🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-WV v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing19 sources retrieved model claude-sonnet-5 · 2026-08-06

West Virginia, USA

US-WV schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 41 claims · 30 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

West Virginia has enacted an enhanced due-diligence mandate targeting elder-fraud prevention for virtual-currency kiosk operators, arriving as part of the broader House Bill 5353 kiosk-licensure reform rather than as a standalone data-protection instrument. Reports indicate the mandate requires kiosk operators to implement a due-diligence process aimed at detecting and preventing fraud targeting elder adults in kiosk transactions, with the obligation becoming effective January 1, 2027 alongside the reform's money-transmission licensure provisions. This is a consumer-protection-adjacent development rather than a data-protection-native one; it sits in the Children and Vulnerable Groups module because it targets a vulnerable population, but its substance is a fraud-prevention control layered on a payments statute rather than a privacy right, processing basis, or data-subject entitlement.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive statute defines material or territorial scope; regulator authority is general consumer-protection power, not a privacy-specific mandate.

Primary frameworkFTC Act Section 5 (federal baseline) + W. Va. Code Chapter 46A, Article 2A (breach notification only)
Supervisory authorityWest Virginia Attorney General
Traffic-light rationale — RedNo comprehensive statute defines material or territorial scope; regulator authority is general consumer-protection power, not a privacy-specific mandate.

Sub-modules (5)

Regulator And AuthorityAmber

The West Virginia Attorney General enforces the state breach-notification statute and exercises general consumer-protection authority; no dedicated DPA exists.

Claims (2):

  • The West Virginia Attorney General is the primary state authority exercising consumer-protection powers relevant to data-privacy matters in West Virginia.
  • The FTC's Section 5 unfair/deceptive-practices authority under the FTC Act applies nationally, including to West Virginia, as the primary federal privacy-enforcement backstop.

Act And InstrumentsRed

The operative state instrument is the Breach of Security of Consumer Information statute; no omnibus privacy act exists despite repeated legislative attempts.

Claims (2):

  • West Virginia's Breach of Security of Consumer Information statute (W. Va. Code Chapter 46A, Article 2A, §46A-2A-101 et seq.) is the state's only codified data-protection-adjacent instrument.
  • Multiple comprehensive consumer-data-protection bills have been introduced in the West Virginia Legislature (e.g., HB 3159 in 2021 and HB 3498 in 2023) but none has been enacted into law.

Material ScopeRed

Material scope is limited to the narrow 'personal information' definition used for breach-notification purposes (e.g., SSN, driver's license/state ID, financial account numbers with access codes); there is no broader definition of 'personal data' as in omnibus regimes.

Claims (1):

  • State breach-notification statutes, including West Virginia's, define 'personal information' narrowly around identity-theft and financial-fraud data elements rather than the broad 'personal data' concept used in comprehensive privacy regimes.

Territorial ScopeAmber

No state statute articulates extraterritorial application; the breach law applies functionally to any entity holding computerized personal information of West Virginia residents, consistent with the general pattern across US state breach statutes.

Claims (1):

  • West Virginia has no statute articulating extraterritorial/non-established-controller application analogous to GDPR Article 3; applicability is inferred functionally from residency of affected individuals under the breach statute.

Regulator Registration And FilingRed

No controller/processor registration or filing obligation exists in West Virginia absent a comprehensive privacy statute.

Claims (1):

  • West Virginia imposes no controller or processor registration/filing obligation for data-processing activities.
Category narrative67 words

