Kentucky
KCDPA Compliance Checklist: Kentucky Privacy Law
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

Complying with the Kentucky Consumer Data Protection Act (KCDPA), KRS 367.3611 to 367.3629, means confirming whether you are covered, posting a conforming privacy notice, getting opt-in consent before processing sensitive data, building consumer-rights and opt-out workflows, conducting data protection assessments, and signing KCDPA-compliant processor contracts. The act took effect January 1, 2026, so covered businesses are obligated now.
As of 2026, the Kentucky Attorney General enforces the KCDPA exclusively under KRS 367.3627, with a permanent 30-day cure period and civil penalties up to $7,500 for each continued violation, deposited into a consumer privacy fund. There is no private right of action, and because Kentucky's law closely mirrors Virginia's, a Virginia-ready program needs only modest tailoring.
Jurisdiction scope: This covers Kentucky's Kentucky Consumer Data Protection Act (KRS 367.3611 to 367.3629). It is general legal information, not legal advice.
Step 1: Determine whether you are covered
The first task is the applicability analysis in KRS 367.3613. The KCDPA reaches a person that conducts business in Kentucky or targets Kentucky residents and that, in a calendar year, controls or processes the personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data.
Count only "consumers," which KRS 367.3611 defines as Kentucky residents acting in an individual context. Employee and business-to-business contacts do not count toward the threshold, so a company should scope its count to consumer-facing data.
Then run the exemption screen under KRS 367.3613(2) and (3). Entity-level exemptions cover categories such as government bodies, GLBA-covered financial institutions, HIPAA-covered entities and business associates, nonprofits (including insurance-fraud-investigation nonprofits), certain small telephone and municipal utilities, and institutions of higher education are exempt at the entity level, and specific data sets such as FCRA, FERPA, and employment data are exempt at the data level. A business can be wholly or partly outside the law, so document the analysis before building controls.
Step 2: Publish a conforming privacy notice
If you are covered, the privacy notice is the most visible obligation. KRS 367.3617(3) requires a reasonably accessible, clear, and meaningful privacy notice with specific contents.
The notice must list the categories of personal data the controller processes, the purpose for processing, and how consumers can exercise their rights under KRS 367.3615, including how to appeal a decision. It must also state the categories of personal data shared with third parties and the categories of third parties that receive the data.
There is an extra disclosure for data sales and targeted advertising. Under KRS 367.3617(4), if a controller sells personal data or processes it for targeted advertising, it must clearly and conspicuously disclose that activity and the manner in which a consumer may opt out.

Step 3: Get opt-in consent for sensitive data
Sensitive data triggers the strictest rule in the act. Under KRS 367.3617(1)(e), a controller may not process sensitive data without first obtaining the consumer's consent.
Sensitive data under KRS 367.3611 includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, plus genetic or biometric data used to identify a person, a known child's data, and precise geolocation data. Map where each category lives in your systems before launch.
Consent must be a clear affirmative act that is freely given, specific, informed, and unambiguous. For data collected from a known child, the controller must instead comply with the federal Children's Online Privacy Protection Act, and KRS 367.3613(4) deems COPPA-compliant parental consent sufficient for the act's parental-consent obligations.
One more consent duty is already enacted but not yet in force, so build for it now. 2026 Ky. Acts ch. 118 (House Bill 692), signed April 13, 2026, adds KRS 367.3617(1)(f), barring a controller from collecting automatic content recognition data without the consumer's consent, and adds the supporting definitions of "automatic content recognition data" and "smart monitor" to KRS 367.3611.
That covers data about a consumer's content viewing history collected through a smart television or smart monitor that identifies the specific content in real time by analyzing audio or video fingerprints, whether the content arrives by broadcast, cable, satellite, streaming, or an external input. The definition excludes interactions with content the controller itself provides, data generated in delivering a feature the consumer requested, and data collected to enforce terms of service. Section 3 of the act sets the effective date at July 1, 2027, so inventory any smart-television or smart-monitor viewing data before then and add a consent gate ahead of that date.
Step 4: Build consumer-rights and opt-out workflows
Covered controllers need an operational pipeline to handle the rights in KRS 367.3615. Consumers can confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, data sales, and profiling.
Set the clock to 45 days. KRS 367.3615(3) requires a response without undue delay and within 45 days, with one permitted 45-day extension if you notify the consumer in time. Responses are free up to twice a year per consumer, and you may charge or decline only for excessive, repetitive, technically infeasible, or manifestly unfounded requests, with the burden on you.
