Kentucky Consumer Data Protection Act (KCDPA)

· About Kentucky Consumer Data Protection Act (KCDPA)

Key Takeaways

  • The Kentucky Consumer Data Protection Act (KCDPA) applies to controllers and processors operating in Kentucky that meet the law’s applicability thresholds, and it became effective on 1 January 2026.[8][11]
  • Kentucky’s Attorney General has exclusive enforcement authority and may seek civil penalties of up to $7,500 per violation after providing notice and an opportunity to cure within 30 days.[8]
  • Controllers must obtain consumer consent before processing sensitive data, and the Attorney General’s published guidance states that sensitive data includes precise geolocation, biometric data used for identification, health data, and data from a known child under 13.[12]
  • A 2026 amendment, HB 692, adds automated content recognition data and smart monitor data to the definition of sensitive data, and those changes take effect on 1 July 2027.[1][3]
  • Kentucky’s 2025 amendment history includes a prospective effective date for some data protection impact assessment obligations tied to processing initiated or generated on or after 1 June 2026.[13]
  • The KCDPA creates consumer rights to access, correct, delete, port, and opt out of certain processing, and it requires a process for consumer appeals after a refusal to act on a request.[8][12]

What It Is

The KCDPA is Kentucky’s comprehensive consumer privacy statute, codified in Chapter 367 of the Kentucky Revised Statutes and commonly described as Kentucky’s state-level data privacy framework for consumer personal data.[8][11] It is enforced exclusively by the Kentucky Attorney General, who administers the state’s consumer privacy enforcement program.[8][12]

The law’s original effective date is 1 January 2026.[8][11] A later 2025 enactment amended the law effective 1 January 2026 in the official chapter materials, while a 2026 amendment, HB 692, takes effect on 1 July 2027 for the smart-TV and smart-monitor ACR changes.[9][11][3]

The 2026 amendment specifically adds automatic content recognition data and smart monitor to Kentucky’s sensitive-data framework and prohibits collection of ACR data without consumer consent beginning 1 July 2027.[1][3] That is a phase-in delay, not a repeal or rollback of the underlying KCDPA.[1][3]

Who Must Comply

The KCDPA applies to controllers and processors that conduct business in Kentucky or target Kentucky residents and meet the statute’s threshold criteria, which are built around volume of data, revenue, or sale-based activity as set out in the law’s applicability section.[8] The official Attorney General guidance describes the regulated actors as controllers and processors and emphasizes that consumer rights run against controllers.[12]

The statute has extraterritorial reach in the sense that it covers entities outside Kentucky if they conduct business in the state or target Kentucky consumers and satisfy the statutory thresholds.[8] That is consistent with the structure of most comprehensive state privacy laws, which regulate entities by consumer location and business activity rather than incorporation alone.[8]

The law contains exemptions for certain entities and data types, including data covered by sectoral laws and data processed in excluded contexts; the statutory exemptions should be checked carefully before assuming coverage.[8] Public guidance from the Attorney General confirms the existence of both entity-level and data-level limitations on the law’s scope.[12]

Core Requirements

  1. Honor consumer rights requests. Controllers must provide mechanisms for consumers to exercise rights to access, correct, delete, obtain a copy of, and opt out of certain processing activities, and they must respond within the statute’s required timeframes.[8][12]
  1. Provide an appeal process. If a controller denies a consumer request, it must maintain a process for the consumer to appeal that denial, and it must disclose the appeal method in its privacy disclosures.[8]
  1. Limit processing of sensitive data. Controllers may not process sensitive data without obtaining the consumer’s consent, and the Attorney General’s guidance identifies sensitive categories that include health data, biometric data for identification, precise geolocation, and data from a known child under 13.[12]
  1. Conduct data protection assessments. Controllers must conduct and document assessments for high-risk processing activities, including processing sensitive data and other activities identified by the statute and subsequent amendments.[8][13]
  1. Maintain processor contracts. Controllers must use contracts with processors that set out instructions, confidentiality, deletion or return obligations, and audit or compliance terms required by the law.[8]
  1. Publish a compliant privacy notice. Controllers must provide a privacy notice describing the categories of personal data processed, purposes, consumer rights, how to appeal denial decisions, and how to contact the controller.[8][12]
  1. Implement reasonable security. Controllers and processors must establish and maintain administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data they process.[8][12]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Original KCDPA effective date | 1 January 2026 | Core controller and processor obligations begin.[8][11] | | DPIA timing milestone referenced in 2025 amendments | 1 June 2026 | Some assessment requirements apply prospectively to processing initiated or generated on or after this date.[13] | | HB 692 enacted | 13 April 2026 | Kentucky adds ACR data and smart monitor data to the sensitive-data framework.[1] | | ACR consent requirement effective | 1 July 2027 | Controllers may not collect ACR data without consumer consent.[1][3] |

