Session Expired

Your session has expired. Please sign in again to continue where you left off.

Sign In Again
VA HB638

VA HB638: Data brokers; regulation, civil penalties. Verified

Sign in to follow

Get emailed when this bill changes status, is amended, or advances.

Disclaimer: This page provides general informational summaries only and does not constitute legal advice. AI-generated content may contain errors. Always consult a qualified attorney for guidance specific to your situation. Read full disclaimer →
AI Summary

This bill regulates data brokers, prohibiting the acquisition of personal data for purposes such as stalking, harassment, fraud, or discrimination, and requires security measures with specific features and annual registration starting December 1, 2027. The provisions take effect on July 1, 2027.

Business Impact

If you operate as a data broker in Virginia, you must register annually and maintain a security program by December 1, 2027, or face penalties.

State
Virginia
Bill Number
HB638
Status
Introduced
Risk Level
Medium
Category
Comprehensive
Effective Date
Dec 1, 2027
Last Action
Feb 9, 2026
Last Verified
May 4, 2026
Data Updated
May 4, 2026
What do these statuses mean?
Introduced — Filed in the legislature; not yet heard in committee
In Committee — Assigned to and being reviewed by a legislative committee
Passed — Approved by one or both chambers; awaiting further action
Signed / Enacted — Signed into law by the governor; may or may not be in effect yet
Dead / Vetoed — Vetoed, failed to pass, or session expired without action
Unknown — Status data not yet available or awaiting classification

Affected Industries

Data Brokerage Finance Technology Employment Information Security Consumer Protection Housing

Topics How we classify →

What This Means

Virginia's HB638 aims to regulate data brokers by prohibiting the acquisition of personally identifiable information for purposes like stalking, harassment, committing fraud, or engaging in unlawful discrimination, and mandating comprehensive security programs with certain features and technical elements. The provisions take effect on July 1, 2027, with registration starting December 1, 2027.

Key Provisions

Latest Legislative Action

Continued to next session in Communications, Technology and Innovation (Voice Vote)

Bill Sponsors (showing 5 of 10)

Name Role
Primary
Primary
Primary
Primary
Primary

Compliance Checklist

Develop and maintain a comprehensive information security program.
Who: Data brokers operating in Virginia.
Deadline: By December 1, 2027.
Penalty: Potential civil penalties under the Virginia Consumer Protection Act.
Register annually with the Secretary of the Commonwealth.
Who: Data brokers operating in Virginia.
Deadline: Starting December 1, 2027.
Penalty: Enforcement actions by the Attorney General for non-compliance.

Full Legal Analysis

HB638 establishes a regulatory framework for data brokers in Virginia, defining key terms such as 'data broker' and 'personally identifiable information.' It prohibits the acquisition of personal data for purposes including stalking, harassment, committing fraud, and engaging in unlawful discrimination. The bill requires the information security program to include certain features and technical elements as specified in the bill. Violations of the bill's provisions are considered prohibited practices under the Virginia Consumer Protection Act and take effect on July 1, 2027.

Official Source


More Virginia AI Legislation

View All VA Laws →

More Virginia AI Laws

Browse all published AI bills and regulations for Virginia.

View VA Laws →

Stay Updated on AI Laws

New AI laws, compliance deadlines, and plain-English breakdowns. Updated daily.

Unsubscribe anytime.
You're subscribed. Check your inbox.
Report an error in this data