Virginia was the first state after California to pass a comprehensive privacy statute, and its structure became the template several later states copied almost line for line. This page explains that law, why it treats business contact and workplace data differently from California's own framework, and why lead.box is built to a stricter European baseline regardless of which state law technically applies.
At a glance
- Framework
- Virginia Consumer Data Protection Act (VCDPA), Va. Code §59.1-575 et seq., effective 1 January 2023
- Supervision
- Virginia Attorney General exclusively; no private right of action; 30-day cure period before enforcement
- Usual legal basis
- Legitimate business purpose; VCDPA's consumer definition excludes commercial and employment-context data, so B2B contact activity sits outside the statute
- Processing location
- ISO-certified EU data centres
The Virginia Consumer Data Protection Act
Regulation at a glance
- FrameworkVirginia Consumer Data Protection Act (VCDPA), Va. Code §59.1-575 et seq., effective 1 January 2023
- SupervisionVirginia Attorney General exclusively; no private right of action; 30-day cure period before enforcement
- Usual legal basisLegitimate business purpose; VCDPA's consumer definition excludes commercial and employment-context data, so B2B contact activity sits outside the statute
- Processing locationISO-certified EU data centres
The Virginia Consumer Data Protection Act, codified at Va. Code §59.1-575 et seq., took effect on 1 January 2023 as the second comprehensive US state privacy law after California's, and its drafting became the reference point for the wave of statutes that followed in Colorado, Connecticut, Utah, Texas and beyond. It applies to entities that control or process the personal data of at least 100,000 Virginia consumers in a calendar year, or that control or process the data of at least 25,000 consumers while deriving more than 50 percent of gross revenue from selling personal data. There is no separate revenue-only threshold, so a company's Virginia obligations turn on the scale of its consumer data processing rather than its overall size.
Enforcement sits exclusively with the Virginia Attorney General; the statute grants no private right of action, so individual consumers cannot sue over an alleged violation directly. Before pursuing a formal action, the Attorney General must give a business 30 days to cure the violation, and only if the cure fails, or is not attempted, do civil penalties become available, running up to 7,500 dollars per violation. That cure period and the absence of private litigation give Virginia's enforcement posture a noticeably more measured character than some other states' regimes.
The VCDPA also requires controllers to carry out and document data protection assessments for higher-risk processing activities such as targeted advertising, the sale of personal data, certain profiling, and processing of sensitive data, and it grants consumers the right to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. None of those obligations attach to activity the statute doesn't classify as covered in the first place, which is exactly the question the next section addresses.
Why B2B contact data sits outside the VCDPA
The VCDPA defines a 'consumer' as a natural person who is a Virginia resident acting only in an individual or household context, and it expressly states that the term does not include a natural person acting in a commercial or employment context. That single sentence draws a boundary California's own CCPA/CPRA no longer has: California's temporary B2B and employee exemptions expired on 1 January 2023, so business contact and workplace data are now fully in scope there, while Virginia's statute has never covered that category at all. A Virginia company handling B2B lead data, work email addresses gathered through sales outreach, or employee records tied to job functions is operating outside the VCDPA's consumer definition for that data, by design rather than by exception.
That carve-out matters directly for how a company evaluates a visitor identification tool. Because company-level identification resolves the organisation behind a visit — a firm name, industry and size band — rather than a named individual acting in a personal capacity, it sits comfortably outside the VCDPA's consumer scope on two independent grounds: the activity isn't about a natural person to begin with, and even where a named contact might later be involved, business-context data of that kind is excluded from the statute's definitions.
That reading is a starting point for your own assessment, not a substitute for it. Whether a specific data flow, integration or downstream use case stays outside VCDPA scope depends on the actual facts of how a business uses the data, and lead.box does not offer this as legal advice; any Virginia business should have its own counsel confirm the analysis against its particular setup before relying on it.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
What Northern Virginia buyers and sales teams expect in practice
Virginia's B2B economy is shaped heavily by federal contracting, data-centre operators and defence-adjacent technology companies clustered around Northern Virginia, and that concentration produces procurement habits that go well beyond a standard privacy checkbox. Vendor security reviews there routinely look like abbreviated FedRAMP-style questionnaires — asking about data residency, encryption in transit and at rest, sub-processor lists, incident response commitments and access controls — even for a lightweight tool that never touches classified or regulated data itself.
For a tool like lead.box, that means the relevant documentation set is a data processing agreement, a published sub-processor list, and a plain description of where data is processed and how it moves, all matched to the language a federal-contractor-adjacent buyer already uses internally. Because processing runs through ISO-certified EU data centres by default, the answers to those questionnaires tend to meet or exceed what a Virginia buyer's own internal security team would otherwise require from a smaller SaaS vendor.
For the sales and marketing team using the tool day to day, the practical value is the same as anywhere else: seeing which companies are reading pricing and case-study pages during a multi-week federal or enterprise procurement cycle, so outreach lands while the account is still evaluating rather than after a decision has already been made.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
The Virginia Consumer Data Protection Act defines a covered 'consumer' as a natural person acting only in an individual or household context and explicitly excludes anyone acting in a commercial or employment context, so purely business-to-business activity generally sits outside the statute's scope from the start. lead.box resolves the organisation behind a website visit — a company name, industry and size band derived from network-level signals — rather than identifying a named person acting in a personal capacity, which keeps the activity further outside the VCDPA's consumer definition on a second, independent basis. Still, the statute's thresholds and exclusions apply to your specific data flows, not to a general product description, so whether a particular integration or downstream use qualifies is fact-specific. lead.box acts as a processor and provides supporting documentation, but the applicability call is the controller's own responsibility — have your own counsel confirm it against your actual setup.
