Key point: Plaintiffs in Virginia have focused on a rarely tested state privacy statute with statutory damages that imposes notice-and-consent obligations on retailers that share or sell in-store customer data.
Most retailers have spent the last several years building their privacy compliance programs around the major comprehensive state privacy laws, such as Virginia’s Consumer Data Protection Act (CDPA), California’s Consumer Privacy Act (CCPA), and their counterparts in a dozen other states. A recent lawsuit filed in the Eastern District of Virginia is a reminder that older, narrower statutes can carry just as much litigation risk, and that the plaintiffs’ bar is actively looking for the next viable theory.
The statute at issue is the Virginia Personal Information Privacy Act (VPIPA). It has been on the books for decades. Until recently, however, it had produced exactly one lawsuit. That may be changing.







