Kentucky Consumer Data Privacy Act (2024)

The Kentucky Consumer Data Privacy Act (KCDPA), enacted in April 2024, makes Kentucky one of the growing number of states to adopt a comprehensive consumer privacy framework. The law follows the now‑established “Virginia/Colorado model,” giving Kentucky residents a set of actionable privacy rights while imposing clear obligations on businesses that collect, use, or share personal data. It takes effect on January 1, 2026.

The KCDPA is designed to be business‑friendly and predictable, aligning closely with the structure used in Virginia, Indiana, Tennessee, and other states in the region.

 

Scope and Applicability

The Act applies to controllers and processors that conduct business in Kentucky or target Kentucky residents and meet certain thresholds, typically based on:

  • The volume of personal data processed, or
  • Revenue derived from the sale of personal data

As with other state privacy laws, the KCDPA includes exemptions for:

  • HIPAA‑regulated entities and data
  • GLBA‑regulated financial institutions
  • FERPA‑covered educational data
  • Nonprofits and government entities
  • Employment‑related data (in most contexts)

 

Consumer Rights

Kentucky residents gain several rights over their personal data, including:

  • Right to access personal data
  • Right to delete personal data
  • Right to correct inaccuracies
  • Right to data portability
  • Right to opt out of:
  • Targeted advertising
  • Sale of personal data
  • Profiling in furtherance of decisions with legal or similarly significant effects

These rights mirror those in Virginia, Tennessee, and Indiana, making multi‑state compliance more uniform.

 

Controller Obligations

Controllers must implement a comprehensive privacy program that includes:

Transparency

A clear privacy notice describing:

  • Categories of personal data collected
  • Processing purposes
  • Consumer rights and how to exercise them
  • Whether data is sold or used for targeted advertising

Data Minimization & Purpose Limitation

Controllers may collect only what is reasonably necessary for disclosed purposes.

Security Measures

Reasonable administrative, technical, and physical safeguards are required.

Sensitive Data

Processing sensitive personal data requires opt‑in consent.

Data Protection Assessments

High‑risk processing—such as targeted advertising, profiling, or processing sensitive data—requires documented assessments.

Processor Contracts

Controllers must enter into binding agreements with processors governing data handling, confidentiality, and security.

 

Enforcement

  • Enforced exclusively by the Kentucky Attorney General
  • No private right of action
  • A cure period may be available for certain violations

 

Why the Kentucky Law Matters

The KCDPA is significant because it:

  • Extends comprehensive privacy protections into the Southeast and Midwest
  • Aligns closely with the dominant U.S. privacy‑law model, simplifying compliance
  • Establishes predictable obligations without imposing unusually burdensome requirements
  • Signals continued momentum toward a nationwide patchwork of state privacy frameworks

For organizations operating across multiple states, Kentucky’s law fits neatly into the emerging baseline of U.S. consumer‑privacy regulation.