Stand up a conspicuous appeal process under KRS 367.3615(4) with a 60-day response window, and provide a way to reach the Attorney General if you deny an appeal. Under KRS 367.3617(5) you cannot force a consumer to create a new account to exercise rights. Note that the KCDPA does not require honoring a universal opt-out signal such as the Global Privacy Control, so your own clearly disclosed opt-out methods satisfy the act, although a multistate program may choose to honor signals voluntarily. The KCDPA consumer rights guide details the request mechanics.
Step 5: Conduct data protection assessments
The KCDPA requires documented risk assessments for higher-risk processing. KRS 367.3621(1) lists the activities that trigger a data protection impact assessment.
Those activities are targeted advertising, the sale of personal data, sensitive-data processing, profiling that presents a reasonably foreseeable risk of unfair treatment or substantial injury, and any processing that presents a heightened risk of harm. Each assessment must weigh the benefits of the processing against the risks to consumers, as mitigated by safeguards.
Timing matters: KRS 367.3621(8) provides that the assessment requirement applies to processing activities created or generated on or after June 1, 2026. The Attorney General may demand an assessment relevant to an investigation under KRS 367.3621(3), and the assessments are confidential under the open-records exemption in KRS 367.3621(4). A single assessment can cover a comparable set of similar processing operations.

Step 6: Put KCDPA processor contracts in place
If a processor handles personal data on your behalf, KRS 367.3619 requires a written contract that governs the processing. The contract must set out the processing instructions, the nature and purpose of processing, the type of data, the duration, and the rights and obligations of both parties.
The contract must also require the processor to keep personnel under a duty of confidentiality, to delete or return all personal data at the end of the services at the controller's direction, and to make available information needed to demonstrate compliance. The processor must allow reasonable assessments, or arrange an independent assessment, and must flow these obligations down to any subcontractor under a written contract.
Both sides keep their own liability. KRS 367.3619(3) provides that the contract does not relieve a controller or processor of the duties tied to its role, and whether a party is a controller or processor is a fact-based determination.
Step 7: Understand enforcement, cure, and penalties
The KCDPA is enforced only by the Attorney General. KRS 367.3627(1) gives the Attorney General exclusive authority to investigate and bring actions, and KRS 367.3627(4) makes clear there is no private right of action.
Before suing, the Attorney General must give 30 days' written notice identifying the alleged violations. If the controller or processor cures within those 30 days and provides a written statement that the violation is cured and will not recur, no damages action follows under KRS 367.3627(2). This 30-day cure period is permanent, with no sunset, which distinguishes Kentucky from states that let their cure windows expire.
If the violation is not cured, the Attorney General may seek civil penalties up to $7,500 for each continued violation under KRS 367.3627(3), plus investigation costs and fees under KRS 367.3627(5). Penalties are deposited into the consumer privacy fund created by KRS 367.3629, an Attorney-General-administered account used to fund enforcement. For the statutory background and the Virginia-clone framing, see the What is the KCDPA? guide.
| Compliance area | KCDPA section | Key requirement |
|---|---|---|
| Applicability | KRS 367.3613 | 100,000 consumers, or 25,000 plus 50% data-sale revenue |
| Privacy notice | KRS 367.3617(3) | Disclose data categories, purposes, rights, sharing |
| Sensitive data | KRS 367.3617(1)(e) | Opt-in consent before processing |
| Automatic content recognition data | KRS 367.3617(1)(f), effective July 1, 2027 | Consent before collecting smart-television or smart-monitor viewing data |
| Consumer requests | KRS 367.3615 | 45-day response; 60-day appeal |
| Assessments | KRS 367.3621 | Document risk for high-risk processing (from June 1, 2026) |
| Processor contracts | KRS 367.3619 | Confidentiality, deletion, audits, flow-down |
| Enforcement | KRS 367.3627 | AG-only; 30-day cure; up to $7,500 per violation |
Related guides
- Kentucky data privacy laws parent hub
- What is the KCDPA?
- KCDPA consumer rights
- State data privacy law comparison
- What is the CCPA?
More Kentucky Laws
Frequently Asked Questions
How do I know if my business must comply with the KCDPA?
Under KRS 367.3613, you are covered if you conduct business in Kentucky or target its residents and, in a calendar year, control or process the personal data of at least 100,000 Kentucky consumers, or at least 25,000 consumers while deriving over 50 percent of gross revenue from selling personal data. Count only consumers acting in an individual context, then apply the entity and data exemptions.
What must a KCDPA privacy notice include?
Under KRS 367.3617(3), the privacy notice must state the categories of personal data processed, the purposes for processing, how consumers exercise and appeal their rights, the categories of data shared with third parties, and the categories of those third parties. If you sell data or run targeted advertising, KRS 367.3617(4) requires a clear, conspicuous disclosure and an opt-out method.
Does the KCDPA require consent for sensitive data?
