The company exposes itself to enforcement action rather than private lawsuits, because the Virginia attorney general handles enforcement. Depending on the violation, regulators can seek fines of up to $7,500 per infraction and an injunction to stop continued noncompliance. In practice, the business also inherits operational disruption, rushed remediation, and heightened scrutiny over its privacy controls.
What the VCDPA changes when consent or assessments are missing
Under the Virginia Consumer Data Protection Act, missing consent or required assessments usually turns a privacy decision into an enforcement problem. The immediate issue is not private litigation, but regulator attention, because the Virginia attorney general is the enforcement authority. That shifts the company from a compliance gap to a public, remediable exposure with penalties and formal corrective pressure.
In practical terms, the legal risk is tied to the type of violation and whether the business keeps processing without curing the defect. Regulators can seek monetary penalties and an injunction, so continued processing can quickly become more expensive than the original control failure. The answer therefore depends less on the paperwork and more on whether the company can prove lawful grounds for processing.
Because the VCDPA is built around lawful processing, the absence of valid consent or a completed assessment is not just a documentation issue. It means the business may have to pause, narrow, or redesign the activity until it can show a defensible basis for collection, use, sharing, and risk review. That is why compliance teams should treat the deficiency as an operational blocker, not a post hoc cleanup item.
Risk and Threat Considerations
The main risk is sustained noncompliance that compounds over time. If the company keeps processing without the required consent or assessment, it can face regulator scrutiny, civil penalties, and an injunction that interrupts the business process being reviewed.
Failure mechanism: The control failure is usually simple, missing lawful basis documentation, incomplete assessment workflow, or processing that continues after consent is absent, withdrawn, or not captured in the required form.
Impact: The likely result is enforcement action, forced remediation, and possible suspension or narrowing of the processing activity, with added operational friction and reputational pressure.
What companies should do before they keep processing
When the risk is active, the first question is whether the processing can be paused safely until the lawful basis is fixed. If the activity is material, the company should prioritize evidence of consent, assessment completion, and scope control before arguing about downstream business need. That sequencing matters because the enforcement response follows the defect, not the intent.
It is also important to verify whether the problem is isolated or systemic. A single missed assessment may be a process failure; repeated gaps usually indicate a governance breakdown in intake, review, or change management. For privacy teams, the practical signal is whether every relevant processing activity can be tied to a current consent state or documented assessment.
For companies with multiple product lines or data flows, the higher-risk cases are the ones that combine broad collection, sensitive data, or a hard-to-reverse operational dependency. In those cases, the corrective plan should focus on narrowing processing first, then rebuilding the legal and procedural record that supports it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | A.5.15 — Identification of processing for lawful basis and governance | Lawful processing and assessment discipline underpins the same privacy-control problem. |
| Recommendation — Map each processing activity to a lawful basis and document the assessment before continuing. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | The issue is a privacy-control failure over personal data governance and compliance. |
| Recommendation — Apply privacy governance controls to verify lawful processing and documented reviews for personal data. | ||
| NIST SP 800-53 Rev 5 | AR-2 — Privacy Impact and Risk Assessment | Required assessments are the core control failure described by the question. |
| AU-2 — Event Logging | Processing without required consent or assessment should still be traceable for review and enforcement response. | |
| Recommendation — Perform and retain privacy risk assessments before processing personal data. Log processing decisions and supporting approvals so compliance gaps can be reconstructed quickly. | ||
Practitioner Guidance
What to prioritize: Confirm which processing activities lack consent or the required assessment, then decide whether each one can be paused, narrowed, or defensibly continued while remediation is underway. The decision should be driven by exposure, not by how disruptive a stop would be.
What to verify: Keep a current record that ties each in-scope activity to a valid lawful basis, the relevant assessment outcome, and the control owner responsible for approval and review. If that chain cannot be produced quickly, the process is not ready for continued operation.
Common mistake: Treating the issue as a paperwork gap and continuing the same processing while the legal review catches up. That shortcut often converts a fixable compliance problem into an avoidable enforcement and remediation event.
Practitioner takeaway: Under the VCDPA, the safest posture is to stop or constrain unsupported processing first, then restart only after the consent and assessment record is complete enough to withstand regulator review.
Related resources from NHI Mgmt Group
- What happens if a business processes sensitive personal information without opt-in consent under TIPA?
- What happens when organisations try to handle personal data under the GDPR without transparent policies and breach processes?
- Who is accountable when a consent framework processes personal data without adequate GDPR controls?
- What happens when personal data is processed without a clear lawful basis under GDPR?