🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-KY · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 14 sources retrieved model claude-sonnet-5 ·

United States – Kentucky

US-KY schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 43 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Primary statute is in force with a clearly identified enforcement authority and Tier-1 (ag.ky.gov) confirmation of effective date and thresholds.

Primary frameworkKentucky Consumer Data Protection Act (KCDPA), KRS 367.3611–367.3629
Traffic-light rationale — GreenPrimary statute is in force with a clearly identified enforcement authority and Tier-1 (ag.ky.gov) confirmation of effective date and thresholds.

Sub-modules (5)

Regulator And AuthorityGreen

The Office of Data Privacy, created within the Kentucky AG's office, has exclusive statutory authority to enforce the KCDPA.

Claims (1):

  • The Kentucky Office of Data Privacy, housed within the Attorney General's office, has exclusive authority to enforce the KCDPA.

Act And InstrumentsGreen

The KCDPA is the sole comprehensive instrument; codified at KRS 367.3611–367.3629, effective January 1, 2026.

Claims (1):

  • The Kentucky Consumer Data Protection Act (KCDPA) went into effect on January 1, 2026 and is codified at KRS 367.3611 to 367.3629.

Material ScopeGreen

Applicability turns on a 100,000-consumer / 25,000-consumer-plus-50%-revenue threshold, with categorical entity exemptions (government, nonprofits, higher education) and data-level exemptions (HIPAA-regulated data).

Claims (2):

  • The KCDPA applies to controllers that control or process personal data of at least 100,000 Kentucky consumers, or that derive over 50% of gross revenue from the sale of personal data while controlling or processing the data of at least 25,000 Kentucky consumers.
  • The KCDPA exempts certain entities, including cities, state agencies and political subdivisions, nonprofit organizations, and institutions of higher education, from its scope.

Territorial ScopeAmber

Coverage is limited to Kentucky-resident consumers, excluding employment/commercial-context individuals; precise extraterritorial-reach statutory language was not independently retrieved from primary text.

Claims (1):

  • The KCDPA's definition of 'consumer' is limited to Kentucky residents, excluding individuals acting in an employment or commercial context.

Regulator Registration And FilingRed

No general controller registration or filing obligation with the Attorney General was identified for the KCDPA (unlike some states' data-broker registries).

Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act controller registration, KCDPA filing requirement Attorney General.

Key findings (3)

  • KCDPA in force Jan 1 2026; sole enforcer AG Office of Data Privacy. — source on file
  • KCDPA in force Jan 1 2026; sole enforcer AG Office of Data Privacy. — source on file
  • KCDPA in force Jan 1 2026; sole enforcer AG Office of Data Privacy. — source on file
Category narrative94 words

Kentucky's comprehensive consumer-privacy regime is the Kentucky Consumer Data Protection Act (KCDPA), enacted as House Bill 15 (signed April 4, 2024) and codified at KRS 367.3611–367.3629, which entered into force January 1, 2026. It is a Virginia-model, controller/processor statute enforced exclusively by a dedicated Office of Data Privacy inside the Attorney General's office (no independent DPA). Material scope is threshold-based (100,000 KY consumers, or 25,000 consumers plus 50% of revenue from data sales) with broad entity- and data-level exemptions (government bodies, nonprofits, higher-education institutions, HIPAA-regulated health data). No freestanding controller registration/filing regime was identified.

Sources and claims (5)
  1. ConfirmedKentucky Attorney General's OfficeThe Kentucky Consumer Data Protection Act (KCDPA) went into effect on January 1, 2026 and is codified at KRS 367.3611 to 367.3629.observed
  2. ConfirmedKentucky Attorney General's OfficeThe Kentucky Office of Data Privacy, housed within the Attorney General's office, has exclusive authority to enforce the KCDPA.observed
  3. ConfirmedIAPPThe KCDPA applies to controllers that control or process personal data of at least 100,000 Kentucky consumers, or that derive over 50% of gross revenue from the sale of personal data while controlling or processing the data of at least 25,000 Kentucky consumers.observed
  4. ConfirmedKentucky Attorney General's OfficeThe KCDPA exempts certain entities, including cities, state agencies and political subdivisions, nonprofit organizations, and institutions of higher education, from its scope.observed
  5. ProbableIAPPThe KCDPA's definition of 'consumer' is limited to Kentucky residents, excluding individuals acting in an employment or commercial context.observed

#

Consent/opt-out structure is well evidenced from Tier-1 sources, but no GDPR Art.6-equivalent lawful-basis enumeration exists, and pseudonymisation/anonymisation safe-harbour detail is only lightly sourced.

