{
 "jurisdiction_id": "US-KY",
 "jurisdiction": "United States – Kentucky",
 "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 43,
  "sub_modules": 57,
  "source_register": 14
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Primary statute is in force with a clearly identified enforcement authority and Tier-1 (ag.ky.gov) confirmation of effective date and thresholds.",
   "claims": [
    {
     "statement": "The Kentucky Consumer Data Protection Act (KCDPA) went into effect on January 1, 2026 and is codified at KRS 367.3611 to 367.3629.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Kentucky Office of Data Privacy, housed within the Attorney General's office, has exclusive authority to enforce the KCDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA applies to controllers that control or process personal data of at least 100,000 Kentucky consumers, or that derive over 50% of gross revenue from the sale of personal data while controlling or processing the data of at least 25,000 Kentucky consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA exempts certain entities, including cities, state agencies and political subdivisions, nonprofit organizations, and institutions of higher education, from its scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA's definition of 'consumer' is limited to Kentucky residents, excluding individuals acting in an employment or commercial context.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/framework-debate-shows-as-kentucky-nears-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent/opt-out structure is well evidenced from Tier-1 sources, but no GDPR Art.6-equivalent lawful-basis enumeration exists, and pseudonymisation/anonymisation safe-harbour detail is only lightly sourced.",
   "claims": [
    {
     "statement": "The KCDPA does not enumerate GDPR-style Article 6 lawful bases; instead it structures processing permissions around consumer consent for sensitive data and opt-out rights for targeted advertising, sale, and certain profiling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers may not process a consumer's sensitive data without first obtaining the consumer's consent under the KCDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA defines 'sensitive data' to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used for personal identification, precise geolocation data, and data collected from a known child under 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Comprehensive state privacy laws coming into effect alongside the KCDPA in 2026, including Kentucky's, include requirements for processing deidentified or pseudonymous data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "All core rights and the response-deadline framework are confirmed directly from Tier-1 ag.ky.gov sources.",
   "claims": [
    {
     "statement": "Kentucky consumers have the right to confirm whether a controller is processing their personal data and to access their collected personal data, without revealing trade secrets.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky consumers have the right to opt out of the processing of their personal data for targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky consumers have the right to obtain a portable copy of their personal data to the extent technically feasible, without revealing trade secrets.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers must respond to KCDPA consumer requests free of charge, up to twice annually per consumer, and must respond within forty-five days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core duties (DPIA, contracts, breach notification) are Tier-1/Tier-3 confirmed; DPO, ROPA and retention/disposal sub-modules carry no direct evidence.",
   "claims": [
    {
     "statement": "The KCDPA requires controllers to conduct Data Protection Impact Assessments in specified circumstances, including profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kentucky-bill-amend-consumer-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 473, signed into law March 15, 2025, amends the KCDPA to narrow the DPIA trigger for profiling to cases involving disparate impact and exempts certain HIPAA-regulated health information, effective June 1, 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kentucky-bill-amend-consumer-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA requires that specific contractual terms be included in agreements between controllers and processors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA imposes obligations on controllers and processors related to data security, as part of its consent, disclosure, and security framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky's data breach notification statute, KRS 365.732, requires notification to affected Kentucky residents, and where a breach affects more than 1,000 Kentucky residents, notification to consumer reporting agencies and nationwide credit bureaus.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA separately contains certain requirements relevant to breach notification, though KRS 365.732 does not explicitly grant the Attorney General enforcement authority over breach-notification violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/kentucky-data-breach",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Genuine regulatory gap: US state consumer-privacy statutes, including the KCDPA, do not contain a transfer-mechanism/adequacy/localisation regime.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Health and insurance overlays are reasonably well evidenced; the financial-sector exemption is inferred from a general US multi-state pattern rather than direct KCDPA statutory text, and telecoms/education sub-modules carry no direct evidence.",
   "claims": [
    {
     "statement": "Most U.S. state comprehensive consumer privacy laws, a category that includes Kentucky's KCDPA, fully exempt financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) from coverage, with only a handful of states (California, Connecticut, Minnesota, Montana, and Oregon) instead applying a narrower data-level GLBA carve-out.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-the-federal-plan-to-modernize-and-preempt-financial-privacy-rules",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA exempts protected health information regulated under HIPAA, health records, and patient-identifying information from its scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 473 (effective June 1, 2026) further exempts information collected by HIPAA-covered health care providers, including information included in a limited data set, from the KCDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kentucky-bill-amend-consumer-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Where a Kentucky data breach affects more than 1,000 residents, notification must also be made to nationwide consumer reporting agencies and credit bureaus.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky has a separate Insurance Data Security Act (new section of KRS Chapter 304, Subtitle 3) governing data security for the insurance sector, distinct from the KCDPA's general consumer-privacy framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Core opt-out/notice duties are Tier-1 confirmed; dark-patterns and UOOM recognition status under the enacted law remain unconfirmed gaps.",
