Latest update · 28 September 2026
Lead Signal
Virginia amended its Consumer Data Protection Act twice this cycle in narrow, targeted directions rather than through a wholesale statutory rewrite. SB338, signed by Governor Spanberger on April 13, 2026, amends the VCDPA to prohibit controllers of personal data from selling, or offering to sell, consumers' precise geolocation data, making Virginia the third US state to enact such a ban. Separately, SB854, in force since January 1, 2026, requires social media platforms to deploy commercially reasonable methods, such as a neutral age-screening mechanism, to determine whether a user is under 16, and to limit such users' platform use absent verifiable parental consent adjusting that limit.
Both developments tighten the VCDPA's commercial-privacy and children's-data perimeter, though SB854 is understood to be the subject of active NetChoice litigation challenging it on First Amendment and Commerce Clause grounds, and the current procedural posture of that litigation was not resolved this cycle.
Other Developments
Enforcement-expanding bills continue to fail to advance. Two bills that would have expanded Virginia's privacy-enforcement or consumer-protection perimeter were both continued to the next session rather than enacted in 2026. SB237 and its House companion HB757, the App Store Accountability Act, which would have required app-store-level age verification and parental consent, were both continued to next session rather than enacted. SB615, which would have amended the VCDPA to prohibit certain online device-based pricing practices, was also continued to the next session in the General Laws and Technology committee on a 15-0 vote.
Standing enforcement architecture unchanged. The VCDPA continues to be enforced exclusively by the Virginia Attorney General, with civil penalties of $7,500 per violation, a permanent 30-day cure period, and no private right of action. Virginia's cure period is understood to be permanent, distinguishing it from several peer states, including Colorado, Connecticut, Oregon, and Montana, that have expired or eliminated theirs.
Cross-Monitor Connections
The App Store Accountability Act's proposed age-verification and parental-consent requirements, had SB237/HB757 advanced, would have intersected with children's-safety themes tracked more broadly by the advennt monitor's consumer-protection and player-protection coverage for age-gating mechanisms generally; this link is noted for context only, not analysed further here. No financial-integrity, world-payments, or crypto cross-reference applies to this cycle's Virginia privacy developments.
Outlook
The procedural posture of the NetChoice litigation challenging SB854 is the most consequential open item for Virginia's children's-privacy regime; its resolution will determine whether the age-screening and screen-time provisions remain enforceable as enacted. Separately, whether SB237/HB757 and SB615 are reintroduced and advance in the 2027 session will indicate whether Virginia's pattern of narrow, targeted VCDPA amendments continues or gives way to broader enforcement-expanding legislation.
Standing brief · as of 26 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
On April 13, 2026, Governor Spanberger signed SB338 into law, amending the Virginia Consumer Data Protection Act to prohibit controllers from selling consumers' precise geolocation data, effective July 1, 2026. The prohibition is structured as an absolute bar rather than a consent gate: a controller shall not sell or offer for sale precise geolocation data concerning a consumer. "Precise geolocation data" is defined by the statute as information derived from technology that directly identifies a person's specific location within a radius of 1,750 feet. The statute also layers a child-specific requirement onto the existing known-child consent framework: controllers must provide known children a persistent signal indicating collection of precise geolocation data, and no controller may engage in such collection from a known child absent parental consent under COPPA. Both the sale-prohibition provision and the underlying statutory definition are sourced to a Tier 1 primary source, the enrolled SB338 text and the Virginia Legislative Information System respectively, and are stated here at High confidence and assertive framing accordingly.
Other Developments
A second, separately enacted statute reached its commencement date this cycle. SB854, which restricts social media use by users under 16 to one hour per day, commenced January 1, 2026. It is understood, rather than independently re-confirmed this cycle, that SB854's underlying commencement details trace to a Tier 3 secondary legislative-history source; the statute is reported to require social media platforms to deploy commercially reasonable methods, such as neutral age-screening mechanisms, to assess whether a user is under 16, and if so to limit that user's service access to one hour per day. Parents may adjust this limit upward or downward by providing verifiable parental consent. The Virginia Attorney General remains the sole enforcement authority for the VCDPA and its amendments generally, since Virginia has no dedicated data-protection authority of its own.
SB338's new controller duty extends into the adtech and commercial-privacy space directly. Because precise geolocation data of the kind SB338 addresses is a common data category in cross-context behavioral advertising, the absolute sale prohibition constrains a specific advertising-adjacent data flow that VCDPA's general consent-based framework had previously governed only through opt-out rights rather than an outright bar.
SB854 is now under active constitutional challenge. NetChoice sued the Virginia Attorney General, claiming SB854 violates the First Amendment and the Commerce Clause. This litigation creates material near-term enforceability uncertainty for what is, on its face, Virginia's most significant new child-safety obligation this cycle, independent of the statute's substantive merits.
Cross-Monitor Connections
The Chapter 19.1 money-transmission statute that reset Virginia's payments-licensing perimeter this cycle is tracked by the World Payments Monitor and the Financial Integrity Monitor under their own respective spines; whether that statute creates any new data-sharing or KYC-retention obligation relevant to VCDPA controller-processor duties has not been assessed here and is logged as an open question for a future cycle.
Outlook
The NetChoice litigation against SB854 is the single most consequential item to watch: whether a court grants preliminary relief, and on what constitutional theory, will determine whether Virginia's one-hour-per-day minors' social-media limit remains enforceable in its current form. On the SB338 side, the July 1, 2026 effective date has already passed as of this cycle's assessment window, meaning the absolute geolocation-sale prohibition and its associated known-child persistent-signal requirement are now live obligations for controllers doing business in Virginia. Compliance teams should also track whether any interim enforcement guidance from the Attorney General's office addresses how the SB338 absolute sale prohibition interacts with the VCDPA's pre-existing consent-based sale provisions for other, non-geolocation data categories.