The Kentucky Consumer Data Privacy Act (KCDPA), enacted in April 2024, makes Kentucky one of the growing number of states to adopt a comprehensive consumer privacy framework. The law follows the now‑established “Virginia/Colorado model,” giving Kentucky residents a set of actionable privacy rights while imposing clear obligations on businesses that collect, use, or share personal data. It takes effect on January 1, 2026.
The KCDPA is designed to be business‑friendly and predictable, aligning closely with the structure used in Virginia, Indiana, Tennessee, and other states in the region.
Scope and Applicability
The Act applies to controllers and processors that conduct business in Kentucky or target Kentucky residents and meet certain thresholds, typically based on:
- The volume of personal data processed, or
- Revenue derived from the sale of personal data
As with other state privacy laws, the KCDPA includes exemptions for:
- HIPAA‑regulated entities and data
- GLBA‑regulated financial institutions
- FERPA‑covered educational data
- Nonprofits and government entities
- Employment‑related data (in most contexts)
Consumer Rights
Kentucky residents gain several rights over their personal data, including:
- Right to access personal data
- Right to delete personal data
- Right to correct inaccuracies
- Right to data portability
- Right to opt out of:
- Targeted advertising
- Sale of personal data
- Profiling in furtherance of decisions with legal or similarly significant effects
These rights mirror those in Virginia, Tennessee, and Indiana, making multi‑state compliance more uniform.
Controller Obligations
Controllers must implement a comprehensive privacy program that includes:
Transparency
A clear privacy notice describing:
- Categories of personal data collected
- Processing purposes
- Consumer rights and how to exercise them
- Whether data is sold or used for targeted advertising
Data Minimization & Purpose Limitation
Controllers may collect only what is reasonably necessary for disclosed purposes.
Security Measures
Reasonable administrative, technical, and physical safeguards are required.
Sensitive Data
Processing sensitive personal data requires opt‑in consent.
Data Protection Assessments
High‑risk processing—such as targeted advertising, profiling, or processing sensitive data—requires documented assessments.
Processor Contracts
Controllers must enter into binding agreements with processors governing data handling, confidentiality, and security.
Enforcement
- Enforced exclusively by the Kentucky Attorney General
- No private right of action
- A cure period may be available for certain violations
Why the Kentucky Law Matters
The KCDPA is significant because it:
- Extends comprehensive privacy protections into the Southeast and Midwest
- Aligns closely with the dominant U.S. privacy‑law model, simplifying compliance
- Establishes predictable obligations without imposing unusually burdensome requirements
- Signals continued momentum toward a nationwide patchwork of state privacy frameworks
For organizations operating across multiple states, Kentucky’s law fits neatly into the emerging baseline of U.S. consumer‑privacy regulation.
