KY

Kentucky Privacy Law

Kentucky Consumer Data Protection Act

Effective: January 1, 2026ActiveReviewed by PrivacyLawMap editorial teamLast verified: January 1, 2026

Overview

The Kentucky Consumer Data Protection Act (KCDPA), enacted as House Bill 15 (KRS 367.600–367.645), was signed into law by Governor Andy Beshear on April 4, 2024, and became effective on January 1, 2026. Kentucky's law follows the Virginia VCDPA model closely but arrived with an immediate enforcement signal: on January 8, 2026 — just eight days after the law took effect — Attorney General Russell Coleman filed the first-ever KCDPA enforcement action against Character Technologies, Inc. (Character.AI), alleging unauthorized processing of minors' sensitive data, failure to implement age verification, exposure of children to harmful content, and repurposing of user data including private emotional disclosures and health statements to train AI models without parental consent. The Character.AI complaint also invoked the Kentucky Consumer Protection Act (KRS 367.110–367.300), demonstrating the AG's willingness to layer multiple statutory frameworks in enforcement. AG Coleman stated the company "prioritized profits over the safety of children" and the Commonwealth is seeking injunctive relief and monetary damages.

The KCDPA grants Kentucky consumers the right to access, correct, delete, and obtain a portable copy of their personal data, as well as rights to opt out of the sale of personal data, targeted advertising, and profiling that produces legal or similarly significant effects. The law recognizes eight categories of sensitive data requiring opt-in consent: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed for identification, precise geolocation data (within a 1,750-foot radius), and personal data of a known child under 13. For children's data, controllers must process it in accordance with the federal Children's Online Privacy Protection Act (COPPA), and a child's parent or legal guardian may invoke consumer rights on the child's behalf. The appeals process requires controllers to respond within 60 days and inform consumers of the right to file a complaint with the Attorney General if the appeal is denied.

The law applies to entities conducting business in Kentucky or targeting Kentucky consumers that control or process personal data of 100,000 or more consumers, or control or process personal data of 25,000 or more consumers while deriving over 50% of gross revenue from the sale of personal data. Kentucky provides entity-level exemptions for HIPAA-covered entities and business associates, GLBA-covered financial institutions, nonprofit organizations, institutions of higher education, and government entities — the exemptions apply at the entity level, not the data level, meaning an exempt entity's entire consumer data processing is excluded even if some data would otherwise be covered. The KCDPA includes a permanent 30-day cure period — the AG must provide written notice of alleged violations and allow 30 days to cure before initiating enforcement — and penalties of up to $7,500 per violation enforced exclusively by the Attorney General through the Office of Consumer Protection. Unlike California, Colorado, and Connecticut, this cure period does not have a sunset provision.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

100,000+
Kentucky consumers' data processed
25,000+ consumers
AND 50%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • Law became effective January 1, 2026 — businesses must be in full compliance with all KCDPA obligations
  • AG Russell Coleman filed first-ever KCDPA enforcement action on January 8, 2026 — just 8 days after effective date — against Character Technologies (Character.AI) for children's data violations
  • Character.AI complaint combined KCDPA violations with Kentucky Consumer Protection Act claims, establishing layered enforcement precedent
  • AG enforcement priority: children's data protection — complaint alleged unauthorized processing of minors' sensitive data, failure to implement age verification, and AI model training on children's emotional disclosures without parental consent
  • Kentucky AG published consumer rights information page (ag.ky.gov) with KCDPA protections guide and consumer complaint filing portal
  • 30-day cure period in effect and permanent — AG must provide written notice before enforcement; unlike CA/CO/CT, Kentucky's cure period does not have a sunset provision
  • No revenue-only threshold — applicability depends on volume of consumer data processed (100K or 25K with 50%+ data sale revenue)
  • Entity-level HIPAA exemption — HIPAA-covered entities and business associates are fully exempt from the KCDPA, not just for HIPAA-regulated data
  • KCDPA does not require Global Privacy Control (GPC) — Kentucky aligns with VA/IN/IA/UT/KY in not mandating universal opt-out signals
  • Eight sensitive data categories require opt-in consent including precise geolocation (1,750-foot radius) and known children's data — original law analysis often missed geolocation and children's categories

