Each one links to its
LexLint note, which carries what it requires and what it flags on.
Requires a commercial entity that knowingly and intentionally publishes or distributes sexual material harmful to minors, where such material is a substantial portion (more than 33.33 percent) of the entity's content, to verify that a user is 18 or older using digital identification or a commercial or governmental age verification system. Exempts news gathering organizations, internet service providers, search engines, and cloud service providers.
Note and primary source →
An individual or entity that owns or licenses computerized data including personal information must give notice of a breach of the security of the system, without unreasonable delay, to any West Virginia resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person, where the breach causes or is reasonably believed to cause identity theft or other fraud.
Personal information is name plus a Social Security number, driver's license or state ID number, or a financial account number with access credential; health information, biometric data, and genetic data are not folded into this definition, unlike South Dakota's narrower biometric fold-in researched alongside this state. An entity required to notify more than 1,000 persons of a breach must also notify nationwide consumer reporting agencies.
A notice violation is deemed an unfair or deceptive act under West Virginia's general Consumer Credit and Protection Act, but the Attorney General has exclusive authority to bring that action (except against a licensed financial institution, enforced instead by its own primary regulator), which closes the private right of action that West Virginia's general unfair-trade-practices statute, W. Va. Code sec. 46A-6-106, would otherwise open for 'any person who purchases or leases goods or services' suffering an ascertainable loss.
This Act's own codified page carries no separate commencement date beyond its 2008 Regular Session enactment (S.B. 340), so no effective_date is recorded here.
What it asks of an app →
House Bill 2987, as passed by the House (Engrossed Committee Substitute), would have created a Consumer Data Protection Act at new Chapter 46A, Article 6O, applying to a person doing business in West Virginia that controls or processes personal data of at least 100,000 consumers, or that derives over 50% of gross revenue from selling personal data while processing at least 25,000 consumers' data.
Controllers would have owed data-subject rights (access, correction, deletion, portability, opt-out of targeted advertising, sale, and significant-effect profiling, on a 45-day response deadline extendable once by 45 days) and data protection assessments for high-risk processing.
Biometric data would have been defined as data from automatic measurements of biological characteristics used to identify a specific individual, but the definition excluded a photograph, video, or audio recording, or data generated from either, unconditionally, with no clawback for data generated to identify someone, the same shape as Indiana's, Florida's, and Pennsylvania's proposed equivalent.
Genetic or biometric data processed to uniquely identify a person would have been sensitive data requiring opt-in consent. This bill passed the House 2025-03-26, was referred to Senate Judiciary and then Finance the next day, and received no further action before the 2025 Regular Session adjourned; West Virginia's annual, non-carrying session numbering means it did not return in 2026, and the bill number was not reused for an unrelated 2026 law.
It never became law and has no current legal effect. A companion article the same bill would have created, Chapter 31A, Article 8H (a cybersecurity-program litigation safe harbor), separately and independently foreclosed a private right of action for its own subject matter.
What it asks of an app →