Kentucky
What Is the KCDPA? Kentucky Consumer Data Privacy
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 9 primary sources cited on this page. How we verify our legal content

The Kentucky Consumer Data Protection Act (KCDPA), codified at KRS 367.3611 to 367.3629, is Kentucky's comprehensive consumer data privacy law. It was enacted as House Bill 15 during the 2024 session, signed by Governor Andy Beshear on April 4, 2024, and takes effect January 1, 2026, giving Kentucky residents rights to access, correct, delete, and port their personal data and to opt out of its sale, targeted advertising, and certain profiling.
As of 2026, the Kentucky Attorney General holds exclusive enforcement authority and may seek damages of up to $7,500 for each continued violation under KRS 367.3627(3), a measure that reaches only violations continuing past the 30-day cure period or breaching a written cure statement. The KCDPA is closely modeled on Virginia's Consumer Data Protection Act, so businesses already aligned with the Virginia framework will find Kentucky's obligations familiar.
Jurisdiction scope: This covers Kentucky's Kentucky Consumer Data Protection Act (KRS 367.3611 to 367.3629). It is general legal information, not legal advice.
What the KCDPA is: statute, enactment, and effective date
The Kentucky Consumer Data Protection Act is Kentucky's first comprehensive consumer data privacy law. It is codified at Kentucky Revised Statutes Sections 367.3611 through 367.3629, inside the state's broader consumer protection chapter. The General Assembly passed it as House Bill 15 during the 2024 regular session.
Governor Andy Beshear signed the bill on April 4, 2024. The legislature built in a long runway: the act does not take effect until January 1, 2026. As of 2026, that date has arrived, so every covered business is now fully subject to the KCDPA.
The act expressly names itself. Section 11 of HB 15 provides that the law "may be cited as the Kentucky Consumer Data Protection Act," and Section 12 sets the January 1, 2026 effective date. The 2025 General Assembly later amended the act through House Bill 473 (Chapter 13), which adjusted exemptions and timing, but the core rights and enforcement framework stayed intact. The 2026 General Assembly amended it again through House Bill 692, which Governor Beshear signed on April 13, 2026 as 2026 Ky. Acts ch. 118. That act does not take effect until July 1, 2027. It amends KRS 367.3611 and KRS 367.3617 to define "automatic content recognition data" and "smart monitor" and to add a new controller duty at KRS 367.3617(1)(f), so the duties described on this page are the operative set until that date.
For the controller and processor obligations, privacy notice rules, and data protection assessment requirements in detail, see the Kentucky data privacy laws parent page.
Who the KCDPA covers: the thresholds
The KCDPA's applicability test lives in KRS 367.3613. The law applies to a person that conducts business in Kentucky, or that produces products or services targeted to Kentucky residents, and that during a calendar year meets one of two data-volume triggers.
The first trigger is controlling or processing the personal data of at least 100,000 consumers. The second is controlling or processing the data of at least 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data.
There is no separate revenue floor. Unlike laws such as California's, which can pull a business in on annual revenue alone, the KCDPA keys solely on consumer volume and the data-sales revenue share. A small company that never crosses 100,000 consumers and does not make most of its money selling data stays outside the law.
A "consumer" under KRS 367.3611 is a natural person who is a Kentucky resident acting only in an individual context. The definition expressly excludes a person acting in a commercial or employment context, so workforce and business-to-business data fall outside the consumer-facing rights.

The KCDPA's exemptions: broad entity-level carve-outs
The KCDPA exempts whole categories of organizations at the entity level under KRS 367.3613(2), a structure that removes many businesses regardless of how much data they hold. Several of these exemptions are sweeping.
Cities, state agencies, and political subdivisions of the state are exempt. So are financial institutions, their affiliates, and data subject to Title V of the federal Gramm-Leach-Bliley Act. Entities and data governed by HIPAA are carved out, as are nonprofit organizations and institutions of higher education.
The act also exempts specific utilities under KRS 367.3613(2)(g): a small telephone utility as defined in KRS 278.516, a Tier III CMRS provider as defined in KRS 65.7621, and a municipally owned utility that does not sell or share personal data with any third party. Beyond entity-level exemptions, KRS 367.3613(3) carves out specific data sets, including protected health information, data regulated by the federal Fair Credit Reporting Act, FERPA-governed education records, and employment and applicant data.
The practical effect is that the KCDPA's covered population is narrower than the consumer-volume thresholds alone suggest. A business should map its status against KRS 367.3613 rather than assume coverage, because the exemptions are framed around specific federal regimes and licensed roles.