Virginia's VCDPA has never covered natural persons acting in a commercial or employment context; that exclusion is written directly into the statute's consumer definition and has applied since the law took effect on 1 January 2023. California took the opposite path: the CCPA and CPRA originally carried temporary exemptions for business-to-business contact and employee data, but those exemptions expired on 1 January 2023, meaning California now fully covers B2B contact information as personal information under its own statute. The practical effect is that identical business contact data can sit outside one state's privacy law while sitting squarely inside another's, purely because of how each legislature chose to define 'consumer'. A Virginia-headquartered company selling nationally still needs to check California's rules separately if it has California business contacts, since Virginia's more permissive B2B treatment doesn't extend beyond its own statute.
The VCDPA requires controllers to conduct and document data protection assessments for higher-risk processing such as targeted advertising, sale of personal data, certain profiling, and processing of sensitive data — obligations that attach to activity involving a covered consumer's personal data under the statute. Because lead.box identifies the visiting company rather than a named individual acting in an individual or household context, and does not sell personal data, run targeted advertising, or build cross-site advertising profiles, the specific processing it performs typically doesn't fall into the categories that trigger a mandatory assessment. Whether your broader use of visitor data — combined with other tools on the same site — crosses into assessment-triggering territory depends on your full data flow, not on lead.box in isolation, so this is worth reviewing with counsel alongside your other marketing and advertising technology rather than in isolation.
Unlike some newer state statutes, the VCDPA builds in a 30-day cure period: if the Virginia Attorney General identifies a potential violation, the business must be given 30 days to correct it before any formal enforcement action or civil penalty can proceed. Only if the cure period passes without resolution, or the violation isn't curable, does the Attorney General move toward civil penalties, which can run up to 7,500 dollars per violation. There is also no private right of action under the VCDPA, so individual Virginia consumers cannot bring their own lawsuit over an alleged violation; enforcement authority rests exclusively with the Attorney General's office. That combination gives Virginia companies a genuine opportunity to correct an issue before it becomes a penalty, which is a meaningfully different enforcement posture than states without a cure period, though it's still not a reason to treat compliance as optional.
The VCDPA grants Virginia consumers the right to opt out of the processing of their personal data for targeted advertising, for the sale of personal data, and for certain profiling that produces legal or similarly significant effects on the consumer. Those rights are tied to the statute's consumer definition, meaning they apply to processing of personal data belonging to a natural person acting in an individual or household context, and they govern activities like cross-context ad targeting and data sales specifically. lead.box does not sell personal data, does not run targeted advertising campaigns using visitor data, and does not build profiles that follow an individual across unrelated sites, so the mechanics behind these opt-out rights address a different kind of data flow than company-level identification performs. Confirming that your overall site setup — including any other advertising or analytics tools — doesn't independently trigger these rights remains your responsibility as controller.
Northern Virginia's concentration of federal contractors, defense-adjacent firms and data-centre operators means vendor security reviews there often resemble abbreviated FedRAMP-style questionnaires, even for tools that never touch classified or regulated data directly: expect questions on data residency, encryption at rest and in transit, sub-processor relationships, incident response, and access controls. lead.box processes data through ISO-certified EU data centres by default and publishes its sub-processor list, so the underlying documentation a Northern Virginia buyer's security team asks for is generally available without a special configuration for that account. Being ready with a signed data processing agreement, a plain-language description of what data is collected — company-level rather than individual — and clear answers on data location tends to move these reviews along faster than treating each questionnaire as a one-off exercise.
That depends entirely on what the combined workflow actually does, not on lead.box's own processing. lead.box itself resolves organisation-level signals — a company name, industry and size band — without identifying a named individual, which keeps its own output outside the VCDPA's personal-data scope for the reasons described elsewhere on this page. If your team later layers on a contact-enrichment tool that attaches named individuals, personal email addresses or job titles to that company record, the combined data set may raise different questions depending on whether those individuals are acting in a business or personal capacity, and depending on how that enriched record is subsequently used. Reviewing the full pipeline, not just the visitor identification step, with your own counsel is the right way to confirm where VCDPA obligations do or don't attach to your specific setup.
No — lead.box applies the same GDPR-informed processing standard, the same data processing agreement structure, and the same published sub-processor list regardless of which US state a customer operates in, rather than tailoring a looser configuration to whichever state law happens to be most permissive. For Virginia specifically, that consistency means a company benefiting from the VCDPA's B2B and employment-context exclusion still gets the stricter European-grade documentation that a Northern Virginia federal-contractor buyer, or a cautious in-house counsel, is likely to ask for anyway. The state law analysis in this page reflects Virginia's statute as currently written, but statutes and their interpretation change, so treat this as background context rather than a final legal determination, and have counsel confirm anything you plan to rely on.
See which Virginia companies are already on your site
Install a first-party snippet, watch the first companies appear, and hand your security team the same documentation a federal-contractor buyer would expect.