Primary frameworkKCDPA, KRS 367.3611 et seq. (consent/opt-out model; no Art.6-style lawful-basis enumeration)
Traffic-light rationale — AmberConsent/opt-out structure is well evidenced from Tier-1 sources, but no GDPR Art.6-equivalent lawful-basis enumeration exists, and pseudonymisation/anonymisation safe-harbour detail is only lightly sourced.

Sub-modules (4)

Lawful BasesAmber

No enumerated lawful-basis list; processing is permitted by default, subject to notice and opt-out/consent overlays.

Claims (1):

  • The KCDPA does not enumerate GDPR-style Article 6 lawful bases; instead it structures processing permissions around consumer consent for sensitive data and opt-out rights for targeted advertising, sale, and certain profiling.

Special CategoriesGreen

Sensitive data is broadly defined and subject to opt-in consent.

Claims (1):

  • The KCDPA defines 'sensitive data' to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used for personal identification, precise geolocation data, and data collected from a known child under 13.

Pseudonymisation And AnonymisationAmber

Kentucky's law, in common with contemporaneous state statutes, includes requirements around processing deidentified/pseudonymous data, though KY-specific statutory text was not directly retrieved.

Claims (1):

  • Comprehensive state privacy laws coming into effect alongside the KCDPA in 2026, including Kentucky's, include requirements for processing deidentified or pseudonymous data.

Key findings (3)

  • Consent/opt-out model, no Art.6-style lawful-basis list; broad sensitive-data definition. — source on file
  • Consent/opt-out model, no Art.6-style lawful-basis list; broad sensitive-data definition. — source on file
  • Consent/opt-out model, no Art.6-style lawful-basis list; broad sensitive-data definition. — source on file
Category narrative62 words

The KCDPA does not use a GDPR-style enumerated lawful-basis model; instead it is a consent/opt-out architecture: general processing is permitted by default subject to disclosure and opt-out rights (targeted advertising, sale, certain profiling), while 'sensitive data' processing requires affirmative prior consent. Sensitive data is broadly defined (race/ethnicity, religion, health diagnosis, sexual orientation, immigration status, biometric/genetic identifiers, precise geolocation, known child data <13).

Sources and claims (4)
  1. ProbableKentucky Attorney General's OfficeThe KCDPA does not enumerate GDPR-style Article 6 lawful bases; instead it structures processing permissions around consumer consent for sensitive data and opt-out rights for targeted advertising, sale, and certain profiling.observed
  2. ConfirmedKentucky Attorney General's OfficeControllers may not process a consumer's sensitive data without first obtaining the consumer's consent under the KCDPA.observed
  3. ConfirmedKentucky Attorney General's OfficeThe KCDPA defines 'sensitive data' to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used for personal identification, precise geolocation data, and data collected from a known child under 13.observed
  4. ProbableIAPPComprehensive state privacy laws coming into effect alongside the KCDPA in 2026, including Kentucky's, include requirements for processing deidentified or pseudonymous data.observed

#

All core rights and the response-deadline framework are confirmed directly from Tier-1 ag.ky.gov sources.

Primary frameworkKCDPA, KRS 367.3611 et seq.
Traffic-light rationale — GreenAll core rights and the response-deadline framework are confirmed directly from Tier-1 ag.ky.gov sources.

Sub-modules (5)

Access RightGreen

Consumers may confirm processing and access their data (trade secrets excluded).

Claims (1):

  • Kentucky consumers have the right to confirm whether a controller is processing their personal data and to access their collected personal data, without revealing trade secrets.

Rectification And ErasureGreen

Consumers may correct inaccuracies and delete personal data.

Claims (1):

  • Kentucky consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them.

Restriction And ObjectionGreen

Consumers may opt out of targeted advertising, sale, and significant-effect profiling.

Claims (1):

  • Kentucky consumers have the right to opt out of the processing of their personal data for targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.

Data PortabilityGreen

Consumers may obtain a portable copy of their data to the extent feasible.

Claims (1):

  • Kentucky consumers have the right to obtain a portable copy of their personal data to the extent technically feasible, without revealing trade secrets.

Deadlines And Response WindowsGreen

Controllers must respond within 45 days, free of charge, up to twice annually per consumer.

