Privacy Law Library

Kentucky Consumer Data Protection Act

KCDPA

Comprehensive privacy · Children · Health · Genetic · Biometric · Location

Kentucky's comprehensive consumer privacy law gives Kentucky residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, obtain consent before processing sensitive data, publish a privacy notice, and conduct data protection impact assessments for higher-risk processing. A 2026 amendment (effective July 1, 2027) bars collection of smart-TV and smart-monitor automatic content recognition data without consent.

Where
Kentucky
Citation
KRS 367.3611 to 367.3629 (enacted 2024 Ky. Acts ch. 72, HB 15; amended 2025 Ky. Acts ch. 13, HB 473; 2026 Ky. Acts ch. 118, HB 692)
Status
In force
In force since
2026-01-01
Last amended
2027-07-01
Enforced by
Kentucky Attorney General (exclusive authority; complaints handled by the AG's Office of Data Privacy)
People can sue
No
Penalties
After a 30-day written notice and cure period, the Attorney General may seek damages of up to $7,500 for each continued violation, plus reasonable investigative expenses, court costs, and attorney's fees. Recoveries go to a consumer privacy fund.
Applies to
  • Persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents and that, in a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data
  • Processors acting on behalf of covered controllers
  • Exempt entities: cities, state agencies and political subdivisions; GLBA financial institutions and their affiliates; HIPAA covered entities and business associates; nonprofits; institutions of higher education; certain insurance-fraud and first-responder support organizations; small telephone utilities, Tier III CMRS providers, and municipally owned utilities that do not sell or share personal data
  • Exempt data include PHI, health records, FCRA-regulated data, FERPA data, DPPA data, employment-context data, and data processed by utilities

What a privacy notice must say

  • Provide a reasonably accessible, clear privacy notice listing categories of data processed, purposes, how to exercise and appeal rights, categories of data shared, and categories of third parties; clearly disclose sale or targeted advertising and how to opt out.KRS 367.3617(3)-(4)

Rights it gives people

  • Consumers may confirm processing and access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising, sale, and profiling for decisions with legal or similarly significant effects; a parent or guardian may act for a child.KRS 367.3615(1)-(2)

Practices it requires

  • Limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes, and obtain consent for incompatible secondary uses.KRS 367.3617(1)(a)-(b)
  • Do not process sensitive data (race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, identifying genetic or biometric data, known-child data, precise geolocation) without consent; process known-child data per COPPA.KRS 367.3617(1)(e); KRS 367.3611 (definition of sensitive data)
  • Do not discriminate against consumers for exercising their rights; bona fide loyalty and rewards programs are permitted. Contract terms waiving consumer rights are void.KRS 367.3617(1)(d), (2)
  • Offer one or more secure and reliable means to submit rights requests, described in the privacy notice, without requiring creation of a new account.KRS 367.3617(5)
  • Do not collect automatic content recognition data (content viewing history identified by smart televisions or smart monitors) without the consumer's consent.KRS 367.3617(1)(f) (as amended by 2026 Ky. Acts ch. 118) · From 2027-07-01
  • Respond to authenticated requests within 45 days (one 45-day extension allowed with notice), free of charge up to twice a year, and provide an appeal process answered within 60 days with a way to complain to the Attorney General if denied.KRS 367.3615(3)-(4)
  • Conduct and document data protection impact assessments for targeted advertising, sale, risky profiling, sensitive data processing, and other heightened-risk processing, and produce them to the Attorney General on investigative demand.KRS 367.3621(1)-(3), (8) · Only if: Applies to processing activities created or generated on or after June 1, 2026 · From 2026-06-01

Security duties

  • Maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.KRS 367.3617(1)(c)

Other duties

  • Controller-processor contracts must set processing instructions, the nature, purpose, type, and duration of processing, and the parties' rights and duties; processors must help controllers with rights requests, security, breach notice under KRS 365.732, and assessments.KRS 367.3619

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.