Skip to main content

How does Cyber Crucible support Virginia's Consumer Data Protection Act (VCDPA)?

Short answer: Cyber Crucible supports a controller's VCDPA obligations as a processor operating under a data processing agreement, helping with data-security duties and consumer-rights requests. Its no-collection design means it holds little to no personal data, which keeps the controller's processing and response burden low.

How it aligns

  • Processor duties — assist with security, breach notification, and data-protection assessments.
  • Data minimization — no customer content, credentials, or keys collected.
  • Purpose limitation — processing strictly on the controller's instructions.

Vendor-selection notes

The VCDPA requires controllers to bind processors by contract and to conduct assessments for higher-risk processing; the minimal personal-data footprint simplifies both. A data processing agreement is available on request.