The Kentucky Consumer Data Protection Act was signed in April 2024 and takes effect January 1, 2026.
Kentucky Privacy & Accessibility Laws
Kentucky enacted the Kentucky Consumer Data Protection Act (KCDPA) in April 2024, making it one of the newer states with comprehensive consumer privacy legislation. The law takes effect January 1, 2026. Kentucky state agencies must also ensure their digital services are accessible to individuals with disabilities.
Privacy Law Status
Accessibility Requirements
Kentucky state agencies must ensure websites and digital services are accessible under ADA Title II and state IT policies.
Kentucky Consumer Data Protection Act (KCDPA)
The KCDPA establishes privacy rights for Kentucky consumers and obligations for businesses that process personal data.
Key Dates
- Enacted: April 4, 2024
- Effective Date: January 1, 2026
- Cure Period: 30 days (permanent)
Who Must Comply?
The KCDPA applies to entities that conduct business in Kentucky or target Kentucky residents AND:
| Threshold | Requirement |
|---|---|
| Data Volume | Control or process personal data of 100,000+ Kentucky consumers |
| Revenue + Data | Derive more than 50% of gross revenue from selling personal data AND process data of 25,000+ consumers |
Consumer Rights Under KCDPA
| Right | Description |
|---|---|
| Right to Know | Confirm whether a controller is processing personal data and access that data |
| Right to Correct | Correct inaccuracies in personal data |
| Right to Delete | Delete personal data provided by or obtained about the consumer |
| Right to Portability | Obtain a copy of personal data in a portable format |
| Right to Opt-Out | Opt out of targeted advertising, sale of personal data, and profiling |
Sensitive Data Categories
The KCDPA requires opt-in consent for processing sensitive data, including:
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic or biometric data for identification
- Personal data of known children
- Precise geolocation data
Accessibility Requirements
Kentucky government agencies must ensure digital accessibility for all residents:
State Government Obligations
- Kentucky state agencies must comply with ADA Title II for all public-facing digital content
- Commonwealth Office of Technology provides accessibility guidance
- State websites must follow WCAG 2.1 Level AA guidelines
- Educational institutions must ensure accessible digital learning materials
- State IT procurement requires vendor accessibility compliance
Private Sector Considerations
- Businesses with physical locations in Kentucky are subject to ADA Title III
- Website accessibility claims can be brought under federal ADA
- Healthcare providers must ensure accessible patient portals
- Financial institutions must provide accessible online banking services
Enforcement
Privacy Enforcement
- Kentucky Attorney General - Exclusive enforcement authority for KCDPA
- 30-day cure period - Permanent (no sunset provision)
- No private right of action - Only AG can enforce
Contact:
Office of the Attorney General
Consumer Protection Division
1024 Capital Center Drive, Suite 200
Frankfort, KY 40601
(502) 696-5389
Accessibility Enforcement
- U.S. Department of Justice - ADA Title II and III enforcement
- Kentucky Commission on Human Rights - State disability discrimination
- Private litigation - Federal ADA claims
Contact:
Kentucky Protection & Advocacy
100 Fair Oaks Lane, 3rd Floor
Frankfort, KY 40601
(502) 564-2967
KCDPA Penalties
| Violation Type | Maximum Penalty |
|---|---|
| Per violation (after cure period) | $7,500 per violation |
| Consumer Protection Act violation | Additional penalties under Kentucky Consumer Protection Act |
| Injunctive relief | Court may order business practices to cease |
Business Obligations
| Obligation | Description |
|---|---|
| Privacy Notice | Clear notice of data categories, purposes, rights, and third-party sharing |
| Data Minimization | Limit collection to what is reasonably necessary for disclosed purposes |
| Purpose Limitation | Process data only for purposes disclosed to consumers |
| Security | Implement appropriate technical and organizational security measures |
| Sensitive Data Consent | Obtain opt-in consent before processing sensitive personal data |
| Request Response | Respond to consumer requests within 45 days (may extend 45 days) |
| Data Processing Agreements | Establish contracts with processors that handle personal data |
Consumer Rights
Kentucky residents have comprehensive privacy rights under the KCDPA:
- Right to Access: Confirm processing and access personal data
- Right to Correct: Correct inaccurate personal data
- Right to Delete: Request deletion of personal data
- Right to Portability: Receive data in portable format
- Right to Opt-Out: Opt out of targeted advertising, sales, and profiling
- Right to Non-Discrimination: Cannot be penalized for exercising rights
- Right to Appeal: Appeal controller's decision on consumer requests
Important Exemptions
The KCDPA exempts state and local governments, nonprofits, higher education institutions, HIPAA-covered entities, financial institutions under GLBA, and data regulated by FERPA, HIPAA, FCRA, or GLBA.
Related Resources
- US Privacy Laws Overview
- State Privacy Law Comparison
- ADA Title II Requirements
- All State Laws
- Privacy Compliance Guide
- Report a Violation
Need Help with Kentucky Compliance?
The KCDPA takes effect January 1, 2026. Businesses should begin preparing now to meet compliance requirements. Contact our experts for guidance on privacy policies, consumer request processes, and data security measures.