West Virginia has no dedicated data-protection authority. Privacy-adjacent enforcement rests with the West Virginia Attorney General's Consumer Protection function acting under general state consumer-protection powers, overlaid by the FTC's Section 5 unfair/deceptive-practices authority at the federal level. The only state-specific codified instrument is the breach-of-security-of-consumer-information statute (W. Va. Code Ch. 46A, Art. 2A); there is no omnibus material-scope or territorial-scope definition, and no controller registration/filing regime exists.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedNAAG — The West Virginia Attorney General is the primary state authority exercising consumer-protection powers relevant to data-privacy matters in West Virginia.observed
  2. ConfirmedFederal Trade Commission — The FTC's Section 5 unfair/deceptive-practices authority under the FTC Act applies nationally, including to West Virginia, as the primary federal privacy-enforcement backstop.observed
  3. ConfirmedDataGuidance / OneTrust — West Virginia's Breach of Security of Consumer Information statute (W. Va. Code Chapter 46A, Article 2A, §46A-2A-101 et seq.) is the state's only codified data-protection-adjacent instrument.observed
  4. ConfirmedDataGuidance / OneTrust — Multiple comprehensive consumer-data-protection bills have been introduced in the West Virginia Legislature (e.g., HB 3159 in 2021 and HB 3498 in 2023) but none has been enacted into law.observed
  5. ProbableIAPP — State breach-notification statutes, including West Virginia's, define 'personal information' narrowly around identity-theft and financial-fraud data elements rather than the broad 'personal data' concept used in comprehensive privacy regimes.observed
  6. UncertainDataGuidance / OneTrust — West Virginia has no statute articulating extraterritorial/non-established-controller application analogous to GDPR Article 3; applicability is inferred functionally from residency of affected individuals under the breach statute.observed
  7. ConfirmedIAPP — West Virginia imposes no controller or processor registration/filing obligation for data-processing activities.observed

#

Absence of any general lawful-basis or special-category statute at state level; coverage is entirely sector-federal.

Primary frameworkHIPAA / GLBA / COPPA (federal sectoral overlays only)
Traffic-light rationale — RedAbsence of any general lawful-basis or special-category statute at state level; coverage is entirely sector-federal.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases for processing exist under West Virginia law; no general processing-lawfulness statute has been enacted.

Claims (1):

  • West Virginia has not enacted a general statute enumerating lawful bases for personal-data processing.

Special CategoriesRed

No state special/sensitive-category data statute exists (health, biometric, genetic, etc. are addressed only through sector-specific federal law or unenacted state bills).

Claims (1):

  • A West Virginia bill relating to genetic information privacy was introduced in 2023 but has not been enacted, leaving genetic data without dedicated state-law protection.

Pseudonymisation And AnonymisationRed

No statutory definition or safe-harbour for pseudonymised or anonymised data exists in West Virginia law.

Claims (1):

  • No West Virginia statute defines pseudonymisation or anonymisation or provides an associated compliance safe-harbour.
Category narrative48 words

West Virginia has no general lawful-basis regime, consent standard, or special-category framework analogous to GDPR Articles 6, 7 and 9. Consent and sensitive-data rules apply only through federal sectoral overlays (HIPAA for health data, GLBA for financial data, COPPA for children's data). No state pseudonymisation/anonymisation safe harbour exists.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedIAPP — West Virginia has not enacted a general statute enumerating lawful bases for personal-data processing.observed
  2. ConfirmedHHS — Consent obligations applicable to entities operating in West Virginia derive from federal sectoral statutes (HIPAA, GLBA, COPPA) rather than a state-level consent standard.observed
  3. ConfirmedDataGuidance / OneTrust — A West Virginia bill relating to genetic information privacy was introduced in 2023 but has not been enacted, leaving genetic data without dedicated state-law protection.observed
  4. UncertainIAPP — No West Virginia statute defines pseudonymisation or anonymisation or provides an associated compliance safe-harbour.observed

#

No enacted data-subject-rights framework exists; only unenacted legislative proposals.

Traffic-light rationale — RedNo enacted data-subject-rights framework exists; only unenacted legislative proposals.

Sub-modules (5)

Access RightRed

No enacted state-law access right; proposed in unenacted bills only.

Claims (1):

  • West Virginia House Bill 3159 (2021) proposed a consumer right to request a copy of personal data collected, but was not enacted.

Rectification And ErasureRed

No enacted correction/deletion right exists at state level.

Claims (1):

  • West Virginia House Bill 3159 (2021) proposed rights to have personal information deleted or corrected, but the bill did not become law.

Restriction And ObjectionRed

No restriction-of-processing or objection/profiling opt-out right exists under West Virginia law.

Data PortabilityRed

No portability right exists under West Virginia law.

Deadlines And Response WindowsRed

No statutory response-window applies to privacy requests since no underlying rights framework exists; only breach-notification timing applies (see controller_processor_duties.breach_notification).