Enforcement Details

Enforced By
Kentucky Attorney General — Office of Consumer Protection
Penalty Per Violation
$7,500
Cure Period
30 days
Private Right of Action
No — AG enforcement only

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusGenetic or biometric data processed for identificationPrecise geolocation data (within 1,750-foot radius)Personal data of a known child under 13

Universal Opt-Out / GPC Requirements

No Universal Opt-Out Requirement

The KCDPA does not require businesses to honor universal opt-out mechanisms such as Global Privacy Control (GPC). Kentucky aligns with Virginia, Indiana, Iowa, and Utah in not mandating GPC recognition. The 12 states that do require GPC are: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. Businesses may voluntarily support GPC and similar signals but are not legally obligated.

Minor / Child Protections

The KCDPA requires opt-in consent before processing personal data of a known child under 13, and such processing must comply with COPPA. A child's parent or legal guardian may exercise consumer rights on the child's behalf. For teens aged 13-17, businesses must obtain consent before processing their data for targeted advertising or sale. The January 2026 Character.AI enforcement action demonstrated that AG Coleman considers children's data protection a top enforcement priority — the complaint alleged the company failed to obtain verifiable parental consent and exposed minors to harmful content.

Compliance Checklist

  1. 1Determine applicability: check whether your entity processes data of 100,000+ Kentucky consumers, or 25,000+ while deriving 50%+ of gross revenue from data sales. Check entity-level exemptions (HIPAA-covered entities, GLBA financial institutions, nonprofits, higher education, government) — these exempt the entire entity, not just specific data types
  2. 2Update privacy notices with all KCDPA-required disclosures: categories of personal data processed, purposes of processing, consumer rights instructions, categories of third-party recipients, and contact information. AG Coleman identified privacy notice compliance as an early enforcement signal in the Character.AI action
  3. 3Implement opt-out mechanisms for data sales, targeted advertising, and profiling. Note that "sale" under the KCDPA follows the VCDPA definition — exchange for monetary consideration — which is narrower than the CCPA's "valuable consideration" standard
  4. 4Obtain opt-in consent for processing all eight sensitive data categories: racial/ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data for identification, precise geolocation (1,750 feet), and known children's data
  5. 5Implement children's data protections: process known children's data (under 13) in compliance with COPPA, obtain verifiable parental consent, and enable parents/guardians to exercise consumer rights on behalf of children. The Character.AI enforcement demonstrates this is the AG's top enforcement priority
  6. 6Create consumer rights request response system: 45-day response deadline (extendable by 45 days with notice), 10-day acknowledgment best practice, support for access, correction, deletion, portability, and opt-out requests
  7. 7Establish an appeals process: controller must respond to appeals within 60 days and inform consumers of the right to file a complaint with the Kentucky Attorney General if the appeal is denied
  8. 8Execute data processing agreements with all processors: require them to assist with consumer rights requests, maintain confidentiality, delete or return personal data at end of service, and allow reasonable audits. Include subcontractor flow-down provisions
  9. 9Conduct data protection assessments for heightened-risk processing: targeted advertising, sale of personal data, profiling with legal or similarly significant effects, processing sensitive data, and processing children's data
  10. 10Prepare for AG enforcement inquiries: establish a 30-day cure-period response protocol with designated compliance contact, document evidence of cure completion, and maintain written statement capability confirming violations were corrected. The AG may accept the cure or proceed with enforcement if the cure is inadequate
  11. 11Implement data minimization practices: limit collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes. Conduct purpose limitation assessments and document data retention policies
  12. 12Map multistate compliance obligations: compare Kentucky's requirements with those of similar VCDPA-model states (VA, IN, IA) and identify delta requirements — Kentucky's permanent cure period, entity-level HIPAA exemption, and narrower sale definition are key differentiators
Put KCDPA Into Practice on Your SiteSponsored

Termly builds and maintains a Kentucky-ready privacy policy, a cookie consent banner, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests KCDPA grants.

Start Free with Termly

Kentucky Privacy Law FAQ

Official Resources