West Virginia · verified through August 25, 2026

West Virginia: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

WV · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified

Official name / citation
n.a.
Status / effective date
n.a.
Principal enforcer
West Virginia Attorney General

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

W. Va. Code § 46A-2A-101 et seq. (notice of breach of security of computerized personal information) - https://code.wvlegislature.gov/46A-2A-102/

Public enforcement context

Tier 1*

23andMe (bankruptcy claims; trustee)

$150 million in allowed state claims, with actual state recovery limited to $18 million; separate $46.75 million consumer class settlement · July 14, 2026

A coalition of 42 attorneys general settled bankruptcy claims arising from the 2023 breach of 23andMe genetic data affecting about 6.9 million customers worldwide. West Virginia is named among the 42 participating jurisdictions on the Michigan AG page; no West Virginia share is stated there.

Legal basis: State data-privacy, consumer-protection and genetic-information privacy claims asserted in the bankruptcy (no single statute named)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.