Claims (1):

  • Controllers must respond to KCDPA consumer requests free of charge, up to twice annually per consumer, and must respond within forty-five days.

Key findings (3)

  • Full Virginia-model rights bundle, 45-day response window. — source on file
  • Full Virginia-model rights bundle, 45-day response window. — source on file
  • Full Virginia-model rights bundle, 45-day response window. — source on file
Category narrative45 words

The KCDPA grants Kentucky consumers a standard Virginia-model rights bundle: confirmation of processing, access, correction, deletion, portability, and opt-out of targeted advertising/sale/certain profiling. Controllers must respond within 45 days, free of charge, up to twice annually, and must provide an appeal mechanism for denied requests.

Sources and claims (5)
  1. ConfirmedKentucky Attorney General's OfficeKentucky consumers have the right to confirm whether a controller is processing their personal data and to access their collected personal data, without revealing trade secrets.observed
  2. ConfirmedKentucky Attorney General's OfficeKentucky consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them.observed
  3. ConfirmedKentucky Attorney General's OfficeKentucky consumers have the right to opt out of the processing of their personal data for targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.observed
  4. ConfirmedKentucky Attorney General's OfficeKentucky consumers have the right to obtain a portable copy of their personal data to the extent technically feasible, without revealing trade secrets.observed
  5. ConfirmedKentucky Attorney General's OfficeControllers must respond to KCDPA consumer requests free of charge, up to twice annually per consumer, and must respond within forty-five days.observed

#

Core duties (DPIA, contracts, breach notification) are Tier-1/Tier-3 confirmed; DPO, ROPA and retention/disposal sub-modules carry no direct evidence.

Primary frameworkKCDPA, KRS 367.3611 et seq.; KRS 365.732 (breach notification)
Traffic-light rationale — AmberCore duties (DPIA, contracts, breach notification) are Tier-1/Tier-3 confirmed; DPO, ROPA and retention/disposal sub-modules carry no direct evidence.

Sub-modules (7)

Accountability And DpiaAmber

DPIAs are required in specified circumstances; HB473 (effective June 1, 2026) narrows the profiling-related trigger to disparate-impact cases and adds a HIPAA-data carve-out.

Claims (2):

  • The KCDPA requires controllers to conduct Data Protection Impact Assessments in specified circumstances, including profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers.
  • House Bill 473, signed into law March 15, 2025, amends the KCDPA to narrow the DPIA trigger for profiling to cases involving disparate impact and exempts certain HIPAA-regulated health information, effective June 1, 2026.

Dpo RequirementsRed

No DPO-appointment or independence requirement was located for the KCDPA.

Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act data protection officer requirement.

Ropa RequirementsRed

No records-of-processing-activity obligation was located for the KCDPA.

Absence provenance: not recorded. Searched: KCDPA records of processing activities requirement.

Joint Controller ArrangementsGreen

The KCDPA mandates specific contractual terms between controllers and processors.

Claims (1):

  • The KCDPA requires that specific contractual terms be included in agreements between controllers and processors.

Security MeasuresAmber

The KCDPA imposes general data-security obligations on controllers and processors, though granular technical/organisational-measure detail was not independently retrieved from primary statutory text.

Claims (1):

  • The KCDPA imposes obligations on controllers and processors related to data security, as part of its consent, disclosure, and security framework.

Breach NotificationAmber

Kentucky's standalone breach-notification statute (KRS 365.732) requires notice to affected residents and, above a 1,000-resident threshold, to nationwide credit bureaus; enforcement-authority attribution under that statute is itself ambiguous per secondary sources.

Claims (2):

  • Kentucky's data breach notification statute, KRS 365.732, requires notification to affected Kentucky residents, and where a breach affects more than 1,000 Kentucky residents, notification to consumer reporting agencies and nationwide credit bureaus.
  • The KCDPA separately contains certain requirements relevant to breach notification, though KRS 365.732 does not explicitly grant the Attorney General enforcement authority over breach-notification violations.

Retention And DisposalRed

No explicit statutory retention-limitation or disposal-duty provision was located for the KCDPA.

Absence provenance: not recorded. Searched: KCDPA data retention limitation disposal requirement.