   "claims": [
    {
     "statement": "The KCDPA requires controllers to disclose in their privacy notice whether they sell personal data to third parties or process it for targeted advertising, and how consumers may exercise applicable opt-out rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky's enacted KCDPA (HB 15) framework has not been confirmed to include an explicit statutory 'dark patterns' prohibition; an earlier competing bill (SB 15) that defined 'dark patterns' was abandoned and not enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/framework-debate-shows-as-kentucky-nears-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "It is unconfirmed whether the enacted KCDPA (HB 15) recognizes universal opt-out mechanisms (e.g., Global Privacy Control); universal opt-out recognition was a feature proposed in the competing, non-enacted SB 15.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/framework-debate-shows-as-kentucky-nears-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling opt-out and biometric/genetic sensitive-data classification are Tier-1 confirmed; AI-risk-assessment and surveillance-carveout sub-modules rely on thinner secondary sourcing or carry no evidence.",
   "claims": [
    {
     "statement": "Kentucky consumers have a right under the KCDPA to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, functioning as the state's analogue to a GDPR Article 22-style automated-decision-making safeguard.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA's DPIA obligation is triggered, among other things, by profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers, providing a risk-assessment mechanism for automated decision-making.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kentucky-bill-amend-consumer-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kentucky's Senate Bill 4 establishes governance and risk-assessment requirements for high-risk artificial-intelligence systems used in the state's public sector, separate from and supplementing the KCDPA's consumer-facing framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Biometric data used for personal identification purposes is classified as 'sensitive data' under the KCDPA, requiring consumer consent prior to processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Genetic data is classified as 'sensitive data' under the KCDPA and may not be processed without the consumer's consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The KCDPA's own under-13 sensitive-data protection is Tier-1 confirmed; the broader minors' online-safety bill landscape (Kids Code, HB12/227) rests on unconfirmed enactment status and is flagged as a gap.",
   "claims": [
    {
     "statement": "Kentucky's House Bill 12 seeks to enhance online protections for minors by regulating social media account creation and enforcing age verification.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA classifies personal data collected from a known child younger than 13 as 'sensitive data,' requiring consumer consent before processing, aligning with COPPA-style protections for young children.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 633, the Kentucky Kids Code, would introduce stringent data-privacy requirements for online services targeting minors; as of the most recent tracked update, this bill's enactment status could not be independently confirmed from ag.ky.gov or verified legislative-history sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kentucky/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers, penalty caps, and recent enforcement activity are corroborated by primary AG court filings and Tier-1 AG guidance pages.",
   "claims": [
    {
     "statement": "The Kentucky Attorney General's Office of Data Privacy has exclusive authority to enforce the KCDPA and may seek injunctive relief, civil penalties, and reasonable attorneys' fees and investigative costs; violators that fail to cure within 30 days of notice face civil penalties of up to $7,500 per violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In January 2026, the Kentucky Attorney General filed a parens patriae enforcement action against Character Technologies, Inc. alleging AI chatbot safety and data-protection violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office / Franklin Circuit Court",
     "source_url": "https://www.ag.ky.gov/Press%20Release%20Attachments/CTI%20Complaint%20Motion%20and%20Order%20Filed.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In July 2025, the Kentucky Attorney General filed a lawsuit against Temu (PDD Holdings/Whaleco) under the Kentucky Consumer Protection Act alleging unlawful collection of sensitive personal information without consent, among other data-practice violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office / Woodford Circuit Court",
     "source_url": "https://www.ag.ky.gov/Press%20Release%20Attachments/2025.07.17%20ACCEPTED%20Temu%20Complaint_Kentucky.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Separately from the KCDPA, Kentucky's general Consumer Protection Act (KRS 367.110 et seq.) has been used by the Attorney General to bring data-practice-related enforcement actions (e.g., against Temu), but this statute likewise does not appear to provide a private class-action mechanism distinct from AG enforcement based on available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Kentucky Attorney General's Office / Woodford Circuit Court",
     "source_url": "https://www.ag.ky.gov/Press%20Release%20Attachments/2025.07.17%20ACCEPTED%20Temu%20Complaint_Kentucky.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The KCDPA does not provide Kentucky consumers with a private right of action; enforcement runs exclusively through the Attorney General's Office of Data Privacy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Kentucky Attorney General's Office",
     "source_url": "https://www.ag.ky.gov/about/Office-Divisions/ODP/KCDPA/Pages/default.aspx",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 473, effective June 1, 2026, amended the KCDPA to exempt certain HIPAA-regulated health information and to narrow the profiling-related DPIA trigger to cases involving disparate impact.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kentucky-bill-amend-consumer-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 692, signed into law in 2026, amends the KCDPA to define 'automatic content recognition' and 'smart monitor' and to require consumer consent for data collection via such technologies, with an effective date of July 1, 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/kentucky",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}