The opt-in sensitive-data rule
Sensitive data carries a stricter rule than ordinary personal data. Under KRS 367.3617(1)(e), a controller may not process sensitive data concerning a consumer without first obtaining the consumer's consent. This is an opt-in model: the default is no processing until the consumer affirmatively agrees.
Sensitive data is defined in KRS 367.3611. It includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status. It also includes genetic or biometric data processed to uniquely identify a person, personal data collected from a known child, and precise geolocation data.
"Consent" under the KCDPA is not a buried checkbox. KRS 367.3611 defines it as a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data. For sensitive data collected from a known child, the controller must instead follow the federal Children's Online Privacy Protection Act. Because the consent gate sits in front of an entire category of data, getting the definition of sensitive data right is an operational priority for covered businesses.
A second consent gate is already enacted but not yet in force. House Bill 692 (2026 Ky. Acts ch. 118) adds KRS 367.3617(1)(f), directing a controller to "not collect automatic content recognition data without a consumer's consent," effective July 1, 2027. The bill defines automatic content recognition data as data about a consumer's content viewing history collected through technology embedded in or operated through a smart television or smart monitor that identifies displayed content in real time by analyzing audio or video fingerprints. That duty does not bind controllers before July 1, 2027, but smart-TV and connected-display businesses have a fixed compliance date.

The Virginia clone: why the KCDPA looks familiar
The KCDPA's signature feature is not a novel provision but its near-identical resemblance to Virginia's Consumer Data Protection Act, the first of the modern state privacy laws. Kentucky's legislature copied the Virginia structure closely, from the definitions in KRS 367.3611 to the rights set in KRS 367.3615 to the enforcement model in KRS 367.3627.
That lineage matters for multistate businesses. A company that built its program around Virginia's law will recognize Kentucky's 100,000-consumer trigger, its opt-in rule for sensitive data, its 45-day response deadline, its data protection assessment duties, and its Attorney-General-only enforcement with a cure period. The terminology of "controller," "processor," "consumer," and "sensitive data" is the same.
One consequence of the Virginia model is what the KCDPA leaves out. The act does not mandate that controllers honor a universal opt-out mechanism such as the Global Privacy Control browser signal. KRS 367.3617 requires controllers to disclose and provide their own opt-out methods, but the statute contains no requirement to recognize a global signal, a feature that several newer state laws added but that Virginia and Kentucky did not.
For the rights themselves and how to invoke them, see the KCDPA consumer rights guide.
KCDPA vs. CCPA: the key differences
Kentucky's KCDPA and California's CCPA are often compared by companies that operate nationally. The state data privacy law comparison page covers the broader multistate picture, but several differences between the KCDPA and California's CCPA stand out.
| Feature | Kentucky KCDPA | California CCPA/CPRA |
|---|---|---|
| Coverage threshold | 100,000 consumers, OR 25,000 consumers plus over 50% revenue from data sales | $25M revenue, OR 100,000 consumers, OR 50% revenue from data sales |
| Revenue-only trigger | No; keys on consumer volume and data-sale revenue share | Yes; $25M annual revenue alone can bring a business in |
| Model | Virginia-style framework (controller and processor) | Stand-alone California framework (business and service provider) |
| Sensitive data | Opt-in consent required (KRS 367.3617(1)(e)) | Right to limit use; opt-out model |
| Universal opt-out signal | Not mandated | Required to honor opt-out preference signals |
| Private right of action | None (KRS 367.3627(4)) | Limited, for certain data breaches |
| Cure period | Permanent 30-day cure (KRS 367.3627(2)) | Cure provision narrowed over time |
The most consequential difference is the threshold structure. California can reach a business on revenue alone, while Kentucky keys on consumer volume and the data-sale revenue share, so a high-revenue company with few Kentucky consumers may sit outside the KCDPA.
The second major difference is the opt-out model. California requires businesses to honor universal opt-out preference signals, while Kentucky does not. A KCDPA-covered business must provide its own opt-out methods but is not required to recognize a global browser signal as of 2026.
Related guides
- Kentucky data privacy laws parent hub
- KCDPA consumer rights
- KCDPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Kentucky Laws
Frequently Asked Questions
What is the KCDPA?
The KCDPA, or Kentucky Consumer Data Protection Act, is Kentucky's comprehensive consumer data privacy law codified at KRS 367.3611 to 367.3629. It was enacted as House Bill 15, signed by Governor Andy Beshear on April 4, 2024, and takes effect January 1, 2026. It gives Kentucky residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and disclose it.
