← All jurisdictions
VA · data breach notification

Virginia

med

Va. Code §18.2-186.6

Individual deadline
No fixed limit
Trigger standard
Risk of harm
AG / regulator
Required
Notice to individualsin the most expedient time possible and without unreasonable delay
Risk-of-harm standardnotice where breach causes or will cause identity theft or other fraud
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeVirginia Attorney General, required for any affected resident; without unreasonable delay
Written notice to AG
Credit reporting agenciesNo CRA-notice requirement.
Substitute noticeAvailable if cost exceeds $50,000 or more than 100,000 affected.
Private right of actionNo, enforcement by the state.
Notes
Separate payroll/income-tax-data rule (employers/payroll providers notify AG with FEIN)
Separate medical-information statute (§32.1-127.1:05)

Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Virginia breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →