Skip to content
Privacy Regulations

Kentucky Consumer Data Protection Act (KCDPA)

Overview

The Kentucky Consumer Data Protection Act (KCDPA) is a comprehensive state privacy law that grants Kentucky residents new rights over their personal data while setting clear compliance requirements for businesses. Signed into law on April 4, 2024, the KCDPA takes effect on January 1, 2026.

Kentuckyโ€™s law follows the Virginia CDPA model, making it business-friendly while still providing strong consumer protections.

Who Must Comply?

The KCDPA applies to businesses that operate in Kentucky or target Kentucky residents and meet one of the following criteria:

โœ” Process personal data of at least 100,000 Kentucky consumers annually
โœ” Process personal data of at least 25,000 Kentucky consumers and derive over 50% of gross revenue from selling personal data

Exemptions:

The law does not apply to:
๐Ÿšซ Government agencies
๐Ÿšซ Nonprofits
๐Ÿšซ Financial institutions subject to GLBA
๐Ÿšซ HIPAA-covered entities
๐Ÿšซ Higher education institutions

Key Consumer Rights Under KCDPA

โœ” Right to Access โ€“ Consumers can request a copy of their personal data.
โœ” Right to Correct โ€“ Consumers can request corrections to inaccurate personal data.
โœ” Right to Delete โ€“ Consumers can request the deletion of personal data.
โœ” Right to Data Portability โ€“ Consumers can receive their data in a portable format.
โœ” Right to Opt-Out โ€“ Consumers can opt out of:

  • Targeted advertising
  • Sale of personal data
  • Automated profiling that affects legal or financial decisions

๐Ÿ“Œ No Private Right of Action โ€“ Unlike Californiaโ€™s CPRA, consumers cannot sue businesses directly for violations.

Business Compliance Requirements

โœ” Universal Opt-Out Mechanism (Starting January 1, 2026) โ€“ Businesses must recognize Global Privacy Control (GPC) signals.
โœ” Opt-In Consent for Sensitive Data โ€“ Businesses must obtain explicit consumer consent before processing:
๐Ÿ“Œ Racial/ethnic origin
๐Ÿ“Œ Religious beliefs
๐Ÿ“Œ Biometric data
๐Ÿ“Œ Health conditions
๐Ÿ“Œ Childrenโ€™s data
โœ” Privacy Policy & Transparency โ€“ Companies must provide clear privacy policies explaining data collection and use.
โœ” Data Protection & Security โ€“ Businesses must implement reasonable safeguards to protect consumer data.
โœ” Risk Assessments for High-Risk Processing โ€“ Companies must conduct Data Protection Assessments (DPA) for:
๐Ÿ“Œ Targeted advertising
๐Ÿ“Œ Data sales
๐Ÿ“Œ AI-driven automated decision-making

Real-World Enforcement Cases

The Kentucky Attorney General enforces the KCDPA, with penalties of up to $7,500 per violation.

๐Ÿ“Œ 30-Day Cure Period for Violations โ€“ Businesses have 30 days to fix compliance issues before fines are imposed.

Since KCDPA does not take effect until January 1, 2026, major enforcement cases have not yet occurred, but companies failing to provide opt-out mechanisms are expected to be early enforcement targets.

๐Ÿ“Œ Comparison with Other State Privacy Laws
The Kentucky KCDPA is more flexible for businesses than Californiaโ€™s CPRA but closely resembles Virginiaโ€™s CDPA:
โœ… No Private Right of Action โ€“ Consumers cannot sue companies directly.
โœ… Stronger Opt-Out Requirements โ€“ Businesses must honor universal opt-out signals in 2026.
โœ… Less Strict Than CPRA โ€“ Kentuckyโ€™s law has fewer compliance obligations than Californiaโ€™s CPRA.

Future of KCDPA Regulation

๐Ÿ“Œ Stronger enforcement expected in 2026, particularly for AI-driven profiling.
๐Ÿ“Œ Possible expansion of consumer rights in future amendments.
๐Ÿ“Œ Potential updates to align with federal privacy laws if enacted.Kentuckyโ€™s KCDPA is a consumer-friendly but business-oriented privacy law, balancing consumer rights with clear compliance measures.

NEW GEN AI

Get answers to even the most complex questions about your data and explore the complexities of your data landscape using Generative AI chat.