EnglishEspañol
Kentucky flag

Kentucky

Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Kentucky have a standalone biometric privacy law like Illinois?

No. Kentucky does not have a dedicated biometric privacy statute. Instead, the Kentucky Consumer Data Protection Act (KCDPA), effective January 1, 2026, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The KCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention, destruction, and private right of action provisions found in Illinois BIPA.

Can I sue a company in Kentucky for collecting my fingerprints without consent?

Not under the KCDPA. The Kentucky Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint with the Kentucky Attorney General's Office of Data Privacy at (502) 892-8538. The AG can investigate and pursue civil penalties of up to $7,500 per violation.

Does the KCDPA protect my biometric data at work?

No. The KCDPA exempts data collected in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the KCDPA does not regulate that activity. Kentucky does not have a separate law governing employer use of biometric data, and the general breach notification law (KRS 365.732) does not cover biometric data, since its definition of personal information is limited to a Social Security number, driver's license number, or financial account number.

What biometric data does the KCDPA cover?

The KCDPA covers data generated by automatic measurements of biological characteristics used to identify a specific individual. This includes fingerprints, voiceprints, eye retinas, irises, and other unique biological patterns. Photographs, video recordings, and audio recordings are not covered unless they are specifically used to identify a particular individual. Data collected for health care treatment, payment, or operations under HIPAA is also excluded.

What happens if a company ignores a biometric data deletion request in Kentucky?

If a covered business fails to respond to your deletion request within 45 days (or 90 days with a valid extension), you can file a complaint with the Kentucky Attorney General. The AG will notify the business and provide 30 days to cure the violation. If the business still does not comply, the AG can pursue civil penalties of up to $7,500 per violation. Repeatedly ignoring consumer rights requests could result in multiple violation counts.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the description of Kentucky's public-agency breach notification law: KRS 61.933 is triggered by a biometric or genetic print only when it is combined with one of the data elements listed in KRS 61.931(6), such as a Social Security number or driver's license number, so a breach of biometric data alone does not require notice from a public agency any more than from a private business.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected: Verified against the mirrored statutes: KRS 61.

Governing law re-checked for recent changes

Corrected a contradiction between the article and KRS 365.732: Kentucky's private-sector breach notification law covers only Social Security number, driver's license number, or financial account number, not biometric or genetic data (that broader definition applies only to government agencies under a separate statute). Also fixed a misattributed non-discrimination right that isn't part of KRS 367.3615's enumerated consumer rights.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Kentucky Consumer Data Protection Act (HB 15)(apps.legislature.ky.gov).gov
  2. KRS 367.3611 - KCDPA Definitions(apps.legislature.ky.gov).gov
  3. KRS 367.3615 - Consumer Rights(apps.legislature.ky.gov).gov
  4. KRS 365.732 - Breach Notification(apps.legislature.ky.gov).gov
  5. KCDPA Chapter 72 Acts (Enrolled Bill)(apps.legislature.ky.gov).gov
  6. Kentucky AG - Consumer Rights Under KCDPA(ag.ky.gov).gov
  7. Kentucky AG - Office of Data Privacy(ag.ky.gov).gov
  8. KRS 367.3613 - Application and Limitations(apps.legislature.ky.gov).gov
  9. KRS 61.931 - Definitions for KRS 61.931 to 61.934 (public-agency breach law)(apps.legislature.ky.gov)
  10. KRS 61.933 - Notification of Personal Information Security Breach (public agencies)(apps.legislature.ky.gov)
Share: