Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when a company processes personal data…
Governance, Ownership & Risk

What happens when a company processes personal data under the VCDPA without the required consent or assessments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

The company exposes itself to enforcement action rather than private lawsuits, because the Virginia attorney general handles enforcement. Depending on the violation, regulators can seek fines of up to $7,500 per infraction and an injunction to stop continued noncompliance. In practice, the business also inherits operational disruption, rushed remediation, and heightened scrutiny over its privacy controls.

Under the Virginia Consumer Data Protection Act, missing consent or required assessments usually turns a privacy decision into an enforcement problem. The immediate issue is not private litigation, but regulator attention, because the Virginia attorney general is the enforcement authority. That shifts the company from a compliance gap to a public, remediable exposure with penalties and formal corrective pressure.

In practical terms, the legal risk is tied to the type of violation and whether the business keeps processing without curing the defect. Regulators can seek monetary penalties and an injunction, so continued processing can quickly become more expensive than the original control failure. The answer therefore depends less on the paperwork and more on whether the company can prove lawful grounds for processing.

Because the VCDPA is built around lawful processing, the absence of valid consent or a completed assessment is not just a documentation issue. It means the business may have to pause, narrow, or redesign the activity until it can show a defensible basis for collection, use, sharing, and risk review. That is why compliance teams should treat the deficiency as an operational blocker, not a post hoc cleanup item.

Risk and Threat Considerations

The main risk is sustained noncompliance that compounds over time. If the company keeps processing without the required consent or assessment, it can face regulator scrutiny, civil penalties, and an injunction that interrupts the business process being reviewed.

Failure mechanism: The control failure is usually simple, missing lawful basis documentation, incomplete assessment workflow, or processing that continues after consent is absent, withdrawn, or not captured in the required form.

Impact: The likely result is enforcement action, forced remediation, and possible suspension or narrowing of the processing activity, with added operational friction and reputational pressure.

What companies should do before they keep processing

When the risk is active, the first question is whether the processing can be paused safely until the lawful basis is fixed. If the activity is material, the company should prioritize evidence of consent, assessment completion, and scope control before arguing about downstream business need. That sequencing matters because the enforcement response follows the defect, not the intent.

It is also important to verify whether the problem is isolated or systemic. A single missed assessment may be a process failure; repeated gaps usually indicate a governance breakdown in intake, review, or change management. For privacy teams, the practical signal is whether every relevant processing activity can be tied to a current consent state or documented assessment.

For companies with multiple product lines or data flows, the higher-risk cases are the ones that combine broad collection, sensitive data, or a hard-to-reverse operational dependency. In those cases, the corrective plan should focus on narrowing processing first, then rebuilding the legal and procedural record that supports it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRA.5.15 — Identification of processing for lawful basis and governanceLawful processing and assessment discipline underpins the same privacy-control problem.
Recommendation — Map each processing activity to a lawful basis and document the assessment before continuing.
ISO/IEC 27001:2022A.5.34 — Privacy and protection of PIIThe issue is a privacy-control failure over personal data governance and compliance.
Recommendation — Apply privacy governance controls to verify lawful processing and documented reviews for personal data.
NIST SP 800-53 Rev 5AR-2 — Privacy Impact and Risk AssessmentRequired assessments are the core control failure described by the question.
AU-2 — Event LoggingProcessing without required consent or assessment should still be traceable for review and enforcement response.
Recommendation — Perform and retain privacy risk assessments before processing personal data. Log processing decisions and supporting approvals so compliance gaps can be reconstructed quickly.

Practitioner Guidance

What to prioritize: Confirm which processing activities lack consent or the required assessment, then decide whether each one can be paused, narrowed, or defensibly continued while remediation is underway. The decision should be driven by exposure, not by how disruptive a stop would be.

What to verify: Keep a current record that ties each in-scope activity to a valid lawful basis, the relevant assessment outcome, and the control owner responsible for approval and review. If that chain cannot be produced quickly, the process is not ready for continued operation.

Common mistake: Treating the issue as a paperwork gap and continuing the same processing while the legal review catches up. That shortcut often converts a fixable compliance problem into an avoidable enforcement and remediation event.

Practitioner takeaway: Under the VCDPA, the safest posture is to stop or constrain unsupported processing first, then restart only after the consent and assessment record is complete enough to withstand regulator review.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org