Claims (1):

  • In the absence of an enacted comprehensive privacy statute, no statutory deadline governs controller responses to consumer privacy requests in West Virginia.
Category narrative52 words

West Virginia confers no statutory consumer rights of access, rectification, erasure, restriction, objection or portability. Several bills (HB 3159/2021, HB 3498/2023) that would have created such rights were introduced but did not pass into law, consistent with West Virginia's absence from the list of 19 US states with enacted comprehensive privacy statutes.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedDataGuidance / OneTrust — West Virginia House Bill 3159 (2021) proposed a consumer right to request a copy of personal data collected, but was not enacted.observed
  2. ConfirmedDataGuidance / OneTrust — West Virginia House Bill 3159 (2021) proposed rights to have personal information deleted or corrected, but the bill did not become law.observed
  3. ConfirmedIAPP — In the absence of an enacted comprehensive privacy statute, no statutory deadline governs controller responses to consumer privacy requests in West Virginia.observed

#

Breach notification is a live, binding, in-force obligation (materiality 5), but all other controller/processor duties are absent at state level.

Primary frameworkW. Va. Code Chapter 46A, Article 2A (breach notification) + HIPAA/GLBA security rules
Supervisory authorityWest Virginia Attorney General
Traffic-light rationale — AmberBreach notification is a live, binding, in-force obligation (materiality 5), but all other controller/processor duties are absent at state level.

Sub-modules (7)

Accountability And DpiaRed

No accountability principle or DPIA-trigger requirement exists under West Virginia state law.

Claims (1):

  • West Virginia has not enacted an accountability principle or DPIA-trigger requirement analogous to GDPR Articles 5, 25 and 35.

Dpo RequirementsRed

No DPO appointment threshold exists under West Virginia law.

Ropa RequirementsRed

No records-of-processing obligation exists under West Virginia law.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists under West Virginia law.

Security MeasuresAmber

Technical and organisational security-of-processing obligations apply to West Virginia entities only through sector-specific federal law (HIPAA Security Rule for PHI; GLBA Safeguards Rule for financial institutions).

Claims (1):

  • The GLBA Safeguards Rule requires financial institutions operating in West Virginia to maintain a comprehensive information-security program protecting nonpublic personal information, and the HIPAA Security Rule imposes analogous obligations on covered health entities.

Breach NotificationGreen

W. Va. Code Chapter 46A, Article 2A imposes a binding breach-notification duty on entities holding computerized personal information of West Virginia residents, generally following the common US-state pattern of notice to affected residents (and, above a numeric threshold, to the Attorney General and consumer reporting agencies).

Claims (1):

  • West Virginia's Breach of Security of Consumer Information statute (W. Va. Code Chapter 46A, Article 2A) requires notification to affected residents following unauthorized acquisition of computerized personal information, consistent with the nationwide pattern of state breach-notice laws now enacted in all 50 states.

Retention And DisposalAmber

No general state-law retention limit exists; retention/disposal duties apply only via sectoral federal rules (e.g., HIPAA, GLBA record-keeping requirements).

Claims (1):

  • No general West Virginia state statute imposes a retention limit or disposal duty on personal data outside sector-specific federal rules.
Category narrative48 words

West Virginia's only enacted controller duty of general applicability is breach notification under W. Va. Code Chapter 46A, Article 2A. Security-of-processing obligations exist only through sectoral federal law (HIPAA Security Rule, GLBA Safeguards Rule). No DPIA, DPO, ROPA, joint-controller, or general retention/disposal duties are imposed by state statute.

Sources and claims (4)
  1. ConfirmedIAPP — West Virginia has not enacted an accountability principle or DPIA-trigger requirement analogous to GDPR Articles 5, 25 and 35.observed
  2. ConfirmedFederal Trade Commission — The GLBA Safeguards Rule requires financial institutions operating in West Virginia to maintain a comprehensive information-security program protecting nonpublic personal information, and the HIPAA Security Rule imposes analogous obligations on covered health entities.observed
  3. ProbableDataGuidance / OneTrust — West Virginia's Breach of Security of Consumer Information statute (W. Va. Code Chapter 46A, Article 2A) requires notification to affected residents following unauthorized acquisition of computerized personal information, consistent with the nationwide pattern of state breach-notice laws now enacted in all 50 states.observed
  4. UncertainIAPP — No general West Virginia state statute imposes a retention limit or disposal duty on personal data outside sector-specific federal rules.observed

#

No transfer-mechanism or localisation regime exists; this module is structurally inapplicable absent a comprehensive state or federal transfer-restriction statute.