The maximum civil penalty is $7,500 per violation.[8] The Attorney General has exclusive enforcement authority, and the statute provides a 30-day cure period after notice before an enforcement action may proceed.[8]

Other sanctions can include injunctive relief and the operational burden of responding to enforcement demands, remedial orders, and contract or program changes needed to cure violations.[8] Because the law is enforced by the Attorney General rather than a private right of action, consumer lawsuits are not the primary enforcement mechanism under the KCDPA.[8]

How to Comply

  1. Build a data inventory. Map personal data, sensitive data, processors, retention periods, and downstream disclosures; this is the foundation for KCDPA notices, rights handling, and assessment scoping.
  1. Classify sensitive data precisely. Separate standard personal data from sensitive data, then add controls for consent capture, storage, and downstream use; the 2026 HB 692 amendment means ACR data will need this treatment from 1 July 2027.[1][3]
  1. Align your privacy governance to ISO 27001. Use the ISMS structure to assign ownership, manage risks, document controls, and track evidence for security and processor oversight.
  1. Operationalize privacy risk controls using NIST CSF 2.0. Map Identify, Protect, Detect, Respond, and Recover activities to data rights intake, security monitoring, incident handling, and remediation.
  1. Use ISO 42001 where automated or AI-enabled systems touch consumer data. The standard is most useful where profiling, automated decisioning, content recommendation, or content-recognition tooling creates privacy and accountability risks.
  1. Create rights-request playbooks. Set SLAs, identity verification rules, appeal templates, and escalation paths so access, deletion, correction, portability, and opt-out requests can be handled consistently.
  1. Prepare data protection assessments. Document risk, necessity, proportionality, safeguards, and residual risk for sensitive processing and other high-risk uses; keep assessments version-controlled and auditable.[8][13]
  1. Review vendor contracts and onboarding. Ensure processor terms require confidentiality, limit use to instructions, support audits, and require deletion or return at termination.

Related Regulations

  • Virginia Consumer Data Protection Act — Kentucky’s law is structurally similar to Virginia’s comprehensive privacy model, so Virginia guidance is often useful for operational design, but the statutes are separate and have different thresholds and enforcement details.
  • Colorado Privacy Act — Colorado overlaps on rights, assessments, and sensitive-data handling, but Kentucky’s enforcement and cure structure are distinct.
  • Connecticut Data Privacy Act — Connecticut is relevant for multi-state programs because it also requires consumer rights workflows and processor contracts, though the statutory definitions differ.
  • Illinois Biometric Information Privacy Act — Illinois is narrower and more punitive on biometric data, so it can conflict with Kentucky program design where biometric collection, consent, and retention are implicated.
  • Federal sectoral privacy laws — HIPAA, GLBA, FERPA, and COPPA can exempt certain data or activities from comprehensive state privacy obligations, so scope analysis must be done before applying the KCDPA.[8][12]

FAQ

Does the Kentucky Consumer Data Protection Act apply to companies outside Kentucky?

Yes, if a company conducts business in Kentucky or targets Kentucky residents and meets the statute’s applicability thresholds.[8] The law is not limited to Kentucky-incorporated entities. Multi-state companies should assume Kentucky exposure if Kentucky consumer data is in scope.

Does the KCDPA require consent for sensitive data?

Yes. Kentucky’s Attorney General guidance states that controllers cannot process a consumer’s sensitive data without first obtaining consent.[12] That consent requirement becomes especially important for the 2027 smart-TV ACR expansion, which adds a new sensitive-data category.[1][3]

When do the smart TV data changes take effect?

The 2026 amendment enacted as HB 692 takes effect on 1 July 2027.[1][3] From that date, automated content recognition data and smart monitor data are treated as sensitive data, and collection without consumer consent is prohibited.[1][3]

What is the penalty for violating the KCDPA?

The Kentucky Attorney General may seek civil penalties of up to $7,500 per violation.[8] The statute also gives the controller or processor 30 days to cure after notice before an action proceeds.[8]

Is there a private right of action under the KCDPA?

No private right of action is indicated in the cited statute materials; enforcement is assigned to the Kentucky Attorney General.[8] That means consumer claims under the KCDPA itself are not the main enforcement route. Organizations should still expect regulatory scrutiny and remediation demands.

Do data protection impact assessments apply right away?

Some assessment obligations apply prospectively under the 2025 amendment history, with processing initiated or generated on or after 1 June 2026 highlighted in secondary analysis.[13] The exact scope should be checked against the statutory text and the organization’s specific processing activities.

Sources

Put it into practice

More compliance guides