EnglishEspañol
Kentucky flag

Kentucky

Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 14 primary sources cited on this page. How we verify our legal content

Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Kentucky residents of a data breach?

Kentucky law requires notification in the most expedient time possible and without unreasonable delay. The state does not set a specific deadline in days. The timeline must account for any measures necessary to determine the scope of the breach and restore the integrity of the data system. Notification may also be delayed if law enforcement determines it would impede a criminal investigation.

Does Kentucky require businesses to notify the Attorney General after a data breach?

No. The private-sector breach notification law (KRS 365.732) does not require businesses to notify the Attorney General. However, government agencies must notify the AG, along with the Auditor of Public Accounts, Kentucky State Police, and other state entities, under KRS 61.933. Businesses may still face AG scrutiny through consumer protection enforcement.

What is Kentucky's encryption safe harbor for data breaches?

Kentucky's breach notification law does not apply to information that was encrypted or redacted at the time of the breach. If you encrypt personal information and an unauthorized party gains access, you are not required to send breach notifications under KRS 365.732. This safe harbor provides a strong incentive for businesses to encrypt stored personal data.

Can individuals sue for damages after a data breach in Kentucky?

KRS 365.732 does not create an explicit private right of action. However, individuals may seek damages under KRS 446.070, Kentucky's general remedy statute, which allows a person injured by any statutory violation to recover damages. The Kentucky Consumer Data Protection Act (KCDPA) also does not provide a private right of action. The Attorney General has exclusive enforcement authority under the KCDPA.

How does the Kentucky Consumer Data Protection Act affect data breach obligations?

The KCDPA, effective January 1, 2026, does not replace the existing breach notification statutes. It adds obligations for businesses to implement reasonable data security practices, obtain consent before processing sensitive data like biometric identifiers, and respond to consumer rights requests. A breach resulting from inadequate security could trigger enforcement under both the KCDPA (up to $7,500 per violation) and the existing breach notification law. The Attorney General's Office of Data Privacy enforces the KCDPA.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the insurance cybersecurity notification section: the three-business-day deadline to the Commissioner of Insurance runs from the determination that an event occurred, not from the event itself, and the 250-consumer trigger in KRS 304.3-760(1)(c) applies to every licensee rather than only to insurers domiciled outside Kentucky.

Corrected a misattributed public-records exemption, clarified the staged multi-agency and 35-day individual-notification steps government agencies face under KRS 61.933, fixed an AND/OR error in the insurance cybersecurity notification trigger, and replaced a dead federal citation.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. KRS 365.732 - Notification to affected persons of computer security breach(apps.legislature.ky.gov).gov
  2. KRS 61.931 - Definitions for government breach notification(apps.legislature.ky.gov).gov
  3. KRS 61.932 - Government agency breach investigation procedures(apps.legislature.ky.gov).gov
  4. KRS 61.933 - Government breach notification requirements(apps.legislature.ky.gov).gov
  5. KRS 61.934 - Legislative and judicial branch breach procedures(apps.legislature.ky.gov).gov
  6. Kentucky Consumer Data Protection Act (KCDPA) - AG guidance(ag.ky.gov).gov
  7. Kentucky Office of Data Privacy(ag.ky.gov).gov
  8. Kentucky AG Identity Theft Resources(ag.ky.gov).gov
  9. KRS 446.070 - Penalty no bar to civil recovery(apps.legislature.ky.gov).gov
  10. HIPAA Information - HHS.gov(hhs.gov).gov
  11. Gramm-Leach-Bliley Act - FTC(ftc.gov).gov
  12. E-SIGN Act - 15 U.S.C. Sec. 7001 (Cornell LII)(law.cornell.edu)
  13. KRS Chapter 365 - Commerce and Trade(apps.legislature.ky.gov).gov
  14. KRS 304.3-760 - Insurance cybersecurity event notification(apps.legislature.ky.gov).gov
  15. HB 15 - Kentucky Consumer Data Protection Act bill text(apps.legislature.ky.gov).gov
Share: