Agent skill

Vcdpa Compliance

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Virginia Consumer Data Protection Act (VCDPA) compliance implementation.

Apache-2.0Auto-check passedLegal & Compliance

Install Vcdpa Compliance

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vcdpa-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills vcdpa-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vcdpa-compliance .claude/skills/vcdpa-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vcdpa-compliance
GitHub stars
301
Token cost
~2.6k tokens
SKILL.md length
1,308 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Virginia Consumer Data Protection Act (VCDPA) compliance implementation.

  • Works in 5 steps: Right to Access (§59.1-577(A)(1)) → Right to Correct (§59.1-577(A)(2)) → Right to Delete (§59.1-577(A)(3)) → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Applicability (§59.1-576), Five Consumer Rights (§59.1-577) and Sensitive Data Processing…, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Vcdpa Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/vcdpa-compliance”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Right to Access (§59.1-577(A)(1))
  2. Right to Correct (§59.1-577(A)(2))
  3. Right to Delete (§59.1-577(A)(3))
  4. Right to Data Portability (§59.1-577(A)(4))
  5. Right to Opt Out (§59.1-577(A)(5))

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vcdpa Compliance loads about 2.6k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 1,308 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,308 words, ~2,590 tokens.

Download SKILL.mdSave it as .claude/skills/vcdpa-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
vcdpa-compliance
description
Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
us-state-privacy-laws
metadata.tags
vcdpa, virginia-privacy, consumer-rights, dpia, ag-enforcement

Virginia Consumer Data Protection Act (VCDPA)

Overview

The Virginia Consumer Data Protection Act (VCDPA), codified as Va. Code §59.1-575 through §59.1-585, was signed into law on March 2, 2021, and became effective on January 1, 2023. Virginia was the second state to enact comprehensive consumer privacy legislation after California. The VCDPA follows the controller-processor model used in the GDPR rather than the business-service provider framework of the CCPA.

The VCDPA is enforced exclusively by the Virginia Attorney General — there is no private right of action and no dedicated privacy enforcement agency. The AG must provide a 30-day cure period before initiating enforcement action under §59.1-584.

Applicability (§59.1-576)

The VCDPA applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents AND:

  1. During a calendar year, control or process personal data of at least 100,000 Virginia consumers; OR
  2. Control or process personal data of at least 25,000 Virginia consumers AND derive over 50% of gross revenue from the sale of personal data.

Exemptions (§59.1-576(B)):

  • Virginia governmental entities
  • Financial institutions subject to GLBA (Title V of Gramm-Leach-Bliley Act, 15 U.S.C. §6801 et seq.)
  • Covered entities and business associates under HIPAA (42 U.S.C. §1320d et seq.)
  • Nonprofit organizations
  • Institutions of higher education
  • Data subject to GLBA, HIPAA, FERPA, FCRA, DPPA, or Farm Credit Act

Liberty Commerce Inc. Assessment: Liberty Commerce Inc. processes personal data of approximately 145,000 Virginia consumers through its e-commerce platform. It meets threshold (1) and is subject to the VCDPA.

Five Consumer Rights (§59.1-577)

1. Right to Access (§59.1-577(A)(1))

Consumers have the right to confirm whether a controller is processing their personal data and to access such personal data.

Liberty Commerce Inc. Implementation: Consumers access their data profile through the privacy portal at privacy.libertycommerce.com/virginia. The system generates a comprehensive data access report including all categories of personal data processed, sources, purposes, and any third-party recipients.

2. Right to Correct (§59.1-577(A)(2))

Consumers have the right to correct inaccuracies in their personal data, taking into account the nature of the personal data and the purposes of the processing.

3. Right to Delete (§59.1-577(A)(3))

Consumers have the right to delete personal data provided by or obtained about the consumer.

Liberty Commerce Inc. Implementation: Deletion requests propagate to all processors within 30 days. Retained data for legal compliance is documented with specific legal basis.

4. Right to Data Portability (§59.1-577(A)(4))

Consumers have the right to obtain a copy of their personal data previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance.

5. Right to Opt Out (§59.1-577(A)(5))

Consumers have the right to opt out of:

  • Targeted advertising — displaying advertisements to a consumer based on personal data obtained from the consumer's activities across nonaffiliated websites, applications, or online services
  • Sale of personal data — exchange of personal data for monetary consideration
  • Profiling — in furtherance of decisions that produce legal or similarly significant effects concerning the consumer

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. provides a unified opt-out mechanism on its Virginia privacy page. Consumers can opt out of each category independently. GPC signals are recognized and honored as opt-out of targeted advertising and sale, consistent with multi-state compliance.

Sensitive Data Processing (§59.1-578(A)(5))

The VCDPA requires opt-in consent before processing sensitive data. This is a stricter standard than CCPA/CPRA (which allows collection without consent but provides a limit right).

Sensitive Data Categories (§59.1-575)
  1. Personal data revealing racial or ethnic origin
  2. Religious beliefs
  3. Mental or physical health diagnosis
  4. Sexual orientation
  5. Citizenship or immigration status
  6. Genetic or biometric data processed for identification
  7. Personal data collected from a known child
  8. Precise geolocation data (within 1,750 feet / 533 meters)

Key difference from CPRA: VCDPA requires prior consent; CPRA permits collection with a post-collection limit right.

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. obtains opt-in consent before processing sensitive data from Virginia consumers. The consent mechanism presents each sensitive data category separately with clear affirmative action (unticked checkbox). Consent records include: consumer ID, category, consent text version, timestamp, and mechanism.