Traffic-light rationale — RedNo transfer-mechanism or localisation regime exists; this module is structurally inapplicable absent a comprehensive state or federal transfer-restriction statute.

Sub-modules (6)

Transfer MechanismsRed

No state-law transfer mechanism (adequacy, SCCs, BCRs, derogations) exists; cross-border flows are governed only by general federal sectoral rules where applicable (e.g., GLBA, HIPAA cross-border considerations).

Claims (1):

  • West Virginia has not enacted any statute establishing a cross-border data-transfer mechanism analogous to GDPR Chapter V.

Adequacy ReceivedRed

West Virginia, as a US state, is not a subject of any foreign adequacy determination.

Adequacy GrantedRed

West Virginia has no authority to grant adequacy status to other jurisdictions.

Sccs And BcrsRed

No SCC/BCR framework exists or is required under West Virginia law.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement exists under West Virginia law.

Data LocalisationRed

No data-localisation mandate exists under West Virginia law.

Claims (1):

  • No West Virginia statute mandates data localisation for personal or sensitive data.
Category narrative36 words

As a US state, West Virginia has no legal mechanism equivalent to GDPR adequacy decisions, SCCs, BCRs, or transfer-impact assessments, and has neither received nor granted adequacy status. No data-localisation mandate exists under West Virginia law.

Sources and claims (2)
  1. ConfirmedIAPP — West Virginia has not enacted any statute establishing a cross-border data-transfer mechanism analogous to GDPR Chapter V.observed
  2. ConfirmedIAPP — No West Virginia statute mandates data localisation for personal or sensitive data.observed

#

Strong federal sectoral coverage for financial/health/credit/education data; gaps in employment, telecoms/ePrivacy, and confirmed insurance-specific state law.

Primary frameworkGLBA / HIPAA / FCRA / FERPA (federal sectoral overlays)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberStrong federal sectoral coverage for financial/health/credit/education data; gaps in employment, telecoms/ePrivacy, and confirmed insurance-specific state law.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA's Privacy Rule and Safeguards Rule govern financial institutions operating in West Virginia; a state-level consumer financial privacy bill was introduced but its enactment status is unconfirmed.

Claims (2):

  • The Gramm-Leach-Bliley Act imposes an affirmative and continuing obligation on financial institutions to protect the privacy and security of customers' nonpublic personal information, applicable to institutions operating in West Virginia.
  • A West Virginia bill on consumer financial privacy was introduced in 2023; this research did not confirm subsequent enactment.

Health Sector OverlayGreen

HIPAA Privacy and Security Rules govern covered entities and business associates handling protected health information in West Virginia.

Claims (1):

  • HIPAA's Privacy and Security Rules apply to covered entities and business associates handling protected health information for West Virginia patients.

Telecoms And EprivacyAmber

No West Virginia state-level ePrivacy or cookie-consent statute exists; federal TCPA/CAN-SPAM rules apply nationally to telemarketing and commercial email.

Claims (1):

  • West Virginia Code Chapter 46A, Article 6F regulates telemarketing activity within the state, supplementing federal telemarketing and commercial-email rules.

Employment DataRed

No West Virginia-specific employment-data-privacy statute was identified in this research pass.

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , e, m, p, l, o, y, m, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , s, t, a, t, u, t, e.

Credit And ScoringGreen

The federal Fair Credit Reporting Act governs credit reporting and scoring activities affecting West Virginia consumers.

Claims (1):

  • The federal Fair Credit Reporting Act governs the collection, use and disclosure of consumer credit information and scoring nationally, including for West Virginia consumers.

EducationAmber

The federal Family Educational Rights and Privacy Act governs education records for West Virginia students; a 2023 state bill addressing minors' online privacy was introduced but not confirmed enacted.

Claims (2):

  • The federal Family Educational Rights and Privacy Act governs the privacy of student education records in West Virginia schools.
  • West Virginia House Bill 2460, seeking to enhance online privacy protection for minors, was introduced to the Legislature in 2023; enactment was not confirmed in this research pass.

