#
No comprehensive statute defines material or territorial scope; regulator authority is general consumer-protection power, not a privacy-specific mandate.
Sub-modules (5)
Regulator And AuthorityAmber
The West Virginia Attorney General enforces the state breach-notification statute and exercises general consumer-protection authority; no dedicated DPA exists.
Claims (2):
- The West Virginia Attorney General is the primary state authority exercising consumer-protection powers relevant to data-privacy matters in West Virginia.
- The FTC's Section 5 unfair/deceptive-practices authority under the FTC Act applies nationally, including to West Virginia, as the primary federal privacy-enforcement backstop.
Act And InstrumentsRed
The operative state instrument is the Breach of Security of Consumer Information statute; no omnibus privacy act exists despite repeated legislative attempts.
Claims (2):
- West Virginia's Breach of Security of Consumer Information statute (W. Va. Code Chapter 46A, Article 2A, §46A-2A-101 et seq.) is the state's only codified data-protection-adjacent instrument.
- Multiple comprehensive consumer-data-protection bills have been introduced in the West Virginia Legislature (e.g., HB 3159 in 2021 and HB 3498 in 2023) but none has been enacted into law.
Material ScopeRed
Material scope is limited to the narrow 'personal information' definition used for breach-notification purposes (e.g., SSN, driver's license/state ID, financial account numbers with access codes); there is no broader definition of 'personal data' as in omnibus regimes.
Claims (1):
- State breach-notification statutes, including West Virginia's, define 'personal information' narrowly around identity-theft and financial-fraud data elements rather than the broad 'personal data' concept used in comprehensive privacy regimes.
Territorial ScopeAmber
No state statute articulates extraterritorial application; the breach law applies functionally to any entity holding computerized personal information of West Virginia residents, consistent with the general pattern across US state breach statutes.
Claims (1):
- West Virginia has no statute articulating extraterritorial/non-established-controller application analogous to GDPR Article 3; applicability is inferred functionally from residency of affected individuals under the breach statute.
Regulator Registration And FilingRed
No controller/processor registration or filing obligation exists in West Virginia absent a comprehensive privacy statute.
Claims (1):
- West Virginia imposes no controller or processor registration/filing obligation for data-processing activities.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (7)
- ConfirmedNAAG — The West Virginia Attorney General is the primary state authority exercising consumer-protection powers relevant to data-privacy matters in West Virginia.observed
- ConfirmedFederal Trade Commission — The FTC's Section 5 unfair/deceptive-practices authority under the FTC Act applies nationally, including to West Virginia, as the primary federal privacy-enforcement backstop.observed
- ConfirmedDataGuidance / OneTrust — West Virginia's Breach of Security of Consumer Information statute (W. Va. Code Chapter 46A, Article 2A, §46A-2A-101 et seq.) is the state's only codified data-protection-adjacent instrument.observed
- ConfirmedDataGuidance / OneTrust — Multiple comprehensive consumer-data-protection bills have been introduced in the West Virginia Legislature (e.g., HB 3159 in 2021 and HB 3498 in 2023) but none has been enacted into law.observed
- ProbableIAPP — State breach-notification statutes, including West Virginia's, define 'personal information' narrowly around identity-theft and financial-fraud data elements rather than the broad 'personal data' concept used in comprehensive privacy regimes.observed
- UncertainDataGuidance / OneTrust — West Virginia has no statute articulating extraterritorial/non-established-controller application analogous to GDPR Article 3; applicability is inferred functionally from residency of affected individuals under the breach statute.observed
- ConfirmedIAPP — West Virginia imposes no controller or processor registration/filing obligation for data-processing activities.observed