Yes. KRS 367.3617(1)(e) requires opt-in consent before processing sensitive data, which under KRS 367.3611 includes racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, immigration status, genetic or biometric identifiers, a known child's data, and precise geolocation. For a known child, you must follow the federal Children's Online Privacy Protection Act. A second consent duty is already on the books but not yet in force: 2026 Ky. Acts ch. 118 adds KRS 367.3617(1)(f), which from July 1, 2027 bars collecting automatic content recognition data from a smart television or smart monitor without the consumer's consent.
Does the KCDPA require honoring universal opt-out signals?
No. The KCDPA does not mandate recognition of a universal opt-out mechanism such as the Global Privacy Control. Under KRS 367.3617, you must provide and disclose your own opt-out methods for targeted advertising, data sales, and profiling, but there is no statutory duty to honor a global browser signal, matching the Virginia model Kentucky followed.
When are KCDPA data protection assessments required?
Under KRS 367.3621, you must conduct and document an assessment for targeted advertising, data sales, sensitive-data processing, high-risk profiling, and any heightened-risk processing. KRS 367.3621(8) provides that the assessment requirement applies to processing activities created or generated on or after June 1, 2026. The Attorney General may demand relevant assessments during an investigation.
What must a KCDPA processor contract include?
Under KRS 367.3619, the contract must set out processing instructions, nature and purpose, data type, and duration, and require the processor to maintain confidentiality, delete or return data at the end of services, demonstrate compliance, allow reasonable assessments, and flow the same obligations down to subcontractors by written contract.
What are the penalties for violating the KCDPA?
Under KRS 367.3627, the Attorney General can seek civil penalties up to $7,500 for each continued violation, plus investigation costs and fees, after a 30-day cure period that is permanent. Penalties go into the consumer privacy fund under KRS 367.3629. There is no private right of action, so only the Attorney General can enforce the law.
Is there a cure period under the KCDPA?
Yes, and it does not expire. Under KRS 367.3627(2), the Attorney General must give 30 days' written notice before suing, and if the business cures the violation and gives a written statement that it is cured and will not recur, no damages action follows. Unlike some states, Kentucky's 30-day cure period has no sunset date as of 2026.
Updates
Added the automatic content recognition consent duty that House Bill 692 (2026 Ky. Acts ch. 118) adds to KRS 367.3617(1)(f) effective July 1, 2027, covering smart-television and smart-monitor viewing data.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION
§ 367.3617Limitations on the collection and use of personal data by a controller --In forcecited in 5 of our articles
Waiver of consumer rights contrary to public policy -- Privacy notice -- Notice for sale of personal data to third party -- Process for consumers to exercise consumer rights requirement. (Effective until July 1, 2027) (1) A controller shall: (a) Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data is processed as disclosed to the consumer; (b) Except as otherwise provided in this section, not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which the personal data is processed as disclosed to the consumer, unless the controller obtains the consumer's consent; (c) Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. The data security practices shall be appropriate to the volume and nature of the personal data at issue; (d) Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: KCDPA Consumer Rights: Kentucky Privacy Rights Guide, What Is the KCDPA? Kentucky Consumer Data Privacy, Kentucky Data Privacy Laws: Consumer Rights Guide (2026)
§ 367.3613Application -- Limitations -- Information and data exemptions -- Compliance with federal children's online privacy lawsIn forcecited in 3 of our articles
(1) KRS 367.3611 to 367.3629 apply to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that during a calendar year control or process personal data of at least: (a) One hundred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data. (2) KRS 367.3611 to 367.3629 shall not apply to any: (a) City, state agency, or any political subdivision of the state; (b) Financial institutions, their affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. sec. 6801 et seq.; (c) Covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder of the entity; and 2.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 367.3615Consumer rights request -- Controller compliance -- Requirements -- Appeal processIn forcecited in 7 of our articles
(1) A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to a controller, via the means specified by the controller pursuant to KRS 367.3617, specifying the consumer rights the consumer wishes to invoke. A child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State
§ 367.3621Data protection impact assessment -- Requirements -- Disclosure to Attorney General -- Confidentiality and exceptions -- ApplicationIn forcecited in 2 of our articles
