EnglishEspañol
Kentucky flag

Kentucky

KCDPA Compliance Checklist: Kentucky Privacy Law

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

KCDPA Compliance Checklist: Kentucky Privacy Law

Frequently Asked Questions

How do I know if my business must comply with the KCDPA?

Under KRS 367.3613, you are covered if you conduct business in Kentucky or target its residents and, in a calendar year, control or process the personal data of at least 100,000 Kentucky consumers, or at least 25,000 consumers while deriving over 50 percent of gross revenue from selling personal data. Count only consumers acting in an individual context, then apply the entity and data exemptions.

What must a KCDPA privacy notice include?

Under KRS 367.3617(3), the privacy notice must state the categories of personal data processed, the purposes for processing, how consumers exercise and appeal their rights, the categories of data shared with third parties, and the categories of those third parties. If you sell data or run targeted advertising, KRS 367.3617(4) requires a clear, conspicuous disclosure and an opt-out method.

Does the KCDPA require consent for sensitive data?

Yes. KRS 367.3617(1)(e) requires opt-in consent before processing sensitive data, which under KRS 367.3611 includes racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, immigration status, genetic or biometric identifiers, a known child's data, and precise geolocation. For a known child, you must follow the federal Children's Online Privacy Protection Act. A second consent duty is already on the books but not yet in force: 2026 Ky. Acts ch. 118 adds KRS 367.3617(1)(f), which from July 1, 2027 bars collecting automatic content recognition data from a smart television or smart monitor without the consumer's consent.

Does the KCDPA require honoring universal opt-out signals?

No. The KCDPA does not mandate recognition of a universal opt-out mechanism such as the Global Privacy Control. Under KRS 367.3617, you must provide and disclose your own opt-out methods for targeted advertising, data sales, and profiling, but there is no statutory duty to honor a global browser signal, matching the Virginia model Kentucky followed.

When are KCDPA data protection assessments required?

Under KRS 367.3621, you must conduct and document an assessment for targeted advertising, data sales, sensitive-data processing, high-risk profiling, and any heightened-risk processing. KRS 367.3621(8) provides that the assessment requirement applies to processing activities created or generated on or after June 1, 2026. The Attorney General may demand relevant assessments during an investigation.

What must a KCDPA processor contract include?

Under KRS 367.3619, the contract must set out processing instructions, nature and purpose, data type, and duration, and require the processor to maintain confidentiality, delete or return data at the end of services, demonstrate compliance, allow reasonable assessments, and flow the same obligations down to subcontractors by written contract.

What are the penalties for violating the KCDPA?

Under KRS 367.3627, the Attorney General can seek civil penalties up to $7,500 for each continued violation, plus investigation costs and fees, after a 30-day cure period that is permanent. Penalties go into the consumer privacy fund under KRS 367.3629. There is no private right of action, so only the Attorney General can enforce the law.

Is there a cure period under the KCDPA?

Yes, and it does not expire. Under KRS 367.3627(2), the Attorney General must give 30 days' written notice before suing, and if the business cures the violation and gives a written statement that it is cured and will not recur, no damages action follows. Unlike some states, Kentucky's 30-day cure period has no sunset date as of 2026.

Updates

Added the automatic content recognition consent duty that House Bill 692 (2026 Ky. Acts ch. 118) adds to KRS 367.3617(1)(f) effective July 1, 2027, covering smart-television and smart-monitor viewing data.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Kentucky HB 15 (2024): Kentucky Consumer Data Protection Act (Enrolled Bill Text)(apps.legislature.ky.gov).gov
  2. KRS 367.3613: Application, Limitations, and Exemptions(apps.legislature.ky.gov).gov
  3. KRS 367.3615: Consumer Rights Request and Appeal Process(apps.legislature.ky.gov).gov
  4. KRS 367.3617: Controller Limitations, Privacy Notice, and Opt-Out Methods(apps.legislature.ky.gov).gov
  5. KRS 367.3619: Processor Obligations and Controller-Processor Contract Requirements(apps.legislature.ky.gov).gov
  6. KRS 367.3621: Data Protection Impact Assessment Requirements(apps.legislature.ky.gov).gov
  7. KRS 367.3627: Attorney General Enforcement, Cure Period, and Civil Penalties(apps.legislature.ky.gov).gov
  8. KRS 367.3629: Consumer Privacy Fund(apps.legislature.ky.gov).gov
  9. Kentucky Attorney General: Office of Data Privacy and the KCDPA(ag.ky.gov).gov
  10. Kentucky HB 692 (2026 Regular Session), signed April 13, 2026, 2026 Ky. Acts ch. 118: amends the KCDPA, effective July 1, 2027(apps.legislature.ky.gov)
  11. Kentucky HB 692 (2026) enrolled bill text: KRS 367.3617(1)(f) automatic content recognition consent duty and KRS 367.3611 definitions(apps.legislature.ky.gov)
  12. KRS 367.3617: Limitations on the collection and use of personal data by a controller (Effective until July 1, 2027)(apps.legislature.ky.gov)
Share: