Key point: Plaintiffs in Virginia have focused on a rarely tested state privacy statute with statutory damages that imposes notice-and-consent obligations on retailers that share or sell in-store customer data.
Most retailers have spent the last several years building their privacy compliance programs around the major comprehensive state privacy laws, such as Virginia’s Consumer Data Protection Act (CDPA), California’s Consumer Privacy Act (CCPA), and their counterparts in a dozen other states. A recent lawsuit filed in the Eastern District of Virginia is a reminder that older, narrower statutes can carry just as much litigation risk, and that the plaintiffs’ bar is actively looking for the next viable theory.
The statute at issue is the Virginia Personal Information Privacy Act (VPIPA). It has been on the books for decades. Until recently, however, it had produced exactly one lawsuit. That may be changing.
What the VPIPA Actually Says
The VPIPA applies to businesses engaged in the sale of goods from a fixed retail location in Virginia. Its core prohibition is straightforward: a merchant cannot sell to a third party any information concerning a purchaser that was gathered in connection with the sale, rental, or exchange of goods at the merchant’s place of business, unless the merchant gives adequate notice and honors any customer request not to sell their information. Notice can be satisfied by a posted sign or other reasonable method, but it must actually happen.
Although the statute contains exceptions, they are relatively limited. For example, the statute exempts information gathered to extend credit, information drawn from public records, and information incidental to a sale of accounts receivable or a business’s retail operations. These exceptions are narrow and are unlikely to cover most modern data-sharing arrangements, such as relationships with data brokers and advertising networks.
The damages exposure is $100 per violation in statutory damages, plus attorneys’ fees and costs. For a retailer processing thousands of transactions per day, even a modest per-violation theory aggregates quickly in a class action.
How We Got Here
The VPIPA’s litigation history is thin. In 2020, a plaintiff filed suit in Massachusetts federal court alleging a VPIPA violation. Notably, the plaintiff had no direct evidence that their own data had been sold. Instead, they relied on a data broker’s marketing materials, which named the retailer and offered its customer data for sale, combined with allegations that store employees had requested customer PII at checkout. The court found that combination sufficient to plausibly allege an unlawful sale and allowed the case to proceed. It settled individually shortly after, never reached class certification, and the statute then went largely quiet.
That quiet is over.
What This Means for Retailers
The combination of a low pleading bar, statutory damages, and an available attorneys’ fees provision makes the VPIPA an attractive vehicle for class action litigation. For any business operating a fixed retail location in Virginia, now is a good time to evaluate:
- Whether customer data gathered from in-store transactions is being shared with any third party, including advertising partners, data brokers, or data clean room providers;
- Whether customers are receiving adequate notice through in-store signage or another reasonable method, and whether opt-out requests are being honored;
- How data-sharing relationships are described in public-facing materials, including vendor and marketing partner websites, which plaintiffs have used as evidence; and
- Whether existing privacy policies, in-store signage, and vendor agreements address the VPIPA specifically, as distinct from broader CDPA or federal compliance efforts.
The VPIPA is not a statute that was designed with modern adtech in mind. But courts are now being asked to apply it to exactly those arrangements. Retailers with Virginia physical locations should assess their exposure before this becomes a larger area of focus for the plaintiffs’ bar.
If you have questions about the VPIPA or want to assess your company’s exposure, please reach out to Dustin Taylor (Dustin.Taylor@troutman.com) or your usual Troutman Pepper Locke contact.