top of page

Data Breach

Data Breach Notification

Kentucky's data breach notification law, KRS 365.732, applies to any person or business entity that conducts business in Kentucky and owns or licenses computerized data that includes personal information, regardless of the business's location. If your business collects and stores personal information about customers electronically, this law likely applies to you.


What Counts as "Personal Information"

The statute's definition of personal information is narrower than many business owners expect. It means an individual's first name or initial plus last name, combined with any one of the following data elements:

  • Social Security number;

  • Driver's license number; or

  • Account number, or credit or debit card number, along with any required password, access code, or security code needed to access the account.

Only computerized (electronic) data is covered — paper records fall outside the statute. Notably absent from this list are categories many businesses assume are protected, such as email address and password combinations, medical records, biometric data, and geolocation information — meaning a breach limited to those categories may not trigger notification under this particular law, even though it could still create other legal exposure.


What Counts as a "Breach"

A breach is defined as the unauthorized acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality, or integrity of personal information, and that actually causes, or leads the business to reasonably believe has caused or will cause, identity theft or fraud against a Kentucky resident. This "harm" qualifier matters: not every unauthorized access incident is automatically a reportable breach — the incident must be reasonably likely to result in identity theft or fraud. Additionally, a good-faith acquisition of the information by an employee or agent of the business, for the business's own purposes, is not considered a breach as long as the information isn't misused or further disclosed.


Encryption also matters significantly here: the statute does not apply to information that is encrypted or redacted, creating a straightforward safe harbor for businesses that encrypt the personal information they store.


Who Must Be Notified, and When

If a breach occurs, the business must disclose the breach to any affected Kentucky resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Kentucky does not set a specific number of days for this — instead, disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Notification may be delayed if a law enforcement agency determines it would impede a criminal investigation, and must then be made promptly once the agency confirms notification will no longer compromise that investigation.


If your business holds personal information on behalf of another company (for example, as a vendor or service provider) rather than owning it outright, you're still obligated to act: the business must notify the owner or licensee of the information as soon as reasonably practicable following discovery of the breach.


How Notice May Be Given

The statute permits notice by any of the following methods: written notice; electronic notice, consistent with federal E-SIGN Act requirements; or substitute notice, if the business can show that the cost of direct notice would exceed $250,000, that the affected group exceeds 500,000 people, or that it lacks sufficient contact information for those affected. Substitute notice generally requires a combination of alternative outreach methods, such as email, a website posting, and notice to major media outlets.


Exemptions

The statute doesn't apply to any person or entity already subject to Title V of the Gramm-Leach-Bliley Act or HIPAA, or to Kentucky state agencies or their local governments and political subdivisions, since those entities follow separate federal or governmental breach notification frameworks.


Enforcement

Unlike the KCDPA, the general breach notification statute does not provide for regulatory enforcement, and there is no private right of action built directly into KRS 365.732. However, business owners should be aware that Kentucky's general negligence-per-se statute, KRS 446.070, allows an individual harmed by a violation of any Kentucky statute to pursue civil damages, provided the person belongs to the group the statute was meant to protect and can show the violation caused their harm. In practice, this means a failure to comply with breach notification obligations can still expose a business to civil liability — including, in a breach affecting many people, potential class-action risk.

chaselawlogo_transparent.png
kcv_2306_primary_icon_rgb_edited.png

Kentucky Commercialization Ventures

NO LEGAL ADVICE — PLEASE READ CAREFULLY

THE CONTENT ON THIS SITE IS PROVIDED FOR GENERAL EDUCATIONAL PURPOSES ONLY

AND DOES NOT CONSTITUTE LEGAL ADVICE.

bottom of page