A BILL to amend the Code of Virginia by adding in Title 59.1 a chapter numbered 60, consisting of sections numbered 59.1-614 through 59.1-618, relating to regulation of data brokers; civil penalties.
HB638 would create a new chapter in Title 59.1 of the Code of Virginia to regulate data brokers and impose civil penalties for violations. The bill defines key terms such as “data broker,” “consumer,” “biometric data,” and “artificial intelligence system,” and it appears aimed at businesses that collect and sell personally identifiable information about consumers with whom they do not have a direct relationship. The text shown also begins listing exclusions for certain businesses and activities that would not be treated as data brokers, indicating the bill is intended to target a specific subset of the data marketplace rather than all companies that handle consumer information.
Although the excerpt provided cuts off before the full regulatory framework, the caption and chapter structure indicate the bill would establish new legal duties for data brokers in Virginia and authorize civil penalties for noncompliance. In practical terms, it would affect businesses whose primary revenue comes from selling consumer data, while likely leaving ordinary service providers and other enumerated exceptions outside the new regime. The bill would add a new statutory chapter in Title 59.1 and expand state oversight of consumer data sales and related privacy practices.
HB638 would add Chapter 60, “Data Broker Regulation,” to Title 59.1 of the Virginia Code and create new statutory definitions and compliance obligations for data brokers. It would likely require covered businesses to follow state rules governing the collection, sale, and possibly disclosure of personally identifiable information, with civil penalties available for violations. The bill would primarily affect data brokers and related information-resale businesses, while carving out certain directory, reporting, and other specified activities from the definition of data broker.
The available legislative history suggests the bill did not advance out of committee and was continued to the next session by voice vote in the House Communications, Technology and Innovation Committee. That procedural outcome indicates the measure had not yet secured enough support for immediate passage, but the absence of recorded opposition or vote breakdown makes the overall sentiment difficult to gauge precisely. Based on the subject matter, the bill appears to have been treated as a serious consumer-privacy and technology-regulation proposal rather than a highly partisan measure.
The main point of contention is likely the scope of the new regulation: which businesses should be treated as data brokers, what kinds of data sales should trigger coverage, and how broad the exemptions should be for businesses that incidentally collect or share consumer information. Another likely issue is the balance between consumer privacy protections and the compliance burden on data-driven businesses, especially those using large-scale data collection, analytics, or artificial intelligence tools. Because the bill was continued rather than voted through, it appears there was at least some unresolved concern about the bill’s details or readiness for enactment.