Yes, Virginia requires breach notification. Under § 18.2-186.6 of the Code of Virginia, you must notify affected Virginia residents and the Office of the Attorney General without unreasonable delay once unencrypted or unredacted personal information has been accessed and acquired in a way that causes, or is reasonably believed to cause, identity theft or fraud. If a large number of residents are involved, nationwide consumer reporting agencies get notified too. Encrypted data generally sits outside this rule, unless the key was compromised.
TL;DR:
- Breach notification in Virginia requires immediate action unless the data was properly encrypted or redacted, with encryption key security being critical to exemption.
- Notices must clearly describe the incident, specify the compromised data, and advise recipients to monitor their accounts, with credit monitoring recommended but not required.
- Reporting to residents is required without unreasonable delay, with delays allowed only for investigations or law enforcement requests documented in writing.
- When more than 1,000 residents are affected, businesses must also notify the Virginia Attorney General and consumer reporting agencies simultaneously.
- Preparedness, including documented risk assessments and encryption deployment, significantly reduces legal and financial risks when a breach occurs.
Table of Contents
- What Virginia’s Data Breach Notification Law Actually Covers
- What Your Breach Notice to Virginia Residents Must Say
- When and How to Deliver Notice Under Virginia Law
- Reporting the Breach to the Virginia Attorney General
- When You Don’t Have to Notify: Encryption and Regulatory Overlap
- Civil Penalties and Legal Exposure Under Section 18.2-186.6
- A Practical Breach Response Checklist for Virginia Businesses
- Where to Find Official Virginia Breach Notification Resources
- Recent Virginia Breach Cases and What They Reveal
- How Virginia’s Breach Law Compares to Federal and Other State Rules
- Why Preparedness Beats Reaction Every Time
- Getting Ahead of Virginia’s Notification Deadlines
- Sources
What Virginia’s Data Breach Notification Law Actually Covers
Section 18.2-186.6 defines a “breach of the security of the system” as unauthorized access and acquisition of unencrypted or unredacted computerized data that compromises the security, confidentiality, or integrity of personal information. Covered fields typically include a name paired with a Social Security number, driver’s license number, or financial account number with an access code.
The law applies to any individual or entity that owns, licenses, or maintains computerized data containing personal information about multiple people, whether that data belongs to a Virginia company or an out of state vendor holding records on Virginia residents. There’s a good faith exception: if an employee or agent acquires data for legitimate work purposes and doesn’t use it for anything unauthorized, that’s not a reportable breach. And the encryption safe harbor sits right in the statute itself, not as guidance layered on top.
What Your Breach Notice to Virginia Residents Must Say
The Virginia Attorney General’s office lays out specific content requirements for notices sent to affected residents, and skipping any of them invites regulatory scrutiny you don’t need. Your notice has to include, at minimum:
- A general description of what happened during the incident
- The specific type of personal information that was compromised (SSN, driver’s license, financial account, etc.)
- A summary of the actions you’ve taken to protect the affected data going forward
- A working contact phone number for questions
- Advice telling recipients to review their account statements and credit reports for suspicious activity
The Attorney General’s guidance also recommends offering credit monitoring in the sample notice where the exposure warrants it. It’s not a strict legal requirement, but the AG’s office views it favorably, and offering it tends to reduce the volume of angry follow-up calls and complaints your team has to field.
Keep the language plain. Avoid legal jargon that makes residents feel like you’re hiding something. A notice that reads like a liability waiver does more damage to your reputation than the breach itself.
When and How to Deliver Notice Under Virginia Law
“Without unreasonable delay” is the timing standard, and it’s intentionally flexible rather than a fixed number of days. You’re allowed a short delay if you’re actively investigating the scope of the breach or restoring the integrity of your systems, but that delay needs a legitimate operational reason behind it, not just convenience.
Law enforcement can also request a delay if immediate notice would interfere with a criminal investigation. Document that request in writing, note who made it and when, and keep it on file. That paper trail is your best defense if anyone later questions why notice took longer than expected.
Permitted delivery methods include:
- Postal mail to the resident’s last known address
- Telephone notice
- Electronic notice, but only if the resident already agreed to receive communications that way
Substitute notice (email plus website posting plus statewide media notice) is allowed when certain cost, scale, or contact information thresholds are met.
