Home Privacy CCPA On The East Coast? Meet CDPA, Virginia’s Consumer Data Protection Act

CCPA On The East Coast? Meet CDPA, Virginia’s Consumer Data Protection Act

SHARE:
Last week, Virginia’s house of representatives and senate passed the Consumer Data Protection Act (CDPA) with sweeping majorities.
A roadside sign welcomes travelers along a rural road to the state of Virginia

Last week, Virginia’s house of representatives and senate passed the Consumer Data Protection Act (CDPA) with sweeping majorities.

And so, once Gov. Ralph Northam signs the bill into law, as he’s expected to do in the coming weeks, you can add “CDPA” to your list of privacy regulation initialisms.

Some are calling the CDPA, which is the second comprehensive data privacy law in the United States, Virginia’s answer to GDPR or the East Coast version of the California Consumer Privacy Act.

But the truth lies somewhere in between. The bill, which would take effect on Jan. 1, 2023 if passed, borrows from both of its high-profile predecessors.

Here’s how CDPA stacks up.

CDPA vs. CCPA vs. GDPR

Although Virginia lawmakers were clearly inspired by California, CDPA is an opt-in law and uses similar language to GDPR to define consent, which needs to be clear, affirmative, freely given, specific, informed and unambiguous.

This standard is higher than what’s called for under CCPA and the California Privacy Rights Act (CPRA), which requires that consumers are given the opportunity to opt out of data collection.

CDPA gives consumers GDPR-like rights.

“Where the CCPA only provides a right to know and a right to be deleted, the CDPA provides a right of access, correction, deletion and portability broadly reflected in the farther-reaching obligations of the GDPR,” said Cillian Kieran, CEO and founder of privacy compliance startup Ethyca.

But when it comes to applicability thresholds, the CDPA is a little looser than the CCPA.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Whereas the CCPA sets a specific revenue threshold – the law applies to any business with annual gross revenue of more than $25 million – the Virginia bill doesn’t. CDPA would apply to anyone that conducts business in the Commonwealth and either controls or processes the personal data of at least 100,000 consumers or derives more than 50% of its gross revenue from the sale or processing data belonging to at least 25,000 consumers.

The CDPA also has a somewhat more limited definition of the term consumer, which only refers to people who reside in Virginia and excludes anyone acting in a commercial capacity or employment context.

Taken together, the lack of a revenue threshold combined with this narrower definition means that the Virginia law would likely apply to fewer businesses overall than CCPA, Kieran said.

Kieran noted that the Virginia bill also contains specific carve outs for businesses that already process data regulated by other laws, such as health data under HIPAA and sensitive financial data governed by the Gramm-Leach-Bliley Act.

No private right of action

One other significant difference between CCPA and the bill in Virginia is that the latter doesn’t provide for a private right of action, meaning that the attorney general is the only one who would have the right to enforce the law.

There is a private right of action under CCPA for violations of the law that involve data breaches, which has opened the door for class-action lawsuits.

If CDPA passes, the attorney general will be able to seek up to $7,500 per violation, including injunctive relief and attorney’s fees, following a 30-day cure period during which the breaching party will have an opportunity to fix whatever mess it’s accused of.

Getting prepped

While Virginia’s privacy law is still a bill, there’s little doubt that Virginia’s governor will sign CDPA into law – and soon.

Although some geo-specific modifications will be necessary, businesses that have already done prep work for CCPA and/or GDPR will be “in a good place” when CDPA hits the books, said Charles Farina, head of innovation at Adswerve.

And “we expect most privacy vendors like OneTrust and Cookiebot to have updates available quickly once [CDPA is] signed into law,” Farina said.

But don’t fall into the trap of thinking that being prepared for CCPA will make CDPA prep into a box-checking exercise, Kieran said. CDPA has a different definition for the term “consumer” and provides increased rights that are more akin to those under GDPR.

“Ensuring your business is completely compliant with the GDPR is a better baseline for preparation for broader data privacy regulations,” Kieran said. “But it’s important to recognize that each state has nuances … there is no one-size-fits-all solution.”

Must Read

Gamera Raises $1.6 Million To Protect The Open Web’s Media Quality

Gamera, a media quality measurement startup for publishers, announced on Tuesday it raised $1.6 million to promote its service that combines data about a site’s ad experience with data about how its ads perform.

Jamie Seltzer, global chief data and technology officer, Havas Media Network, speaks to AdExchanger at CES 2026.

CES 2026: What’s Real – And What’s BS – When It Comes To AI

Ad industry experts call out trends to watch in 2026 and separate the real AI use cases having an impact today from the AI hype they heard at CES.

New Startup Pinch AI Tackles The Growing Problem Of Ecommerce Return Scams

Fraud is eating into retail profits. A new startup called Pinch AI just launched with $5 million in funding to fight back.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Comic: Shopper Marketing Data

CPG Data Seller SPINS Moves Into Media With MikMak Acquisition

On Wednesday, retail and CPG data company SPINS added a new piece with its acquisition of MikMak, a click-to-buy ad tech and analytics startup that helps optimize their commerce media.

How Valvoline Shifted Marketing Gears When It Became A Pure-Play Retail Brand

Believe it or not, car oil change service company Valvoline is in the midst of a fascinating retail marketing transformation.

AdExchanger's Big Story podcast with journalistic insights on advertising, marketing and ad tech

The Big Story: Live From CES 2026

Agents, streamers and robots, oh my! Live from the C-Space campus at the Aria Casino in Las Vegas, our team breaks down the most interesting ad tech trends we saw at CES this year.