InsuranceRed

No confirmation was found that West Virginia has adopted the NAIC Insurance Data Security Model Law; insurance entities remain subject to GLBA as a baseline federal overlay.

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , I, n, s, u, r, a, n, c, e, , D, a, t, a, , S, e, c, u, r, i, t, y, , A, c, t, , N, A, I, C, , m, o, d, e, l, , l, a, w, , a, d, o, p, t, i, o, n.

Claims (1):

  • The NAIC Insurance Data Security Model Law is a non-binding model instrument; this research did not confirm its adoption into West Virginia statute.
Category narrative56 words

West Virginia's data-protection landscape is dominated by federal sectoral overlays: GLBA for financial institutions, HIPAA for health entities, FCRA for credit reporting/scoring, and FERPA for education records. No state-specific telecoms/ePrivacy, employment-data, or confirmed insurance-data-security statute was identified; a West Virginia bill on consumer financial privacy was introduced but enactment status is unconfirmed by this research pass.

no periodic updates on record for this sub-brief

Sources and claims (8)
  1. ConfirmedFederal Trade Commission — The Gramm-Leach-Bliley Act imposes an affirmative and continuing obligation on financial institutions to protect the privacy and security of customers' nonpublic personal information, applicable to institutions operating in West Virginia.observed
  2. UncertainDataGuidance / OneTrust — A West Virginia bill on consumer financial privacy was introduced in 2023; this research did not confirm subsequent enactment.observed
  3. ConfirmedHHS — HIPAA's Privacy and Security Rules apply to covered entities and business associates handling protected health information for West Virginia patients.observed
  4. ProbableDataGuidance / OneTrust — West Virginia Code Chapter 46A, Article 6F regulates telemarketing activity within the state, supplementing federal telemarketing and commercial-email rules.observed
  5. ConfirmedFederal Trade Commission — The federal Fair Credit Reporting Act governs the collection, use and disclosure of consumer credit information and scoring nationally, including for West Virginia consumers.observed
  6. ConfirmedU.S. Department of Education — The federal Family Educational Rights and Privacy Act governs the privacy of student education records in West Virginia schools.observed
  7. UncertainDataGuidance / OneTrust — West Virginia House Bill 2460, seeking to enhance online privacy protection for minors, was introduced to the Legislature in 2023; enactment was not confirmed in this research pass.observed
  8. UncertainIAPP — The NAIC Insurance Data Security Model Law is a non-binding model instrument; this research did not confirm its adoption into West Virginia statute.observed

#

Commercial adtech privacy protections that exist in comprehensive-law states (cookie consent, GPC recognition, sale/share opt-out) are entirely absent in West Virginia.

Primary frameworkW. Va. Code Chapter 46A, Article 6F (telemarketing) — direct marketing only
Supervisory authorityWest Virginia Attorney General
Traffic-light rationale — RedCommercial adtech privacy protections that exist in comprehensive-law states (cookie consent, GPC recognition, sale/share opt-out) are entirely absent in West Virginia.

Sub-modules (6)

Cookies And TrackersRed

No state cookie/tracker consent statute exists in West Virginia.

Claims (1):

  • West Virginia has not enacted a cookie or tracker consent statute of the kind found in comprehensive state privacy laws.

Dark PatternsRed

No West Virginia statute prohibits dark patterns in consent or privacy interfaces.

Opt Out SignalsRed

West Virginia does not require recognition of Global Privacy Control or other universal opt-out signals.

Claims (1):

  • West Virginia law does not mandate recognition of universal opt-out mechanisms such as Global Privacy Control.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regulation exists under West Virginia law.

Cross Context AdvertisingRed

No CPRA-style 'sale' or 'share' opt-out right exists for cross-context behavioral advertising under West Virginia law.

Claims (1):

  • No enacted West Virginia statute provides consumers an opt-out right for the sale or sharing of personal information for cross-context behavioral advertising.

Direct MarketingAmber

West Virginia's telemarketing statute (Ch. 46A, Art. 6F) is the only direct-marketing-adjacent instrument, alongside applicability of the federal Telephone Consumer Protection Act and CAN-SPAM Act.

Claims (1):

  • West Virginia Code Chapter 46A, Article 6F regulates telemarketing practices within the state.
Category narrative39 words

West Virginia has no cookie/tracker consent statute, no recognition of universal opt-out signals (e.g., Global Privacy Control), no dark-pattern prohibition, and no CPRA-style 'sale'/'share' opt-out right. The only adjacent instrument is the state telemarketing statute governing direct marketing calls.

