Other Laws and Regulations
Other Laws Impacting Online Business
Businesses operating a website often assume Kentucky and federal privacy law are the whole picture. In reality, several additional laws can apply depending on who visits your site, what industry you're in, and what you do there — regardless of your business's size or location.
COPPA (Children's Online Privacy Protection Act)
COPPA is a federal law enforced by the FTC that requires businesses to comply if their website or online service is directed to children under 13 and collects personal information from them. Importantly, COPPA isn't limited to sites built for kids: it also applies to operators of general-audience sites and services when they have "actual knowledge" that they're collecting information from a child under 13.
If COPPA applies to your business, you generally must:
Post a privacy policy that complies with COPPA;
Notify parents directly before collecting personal information from their children;
Obtain parents' verifiable consent before collecting that information;
Honor parents' ongoing rights regarding information collected from their children; and
Implement reasonable security procedures, along with data retention and deletion practices.
COPPA applies to commercial websites, online services, mobile apps, and IoT devices, and nonprofit entities engaged in noncommercial activities are generally exempt. If your business doesn't intend to collect information from children under 13, the practical takeaway is to avoid asking for birthdates, grade levels, or other age-identifying information you don't need — collecting it can itself trigger COPPA's obligations.
ADA (Americans with Disabilities Act) and Website Accessibility
Website accessibility litigation under Title III of the ADA has become one of the more common — and often surprising — legal risks for small online businesses. The ADA doesn't reference a specific technical standard for website compliance, and there is no dedicated federal regulation spelling out exact website requirements for private businesses. In the absence of clear rules, the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA have become the de facto standard used by courts in evaluating whether a website meets the ADA's accessibility requirements.
A few things are worth knowing:
Even the smallest companies with an online presence are at risk of suit, and businesses with a physical location are at even higher risk.
Courts are split on whether a website needs some connection to a physical location to be covered by the ADA at all, but the trend has been toward finding that online-only businesses can be covered as well.
Website accessibility lawsuits have been increasing significantly year over year, and no particular website platform or builder is automatically compliant, including popular small-business site builders.
Businesses found in violation can face injunctive relief and attorneys' fees, and in some states, monetary damages as well.
Because there's no formal safe harbor or cure period under the ADA, the most practical protection is proactive: reviewing your website against WCAG 2.1 AA guidelines (things like alt text for images, keyboard navigability, and screen-reader compatibility) before a complaint or demand letter arrives, rather than after.
HIPAA (Health Insurance Portability and Accountability Act)
HIPAA applies more narrowly than many business owners assume — it's not triggered simply because a business handles health-related information in some general sense. HIPAA applies to "covered entities" (health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with certain standardized transactions) and to their "business associates" — meaning any person or company that performs a function or service involving protected health information (PHI) on a covered entity's behalf.
For a small business operating a website, HIPAA becomes relevant in two main scenarios:
Your business is itself a covered entity — for example, you run a medical, dental, chiropractic, or similar healthcare practice with an online presence (appointment scheduling, patient portals, intake forms, etc.).
Your business is a business associate — for example, you provide billing, scheduling, data storage, IT, marketing, or software services to a healthcare provider, and your work involves creating, receiving, storing, or transmitting PHI on their behalf. If so, you'll typically be required to sign a Business Associate Agreement (BAA) with that covered entity, obligating you to follow many of HIPAA's privacy and security requirements directly.
A common misconception is that any business touching "health-adjacent" data is automatically covered. A general wellness blog, a fitness app not affiliated with a healthcare provider, or a business that merely asks customers about dietary preferences generally is not subject to HIPAA — HIPAA's obligations are triggered by the covered-entity/business-associate relationship, not simply by the presence of health-related information.
Other States' Data Privacy Laws
This is a bigger issue than it might seem. As of 2026, roughly 20 states have their own comprehensive consumer privacy laws — including California, Virginia, Colorado, Connecticut, Utah, Texas, and others — each with its own thresholds, rights, and enforcement mechanisms. These laws generally apply based on where your customers are located, not where your business is based. A Kentucky business with no employees or offices outside the state can still fall within another state's law if it serves enough of that state's residents online.
A few important points for a small business:
Thresholds vary but often key off data volume, not revenue. Many of these laws (like Kentucky's own KCDPA) apply once a business processes personal data belonging to a certain number of residents of that state (commonly 100,000, or 25,000 if a large share of revenue comes from selling data) — meaning a small business with a national online customer base could cross a threshold in another state without realizing it.
California is the outlier. The CCPA is the only one of these laws with a private right of action (letting individual consumers sue directly, currently for certain data breaches) and the only one with a specific revenue threshold ($26.625 million or more) as an independent trigger for coverage, separate from the consumer-count thresholds.
"Doing business" in a state can be broadly interpreted. Simply operating a website or app that residents of a state use to submit personal information can, in some cases, be enough to bring a business within a state's law — you don't need a physical location there.
Requirements are largely similar, but not identical, across most of these laws (drawing from Virginia's model, similar to Kentucky's own KCDPA), so a business that builds a solid privacy compliance program to meet Kentucky's requirements is generally well-positioned for many other states too — but gaps can still exist (for example, some states have shorter or no cure periods, some cover employee data, and several restrict data from minors more broadly than COPPA's under-13 standard).
GDPR (General Data Protection Regulation)
The GDPR is a European Union law, but it can still apply to a Kentucky business with no physical presence in Europe. A U.S. business generally falls under the GDPR's scope if it provides goods or services accessible to consumers in the EU or EEA, even if no monetary transaction is required, or monitors the online behavior of individuals in the EU or EEA. Notably, the GDPR doesn't impose a size or revenue threshold like some U.S. state privacy laws — a small Kentucky business can be squarely within its scope. That said, the GDPR does free small and medium-sized businesses (generally, those with fewer than 250 employees) from most detailed record-keeping obligations, even where the rest of the law still applies.
Two scenarios most commonly bring a small business within reach of the GDPR: intentionally marketing to or selling to EU customers, or using tracking scripts, cookies, analytics tools, or advertising pixels that track the behavior of EU visitors — even incidentally. Simply having a website that happens to be accessible from Europe is not, by itself, enough to trigger GDPR obligations; GDPR applies when there is a clear intention to offer goods or services to people in the EU, or when EU visitor behavior is actively tracked. Non-compliance carries significant potential penalties — fines of up to 4% of global annual revenue or €20 million, whichever is greater.
Other Laws Worth Being Aware Of
Beyond consumer privacy specifically, a handful of other federal laws commonly apply to businesses operating online, regardless of size:
CAN-SPAM Act — governs commercial email, requiring accurate sender information, a working opt-out mechanism, and honoring opt-out requests promptly. Learn More.
TCPA (Telephone Consumer Protection Act) — restricts unsolicited text messages and calls, including automated marketing texts, and requires prior consent in most cases. Learn more.
State sales tax nexus rules — following the U.S. Supreme Court's Wayfair decision, a business selling goods online may be required to collect and remit sales tax in other states once it crosses that state's economic nexus threshold (commonly based on sales revenue or transaction volume), even without a physical presence there. Learn more.
PCI DSS — not a law but a contractual security standard imposed by payment card networks; any business accepting credit or debit card payments online is generally required to comply as a condition of its merchant agreement. Learn more.
State unfair and deceptive trade practices (UDAP) laws — most states, including Kentucky, have their own general consumer protection statutes that can apply to misleading online advertising, pricing, or business practices, separate from privacy-specific laws.