Key findings (3)

  • DPIA/contract/breach duties confirmed; DPO/ROPA/retention gaps; HB473 date bifurcation corrected. — source on file
  • DPIA/contract/breach duties confirmed; DPO/ROPA/retention gaps; HB473 date bifurcation corrected. — source on file
  • DPIA/contract/breach duties confirmed; DPO/ROPA/retention gaps; HB473 date bifurcation corrected. — source on file
Category narrative44 words

Controllers/processors face DPIA obligations (narrowed by HB473, effective June 1, 2026), mandatory controller-processor contract terms, general security and breach-notification duties (KRS 365.732, plus KCDPA breach-adjacent provisions), but no explicit DPO-appointment or ROPA requirement, and no explicit statutory retention/disposal duty, was located in available sources.

Sources and claims (6)
  1. ProbableDataGuidanceThe KCDPA requires controllers to conduct Data Protection Impact Assessments in specified circumstances, including profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers.observed
  2. ConfirmedDataGuidanceHouse Bill 473, signed into law March 15, 2025, amends the KCDPA to narrow the DPIA trigger for profiling to cases involving disparate impact and exempts certain HIPAA-regulated health information, effective June 1, 2026.observed
  3. ConfirmedKentucky Attorney General's OfficeThe KCDPA requires that specific contractual terms be included in agreements between controllers and processors.observed
  4. ProbableDataGuidanceThe KCDPA imposes obligations on controllers and processors related to data security, as part of its consent, disclosure, and security framework.observed
  5. ConfirmedDataGuidanceKentucky's data breach notification statute, KRS 365.732, requires notification to affected Kentucky residents, and where a breach affects more than 1,000 Kentucky residents, notification to consumer reporting agencies and nationwide credit bureaus.observed
  6. ProbableDataGuidanceThe KCDPA separately contains certain requirements relevant to breach notification, though KRS 365.732 does not explicitly grant the Attorney General enforcement authority over breach-notification violations.observed

#

Genuine regulatory gap: US state consumer-privacy statutes, including the KCDPA, do not contain a transfer-mechanism/adequacy/localisation regime.

Traffic-light rationale — RedGenuine regulatory gap: US state consumer-privacy statutes, including the KCDPA, do not contain a transfer-mechanism/adequacy/localisation regime.

Sub-modules (6)

Transfer MechanismsRed

No KCDPA or other Kentucky-specific cross-border transfer mechanism was located.

Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act cross-border data transfer mechanism.

Adequacy ReceivedRed

Not applicable; the US federal system, and Kentucky specifically, is not a recipient of foreign adequacy determinations at sub-federal level.

Absence provenance: not recorded. Searched: Kentucky adequacy decision received.

Adequacy GrantedRed

Kentucky, as a US state, has no independent authority to grant adequacy decisions to other regimes.

Absence provenance: not recorded. Searched: Kentucky adequacy decision granted.

Sccs And BcrsRed

No SCC/BCR uptake regime exists under the KCDPA.

Absence provenance: not recorded. Searched: KCDPA standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No transfer-impact-assessment obligation was located under the KCDPA.

Absence provenance: not recorded. Searched: KCDPA transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate was located under the KCDPA.

Absence provenance: not recorded. Searched: Kentucky data localisation requirement consumer data.

Key findings (3)

  • No transfer/adequacy/localisation regime; structural US state-law gap. — source on file
  • No transfer/adequacy/localisation regime; structural US state-law gap. — source on file
  • No transfer/adequacy/localisation regime; structural US state-law gap. — source on file
Category narrative75 words

No cross-border transfer mechanism, adequacy determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate was located for the KCDPA or any other Kentucky state instrument. This is consistent with the general pattern of US state comprehensive consumer-privacy laws, which do not operate an adequacy or SCC framework analogous to GDPR Chapter V; cross-border data flows involving Kentucky-collected personal data are governed only indirectly, via federal sectoral regimes (e.g., export-control, CFIUS) that fall outside DP consumer-level scope.

#

Health and insurance overlays are reasonably well evidenced; the financial-sector exemption is inferred from a general US multi-state pattern rather than direct KCDPA statutory text, and telecoms/education sub-modules carry no direct evidence.

Primary frameworkKCDPA sectoral exemptions; Kentucky Insurance Data Security Act (KRS Ch. 304, Subtit. 3); federal HIPAA/GLBA overlays
Traffic-light rationale — AmberHealth and insurance overlays are reasonably well evidenced; the financial-sector exemption is inferred from a general US multi-state pattern rather than direct KCDPA statutory text, and telecoms/education sub-modules carry no direct evidence.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA-regulated financial institutions are presumed exempted at entity level under the general state-law pattern; KY-specific statutory text was not independently retrieved.

