Kentucky
Kentucky Data Privacy Laws: Consumer Rights Guide (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 20 primary sources cited on this page. How we verify our legal content

The Kentucky Consumer Data Protection Act, codified at KRS 367.3611 through 367.3629, took effect January 1, 2026, granting Kentucky residents the right to access, correct, delete, and opt out of personal data processing. Qualifying businesses must comply, and the Kentucky Attorney General enforces the law with civil penalties up to $7,500 per violation.
Kentucky enacted one of the most significant data privacy laws in the nation when Governor Andy Beshear signed the Kentucky Consumer Data Protection Act into law on April 4, 2024. The KCDPA, codified at KRS 367.3611 through 367.3629, made Kentucky the fifteenth state to adopt a comprehensive consumer data privacy statute. It took effect January 1, 2026.
This guide covers the full scope of Kentucky's data privacy framework, including the KCDPA, the state's data breach notification law, the first enforcement action under the new law, federal overlay statutes, and practical steps for consumers and businesses.
Kentucky Consumer Data Protection Act (KCDPA)
The Kentucky Consumer Data Protection Act is codified in KRS 367.3611 through 367.3629. It governs how businesses collect, use, process, and store personal data belonging to Kentucky consumers.

The KCDPA closely resembles Virginia's Consumer Data Protection Act and Connecticut's Data Privacy Act. It establishes an opt-out framework for general personal data processing while requiring opt-in consent for sensitive data categories.
Who the KCDPA Applies To
The KCDPA applies to any person or entity that conducts business in the Commonwealth of Kentucky or produces products or services targeted to Kentucky residents, and that during a calendar year meets either of these thresholds:
Threshold one. Controls or processes the personal data of at least 100,000 Kentucky consumers.
Threshold two. Controls or processes the personal data of at least 25,000 Kentucky consumers while deriving over 50% of gross revenue from the sale of personal data.
Unlike some state privacy laws, the KCDPA does not include a separate revenue threshold. A business of any size can fall under the law if it meets one of the two processing thresholds above.
The law defines a "consumer" as a natural person who is a Kentucky resident acting in an individual context. People acting in a commercial or employment context are not considered consumers under the KCDPA.
Exempt Entities
The KCDPA exempts several categories of organizations from its requirements entirely:
- State agencies, city governments, and political subdivisions of the Commonwealth
- Financial institutions and their affiliates subject to the Gramm-Leach-Bliley Act (GLBA)
- Covered entities and business associates governed by the Health Insurance Portability and Accountability Act (HIPAA)
- Nonprofit organizations
- Institutions of higher education
- Organizations that assist law enforcement with insurance fraud investigations
- Organizations assisting first responders during catastrophic events
- Certain small telephone utilities and Tier III CMRS providers
- Municipal utilities that do not sell or share consumer data with third-party processors
Data-Level Exemptions
Beyond entity-level exemptions, the KCDPA also exempts specific categories of data from its coverage, regardless of who holds the data:
- Publicly available information and de-identified data
- Data processed under the Fair Credit Reporting Act (FCRA)
- Data regulated under GLBA or HIPAA
- Data protected under the Driver's Privacy Protection Act (DPPA)
- Education records covered by the Family Educational Rights and Privacy Act (FERPA)
- Employment and independent contractor data
- Emergency contact information
- Farm Credit Act data
- Health care quality improvement and patient safety activity data
Consumer Rights Under the KCDPA
The KCDPA grants Kentucky residents five core rights over their personal data. These rights are detailed in KRS 367.3615.
Right to confirm and access. You can request that a business confirm whether it processes your personal data and obtain access to that data, provided the disclosure does not reveal trade secrets.
Right to correct. You can request that a business correct inaccurate personal data it holds about you.
Right to delete. You can request deletion of personal data you provided or that the business obtained about you.
Right to data portability. You can request a copy of your personal data in a portable and readily usable format, again subject to trade secret protections.
Right to opt out. You can opt out of the processing of your personal data for three specific purposes: targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects.
How to Exercise Your Rights
Controllers must respond to consumer rights requests without undue delay and no later than 45 days after receiving the request. This window can be extended by an additional 45 days if reasonably necessary, as long as the controller notifies the consumer of the extension and explains the reason.
