Virginia Controller-Processor Contract & Vendor Compliance Kit
Virginia's CDPA requires specific contractual terms between controllers and processors — confidentiality, data return/deletion, compliance demonstration, audit rights, and subcontractor flow-down. This kit provides the contract templates and audit questionnaire.
Penalties for Non-Compliance
Virginia Attorney General exclusive enforcement (§ 59.1-584(A)). No private right of action. AG must provide 30-day cure period before seeking penalties (§ 59.1-584(B)). Civil penalties up to $7,500 per violation (§ 59.1-584(C)).
Maximum: Up to $7,500 per violation (§ 59.1-584(C))
Who Must Comply
Controllers doing business in VA or targeting VA residents that (1) process personal data of 100,000+ consumers/year OR (2) derive 50%+ revenue from data sales and process data of 25,000+ consumers.
What's Included (3 Documents)
Processor DPA Template
Processor Audit Questionnaire
Subcontractor Flowdown Addendum
All documents include electronic signature blocks compliant with the ESIGN Act (15 U.S.C. § 7001) and UETA.
What Happens After You Purchase
Your documents generate instantly as fillable PDFs, packaged in a single zip file.
Download directly to your device or email to up to 3 team members.
Fill in the highlighted form fields with your company-specific information. Each document includes clear instructions.
Sign using the electronic signature blocks — ESIGN Act compliant, no printing required.
Have your legal team review the completed documents before deployment.
Statutory Authority
Citation: Va. Code §§ 59.1-575 through 59.1-584
View official source(opens in new tab)Complete Package
$89
One-time purchase. Instant download.
- 3 customized documents
- Instant digital download
- Based on Va. Code §§ 59.1-575 through 59.1-584
- Secure checkout via Stripe
vs. $5,000–$25,000 at a law firm
Verified against enacted statute text
Source: Va. Code §§ 59.1-575 through 59.1-584Questions before purchasing? Email us
Step 1 of 3
Company Information
You May Also Need
Strengthen your compliance program with related documentation.
NYC Local Law 144
If you hire in New York City and use any automated tool to screen or evaluate candidates, you need a...
Texas TDPSA
The Texas Data Privacy and Security Act requires data protection assessments for targeted advertisin...
Delaware PDPA
Delaware has the lowest applicability threshold of any state privacy law — just 35,000 consumers. If...