HomeState LawsKentucky

Kentucky Privacy & Accessibility Laws

Kentucky enacted the Kentucky Consumer Data Protection Act (KCDPA) in April 2024, making it one of the newer states with comprehensive consumer privacy legislation. The law takes effect January 1, 2026. Kentucky state agencies must also ensure their digital services are accessible to individuals with disabilities.

Privacy Law Status

KCDPA Enacted

The Kentucky Consumer Data Protection Act was signed in April 2024 and takes effect January 1, 2026.

Accessibility Requirements

State Government Websites

Kentucky state agencies must ensure websites and digital services are accessible under ADA Title II and state IT policies.

Kentucky Consumer Data Protection Act (KCDPA)

The KCDPA establishes privacy rights for Kentucky consumers and obligations for businesses that process personal data.

Key Dates

  • Enacted: April 4, 2024
  • Effective Date: January 1, 2026
  • Cure Period: 30 days (permanent)

Who Must Comply?

The KCDPA applies to entities that conduct business in Kentucky or target Kentucky residents AND:

Threshold Requirement
Data Volume Control or process personal data of 100,000+ Kentucky consumers
Revenue + Data Derive more than 50% of gross revenue from selling personal data AND process data of 25,000+ consumers

Consumer Rights Under KCDPA

Right Description
Right to Know Confirm whether a controller is processing personal data and access that data
Right to Correct Correct inaccuracies in personal data
Right to Delete Delete personal data provided by or obtained about the consumer
Right to Portability Obtain a copy of personal data in a portable format
Right to Opt-Out Opt out of targeted advertising, sale of personal data, and profiling

Sensitive Data Categories

The KCDPA requires opt-in consent for processing sensitive data, including:

Accessibility Requirements

Kentucky government agencies must ensure digital accessibility for all residents:

State Government Obligations

Private Sector Considerations

Enforcement

Privacy Enforcement

  • Kentucky Attorney General - Exclusive enforcement authority for KCDPA
  • 30-day cure period - Permanent (no sunset provision)
  • No private right of action - Only AG can enforce

Contact:
Office of the Attorney General
Consumer Protection Division
1024 Capital Center Drive, Suite 200
Frankfort, KY 40601
(502) 696-5389

Accessibility Enforcement

  • U.S. Department of Justice - ADA Title II and III enforcement
  • Kentucky Commission on Human Rights - State disability discrimination
  • Private litigation - Federal ADA claims

Contact:
Kentucky Protection & Advocacy
100 Fair Oaks Lane, 3rd Floor
Frankfort, KY 40601
(502) 564-2967

KCDPA Penalties

Violation Type Maximum Penalty
Per violation (after cure period) $7,500 per violation
Consumer Protection Act violation Additional penalties under Kentucky Consumer Protection Act
Injunctive relief Court may order business practices to cease

Business Obligations

Obligation Description
Privacy Notice Clear notice of data categories, purposes, rights, and third-party sharing
Data Minimization Limit collection to what is reasonably necessary for disclosed purposes
Purpose Limitation Process data only for purposes disclosed to consumers
Security Implement appropriate technical and organizational security measures
Sensitive Data Consent Obtain opt-in consent before processing sensitive personal data
Request Response Respond to consumer requests within 45 days (may extend 45 days)
Data Processing Agreements Establish contracts with processors that handle personal data

Consumer Rights

Kentucky residents have comprehensive privacy rights under the KCDPA:

Important Exemptions

The KCDPA exempts state and local governments, nonprofits, higher education institutions, HIPAA-covered entities, financial institutions under GLBA, and data regulated by FERPA, HIPAA, FCRA, or GLBA.

Related Resources

Need Help with Kentucky Compliance?

The KCDPA takes effect January 1, 2026. Businesses should begin preparing now to meet compliance requirements. Contact our experts for guidance on privacy policies, consumer request processes, and data security measures.

Contact Us