If a controller denies a request, it must provide an appeals process. Consumers who are dissatisfied with the outcome of an appeal can file a complaint with the Kentucky Attorney General's Office of Data Privacy.
No Authorized Agent or Universal Opt-Out
One notable limitation of the KCDPA is that it does not require controllers to recognize universal opt-out mechanisms such as Global Privacy Control (GPC). Consumers must submit individual opt-out requests directly to each business.
The KCDPA also does not provide a mechanism for authorized agents to submit requests on behalf of consumers. This stands in contrast to laws in California, Colorado, Connecticut, and several other states that require recognition of these tools.
Personal Data and Sensitive Data Definitions
The KCDPA defines "personal data" as any information that is linked or reasonably linkable to an identified or identifiable natural person. De-identified data and publicly available information are excluded from this definition.

Sensitive Data Categories
"Sensitive data" receives heightened protections under the KCDPA and includes:
- Personal data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for the purpose of uniquely identifying a natural person
- Biometric data used to identify a specific individual
- Personal data collected from a known child
- Precise geolocation data
Controllers must obtain the consumer's opt-in consent before processing any category of sensitive data. That consent must be freely given, specific, informed, and unambiguous.
Children's Data Protections
The KCDPA treats personal data collected from a known child as sensitive data, requiring opt-in consent. Controllers that comply with the verifiable parental consent requirements of the federal Children's Online Privacy Protection Act (COPPA) are deemed compliant with the KCDPA's requirements for children's data.
The Kentucky Attorney General demonstrated immediate commitment to enforcing children's data protections. On January 8, 2026, just eight days after the KCDPA took effect, AG Russell Coleman filed suit in Franklin Circuit Court against Character Technologies, the operator of the Character.AI chatbot platform. The complaint alleged the company failed to obtain parental consent before collecting and processing children's sensitive data, exposed minors to harmful content, and repurposed private emotional disclosures and health statements to train AI models without consent. The AG sought $2,000 per count in civil relief, plus injunctive relief.
Notably, the AG filed without first issuing the 30-day cure notice the KCDPA ordinarily requires. The complaint pursued claims under both the KCDPA and the Kentucky Consumer Protection Act, a consumer-protection statute that does not carry a statutory cure-period requirement. This enforcement approach signals that the AG's office will pursue children's data violations aggressively, potentially pairing KCDPA claims with other statutes to work around the cure period when sensitive data is involved.
Sale of Personal Data
The KCDPA defines the "sale" of personal data narrowly, covering only exchanges of personal data for monetary consideration. This is a business-friendly definition that mirrors the approach used in Virginia and Utah, and excludes data exchanges made for other types of valuable consideration such as improved services or analytics.
Controller and Processor Obligations
Controller Duties
Businesses that qualify as data controllers under the KCDPA must meet several core obligations outlined in KRS 367.3617:
Data minimization. Controllers must limit data collection to what is adequate, relevant, and reasonably necessary for the disclosed processing purpose.
Purpose limitation. Controllers must not process personal data for purposes that are not reasonably necessary to or compatible with the purposes they disclosed to consumers.
Security practices. Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.
Nondiscrimination. Controllers must not discriminate against consumers who exercise their data privacy rights, though reasonable differences related to loyalty, rewards, or premium programs are permitted.
Privacy notice. Controllers must provide a clear, accessible privacy notice that discloses the categories of personal data processed, the purposes of processing, how consumers can exercise their rights, the categories of data shared with third parties, and the categories of those third parties.
Disclosure of sales and targeted advertising. If a controller sells personal data or processes it for targeted advertising, it must clearly and conspicuously disclose that practice.
Automatic content recognition consent (effective July 1, 2027). HB 692 (2026 Regular Session), enacted as 2026 Ky. Acts ch. 118 and signed April 13, 2026, adds a new controller duty at KRS 367.3617(1)(f): controllers must not collect automatic content recognition data without a consumer's consent. The Act defines that term at KRS 367.3611(3) as data about a consumer's content viewing history collected through technology embedded in or operated through a smart television or smart monitor that identifies the specific content displayed in real time by analyzing audio or video fingerprints. It is a standalone obligation, not a new category of sensitive data, so the consequences that attach to sensitive data, including mandatory data protection assessments, do not apply to it. The requirement takes effect July 1, 2027.