(1) Controllers shall conduct and document a data protection impact assessment of each of the following processing activities involving personal data: (a) The processing of personal data for the purposes of targeted advertising; (b) The processing of personal data for the purposes of selling of personal data; (c) The processing of personal data for the purposes of profiling, where the profiling presents a reasonably foreseeable risk of: 1. Unfair or deceptive treatment of consumers or unlawful, disparate impact on consumers; 2. Financial, physical, or reputational injury to consumers; 3. A physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where an intrusion would be offensive to a reasonable person; or 4. Other substantial injury to consumers; (d) The processing of sensitive data; and (e) Any processing of personal data that presents a heightened risk of harm to consumers.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3619Data processing responsibilities to controller -- Contract requirements between controller and processorIn forcecited in 2 of our articles
(1) A processor shall adhere to the instructions of a controller and shall assist the controller in meeting its obligations under KRS 367.3611 to 367.3629. Such assistance shall include: (a) Taking into account the nature of processing and the information available to the processor, by appropriate technical and organizational measures, insofar as this is reasonably practicable, to fulfill the controller's obligation to respond to consumer rights requests pursuant to KRS 367.3615; (b) Taking into account the nature of processing and the information available to the processor, by assisting the controller in meeting the controller's obligations in relation to the security of processing the personal data and in relation to the notification of a breach of the security of the system of the processor pursuant to KRS 365.732; and (c) Providing necessary information to enable the controller to conduct and document data protection assessments pursuant to KRS 367.3621. (2) A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3627Enforcement authority of Attorney General -- Written notice of violation -- Civil action -- Damages -- Recovery of expensesIn forcecited in 3 of our articles
(1) The Attorney General shall have exclusive authority to enforce violations of KRS 367.3611 to 367.3629. The Attorney General may enforce KRS 367.3611 to 367.3629 by bringing an action in the name of the Commonwealth of Kentucky or on behalf of persons residing in this Commonwealth. The Attorney General shall have all powers and duties granted to the Attorney General under KRS Chapter 15 to investigate and prosecute any violation of KRS 367.3611 to 367.3629. The Attorney General may demand any information, documentary material, or physical evidence from any controller or processor believed to be engaged in, or about to engage in, any violation of KRS 367.3611 to 367.3629. (2) Prior to initiating any action for violation of KRS 367.3611 to 367.3629, the Attorney General shall provide a controller or processor thirty (30) days' written notice identifying the specific provisions of KRS 367.3611 to 367.3629, the Attorney General alleges have been or are being violated.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3629Consumer privacy fundIn forcecited in 3 of our articles
There is hereby created a trust and agency account to be known as the consumer privacy fund. The fund shall be administered by the Office of the Attorney General. All civil penalties collected pursuant to KRS 367.3611 to 367.3629 shall be deposited into the fund. Interest earned on moneys in the fund shall accrue to the fund. Moneys in the fund shall be used by the Office of the Attorney General to enforce KRS 367.3611 to 367.3629. Notwithstanding KRS 45.229, any moneys remaining in the fund at the close of the fiscal year shall not lapse but shall be carried forward into the succeeding fiscal year to be used by the Office of the Attorney General for the purposes set forth in KRS 367.3611 to 367.3629.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3611Definitions for KRS 367.3611 to 367.3629. (Effective until July 1, 2027)In forcecited in 6 of our articles
As used in KRS 367.3611 to 367.3629: (1) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company; (2) "Authenticate" means verifying through reasonable means that the consumer entitled to exercise his or her consumer rights in KRS 367.3615 is the same consumer exercising such consumer rights with respect to the personal data at issue; (3) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Kentucky HB 15 (2024): Kentucky Consumer Data Protection Act (Enrolled Bill Text)(apps.legislature.ky.gov).gov
- KRS 367.3613: Application, Limitations, and Exemptions(apps.legislature.ky.gov).gov
- KRS 367.3615: Consumer Rights Request and Appeal Process(apps.legislature.ky.gov).gov
- KRS 367.3617: Controller Limitations, Privacy Notice, and Opt-Out Methods(apps.legislature.ky.gov).gov
- KRS 367.3619: Processor Obligations and Controller-Processor Contract Requirements(apps.legislature.ky.gov).gov
- KRS 367.3621: Data Protection Impact Assessment Requirements(apps.legislature.ky.gov).gov
- KRS 367.3627: Attorney General Enforcement, Cure Period, and Civil Penalties(apps.legislature.ky.gov).gov
- KRS 367.3629: Consumer Privacy Fund(apps.legislature.ky.gov).gov
- Kentucky Attorney General: Office of Data Privacy and the KCDPA(ag.ky.gov).gov
- Kentucky HB 692 (2026 Regular Session), signed April 13, 2026, 2026 Ky. Acts ch. 118: amends the KCDPA, effective July 1, 2027(apps.legislature.ky.gov)
- Kentucky HB 692 (2026) enrolled bill text: KRS 367.3617(1)(f) automatic content recognition consent duty and KRS 367.3611 definitions(apps.legislature.ky.gov)
- KRS 367.3617: Limitations on the collection and use of personal data by a controller (Effective until July 1, 2027)(apps.legislature.ky.gov)