Controller Obligations (§59.1-578)

Data Minimization (§59.1-578(A)(1))

Limit collection to what is adequate, relevant, and reasonably necessary in relation to the purposes.

Purpose Limitation (§59.1-578(A)(2))

Do not process personal data for purposes not reasonably necessary to or compatible with the disclosed purposes.

Security (§59.1-578(A)(3))

Establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue.

Non-Discrimination (§59.1-578(A)(4))

Do not process personal data in violation of state and federal antidiscrimination laws.

Obtain consent before processing sensitive data.

Show full SKILL.md (530 more words)Show less
Privacy Notice (§59.1-578(B))

Provide a reasonably accessible, clear, and meaningful privacy notice that includes:

  • Categories of personal data processed
  • Purpose for processing
  • How consumers may exercise their rights (including appeal)
  • Categories of personal data shared with third parties
  • Categories of third parties with whom data is shared
  • Contact information for the controller
Response Timeline (§59.1-578(C))
  • Respond within 45 days of receipt
  • Extension: Up to 45 additional days (90 total) with notice to consumer

Data Protection Impact Assessments (§59.1-580)

Controllers must conduct and document DPIAs for processing activities that present a heightened risk of harm to consumers. Required for:

  1. Targeted advertising processing
  2. Sale of personal data
  3. Profiling where it presents a reasonably foreseeable risk of:
    • Unfair or deceptive treatment or unlawful disparate impact
    • Financial, physical, or reputational injury
    • Physical intrusion or surveillance creating offense to a reasonable person
    • Other substantial injury
  4. Sensitive data processing
  5. Any processing activity involving personal data that presents a heightened risk of harm
DPIA Content Requirements
  • Identify and weigh the benefits from the processing against potential risks
  • Consider use of de-identified data
  • Factor in the reasonable expectations of consumers
  • Consider the context of processing and the relationship between controller and consumer

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. has completed DPIAs for:

  • Targeted advertising program (AdReach Network partnership)
  • Marketplace seller data sale to analytics partners
  • Consumer credit scoring for buy-now-pay-later feature
  • Precise geolocation processing for delivery optimization
  • Sensitive data processing (optional diversity surveys)

Each DPIA is reviewed annually and upon material changes. DPIAs are retained for five years.

Processor Requirements (§59.1-579)

Processing must be governed by a contract between the controller and processor that includes:

  • Instructions for processing data
  • Nature and purpose of processing
  • Type of data subject to processing and duration
  • Rights and obligations of both parties
  • Requirement that the processor ensure persons processing data are subject to a duty of confidentiality
  • Requirement to delete or return all personal data at controller's direction upon end of services
  • Requirement to make available information to demonstrate compliance (upon reasonable request)
  • Requirement to allow and cooperate with reasonable assessments by the controller or the controller's designated assessor
  • Requirement that the processor engage sub-processors only pursuant to a written contract with obligations no less protective than the controller-processor contract

Enforcement (§59.1-584)

Attorney General Authority
  • Exclusive enforcement authority under the VCDPA
  • May investigate potential violations
  • May issue civil investigative demands (CIDs)
  • Must provide 30-day written notice of alleged violations before bringing action
30-Day Cure Period
  • Controller or processor has 30 days after receiving AG notice to cure the alleged violation
  • If cured: AG may not bring action for that violation
  • If not cured: AG may bring action under the Virginia Consumer Protection Act (§59.1-196 et seq.)
Penalties
  • Civil penalties up to $7,500 per violation
  • Reasonable expenses including attorney fees
  • Injunctive relief

Key Regulatory References

  • Va. Code §59.1-575 — Definitions
  • Va. Code §59.1-576 — Applicability and exemptions
  • Va. Code §59.1-577 — Consumer rights
  • Va. Code §59.1-578 — Controller obligations
  • Va. Code §59.1-579 — Processor requirements
  • Va. Code §59.1-580 — Data protection impact assessments
  • Va. Code §59.1-581 — De-identified data
  • Va. Code §59.1-582 — Limitations
  • Va. Code §59.1-583 — Consumer rights request procedures
  • Va. Code §59.1-584 — Enforcement, 30-day cure period
  • Va. Code §59.1-585 — Relation to other laws

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vcdpa-compliance of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Vcdpa Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vcdpa Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vcdpa Compliance this skillmukul975/Privacy-Data-Protection-Skills301—~2.6kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Vcdpa Compliance

What does Vcdpa Compliance do?

Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Vcdpa Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Virginia Consumer Data Protection Act (VCDPA) compliance implementation.

When should I use Vcdpa Compliance?

Vcdpa Compliance fits situations like: tasks that involve Privacy and GDPR.

How do I install Vcdpa Compliance in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vcdpa-compliance -a claude-code`. Or copy the skill folder (skills/privacy/vcdpa-compliance in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vcdpa-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Vcdpa Compliance in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vcdpa-compliance -a codex`. Or copy the skill folder (skills/privacy/vcdpa-compliance in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vcdpa-compliance in your project. Codex loads it when a task matches its description.

Can I use Vcdpa Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vcdpa-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vcdpa-compliance, .gemini/skills/vcdpa-compliance, .github/skills/vcdpa-compliance and .opencode/skills/vcdpa-compliance in your project.

What does Vcdpa Compliance need to run?

Going by SKILL.md and its folder, Vcdpa Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Vcdpa Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vcdpa Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vcdpa Compliance use?

Vcdpa Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vcdpa Compliance use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Vcdpa Compliance?

Skills that share tags, products or a category with Vcdpa Compliance: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vcdpa Compliance?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.