Processor Duties
Data processors acting on behalf of controllers must enter into binding contracts that include provisions outlined in KRS 367.3619. These contracts must require the processor to:
- Follow the controller's instructions regarding data processing
- Maintain confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the controller in responding to consumer rights requests
- Cooperate with data protection assessments
- Delete or return personal data at the end of the contract relationship
- Allow the controller to conduct compliance audits or designate a qualified assessor
Data Protection Assessments
The KCDPA requires controllers to conduct and document data protection assessments for processing activities that present a heightened risk to consumers. These assessment requirements apply to processing activities created or generated on or after June 1, 2026.
Compliance note: June 1, 2026 has passed. Controllers must now have data protection assessment procedures in place for any covered processing activity, including targeted advertising, data sales, sensitive data processing, and high-risk profiling, that was initiated on or after that date. This is an ongoing, standing obligation rather than a one-time deadline.
Assessments are required for the following activities:
- Processing personal data for targeted advertising
- Selling personal data
- Profiling that presents a foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial or physical or reputational injury, or intrusion on solitude or seclusion
- Processing sensitive data
- Any processing activity that presents a heightened risk of harm to consumers
Each assessment must identify and weigh the benefits of the processing activity to the controller, the consumer, other stakeholders, and the public against the potential risks to consumer rights. The Attorney General can request these assessments during investigations.
Controllers may use data protection assessments conducted under other reasonably comparable laws, including the European Union's General Data Protection Regulation (GDPR), to satisfy the KCDPA requirement.
Enforcement and Penalties

Attorney General Authority
The Kentucky Attorney General has exclusive enforcement authority over the KCDPA. The law does not create a private right of action, meaning individual consumers cannot sue businesses directly for KCDPA violations.
The AG's Office of Data Privacy was created specifically to enforce the KCDPA. This office has the authority to seek injunctive relief, civil penalties, and reasonable attorneys' fees and investigative costs.
30-Day Cure Period
Before filing a formal enforcement action, the Attorney General must ordinarily provide the business with a written notice identifying the specific alleged violation and allow 30 days to cure the violation. If the business cures the violation within 30 days and provides a written statement with supporting documentation that the violation has been remedied and will not recur, the AG cannot pursue enforcement for that specific violation.
This 30-day cure period is permanent. Unlike the cure periods in New Hampshire, New Jersey, and several other state privacy laws, the KCDPA's cure provision does not include a sunset date. Businesses will always have the opportunity to cure violations before facing penalties, as long as the AG issues a cure notice.
However, the first KCDPA enforcement action, filed January 8, 2026 against Character Technologies, showed that the AG can bypass the cure period by pairing KCDPA claims with other statutes, such as the Kentucky Consumer Protection Act, that do not carry a cure-notice requirement. Hunton and Williams noted that this dual-statute approach is a significant development for businesses assessing their KCDPA risk exposure.
Civil Penalties
If a business fails to cure a violation within the 30-day window, or if it breaches its written compliance commitment, the Attorney General can pursue civil penalties of up to $7,500 per violation. The AG can also seek injunctive relief and recover attorneys' fees and investigation costs.
Consumer Privacy Fund
The KCDPA established a Consumer Privacy Fund (KRS 367.3629) to receive any penalties collected through enforcement actions. These funds support ongoing privacy enforcement efforts.
First Enforcement Action: Character.AI (January 2026)
On January 8, 2026, AG Russell Coleman announced suit against Character Technologies in Franklin Circuit Court. The complaint alleged the company's platform preyed on children by failing to implement meaningful protections for minors, including unauthorized processing of minors' sensitive data without parental consent, failure to implement age verification, exposure of children to harmful AI-generated content, and use of private emotional disclosures and health statements to train AI models. The AG sought $2,000 per count in civil relief plus injunctive relief. The case remains ongoing as of May 2026.