Sources and claims (4)
  1. ConfirmedIAPP — West Virginia has not enacted a cookie or tracker consent statute of the kind found in comprehensive state privacy laws.observed
  2. ConfirmedIAPP — West Virginia law does not mandate recognition of universal opt-out mechanisms such as Global Privacy Control.observed
  3. ConfirmedIAPP — No enacted West Virginia statute provides consumers an opt-out right for the sale or sharing of personal information for cross-context behavioral advertising.observed
  4. ProbableDataGuidance / OneTrust — West Virginia Code Chapter 46A, Article 6F regulates telemarketing practices within the state.observed

#

All sub-modules are structurally unpopulated by enacted law; only proposed/unenacted bills exist.

Traffic-light rationale — RedAll sub-modules are structurally unpopulated by enacted law; only proposed/unenacted bills exist.

Sub-modules (6)

Profiling RestrictionsRed

No enacted profiling-restriction statute analogous to GDPR Article 22 exists in West Virginia.

Claims (1):

  • West Virginia has not enacted a profiling-restriction statute analogous to GDPR Article 22.

Automated Decision Making TransparencyRed

No ADM transparency or explanation-right statute exists under West Virginia law.

Ai Risk AssessmentsRed

No AI-specific risk-assessment requirement exists under West Virginia law.

Biometric RegimeAmber

A Biometric Information Privacy Act bill was introduced in the West Virginia Legislature in February 2026 but has not been confirmed enacted.

Claims (1):

  • A bill proposing a West Virginia Biometric Information Privacy Act was introduced in the state Legislature in February 2026.

Genetic DataAmber

A bill relating to genetic information privacy was introduced in West Virginia in 2023 but has not been confirmed enacted.

Claims (1):

  • A West Virginia bill relating to genetic information privacy was introduced in February 2023 but has not been confirmed enacted into law.

State Surveillance CarveoutsRed

No West Virginia-specific state-surveillance carve-out framework was identified; national-security/law-enforcement exemptions operate through general federal law only.

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , s, t, a, t, e, , s, u, r, v, e, i, l, l, a, n, c, e, , c, a, r, v, e, o, u, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , l, a, w, , e, n, f, o, r, c, e, m, e, n, t, , e, x, e, m, p, t, i, o, n.

Category narrative47 words

West Virginia has no enacted profiling-restriction, ADM-transparency, AI-risk-assessment, biometric-privacy, or genetic-data statute. A Biometric Information Privacy Act bill was introduced in February 2026, and a genetic-information-privacy bill was introduced in 2023; neither is confirmed enacted. No state-specific surveillance carve-out framework was identified beyond general federal national-security exemptions.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedIAPP — West Virginia has not enacted a profiling-restriction statute analogous to GDPR Article 22.observed
  2. ConfirmedDataGuidance / OneTrust — A bill proposing a West Virginia Biometric Information Privacy Act was introduced in the state Legislature in February 2026.observed
  3. ConfirmedDataGuidance / OneTrust — A West Virginia bill relating to genetic information privacy was introduced in February 2023 but has not been confirmed enacted into law.observed

#

Federal COPPA provides a binding baseline for children under 13; no West Virginia-specific enacted statute extends protections to teens, profiling bans, or dependent adults.

Primary frameworkCOPPA (federal)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal COPPA provides a binding baseline for children under 13; no West Virginia-specific enacted statute extends protections to teens, profiling bans, or dependent adults.

Sub-modules (5)

Age VerificationAmber

No West Virginia state-law age-verification mandate was confirmed enacted; federal COPPA age-verification/actual-knowledge standards apply to operators nationally.

Claims (1):

  • COPPA imposes requirements on operators of websites or online services directed to children under 13, or with actual knowledge of collecting children's personal information, applicable nationally including West Virginia.

Minor Profiling BansRed

No West Virginia statute bans profiling of minors.

Education SettingsAmber

FERPA governs education-record privacy for West Virginia students; no state-specific education-privacy statute beyond FERPA was confirmed.

Claims (1):

  • FERPA governs the privacy of student education records nationally, including for West Virginia students, absent a state-specific supplementary statute.