Reporting the Breach to the Virginia Attorney General
Once you notify Virginia residents, a separate track kicks in for regulatory reporting. If more than 1,000 residents are affected, you must also notify the Office of the Attorney General and all nationwide consumer reporting agencies without unreasonable delay, matching the timing, distribution, and content of the notice sent to residents.
The AG’s office expects a specific packet, not just a phone call. According to its published guidance, that packet should include a cover letter on official letterhead, the approximate date of the incident, how it was discovered, the likely cause, the number of Virginia residents affected, the remedial steps you’ve already taken, and a copy of the actual sample notice sent to residents.
If the breach involves payroll or tax records, there’s an added wrinkle. Virginia Tax requires immediate notification when taxpayer identification numbers combined with withheld income tax are exposed, and employers or payroll providers must supply their FEIN to the AG’s office, which then loops in the Department of Taxation on your behalf.
When You Don’t Have to Notify: Encryption and Regulatory Overlap
Notice isn’t automatic just because a system got breached. If the compromised data was encrypted or properly redacted, and the encryption key itself wasn’t accessed or compromised, you generally aren’t required to notify under Virginia law. This is the encryption safe harbor, and it’s a real financial incentive to encrypt sensitive fields at rest, not just in transit.
There’s also a compliance shortcut for regulated industries. If you’re already subject to the Gramm Leach Bliley Act, HIPAA, or another primary regulator’s breach notification framework, and you follow those procedures, Virginia treats you as compliant with its own requirements. You don’t have to run two parallel notification processes.
Whichever exemption you rely on, write down why. A short memo explaining that the data was encrypted, the key was never exposed, and who verified that determination will matter enormously if a regulator or plaintiff’s attorney later asks why no notice went out.
Civil Penalties and Legal Exposure Under Section 18.2-186.6
The Attorney General can seek civil penalties of up to $150,000 per breach or series of related breaches discovered in a single investigation. That’s not a per-resident fine, it’s a per-incident ceiling, but it adds up fast across multiple violations.
The statute also preserves a private right of action. Individuals who suffer direct economic damages because you failed to notify them properly can sue. Speed and documentation aren’t optional extras here. They’re what separates a defensible response from an expensive one.
A Practical Breach Response Checklist for Virginia Businesses
When you discover a potential breach, the clock is already running, even if you haven’t confirmed the scope yet. Here’s the sequence that holds up under scrutiny:
- Contain the incident. Isolate affected systems, but don’t wipe anything. Preserve logs and forensic artifacts before you touch anything else.
- Run a documented risk of harm assessment. This is where “reasonable belief” of identity theft or fraud gets decided, and it’s often contested later, so write down who made the call, what evidence supported it, and when.
- Assemble your AG packet early. Draft the cover letter, timeline, and remedial steps in parallel with your investigation rather than waiting until everything is fully resolved.
- Draft the consumer notice using the statutory checklist, and consider offering credit monitoring if the exposure includes SSNs or financial account data.
- Notify residents, the AG, and consumer reporting agencies (if over 1,000 affected) on matching timelines.
- Remediate afterward. Review vendor contracts, roll out encryption where gaps existed, retrain staff, and retain records of the entire response.
Pro Tip: Build your risk of harm assessment template before you ever need it. Trying to design a defensible documentation process in the middle of an active breach is how companies miss deadlines and make avoidable mistakes.
Total Cyber’s Virginia breach response planning resources walk through this sequence in more detail, and our cyber awareness training program addresses the root cause behind a large share of these incidents: phishing and social engineering that never should have reached an employee’s inbox in the first place.
Where to Find Official Virginia Breach Notification Resources
Start with the primary sources rather than secondhand summaries, since notification law gets misquoted constantly online. The core references you’ll want bookmarked:
- § 18.2-186.6 of the Code of Virginia, the actual statutory text governing the notification duty
- The Attorney General’s Data Breach Notification Requirements PDF, which spells out required notice content and the AG packet format
- Virginia Tax’s breach reporting page, specifically for payroll and tax data incidents
- The Attorney General’s Computer Crime Section, which handles breach reports and investigative referrals
Total Cyber maintains internal templates built around these exact requirements, including an AG packet checklist, a consumer notice draft, and an incident timeline framework, so your team isn’t starting from a blank page while the clock is running on your notification deadline.
