Personal Information Security and Breach Investigation Law for Public Agencies and Nonaffiliated Third Parties
KY Public Agency / Vendor Data Security (HB 5)
Data security · Breach notification · Government records · Biometric · Genetic · Health
Requires public agencies and the private contractors that receive personal information from them to maintain reasonable security and breach investigation procedures. Contractors must report breaches to the agency within 72 hours, and agencies must notify state officials within 72 hours, investigate, and notify affected individuals within 35 days of concluding misuse is likely. Personal information includes name, personal mark, or a biometric or genetic print combined with identifiers such as SSN, account numbers, ID numbers, or health information.
- Where
- Kentucky
- Citation
- KRS 61.931 to 61.934 (created 2014 Ky. Acts ch. 74)
- Status
- In force
- In force since
- 2015-01-01
- Enforced by
- Kentucky Attorney General (Franklin Circuit Court)
- People can sue
- No
- Penalties
- The Attorney General may seek injunctive relief against agencies and nonaffiliated third parties, and other legal remedies against nonaffiliated third parties that are not agencies. No private right of action.
- Applies to
- Kentucky state and local public agencies, public school districts, and public postsecondary institutions
- Nonaffiliated third parties: any person that contracts with such an agency and receives personal information from it (private vendors are directly bound)
- Legislative and judicial branches under KRS 61.934
What a privacy notice must say
- Individual notice must include website posting, media notice, and personal communication by the method most likely to reach each person.KRS 61.933(2)
Security duties
- Agencies and nonaffiliated third parties holding personal information must implement, maintain, and update security procedures and practices, including corrective action, to safeguard against breaches.KRS 61.932(1)(a)
Breach duties
- Agencies must notify the State Police, Auditor of Public Accounts, and Attorney General (plus oversight bodies) within 72 hours of determining a breach and promptly investigate whether misuse is likely.KRS 61.933(1)(a)
- A nonaffiliated third party must notify the contracting agency of a security breach in the most expedient time possible and within 72 hours of determining it, sharing all information then known (law-enforcement delay allowed).KRS 61.932(2)(b)
- If misuse is likely, notify officials within 48 hours of concluding the investigation and affected individuals within 35 days after that; if over 1,000 individuals, notify oversight bodies and nationwide consumer reporting agencies at least 7 days before individual notice.KRS 61.933(1)(b)
Other duties
- A vendor that must investigate or notify under federal law for the same data elements satisfies the Kentucky law by giving the agency copies of its federally required reports.KRS 61.932(1)(c)2.
- Agency contracts executed or amended on or after January 1, 2015 that involve disclosing personal information must require the vendor to maintain security and breach investigation procedures at least as stringent as the agency's.KRS 61.932(2)(a)
Sources
- Official text
- KRS 61.931 definitions (Kentucky Legislature)
- KRS 61.932 (Kentucky Legislature)
- KRS 61.933 (Kentucky Legislature)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The short name 'HB 5' for the 2014 act is from memory; the statute history confirms only 2014 Ky. Acts ch. 74. | KRS 61.934 (legislative and judicial branches) was read from the chapter index title only.
Research reference, not legal advice.