Guide

The Virginia CDPA and GA4: A Compliance Overview

Virginia's Consumer Data Protection Act uses an opt-out model built around 'targeted advertising' rather than 'sale.' Here's what that means for a standard GA4 setup.

Published August 26, 2026·Last updated August 26, 2026

Virginia’s Consumer Data Protection Act (CDPA), effective January 1, 2023, was the second comprehensive state privacy law in the US and the template several other states followed. It matters for GA4 specifically because of a framing difference from California’s CCPA that trips people up: the CDPA doesn’t require a “sale” to trigger an opt-out right, it regulates “targeted advertising” directly.

Who the CDPA applies to

The CDPA applies to businesses that, during a calendar year, either:

  • Control or process personal data of at least 100,000 Virginia consumers, or
  • Control or process personal data of at least 25,000 Virginia consumers and derive over 50% of gross revenue from the sale of personal data.

Unlike the CCPA, there’s no minimum revenue threshold on its own, a smaller business with enough Virginia traffic can be in scope even without CCPA-level revenue.

Why “targeted advertising” matters more than “sale” here

The CDPA defines targeted advertising broadly: displaying ads to a consumer based on personal data obtained from that consumer’s activity across nonaffiliated websites or apps, to predict preferences or interests. That’s a functional description of what GA4’s Google Signals feature and any ads-linked audience does, whether or not Google technically “sells” the data to you or a third party. Practically, that means:

  • A standard GA4 + Google Ads Linking setup likely counts as targeted advertising under the CDPA, independent of whether you’d also call it a “sale.”
  • Consumers have the right to opt out of targeted advertising, and you need a functioning mechanism for that, not just a privacy policy disclosure.
  • The CDPA recognizes universal opt-out mechanisms, meaning a properly configured Global Privacy Control signal has to be honored as a valid opt-out request; see our GPC and GA4 guide for the technical side of that.

What the CDPA does not include (compared to CCPA)

  • No private right of action. Enforcement is exclusively through the Virginia Attorney General, with a 30-day cure period before penalties, so the practical litigation risk profile is different from California’s, though not zero.
  • No dedicated privacy agency like California’s CPPA, enforcement sits with the AG’s office directly.
  • Right to opt out of “sale,” “targeted advertising,” and “profiling” are each named separately, giving Virginia residents a slightly more granular set of opt-out categories than the CCPA’s original “sale” framing.

Configuring GA4 for CDPA compliance

Our recommendation

Enzuzo

Enzuzo bundles a targeted-advertising opt-out mechanism with the privacy policy language needed to disclose it, useful for smaller teams handling CDPA and CCPA obligations without a dedicated legal or compliance function.

Try Enzuzo
  1. Disclose GA4 and any ads-linked features in your privacy policy using language that maps to the CDPA’s own categories (targeted advertising, sale, profiling), not just generic “we use analytics” boilerplate.
  2. Provide a functioning opt-out for targeted advertising, gating Google Signals and ads personalization behind it, the same technical work needed for CCPA’s “share” category largely satisfies this too.
  3. Honor GPC as a universal opt-out signal.
  4. Don’t assume a small Virginia audience means you’re exempt, the 25,000-consumer threshold with the revenue condition is lower than most businesses expect.

How this compares to other states

Virginia’s “targeted advertising” framing is closer to Colorado’s and Connecticut’s approach than to California’s original “sale” language. See our state-by-state breakdown and our Colorado Privacy Act guide for the closest comparison.

This overview is educational and not legal advice. Whether the CDPA applies to your business and what your specific GA4 configuration requires depends on facts a privacy attorney should review.