When did the KCDPA take effect?
The KCDPA takes effect January 1, 2026, more than a year and a half after it was signed on April 4, 2024. The long runway gave covered businesses time to build privacy programs before their obligations began. As of 2026, the effective date has arrived and every covered business is fully subject to the law.
Who has to comply with the KCDPA?
Under KRS 367.3613, the KCDPA applies to a business that conducts business in Kentucky or targets Kentucky residents and that, in a calendar year, controls or processes the personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data. There is no separate revenue-only trigger.
Is the KCDPA the same as Virginia's privacy law?
Nearly. Kentucky's legislature modeled the KCDPA closely on Virginia's Consumer Data Protection Act, sharing the same definitions, the same rights set in KRS 367.3615, the same opt-in rule for sensitive data, and the same Attorney-General-only enforcement with a cure period. A business already aligned with Virginia's framework will find Kentucky's obligations familiar.
Does the KCDPA require consent for sensitive data?
Yes. Under KRS 367.3617(1)(e), a controller may not process sensitive data without first obtaining the consumer's consent, an opt-in model. Sensitive data under KRS 367.3611 includes data revealing racial or ethnic origin, religious beliefs, a health diagnosis, sexual orientation, or immigration status, plus genetic or biometric data used to identify a person, a known child's data, and precise geolocation.
Does the KCDPA require honoring a universal opt-out signal?
No. The KCDPA does not mandate that controllers recognize a universal opt-out mechanism such as the Global Privacy Control browser signal. KRS 367.3617 requires controllers to disclose and provide their own opt-out methods, but the statute contains no requirement to honor a global opt-out signal, matching the Virginia model it was based on.
How is the KCDPA different from the CCPA?
The KCDPA keys on consumer volume and data-sale revenue share rather than offering a revenue-only trigger like California's $25 million floor. It uses an opt-in model for sensitive data, while California uses a right to limit. It does not require honoring universal opt-out signals, while California does. And it has no private right of action, while California allows a limited one for certain breaches.
Is the KCDPA being amended after 2026?
Yes. House Bill 692, signed April 13, 2026 as 2026 Ky. Acts ch. 118, amends KRS 367.3611 and KRS 367.3617 but does not take effect until July 1, 2027. It defines automatic content recognition data and smart monitor, and adds KRS 367.3617(1)(f), which bars a controller from collecting automatic content recognition data without a consumer's consent. Until July 1, 2027, the controller duties described on this page are the operative set.
Who enforces the KCDPA?
The Kentucky Attorney General has exclusive enforcement authority under KRS 367.3627. There is no private right of action. Before suing, the Attorney General must give a 30-day written notice and cure opportunity, and that cure period is permanent with no sunset. Under KRS 367.3627(3) the Attorney General may then seek damages of up to $7,500 for each continued violation, meaning a violation that continues after the cure period or that breaches the written cure statement. Civil penalties collected are deposited into the consumer privacy fund under KRS 367.3629.
Updates
Corrected the KCDPA penalty measure to $7,500 for each continued violation under KRS 367.3627(3), restated the KRS 367.3613(2)(g) utility exemption to match the statute including the Tier III CMRS carve-out, and added the enacted 2026 amendment (House Bill 692, 2026 Ky. Acts ch. 118) that bars collecting automatic content recognition data without consent starting July 1, 2027.
