Virginia bans sale of geolocation data — and the rest of the world is watching
Virginia has passed legislation banning the sale of precise geolocation data — making it the first US state to target this category of personal data directly. The law prohibits data brokers and other entities from selling or transferring location information at a granular level, closing a loophole that has allowed precise movement histories to be monetised with minimal restriction.
What the Law Actually Covers
The practical scope is significant. Precise geolocation data has been used by insurers, employers, political campaigns, law enforcement agencies, and commercial advertisers to track individual movements without meaningful consent. Virginia’s law does not apply to all location data — emergency services, navigation functions, and aggregated analytics are carved out — but it directly targets the commercial resale market for granular location histories.
For any business that collects location data from users — whether through a mobile app, fleet tracking system, retail analytics platform, or HR technology — this law raises immediate questions about current data practices and where they might fall short.
A Direction of Travel, Not an Isolated Event
State-level privacy legislation has increasingly set the pace for data regulation in the US, and Virginia’s law represents a meaningful escalation in that trajectory. California, Colorado, and Connecticut have already enacted broad privacy frameworks; this geolocation-specific ban signals that regulators are now targeting specific high-risk data categories rather than waiting for comprehensive legislation.
UK and EU operators should read this carefully. The ICO has signalled increasing scrutiny of location data processing under UK GDPR, and the regulatory environment is converging toward tighter restrictions on how precise movement data can be used and shared commercially. Businesses that built data strategies around location monetisation should be reviewing those strategies today, not when their jurisdiction catches up.
The Right Question for Compliance and Ops Teams
The question is not simply “do we sell location data?” Many organisations would answer no — and still hold significant exposure. The better question is: what location data do we collect, where is it stored, who can access it, under what terms is it shared with third parties, and what is our lawful basis for processing it at all?
For many organisations, the honest answer is that this has not been fully mapped. A location data audit is a prudent step regardless of jurisdiction — and much easier to conduct proactively than reactively.