Penalty Summary Table
| Law | Statute | Penalty Per Violation | Cure Period | Enforced By |
|---|---|---|---|---|
| KCDPA | KRS 367.3611-367.3629 | Up to $7,500 | 30 days (permanent) | Attorney General |
| Data Breach Notification | KRS 365.732 | Damages under KRS 446.070 | None | Private action via KRS 446.070 |
Kentucky Data Breach Notification Law (KRS 365.732)
Kentucky's data breach notification law, KRS 365.732, has been in effect since 2014 and operates independently of the KCDPA. It applies to any person or business entity that conducts business in Kentucky and owns, licenses, or maintains computerized personal information.

What Triggers a Notification
A notification obligation arises when there is an unauthorized acquisition of unencrypted, unredacted computerized data that compromises the security, confidentiality, or integrity of personal information, and the breach actually causes or is reasonably believed to have caused or will cause identity theft or fraud against a Kentucky resident.
Protected Personal Information
Under KRS 365.732, personal information is defined as an individual's first name or first initial and last name combined with one or more of these data elements:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password
The information must be unencrypted and unredacted to trigger notification obligations. If the compromised data was encrypted or redacted, notification is not required.
Notification Timeline and Methods
Kentucky does not set a specific number of days for breach notification. Instead, the law requires notification in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and measures necessary to determine the scope of the breach.
Notification may be provided through:
- Written notice sent to the affected individual
- Electronic notice (consistent with the federal E-SIGN Act)
- Substitute notice (when specific conditions are met)
Substitute Notice
A business may use substitute notice if the cost of direct notification would exceed $250,000, the number of affected individuals exceeds 500,000, or the business does not have sufficient contact information. Substitute notice requires all three of the following:
- Email notice to affected individuals for whom email addresses are available
- Conspicuous posting on the business's website
- Notification to major statewide media outlets
Large-Scale Breach Reporting
When a breach affects more than 1,000 individuals at one time, the business must also notify all nationwide consumer reporting agencies about the timing, distribution, and content of the breach notices.
Exemptions from Breach Notification
The breach notification law does not apply to entities already subject to the Gramm-Leach-Bliley Act or HIPAA, as those entities follow separate federal breach notification requirements. State and local government bodies follow separate breach notification provisions under KRS 61.931 through 61.934.
Breach Notification Enforcement
KRS 365.732 does not contain a specific penalty provision or direct enforcement mechanism. However, injured individuals may seek damages under KRS 446.070, Kentucky's general statute allowing private actions for violations of state law. A good-faith acquisition of personal information by an employee or agent of the business entity is not considered a breach, provided there is no further unauthorized disclosure.
Federal Privacy Laws That Apply in Kentucky
Several federal statutes create data privacy and security obligations that apply alongside the KCDPA. Businesses operating in Kentucky must account for all applicable layers.

TAKE IT DOWN Act (Pub. L. 119-12, effective May 19, 2026). The FTC began enforcing the TAKE IT DOWN Act on May 19, 2026. The law requires covered online platforms to establish a process for victims to request removal of nonconsensual intimate images, including AI-generated deepfakes, and to remove that content and known identical copies within 48 hours of a valid request. Civil penalties for platform violations can reach $53,088 per violation. The criminal prohibition on publishing such images took effect when the law was signed on May 19, 2025.
HIPAA. The Health Insurance Portability and Accountability Act governs how covered entities (health plans, providers, and clearinghouses) and their business associates collect, use, and disclose protected health information. HIPAA-regulated entities are exempt from the KCDPA's scope entirely.
Gramm-Leach-Bliley Act (GLBA). The GLBA requires financial institutions to explain their information-sharing practices to customers and to protect sensitive data. GLBA-regulated institutions are exempt from the KCDPA.
FCRA and FACTA. The Fair Credit Reporting Act governs consumer reporting agencies and the use of consumer report information. FCRA-covered data is exempt from the KCDPA.
COPPA. The Children's Online Privacy Protection Act requires verifiable parental consent before collecting personal information from children under 13. The KCDPA treats COPPA compliance as satisfying the KCDPA's children's data consent requirements.
FTC Act Section 5. The FTC's general authority to prohibit deceptive or unfair business practices applies to any entity subject to FTC jurisdiction, regardless of whether a state privacy law covers it.
