the actual site in logged-in and logged-out states and document:

  • Which scripts, pixels, embeds, and cookies load before and after a choice
  • Whether an opt-out reaches each advertising, sale, or profiling vendor
  • Whether request records are authenticated, timestamped, searchable, and exportable
  • Whether deletion, correction, and suppression actions propagate to connected systems
  • Whether the notice matches the categories, purposes, recipients, and retention actually observed

No WordPress-specific setup or product, by itself, is evidence of compliance. Evidence comes from the operator’s scope analysis, data inventory, notice, contracts, rights records, security measures, assessments, and tested configurations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep the program current

Virginia Code pages used for this guide showed updates in 2026, and statutory language can change. Recheck the live official sections—especially scope, rights, controller duties, processor duties, and assessments—when launching a new data use or revising the program. For a business-specific applicability, exemption, contract, or interpretation question, obtain advice from a qualified privacy lawyer.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.