Dependent AdultsRed

No West Virginia statute specifically addresses data protection for dependent adults (elderly or mentally incapacitated persons).

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , e, l, d, e, r, l, y, , p, r, i, v, a, c, y, , s, t, a, t, u, t, e.

Category narrative55 words

Children's data protection in West Virginia is governed by the federal COPPA regime; the state itself has not enacted comprehensive minors'-privacy legislation, though a bill on online privacy protection for minors (HB 2460) was introduced in 2023. No parental-consent mechanism beyond COPPA, minor-profiling ban, education-settings-specific rule, or dependent-adults protection statute was identified at state level.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

West Virginia's 2026 House Bill 5353, primarily a money-transmission licensure reform for virtual-currency kiosk operators, is reported to require an enhanced due-diligence process aimed at detecting and preventing fraud targeting elderly adults in kiosk transactions. The obligation attaches to virtual-currency kiosk operators specifically and takes effect January 1, 2027, alongside the reform's broader licensure provisions. This is a consumer-protection-adjacent instrument rather than a data-protection-native one: it does not confer a data-subject right, does not establish a lawful-processing basis, and does not create a controller or processor duty in the sense used elsewhere in this monitor's taxonomy. It is surfaced here because it names a specifically vulnerable population, elderly adults, as the intended beneficiary of a fraud-prevention control. No broader child-specific or vulnerable-groups data-protection framework, covering matters such as parental consent for data collection, age-verification duties, or heightened processing restrictions for minors' data, was identified in West Virginia this cycle or in prior coverage. The mandate should be read alongside the crypto and financial-integrity monitors' coverage of the same House Bill 5353 reform, where the licensure and payments dimensions of the statute are addressed directly.

Outlook

The due-diligence mandate becomes effective January 1, 2027. No confirmation has been located of implementing guidance from the Division of Financial Institutions specifying what the due-diligence process must consist of in practice, and that is the item to watch as the effective date approaches. No indication was found of any broader vulnerable-groups or children's data-protection legislative activity in West Virginia beyond this narrowly scoped, payments-adjacent mandate.

Sources and claims (3)
  1. ConfirmedFederal Trade Commission — COPPA imposes requirements on operators of websites or online services directed to children under 13, or with actual knowledge of collecting children's personal information, applicable nationally including West Virginia.observed
  2. UncertainDataGuidance / OneTrust — A West Virginia bill (HB 2460) seeking to enhance online privacy protection for minors was introduced to the Legislature in January 2023; this research did not confirm its enactment.observed
  3. ConfirmedU.S. Department of Education — FERPA governs the privacy of student education records nationally, including for West Virginia students, absent a state-specific supplementary statute.observed

#

Enforcement exists only through general consumer-protection/breach-notification powers and the federal FTC backstop; no dedicated privacy-penalty regime.

Primary frameworkFTC Act Section 5 + W. Va. Code Chapter 46A, Article 2A
Supervisory authorityWest Virginia Attorney General
Traffic-light rationale — AmberEnforcement exists only through general consumer-protection/breach-notification powers and the federal FTC backstop; no dedicated privacy-penalty regime.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The West Virginia Attorney General may bring enforcement actions for breach-notification violations under general consumer-protection powers; the FTC may act under Section 5 for unfair/deceptive privacy practices nationally.

Claims (1):

  • The FTC exercises Section 5 unfair/deceptive-practices enforcement authority nationally, including over entities operating in West Virginia, as the principal federal backstop absent a state comprehensive-privacy penalty regime.

Enforcement Activity IndexAmber

No major West Virginia-specific privacy/breach enforcement action was identified in this research pass covering the last 12 months.

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , d, a, t, a, , b, r, e, a, c, h, , e, n, f, o, r, c, e, m, e, n, t, , a, c, t, i, o, n, , 2, 0, 2, 5, , 2, 0, 2, 6.

Regulator Funding And CapacityRed

No specific funding or headcount data for a dedicated privacy unit within the West Virginia Attorney General's office was identified; privacy enforcement is folded into general consumer-protection functions.

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , c, o, n, s, u, m, e, r, , p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , s, t, a, f, f, i, n, g, , b, u, d, g, e, t.