Recent Virginia Breach Cases and What They Reveal
Virginia’s enforcement pattern under Section 18.2-186.6 tends to follow a consistent script: the AG’s office gets involved when notification is late, incomplete, or skipped entirely, rather than purely because a breach happened. Companies that notify promptly and file a complete AG packet rarely face penalty actions, even for large scale incidents. That’s a meaningful signal for compliance teams weighing how much effort to put into documentation versus how much to spend on legal defense after the fact.
Cases involving healthcare providers, payroll processors, and retail point of sale systems show up disproportionately in breach reports filed with the Virginia AG, largely because those sectors handle the exact data categories the statute targets most directly: Social Security numbers, financial account numbers, and taxpayer identification numbers. Payroll related incidents carry an extra layer of complexity, since they trigger both the standard AG notification and the separate Virginia Tax reporting obligation.
The practical lesson from how these cases resolve isn’t about the breach itself. It’s about the response. Organizations that documented their risk of harm assessment, moved quickly on resident notice, and submitted a complete AG packet tend to close out regulatory involvement faster and with less financial exposure. Organizations that treated notification as an afterthought, or tried to notify only a subset of affected residents to save money, ended up spending far more on legal fees and reputational cleanup than the notification process would have cost in the first place. Speed and completeness aren’t just legal checkboxes. They’re the difference between a contained incident and a prolonged one.

How Virginia’s Breach Law Compares to Federal and Other State Rules
Virginia doesn’t operate in isolation, and if your business handles data across state lines, you’re likely juggling multiple notification frameworks simultaneously. The federal government has no single, comprehensive breach notification law covering all industries. Instead, sector specific rules apply: HIPAA governs healthcare data, GLBA governs financial institutions, and Virginia’s statute explicitly defers to those frameworks when they apply, meaning compliant entities don’t have to duplicate their notification process.
Compared to other states, Virginia’s law is relatively moderate in scope. Some states set lower or higher thresholds for triggering the >1,000 resident rule that requires consumer reporting agency notification, and definitions of “personal information” vary meaningfully. A few states include biometric data or health insurance information in their covered categories; Virginia’s core definition centers on Social Security numbers, driver’s license numbers, and financial account numbers combined with access codes.
The encryption safe harbor is fairly standard across states, but the specific conditions under which it applies, particularly around whether a compromised key voids the exemption, differ enough that a one size fits all compliance policy is risky. If your business operates in Virginia and even one or two neighboring states, map out each state’s notification triggers separately rather than assuming Virginia’s rules will satisfy everyone else’s requirements. The $150,000 civil penalty ceiling under Virginia’s statute is also notably specific compared to states that scale penalties per affected resident, which can produce far larger exposure at scale.

Why Preparedness Beats Reaction Every Time
Companies that treat breach notification as a legal afterthought consistently pay more, in penalties, in legal fees, and in the credibility they lose with customers. The businesses that come through a breach intact are the ones with a documented risk assessment process already built, encryption already deployed on sensitive fields, and staff who’ve actually been trained to spot the phishing attempt before it becomes an incident report.
None of that happens by accident. It happens because someone decided readiness mattered before the breach, not during it.
— Alden
Getting Ahead of Virginia’s Notification Deadlines
Meeting Virginia’s notification deadlines is a lot easier when you’re not scrambling to figure out what happened while the clock is already running. Total Cyber Solutions works with Virginia businesses on the pieces that actually reduce breach risk and speed up response: incident response and forensic support when something does happen, encryption rollout for the data fields the statute cares about most, and compliance consulting that maps directly to frameworks like HIPAA, CMMC, and NIST.

When an incident does occur, our team helps assemble the Attorney General packet and draft the consumer notice using the exact checklist regulators expect, so you’re not reinventing that process under deadline pressure. Pairing that response capability with managed cybersecurity services means the monitoring that catches an incident early is already in place before you ever need the notification playbook.
If you want a Virginia-based team that understands both the technical and regulatory sides of a breach, request a consultation through our MSP form and we’ll walk through where your current setup has gaps.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Data Breach Notification Requirements — Office of the Attorney General of Virginia
- § 18.2-186.6. Breach of personal information notification — Code of Virginia
- Report a Data Breach | Virginia Tax