Compliance and Risk Management
2
Minutes to read
Virginia Governor Ralph Northam signed the Virginia Consumer Data Protection Act (CDPA) in March 2021 and grants the Attorney General exclusive authority to enforce violations of the law.
The CDPA establishes a framework for controlling and processing the personal consumer data of Virginia residents, and the bill applies to all persons that conduct business in the Commonwealth. Businesses must either control or process personal data of at least 100,000 consumers or derive over 50 percent of gross revenue from the sale of personal data and control or process data of at least 25,000 consumers. The bill outlines responsibilities and privacy protection standards for data controllers and processors.
Technically speaking, the most labor-intensive exercise for a business is developing and testing a workflow where Virginia data subjects can execute their rights. Specifically:
Furthermore, the CDPA has a few important exemptions around data covered by other laws, such as HIPAA, Gramm-Leach-Bliley (GLBA), FCRA, FERPA, and COPPA.
The bill has a delayed effective date of January 1, 2023.
The scope includes personal consumer data that has not been de-identified or is not publicly available for a Virginia resident.
Violations of the CDPA will result in fines of up to $7,500 for each violation (not including expenses and any attorney fees incurred in connection with the investigation). In addition, a violation may lead to injunctions and civil penalties.
The Clearview Group has a six-step approach to Data Privacy. We help your business address compliance and identify GAPs by:
For more information, contact our Compliance and Risk Management team.
We are a full-service management consulting and CPA firm covering all aspects of audit, compliance, risk management, accounting, finance, tax, IT risk, and more. Just let us know what you need help with and an expert will be in touch!
Request Your ConsultationClearview Group is an award-winning, dynamic management consulting and CPA firm offering services that are flexible and scalable to meet the specific needs of our clients of all sizes and industries. Committed to providing real solutions that offer practical and efficient improvements to processes, procedures and operations, Clearview Group delivers exemplary client services normally associated with national firms, but with the hands-on, personalized feel of a local firm.
11155 Red Run Boulevard, Suite 410
Owings Mills, MD 21117
410-415-9700