Virginia VCDPA 2026 — AI Voice, Chat, and the Geolocation/Minors Amendments
Virginia amended the VCDPA in 2025 with sweeping geolocation and minors provisions effective January 1, 2026. The Attorney General opened the year with 30-day cure notices. Here is what AI voice and chat must do.
Virginia was the second US state with a comprehensive privacy law and the first to enforce minors' social-media restrictions through it. In 2026 the VCDPA reaches AI voice and chat that touches geolocation, minors, or "significant" automated decisions.
What the law says
The Virginia Consumer Data Protection Act (VCDPA) — Title 59.1, Chapter 53 — has been in force since 1 January 2023 and was amended through 2025. SB 338 and companion bills tightened minors' protections and introduced new geolocation rules effective 1 January 2026. Controllers may not sell precise geolocation data without consent. Social-media platforms must use commercially reasonable age-determination methods, limit minors under 16 to one hour of platform use per day, and require verifiable parental consent to lift the cap. Sensitive data — racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship, genetic or biometric data for unique identification, children's data, and precise geolocation — still requires consent before processing.
The VCDPA grants consumers rights to access, correct, delete, port, and opt out of targeted advertising, sale, and profiling in furtherance of decisions that produce legal or similarly significant effects. Data protection assessments are required for targeted-advertising processing, sale, sensitive-data processing, and profiling that creates risk of unfair treatment, financial injury, or intrusion on private affairs. Enforcement is exclusive to the Attorney General; civil penalties up to $7,500 per violation. Virginia AG Jay Jones announced in February 2026 that 30-day cure notices were going out for the new minors' provisions.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
What AI voice/chat must do
Voice and chat agents that capture precise geolocation — caller ZIP plus device coordinates, in-app location, address normalisation — need consent up front. Agents serving Virginia minors must inhibit design patterns that "significantly increase, sustain, or extend" engagement: no infinite-scroll equivalents, no autoplay loops, no dark-pattern up-sells. Profiling that drives a significant decision (credit, housing, education, employment, healthcare access) needs an opt-out and a data protection assessment. Sensitive-data inference — health, mental status, sexual orientation — defaults to consent unless an exemption applies.
CallSphere posture
CallSphere — 37 agents, 90+ tools, 115+ DB tables, 6 verticals, 50+ businesses at 4.8/5, HIPAA and SOC 2 aligned — ships VCDPA-ready defaults: consent capture for precise geolocation embedded in the voice flow, age-determination prompts on minor-facing channels, profiling opt-out exposed in the agent and on the website, and a Virginia-specific data protection assessment template. The voice agent never auto-extends a session beyond a configured cap when a minor is detected. Sensitive-data inference is gated and logged. Pricing $149 / $499 / $1,499; 14-day trial; 22% lifetime affiliate; see /pricing and /contact.
flowchart LR
A[VA Caller] --> B[Voice Agent]
B --> C[Geo Consent]
B --> D[Minor Check]
D --> E[Time Cap]
B --> F[Profiling\nOpt-Out]
F --> G[DPA Doc]
Compliance checklist
- Map every workflow that captures precise geolocation; gate behind consent.
- Implement age-determination on consumer-facing voice/chat surfaces; cap minor sessions.
- Surface a profiling opt-out in the voice menu and on the privacy page.
- Complete a data protection assessment for each profiling-for-significant-effect workflow.
- Treat sensitive-data inference as processing — get consent before inference, not after.
- Build the consumer-rights intake for access, correction, deletion, portability with a 45-day SLA.
- Track cure-notice deadlines (30 days) on a single dashboard.
- Avoid engagement-extending design features on minor-facing flows.
- Retain assessment evidence; the AG can request it on a 14-day notice.
- Refresh annually — Virginia amends the VCDPA most legislative sessions.
FAQ
Is voice metadata "precise geolocation"? Carrier-derived city is not. GPS-grade coordinates and rooftop addresses are. Default to consent if you cannot prove the latter.
How does VCDPA treat AI training? Training on Virginia residents' data needs a lawful basis; sensitive data needs consent. The 2026 amendments do not carve out training.
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
Does the VCDPA apply to B2B voice agents? Employee and B2B contact data have a narrower scope, but you still owe the consumer-facing controls if the same agent serves consumers.
What is the threshold to be a controller? Process the personal data of 100,000 Virginia consumers, or 25,000 if more than half of revenue comes from data sale.
Are HIPAA-covered entities exempt? Entity-level exemption for HIPAA-covered entities exists; data-level exemption for protected health information. Verify the boundary.
Sources
- Code of Virginia Title 59.1, Chapter 53: https://law.lis.virginia.gov/vacode/title59.1/chapter53/
- Virginia AG Consumer Privacy Page: https://www.oag.state.va.us/consumer-protection/index.php/tips-and-consumer-information/consumer-privacy-and-data-protection
- VCDPA 2026 Amendments — Akin Gump: https://www.akingump.com/en/insights/blogs/ag-data-dive/virginias-new-amendments-to-the-vcdpa
- Virginia AG Press — Minors Enforcement Feb 2026: https://www.oag.state.va.us/media-center/news-releases
- Securiti VCDPA Guide: https://securiti.ai/privacy-laws/us/virginia/
Try CallSphere AI Voice Agents
See how AI voice agents work for your industry. Live demo available -- no signup required.