{"data":{"id":"us-va/14vac5-430-70","jurisdiction":"us-va","citation":"14VAC5-430-70","heading":"Consumer notification provisions","body":"A. Licensees, except those exempted under subsection A 1 or A 2 of § 38.2-629 of the Code of Virginia, that determine a cybersecurity event has occurred and has caused or has a reasonable likelihood of causing identity theft or other fraud to consumers whose information was accessed or acquired shall notify those consumers in accordance with § 38.2-626 of the Code of Virginia, subject to any applicable numerical threshold.\n\nB. Each licensee required to notify consumers of a cybersecurity event that does not intend to notify consumers based on a belief that the cybersecurity event does not have a reasonable likelihood of causing identity theft or other fraud to the consumers shall notify the commissioner, without unreasonable delay, of its position and provide an explanation supporting the licensee's position.","path":["Title 14. Insurance","Agency 5. State Corporation Commission, Bureau of Insurance","Chapter 430. Insurance Data Security Risk Assessment and Reporting"],"source_url":"https://law.lis.virginia.gov/admincode/title14/agency5/chapter430/section70/","current_through":"2026 Regular Session (effective July 1, 2026)","vintage":"","retrieved_at":"2026-09-14T04:52:03Z","sha256":"22317163e80bfa0c7d6f5af65be67407b06e5573b25483617a485bcf0311dd62","source_id":"us-va-vac","stale":false,"prev":"us-va/14vac5-430-60","next":"us-va/14vac7-10-10"},"notice":"GroundRules: Original legal text. Not legal advice."}