How the KCDPA Compares to Other State Privacy Laws
The KCDPA is widely regarded as one of the more business-friendly comprehensive state privacy laws enacted through 2026. Several provisions distinguish it from stricter frameworks.
Kentucky took effect January 1, 2026, alongside two other state privacy laws: Indiana's Consumer Data Protection Act (INCDPA) and Rhode Island's Data Transparency and Privacy Protection Act (RIDTPPA). Privacy practitioners refer to this group as the "2026 trinity." All three share similar consumer-rights frameworks, but Kentucky is the most business-friendly of the three because of its permanent cure period and its narrow "sale" definition covering only monetary exchanges.
| Feature | Kentucky KCDPA | Indiana INCDPA | Rhode Island RIDTPPA |
|---|---|---|---|
| Effective date | Jan 1, 2026 | Jan 1, 2026 | Jan 1, 2026 |
| Consumer threshold | 100,000 / 25,000 + 50% | 100,000 / 25,000 + 50% | 35,000 / 10,000 + 20% |
| Universal opt-out (GPC) | Not required | Not required | Required |
| Private right of action | No | No | No |
| Cure period | 30 days (permanent) | 30 days (permanent) | None |
| Max penalty per violation | $7,500 | $7,500 | $10,000 |
| Enforced by | AG | AG | AG |
No universal opt-out requirement. Unlike California, Colorado, Connecticut, Montana, Delaware, and several other states, Kentucky does not require businesses to honor Global Privacy Control or similar universal opt-out signals.
Permanent cure period. The 30-day cure period never expires. New Hampshire and New Jersey give businesses a right to cure that sunsets after an initial period, and Delaware's Personal Data Privacy Act required a 60-day cure opportunity only through December 31, 2025, after which the cure opportunity became discretionary. Rhode Island's RIDTPPA provides no right to cure at all: R.I. Gen. Laws 6-48.1-8 goes straight to Attorney General enforcement with no notice-and-cure step. Kentucky gives businesses a permanent opportunity to fix violations before facing penalties, subject to the AG's discretion in enforcement strategy.
Narrow sale definition. The KCDPA only covers data exchanges made for monetary consideration. States like California and Colorado define "sale" more broadly to include exchanges for other valuable consideration.
No authorized agent provisions. Consumers cannot designate a third party to submit data rights requests on their behalf.
Broad entity exemptions. The KCDPA exempts nonprofits and higher education institutions, which are covered under some other state laws.
Practical Compliance Steps for Businesses
Businesses that fall within the KCDPA's thresholds and are not fully exempt should confirm the following are in place. The June 1, 2026 data protection assessment deadline has already passed, so these are ongoing compliance obligations, not upcoming ones:
1. Confirm scope. Determine whether you meet either the 100,000-consumer or the 25,000-consumer-plus-50%-revenue threshold. Document your determination.
2. Update your privacy notice. Your public-facing privacy notice must disclose the categories of personal data you process, the purposes, how consumers exercise their five KCDPA rights, and which third parties receive your data.
3. Build a rights-request process. You need a mechanism for consumers to submit and track requests to access, correct, delete, and port their data, and to opt out of data sales, targeted advertising, and profiling. You must respond within 45 days.
4. Audit your sensitive data processing. If you process any sensitive data categories (health diagnoses, biometrics, children's data, precise geolocation, and others listed above), verify you have opt-in consent in place. This obligation has applied since the KCDPA took effect on January 1, 2026 and continues on an ongoing basis.
5. Complete data protection assessments on an ongoing basis. For all processing activities in categories covered by KRS 367.3621 that were initiated on or after June 1, 2026, you must document a formal assessment weighing benefits against consumer risks. This obligation applies to any newly initiated covered activity going forward, not just a one-time deadline. Prior-initiated activities are grandfathered.
6. Review processor contracts. Any data processing agreement with a vendor must include the provisions required by KRS 367.3619, including the right to audit, instructions on return or deletion of data, and confidentiality obligations.
7. Assess TAKE IT DOWN Act obligations. If you operate an online platform that hosts user-generated content, review whether the TAKE IT DOWN Act's takedown-request process requirements apply to your platform beginning May 19, 2026.
