Kentucky Security Breach Notification Law
KY Breach Notification
Breach notification
Requires businesses to notify Kentucky residents when unencrypted, unredacted computerized personal information (name plus SSN, driver's license number, or financial account or card number with its access code) is acquired without authorization in a way that causes or is reasonably believed to cause identity theft or fraud. Notice must go out in the most expedient time possible and without unreasonable delay, and consumer reporting agencies must be told when more than 1,000 people are notified.
- Where
- Kentucky
- Citation
- KRS 365.732 (enacted 2014 Ky. Acts ch. 84, HB 232)
- Status
- In force
- In force since
- 2014-07-15
- Enforced by
- Not specified in KRS 365.732
- People can sue
- No
- Penalties
- The section itself states no penalty or enforcement mechanism.
- Applies to
- Any person or business entity that conducts business in Kentucky (information holder)
- Persons maintaining computerized personally identifiable information they do not own
- Exempt: persons subject to Title V of the Gramm-Leach-Bliley Act or HIPAA, and Kentucky state agencies, local governments, and political subdivisions (public agencies are covered separately by KRS 61.931 to 61.934)
Breach duties
- Notify affected Kentucky residents in the most expedient time possible and without unreasonable delay after discovering a breach of unencrypted personally identifiable information that causes or is reasonably believed to cause identity theft or fraud.KRS 365.732(1)(a), (2)
- A holder of data it does not own must notify the owner or licensee as soon as reasonably practicable after discovery.KRS 365.732(3)
- Notice may be delayed while a law enforcement agency determines that notice would impede a criminal investigation, and must follow promptly once cleared.KRS 365.732(4)
- Notice may be written or electronic (E-SIGN compliant); substitute notice (email, website posting, and statewide media) is allowed if cost exceeds $250,000, more than 500,000 people are affected, or contact information is insufficient.KRS 365.732(5)
- If more than 1,000 persons must be notified at one time, also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the notices.KRS 365.732(7) · Only if: More than 1,000 persons notified at one time
Other duties
- An information holder following its own notification procedures in an information security policy that is consistent with the statute's timing is deemed compliant.KRS 365.732(6)
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Whether the Attorney General treats a violation as an unfair or deceptive act under KRS 367.170 is not stated in the statute and was not confirmed. | Bill number HB 232 (2014) is from memory; the statute history confirms only 2014 Ky. Acts ch. 84, sec. 1.
Research reference, not legal advice.