Data Breach Notification Statutes – Virginia
Last Updated: 02/28/2024
- Applicable Statute: Va. Code Ann. § 18.2-186.6
- Attorney General Notice Required: Yes.
- Timing: Not specified
- Method: Mail to: Computer Crime Section Virginia Attorney General’s Office 202 North 9th Street Richmond, VA 23219
- Content: As part of the notification, the Virginia Attorney General’s Office requests the following information from the individual or entity making the notification: 1. A cover letter on official letterhead to the Virginia Attorney General’s Office as notification of the breach; 2. Approximate date of the incident to include how the breach was discovered; 3. Cause of breach; 4. Number of Virginia residents affected by the breach; 5. The steps taken to remedy the breach; 6. If an organization’s employees’ tax identification numbers and amount of tax withheld are breached, the Federal Employer Identification Number (FEIN) of the organization; and 7. A sample of the notification made to the affected parties, to include any possible offers of free credit monitoring.
- Consumer Notice Requirements:
- Timing: Must be made without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the system.
- Content: The notification must include description of the following:
- The breach incident in general terms;
- The types of personal information that was subject to the unauthorized access and acquisition;
- The acts taken to protect the personal information from further unauthorized access;
- A telephone number that the person may call for further information and assistance, if one exists; and
- Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.
- Method: Written notice to last known postal address, by telephone, or electronic notice. Substitute notice is available under certain conditions.
- Consumer Reporting Agency Obligations: If more than 1,000 persons are notified, must also notify all nationwide consumer reporting agencies of the timing, distribution and content of the notice. If one Virginia resident is included then the Attorney General must also be notified.