Collective Redress And Class ActionsRed

No data-privacy-specific collective-redress mechanism was confirmed for West Virginia; general consumer-protection class-action avenues may apply under state civil procedure.

Absence provenance: unavailable. Searched: W, e, s, t, , V, i, r, g, i, n, i, a, , d, a, t, a, , b, r, e, a, c, h, , c, l, a, s, s, , a, c, t, i, o, n, , p, r, i, v, a, t, e, , r, i, g, h, t, , o, f, , a, c, t, i, o, n, , s, t, a, t, u, t, e.

Private Right Of ActionRed

West Virginia's breach-notification statute does not appear to confer a private right of action distinct from general consumer-protection remedies; this was not independently confirmed via direct statutory text in this research pass.

Claims (1):

  • This research did not confirm a data-privacy-specific private right of action under West Virginia state law distinct from general consumer-protection remedies.

Recent Developments 180DAmber

The most notable recent development is the February 2026 introduction of a West Virginia Biometric Information Privacy Act bill; no comprehensive privacy statute has been enacted in West Virginia within the last 180 days.

Claims (1):

  • A bill proposing a West Virginia Biometric Information Privacy Act was introduced in February 2026, representing the most recent notable state-level privacy legislative development.
Category narrative63 words

Enforcement of West Virginia's breach-notification statute rests with the state Attorney General; the FTC provides the federal enforcement backstop under Section 5. No comprehensive-privacy-law penalty structure exists (unlike CPRA/CDPA-style states). No collective-redress mechanism or private right of action specific to data privacy was confirmed; general consumer-protection remedies may apply. No major West Virginia-specific privacy enforcement action was identified in the last 180 days.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedFederal Trade Commission — The FTC exercises Section 5 unfair/deceptive-practices enforcement authority nationally, including over entities operating in West Virginia, as the principal federal backstop absent a state comprehensive-privacy penalty regime.observed
  2. UncertainDataGuidance / OneTrust — This research did not confirm a data-privacy-specific private right of action under West Virginia state law distinct from general consumer-protection remedies.observed
  3. ConfirmedDataGuidance / OneTrust — A bill proposing a West Virginia Biometric Information Privacy Act was introduced in February 2026, representing the most recent notable state-level privacy legislative development.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct30.43
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for West Virginia, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s) (41 category placement(s)), 30 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated. Coverage is strongest (T1/T2) for regulator_and_framework, controller_processor_duties.breach_notification, and the federal sectoral overlays cited in sectoral_watch and children_and_vulnerable_groups (HIPAA, GLBA, COPPA, FCRA, FERPA — all T1 primary-source URLs). Coverage relies on T3 (IAPP/DataGuidance secondary aggregators) for confirming West Virginia's absence from the 19-state comprehensive-privacy-law list, and for tracking unenacted West Virginia bills (consumer data protection, biometric, genetic, minors' online privacy, financial privacy, cybersecurity). Several sub-modules (employment_data, dependent_adults, state_surveillance_carveouts, regulator_funding_and_capacity, collective_redress_and_class_actions) carry no findings and are marked with explicit absent_field_provenance rather than silent omission. The precise numeric notification threshold and exact 'personal information' definition text of W. Va. Code Chapter 46A, Article 2A were not independently verified against the primary state code website in this pass (only via T2 secondary legal-research aggregator), and are flagged Probable rather than Confirmed accordingly. Confirmation that West Virginia has NOT adopted the NAIC Insurance Data Security Model Law is an absence-of-evidence finding, not a verified negative.

Unresolved questions (5):

  • Exact statutory notification-threshold number and deadline (days) for regulator/AG notice under W. Va. Code §46A-2A-101 et seq. were not independently verified against primary WV Code text in this pass.
  • Whether West Virginia has adopted the NAIC Insurance Data Security Model Law in any form was not confirmed.
  • Current enactment status of the West Virginia Biometric Information Privacy Act bill (introduced Feb 2026) and the 2023 genetic-information-privacy bill was not confirmed as of the run date.
  • Whether West Virginia House Bill 2460 (minors' online privacy, 2023) was enacted was not confirmed.
  • Whether the West Virginia AG's office maintains a dedicated privacy/data-security enforcement unit (funding/headcount) versus folding this into general consumer protection was not confirmed.

Escalate to primary-source review: yes