Filing a Data Privacy Complaint in Kentucky
If you believe a business has violated your rights under the KCDPA, you can contact the Kentucky Attorney General's Office of Data Privacy. This office was established specifically to handle KCDPA enforcement and consumer complaints.
You can also file a general consumer protection complaint through the Attorney General's Consumer Protection Division.
More Kentucky Laws
Looking for information on other Kentucky laws? Visit our Data Privacy Laws by State hub to compare Kentucky with other states. You can also explore related topics:
- Kentucky AI Meeting Recording Laws
- Kentucky Alimony Laws
- Kentucky At-Will Employment Laws
- Kentucky Car Accident Laws
- Kentucky Car Seat Laws
- Kentucky Child Custody Laws
- Kentucky Child Support Laws
- Kentucky Common Law Marriage Laws
- Kentucky Deepfake Laws
- Kentucky Divorce Laws
- Kentucky Dog Bite Laws
- Kentucky Emancipation Laws
- Kentucky Expungement Laws
- Kentucky Hit and Run Laws
- Kentucky Landlord-Tenant Laws
- Kentucky Lemon Laws
- Kentucky Employee Monitoring Laws
- Kentucky Recording Laws
In-depth guides
- What Is the KCDPA? Kentucky Consumer Data Protection Act
- KCDPA Consumer Rights: Your Data Privacy Rights
- KCDPA Compliance Checklist for Businesses (2026)
More Kentucky Laws
Updates
Corrected the description of 2026 House Bill 692: automatic content recognition data is a standalone controller consent duty under KRS 367.3617(1)(f) effective July 1, 2027 rather than a new sensitive data category, and corrected the multistate comparison, which had wrongly credited Rhode Island with an expiring 60-day cure period when its privacy act provides no right to cure at all.
Updated the data protection assessment deadline from upcoming to already-passed framing (June 1, 2026 has passed), added the 2026 HB 692 amendment adding smart-TV/ACR viewing data as a protected sensitive-data category (effective July 1, 2027), corrected the assessment trigger to the current 'unlawful disparate impact' language, and fixed the comparison table's Rhode Island entry, which now has no cure period rather than a 30-day period that sunsets in 2028.
Independently fact-checked against the cited primary sources
Governing law re-checked for recent changes
Corrected the breach-notification methods list: KRS 365.732(5) allows only written, electronic, and substitute notice; a fabricated 'telephone notice' option was removed.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION
§ 367.3615Consumer rights request -- Controller compliance -- Requirements -- Appeal processIn forcecited in 5 of our articles
(1) A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to a controller, via the means specified by the controller pursuant to KRS 367.3617, specifying the consumer rights the consumer wishes to invoke. A child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026), KCDPA Compliance Checklist: Kentucky Privacy Law, KCDPA Consumer Rights: Kentucky Privacy Rights Guide
§ 367.3617Limitations on the collection and use of personal data by a controller --In forcecited in 5 of our articles
Waiver of consumer rights contrary to public policy -- Privacy notice -- Notice for sale of personal data to third party -- Process for consumers to exercise consumer rights requirement. (Effective until July 1, 2027) (1) A controller shall: (a) Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data is processed as disclosed to the consumer; (b) Except as otherwise provided in this section, not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which the personal data is processed as disclosed to the consumer, unless the controller obtains the consumer's consent; (c) Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. The data security practices shall be appropriate to the volume and nature of the personal data at issue; (d) Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: What Is the KCDPA? Kentucky Consumer Data Privacy
§ 367.3611Definitions for KRS 367.3611 to 367.3629. (Effective until July 1, 2027)In forcecited in 6 of our articles
As used in KRS 367.3611 to 367.3629: (1) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company; (2) "Authenticate" means verifying through reasonable means that the consumer entitled to exercise his or her consumer rights in KRS 367.3615 is the same consumer exercising such consumer rights with respect to the personal data at issue; (3) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 367.3619Data processing responsibilities to controller -- Contract requirements between controller and processorIn forcecited in 2 of our articles
