Didomi enables you to build consent notices compliant with Virginia Consumer Data Protection Act (VCDPA). The VCDPA features particular requirements that must be included in your notice,
- Vendors processing Sensitive Personal Information (SPI) must be displayed
- Purposes have to be grouped into pre-defined categories
- Global Privacy Control (GPC) must be taken into consideration
The following steps show you how to properly configure VCDPA on your notice.
⚠️ The IAB TCF framework does not apply to VCDPA regulation. It is only valid for GDPR.
⚠️ For now, only the English language is supported for VCDPA.
⚠️ Multi multi-regations approach is not yet compatible with the Didomi Consents API. As a result, the Cross-Device and Batch Export features cannot be used for VCDPA but for GDPR only.
✅ Add SPI to your vendors
Sensitive Personal Information (SPI) is defined as personal information that is not publicly available, and which reveals information related to:
- Racial or Ethnic Origin,
- Religious Beliefs,
- Mental or Physical Health Diagnosis,
- Sexual life or Orientation,
- Citizenship or Citizenship status,
- Genetic data that may be processed for the purpose of uniquely identifying an individual,
- Biometric data that may be processed for the purpose of uniquely identifying an individual,
- Information of Known Child
The list of possible SPI is specified in VCDPA regulations and cannot be customized.
Vendors collecting SPI need to be declared in the Didomi console so this can be reflected in your notice:
- Go to the Vendors tab in the Data Manager.
- Choose Edit Vendor.
- Scroll down to the Sensitive Personal Information.
- Select the SPI relevant to your vendor.
- Hit the Save button.
If your vendor does not process SPI, you can leave the above section empty.
SPI information will not be disclosed in your notices for other regulations if you use the same vendor for VCDPA and other regulations. Except if they use the same SPI.
It is not possible to add SPI to IAB vendors, since IAB vendor information is populated directly from the IAB, and they do not yet support VCDPA.
In this case, you need to create a custom vendor instead of using the IAB option.
✅ Configure your VCDPA notice
To create your VCDPA notice, follow these steps:
- Go to Consent notices and choose Edit Notice.
- In the Regulations tab of step 1. Regulations, select VCDPA from the list of regulations (additional several regulations can be selected, since Didomi supports multiple regulations).
- Click on Edit Vendors & Purposes.
- Select the vendors to be added to your VCDPA notice. To create custom vendors, click on Add a new vendor.
- Scroll down to the Sensitive Personal Information section.
- If any of the vendors you selected process SPI, these will be listed.
If you click on the Preview button next to an SPI, you can access the list of vendors processing this SPI and update it accordingly.
- If none of the selected vendors process SPI, this section remains empty.
- If any of the vendors you selected process SPI, these will be listed.
- Scroll down to the Purposes section. The purposes associated with the selected vendors appear above the three mandatory VCDPA categories.
This is mandatory to drag and drop each purpose into one of the categories. There can only be one category per purpose. - Hit the Save button.

Don't forget to fill in specific VCDPA parameters for each step (Look & feel, Content editor, and Integrations, especially).
For now, only the English language is supported for VCDPA notices.
✅ This is how your VCDPA notice will look:
- 1st layer
- Personal information layer
- Sensitive Personal Information (SPI) layer
- Partners layer
✅ GPC signal
Global Privacy Control (GCP) is a privacy signal supported by several browsers for users to specify at the browser level that they do not want their data to be processed (more details about GPC and supported browsers available in GPC specifications).
Didomi VCDPA notices support GPC automatically.
As soon as the signal is detected, your VCDPA notice is adjusted to respect the user choice via GPC:
- A "GPC signal detected" icon is displayed in the notice.
- All personal information will be set to Do not sell / Do not share.
- All SPI will be set to Disagree.
- Instead of Agree and Close there will be a Close button.
There is no option yet to enable or disable GPC from the console. It is automatically supported.