Privacy Law Library

Kentucky Security Breach Notification Law

KY Breach Notification

Breach notification

Requires businesses to notify Kentucky residents when unencrypted, unredacted computerized personal information (name plus SSN, driver's license number, or financial account or card number with its access code) is acquired without authorization in a way that causes or is reasonably believed to cause identity theft or fraud. Notice must go out in the most expedient time possible and without unreasonable delay, and consumer reporting agencies must be told when more than 1,000 people are notified.

Where
Kentucky
Citation
KRS 365.732 (enacted 2014 Ky. Acts ch. 84, HB 232)
Status
In force
In force since
2014-07-15
Enforced by
Not specified in KRS 365.732
People can sue
No
Penalties
The section itself states no penalty or enforcement mechanism.
Applies to
  • Any person or business entity that conducts business in Kentucky (information holder)
  • Persons maintaining computerized personally identifiable information they do not own
  • Exempt: persons subject to Title V of the Gramm-Leach-Bliley Act or HIPAA, and Kentucky state agencies, local governments, and political subdivisions (public agencies are covered separately by KRS 61.931 to 61.934)

Breach duties

  • Notify affected Kentucky residents in the most expedient time possible and without unreasonable delay after discovering a breach of unencrypted personally identifiable information that causes or is reasonably believed to cause identity theft or fraud.KRS 365.732(1)(a), (2)
  • A holder of data it does not own must notify the owner or licensee as soon as reasonably practicable after discovery.KRS 365.732(3)
  • Notice may be delayed while a law enforcement agency determines that notice would impede a criminal investigation, and must follow promptly once cleared.KRS 365.732(4)
  • Notice may be written or electronic (E-SIGN compliant); substitute notice (email, website posting, and statewide media) is allowed if cost exceeds $250,000, more than 500,000 people are affected, or contact information is insufficient.KRS 365.732(5)
  • If more than 1,000 persons must be notified at one time, also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the notices.KRS 365.732(7) · Only if: More than 1,000 persons notified at one time

Other duties

  • An information holder following its own notification procedures in an information security policy that is consistent with the statute's timing is deemed compliant.KRS 365.732(6)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Whether the Attorney General treats a violation as an unfair or deceptive act under KRS 367.170 is not stated in the statute and was not confirmed. | Bill number HB 232 (2014) is from memory; the statute history confirms only 2014 Ky. Acts ch. 84, sec. 1.

Research reference, not legal advice.