top of page

The Kentucky Consumer Data Protection Act (KCDPA)

Kentucky Consumer Data Protection Act (KCDPA)

The Kentucky Consumer Data Protection Act (KCDPA), codified at KRS 367.3611 to 367.3629, became effective January 1, 2026. It establishes new privacy rights for Kentucky consumers and imposes compliance obligations on businesses that meet certain thresholds — but importantly, it does not apply to every business operating online.


Which Businesses Are Covered

The KCDPA applies to organizations that conduct business in Kentucky or produce products or services targeted at Kentucky residents, but only if they also meet one of two data-processing thresholds during a calendar year. A business is covered if it:

  • Controls or processes the personal data of at least 100,000 Kentucky consumers; or

  • Controls or processes the personal data of at least 25,000 Kentucky consumers and derives 50% or more of its gross revenue from the sale of personal data.

Notably, the KCDPA does not include a standalone minimum revenue threshold — coverage is based on the volume of consumer data processed, not how much money the business makes. This means a smaller business that handles a large volume of consumer data could still be covered, even without significant revenue.


Which Businesses Are Exempt

Certain entities are exempt from the KCDPA regardless of size, including cities, state agencies, or any political subdivision of the state; nonprofit organizations; and institutions of higher education, along with financial institutions or affiliates subject to the Gramm-Leach-Bliley Act, and covered entities or business associates governed by HIPAA. Certain small utilities and entities that process data solely to assist law enforcement with insurance-related fraud or to support first responders during catastrophic events are also exempt.


What Covered Businesses Must Do

Businesses that meet the thresholds above must:

  • Provide consumers with an "accessible, clear, and meaningful" privacy notice describing their data practices;

  • Honor consumer requests to confirm whether their personal data is being processed, access it, correct inaccuracies, delete it, and obtain a portable copy of it;

  • Allow consumers to opt out of the processing of their data for targeted advertising, the sale of personal data, or certain profiling;

  • Obtain a consumer's consent before processing that consumer's "sensitive data," which includes racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation data, and data collected from a known child under 13;

  • Limit data collection to what is "reasonably necessary" for the purposes disclosed to the consumer, and use appropriate security safeguards; and

  • Enter into data processing agreements with any processors that handle personal data on the business's behalf.

Businesses generally must respond to a consumer's rights request within 45 days, with a possible 45-day extension where needed.


Penalties for Noncompliance

The Attorney General has sole authority to enforce the KCDPA — there is no ability for individual consumers to sue a business directly under the law. If a violation occurs, the Attorney General must first provide written notice, and the business then has 30 days to cure the violation and confirm in writing that it has done so. If the business fails to cure the violation within that window, the Attorney General's office can file a lawsuit and may seek civil penalties of up to $7,500 for each violation. Unlike some other states, Kentucky's 30-day cure period is permanent and does not expire over time, giving businesses an ongoing opportunity to correct problems before facing penalties — though repeated or systemic violations could still result in substantial cumulative penalties.


A Note on Enforcement in Practice

Kentucky's Attorney General has shown a willingness to act quickly: on January 8, 2026 — just eight days after the KCDPA took effect — the Attorney General sued an AI chatbot company for allegedly collecting children's sensitive data without parental consent, filing without first issuing the standard 30-day cure notice by pairing the claim with a separate consumer protection statute that doesn't carry a cure-period requirement. This suggests that while the cure period offers real protection for most violations, cases involving children's data or other aggravated conduct may be treated differently.


Other Important Notes for Small Business Owners

  • Businesses that already comply with the federal Children's Online Privacy Protection Act's (COPPA) parental consent requirements are deemed compliant with the KCDPA's requirements for children's data.

  • Covered businesses must also complete data protection impact assessments for certain high-risk processing activities, a requirement that applies prospectively to newly initiated processing.

  • Because the thresholds are relatively high, most small businesses will fall outside the KCDPA's scope — but businesses should periodically reassess as their customer base and data practices grow, since crossing either threshold triggers full compliance obligations going forward.

chaselawlogo_transparent.png
kcv_2306_primary_icon_rgb_edited.png

Kentucky Commercialization Ventures

NO LEGAL ADVICE — PLEASE READ CAREFULLY

THE CONTENT ON THIS SITE IS PROVIDED FOR GENERAL EDUCATIONAL PURPOSES ONLY

AND DOES NOT CONSTITUTE LEGAL ADVICE.

bottom of page