(1) A processor shall adhere to the instructions of a controller and shall assist the controller in meeting its obligations under KRS 367.3611 to 367.3629. Such assistance shall include: (a) Taking into account the nature of processing and the information available to the processor, by appropriate technical and organizational measures, insofar as this is reasonably practicable, to fulfill the controller's obligation to respond to consumer rights requests pursuant to KRS 367.3615; (b) Taking into account the nature of processing and the information available to the processor, by assisting the controller in meeting the controller's obligations in relation to the security of processing the personal data and in relation to the notification of a breach of the security of the system of the processor pursuant to KRS 365.732; and (c) Providing necessary information to enable the controller to conduct and document data protection assessments pursuant to KRS 367.3621. (2) A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3621Data protection impact assessment -- Requirements -- Disclosure to Attorney General -- Confidentiality and exceptions -- ApplicationIn forcecited in 2 of our articles
(1) Controllers shall conduct and document a data protection impact assessment of each of the following processing activities involving personal data: (a) The processing of personal data for the purposes of targeted advertising; (b) The processing of personal data for the purposes of selling of personal data; (c) The processing of personal data for the purposes of profiling, where the profiling presents a reasonably foreseeable risk of: 1. Unfair or deceptive treatment of consumers or unlawful, disparate impact on consumers; 2. Financial, physical, or reputational injury to consumers; 3. A physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where an intrusion would be offensive to a reasonable person; or 4. Other substantial injury to consumers; (d) The processing of sensitive data; and (e) Any processing of personal data that presents a heightened risk of harm to consumers.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3629Consumer privacy fundIn forcecited in 3 of our articles
There is hereby created a trust and agency account to be known as the consumer privacy fund. The fund shall be administered by the Office of the Attorney General. All civil penalties collected pursuant to KRS 367.3611 to 367.3629 shall be deposited into the fund. Interest earned on moneys in the fund shall accrue to the fund. Moneys in the fund shall be used by the Office of the Attorney General to enforce KRS 367.3611 to 367.3629. Notwithstanding KRS 45.229, any moneys remaining in the fund at the close of the fiscal year shall not lapse but shall be carried forward into the succeeding fiscal year to be used by the Office of the Attorney General for the purposes set forth in KRS 367.3611 to 367.3629.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Kentucky Revised Statutes, Chapter 365: TRADE PRACTICES
§ 365.732Notification to affected persons of computer security breach involving their unencrypted personally identifiable informationIn forcecited in 3 of our articles
(1) As used in this section, unless the context otherwise requires: (a) "Breach of the security of the system" means unauthorized acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality, or integrity of personally identifiable information maintained by the information holder as part of a database regarding multiple individuals that actually causes, or leads the information holder to reasonably believe has caused or will cause, identity theft or fraud against any resident of the Commonwealth of Kentucky. Good-faith acquisition of personally identifiable information by an employee or agent of the information holder for the purposes of the information holder is not a breach of the security of the system if the personally identifiable information is not used or subject to further unauthorized disclosure; (b) "Information holder" means any person or business entity that conducts business in this state; and (c) "Personally identifiable information" means an individual's first name or first initial and last name in combination with any one (1) or more of the following data elements, when the name or data element is not redacted: 1.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Peppy Martin v. Jeffrey Callen (Court of Appeals of Kentucky 2022)“…leging that the appellees had violated 18 U.S.C. § 981 and KRS 365.732 by improperly seeking to harvest her pe…”
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)“…ia claim survives. Kentucky’s statute is likewise silent. Ky.Rev.Stat. Ann. § 365.732(2). But Kentucky law elsewhere provides…”