Independently fact-checked against the cited primary sources
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION
§ 367.3615Consumer rights request -- Controller compliance -- Requirements -- Appeal processIn forcecited in 7 of our articles
(1) A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to a controller, via the means specified by the controller pursuant to KRS 367.3617, specifying the consumer rights the consumer wishes to invoke. A child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Data Privacy Laws: Consumer Rights Guide (2026), Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026), KCDPA Compliance Checklist: Kentucky Privacy Law
§ 367.3613Application -- Limitations -- Information and data exemptions -- Compliance with federal children's online privacy lawsIn forcecited in 3 of our articles
(1) KRS 367.3611 to 367.3629 apply to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that during a calendar year control or process personal data of at least: (a) One hundred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data. (2) KRS 367.3611 to 367.3629 shall not apply to any: (a) City, state agency, or any political subdivision of the state; (b) Financial institutions, their affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. sec. 6801 et seq.; (c) Covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder of the entity; and 2.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3617Limitations on the collection and use of personal data by a controller --In forcecited in 5 of our articles
Waiver of consumer rights contrary to public policy -- Privacy notice -- Notice for sale of personal data to third party -- Process for consumers to exercise consumer rights requirement. (Effective until July 1, 2027) (1) A controller shall: (a) Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data is processed as disclosed to the consumer; (b) Except as otherwise provided in this section, not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which the personal data is processed as disclosed to the consumer, unless the controller obtains the consumer's consent; (c) Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. The data security practices shall be appropriate to the volume and nature of the personal data at issue; (d) Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: KCDPA Consumer Rights: Kentucky Privacy Rights Guide
§ 367.3611Definitions for KRS 367.3611 to 367.3629. (Effective until July 1, 2027)In forcecited in 6 of our articles
As used in KRS 367.3611 to 367.3629: (1) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company; (2) "Authenticate" means verifying through reasonable means that the consumer entitled to exercise his or her consumer rights in KRS 367.3615 is the same consumer exercising such consumer rights with respect to the personal data at issue; (3) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 367.3627Enforcement authority of Attorney General -- Written notice of violation -- Civil action -- Damages -- Recovery of expensesIn forcecited in 3 of our articles
(1) The Attorney General shall have exclusive authority to enforce violations of KRS 367.3611 to 367.3629. The Attorney General may enforce KRS 367.3611 to 367.3629 by bringing an action in the name of the Commonwealth of Kentucky or on behalf of persons residing in this Commonwealth. The Attorney General shall have all powers and duties granted to the Attorney General under KRS Chapter 15 to investigate and prosecute any violation of KRS 367.3611 to 367.3629. The Attorney General may demand any information, documentary material, or physical evidence from any controller or processor believed to be engaged in, or about to engage in, any violation of KRS 367.3611 to 367.3629. (2) Prior to initiating any action for violation of KRS 367.3611 to 367.3629, the Attorney General shall provide a controller or processor thirty (30) days' written notice identifying the specific provisions of KRS 367.3611 to 367.3629, the Attorney General alleges have been or are being violated.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
§ 367.3629Consumer privacy fundIn forcecited in 3 of our articles
There is hereby created a trust and agency account to be known as the consumer privacy fund. The fund shall be administered by the Office of the Attorney General. All civil penalties collected pursuant to KRS 367.3611 to 367.3629 shall be deposited into the fund. Interest earned on moneys in the fund shall accrue to the fund. Moneys in the fund shall be used by the Office of the Attorney General to enforce KRS 367.3611 to 367.3629. Notwithstanding KRS 45.229, any moneys remaining in the fund at the close of the fiscal year shall not lapse but shall be carried forward into the succeeding fiscal year to be used by the Office of the Attorney General for the purposes set forth in KRS 367.3611 to 367.3629.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Kentucky HB 15 (2024): Kentucky Consumer Data Protection Act (Enrolled Bill Text)(apps.legislature.ky.gov).gov
- Kentucky General Assembly: HB 15 Bill Page (2024 Regular Session)(apps.legislature.ky.gov).gov
- KRS 367.3611: Definitions for KRS 367.3611 to 367.3629(apps.legislature.ky.gov).gov
- KRS 367.3613: Application, Limitations, and Exemptions(apps.legislature.ky.gov).gov
- KRS 367.3615: Consumer Rights Request and Appeal Process(apps.legislature.ky.gov).gov
- KRS 367.3617: Controller Limitations and Sensitive Data Consent(apps.legislature.ky.gov).gov
- KRS 367.3627: Attorney General Enforcement, Cure Period, and Civil Penalties(apps.legislature.ky.gov).gov
- KRS 367.3629: Consumer Privacy Fund(apps.legislature.ky.gov).gov
- Kentucky Attorney General: Rights of Kentuckians under the Kentucky Consumer Data Protection Act(ag.ky.gov).gov
- Kentucky General Assembly: HB 692 Bill Page (2026 Regular Session), signed April 13, 2026 as Acts ch. 118(apps.legislature.ky.gov)
- Kentucky HB 692 (2026): Enrolled Bill Text amending KRS 367.3611 and KRS 367.3617, effective July 1, 2027(apps.legislature.ky.gov)
- KRS 367.3627: Attorney General Enforcement, Written Notice of Violation, Cure Period, and Damages(apps.legislature.ky.gov)
- KRS 367.3617: Limitations on the Collection and Use of Personal Data by a Controller(apps.legislature.ky.gov)
- KRS 367.3615: Consumer Rights Request, Controller Compliance, and Appeal Process(apps.legislature.ky.gov)
- KRS 367.3629: Consumer Privacy Fund(apps.legislature.ky.gov)