- Alonso v. Blue Sky Resorts, LLC (District Court, S.D. Indiana 2016, 179 F. Supp. 3d 857)“…ana, Kentucky has a Disclosure of. Security Breach statute (KRS § 365.732). And : like Indiana’s statute, Kentuck…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Kentucky Revised Statutes, Chapter 446: CONSTRUCTION OF STATUTES
§ 446.070Penalty no bar to civil recoveryIn forcecited in 2 of our articles
A person injured by the violation of any statute may recover from the offender such damages as he sustained by reason of the violation, although a penalty or forfeiture is imposed for such violation.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Cited in 282 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Firestone Textile Co. Division v. Meadows (Kentucky Supreme Court 1983, 666 S.W.2d 730)“…a statute. This foundation is necessary for the reliance on KRS 446.070, a person injured by the violation of a…”
- Stringer v. Wal-Mart Stores, Inc. (Kentucky Supreme Court 2004, 151 S.W.3d 781)“…usion upon the plaintiff's seclusion [68] or a claim under KRS 446.070 to recover damages for a violation of u…”
- Davidson v. American Freightways, Inc. (Kentucky Supreme Court 2000, 25 S.W.3d 94)“…in Reeder was premised solely upon the provisions of KRS 446.070, Reeder, supra, at 117-18 , which…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Kentucky Revised Statutes, Chapter 61: GENERAL PROVISIONS AS TO OFFICES AND OFFICERS -- SOCIAL SECURITY FOR PUBLIC EMPLOYEES -- EMPLOYEES RETIREMENT SYSTEM
§ 61.931Definitions for KRS 61.931 to 61.934In forcecited in 3 of our articles
As used in KRS 61.931 to 61.934: (1) "Agency" means: (a) The executive branch of state government of the Commonwealth of Kentucky; (b) Every county, city, municipal corporation, urban-county government, charter county government, consolidated local government, and unified local government; (c) Every organizational unit, department, division, branch, section, unit, office, administrative body, program cabinet, bureau, board, commission, committee, subcommittee, ad hoc committee, council, authority, public agency, instrumentality, interagency body, special purpose governmental entity, or public corporation of an entity specified in paragraph (a) or (b) of this subsection or created, established, or controlled by an entity specified in paragraph (a) or (b) of this subsection; (d) Every public school district in the Commonwealth of Kentucky; and (e) Every public institution of postsecondary education, including every public university in the Commonwealth of Kentucky and public college of the entire Kentucky Community and Technical College System; (2) "Commonwealth Office of Technology" means the office established by KRS 42.724; (3) "Encryption" means the conversion of data…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Explore the law
This article also draws on these acts and chapters (opening at their first section): Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION § 367.010 (Repealed, 1972.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Kentucky Revised Statutes Chapter 367 - Consumer Data Protection (KCDPA)(apps.legislature.ky.gov).gov
- KRS 367.3611 - KCDPA Definitions(apps.legislature.ky.gov).gov
- KRS 367.3615 - Consumer Rights Under KCDPA(apps.legislature.ky.gov).gov
- KRS 367.3619 - Processor Contract Requirements(apps.legislature.ky.gov).gov
- Chapter 72 (HB 15) - KCDPA Enrolled Act Text(apps.legislature.ky.gov).gov
- 24RS HB 15 - Bill Record(apps.legislature.ky.gov).gov
- Kentucky Attorney General - Office of Data Privacy(ag.ky.gov).gov
- Kentucky Attorney General - KCDPA Consumer Rights(ag.ky.gov).gov
- AG Coleman - Character AI Enforcement Press Release(kentucky.gov).gov
- KRS 365.732 - Data Breach Notification(apps.legislature.ky.gov).gov
- KRS 61.931-61.934 - Government Entity Breach Notification(apps.legislature.ky.gov).gov
- FTC - TAKE IT DOWN Act Enforcement Begins May 19, 2026(ftc.gov).gov
- FTC - Complying With the Take It Down Act(ftc.gov).gov
- Federal Trade Commission - Gramm-Leach-Bliley Act(ftc.gov).gov
- U.S. Department of Health and Human Services - HIPAA(hhs.gov).gov
- Federal Trade Commission - COPPA Rule(ftc.gov).gov
- U.S. Department of Education - FERPA(ed.gov).gov
- Hunton Andrews Kurth - Kentucky AG First Enforcement Action Under KCDPA(hunton.com)
- Koley Jessen - New State Privacy Laws Effective January 1, 2026(koleyjessen.com)
- Davis Wright Tremaine - Kentucky Data Breach Notification Chart(dwt.com)
- 2026 Ky. Acts ch. 118 (HB 692) - Enrolled Act Adding the Automatic Content Recognition Consent Duty(apps.legislature.ky.gov).gov
- R.I. Gen. Laws 6-48.1-8 - RIDTPPA Violations and Enforcement(webserver.rilegislature.gov).gov
- 6 Del. C. ch. 12D - Delaware Personal Data Privacy Act (Enforcement and Cure Period)(delcode.delaware.gov).gov