Claims (1):

  • Most U.S. state comprehensive consumer privacy laws, a category that includes Kentucky's KCDPA, fully exempt financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) from coverage, with only a handful of states (California, Connecticut, Minnesota, Montana, and Oregon) instead applying a narrower data-level GLBA carve-out.

Health Sector OverlayGreen

HIPAA-regulated PHI, health records, and patient-identifying information are exempt; HB473 (effective June 1, 2026) extends the exemption to HIPAA-covered-provider data including limited data sets.

Claims (2):

  • The KCDPA exempts protected health information regulated under HIPAA, health records, and patient-identifying information from its scope.
  • House Bill 473 (effective June 1, 2026) further exempts information collected by HIPAA-covered health care providers, including information included in a limited data set, from the KCDPA.

Telecoms And EprivacyRed

No telecoms- or ePrivacy-specific overlay statute was located for Kentucky.

Absence provenance: not recorded. Searched: Kentucky telecoms ePrivacy cookie law.

Employment DataAmber

The KCDPA's consumer definition excludes individuals acting in an employment context, effectively carving employment data out of general consumer-privacy coverage.

Credit And ScoringAmber

Kentucky's breach law requires notification to nationwide consumer reporting agencies/credit bureaus for large breaches, giving a credit-reporting dimension to the state's data-security regime.

Claims (1):

  • Where a Kentucky data breach affects more than 1,000 residents, notification must also be made to nationwide consumer reporting agencies and credit bureaus.

EducationRed

No education-sector-specific data-privacy overlay statute was located for Kentucky.

Absence provenance: not recorded. Searched: Kentucky student data privacy law.

InsuranceAmber

Kentucky maintains a separate Insurance Data Security Act governing insurer data security independent of the KCDPA.

Claims (1):

  • Kentucky has a separate Insurance Data Security Act (new section of KRS Chapter 304, Subtitle 3) governing data security for the insurance sector, distinct from the KCDPA's general consumer-privacy framework.

Key findings (3)

  • HIPAA/GLBA overlays and separate Insurance Data Security Act. — source on file
  • HIPAA/GLBA overlays and separate Insurance Data Security Act. — source on file
  • HIPAA/GLBA overlays and separate Insurance Data Security Act. — source on file
Category narrative92 words

The KCDPA layers onto pre-existing Kentucky sectoral regimes. It exempts HIPAA-regulated health data (narrowed further by HB473 from June 1, 2026); financial institutions subject to GLBA are, per the general multi-state pattern, most likely fully exempted at the entity level (Kentucky is not among the five states that instead apply only a narrower GLBA data-level carve-out). A distinct Insurance Data Security Act (new KRS Chapter 304, Subtitle 3) governs insurer data security separately from the KCDPA. No telecoms/ePrivacy-specific, education-specific, or employment-specific overlay statute (beyond the KCDPA's employment-context consumer exclusion) was independently located.

Sources and claims (5)
  1. ProbableIAPPMost U.S. state comprehensive consumer privacy laws, a category that includes Kentucky's KCDPA, fully exempt financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) from coverage, with only a handful of states (California, Connecticut, Minnesota, Montana, and Oregon) instead applying a narrower data-level GLBA carve-out.observed
  2. ConfirmedKentucky Attorney General's OfficeThe KCDPA exempts protected health information regulated under HIPAA, health records, and patient-identifying information from its scope.observed
  3. ConfirmedDataGuidanceHouse Bill 473 (effective June 1, 2026) further exempts information collected by HIPAA-covered health care providers, including information included in a limited data set, from the KCDPA.observed
  4. ConfirmedDataGuidanceWhere a Kentucky data breach affects more than 1,000 residents, notification must also be made to nationwide consumer reporting agencies and credit bureaus.observed
  5. ProbableDataGuidanceKentucky has a separate Insurance Data Security Act (new section of KRS Chapter 304, Subtitle 3) governing data security for the insurance sector, distinct from the KCDPA's general consumer-privacy framework.observed

#

Core opt-out/notice duties are Tier-1 confirmed; dark-patterns and UOOM recognition status under the enacted law remain unconfirmed gaps.

Primary frameworkKCDPA, KRS 367.3611 et seq.
Traffic-light rationale — AmberCore opt-out/notice duties are Tier-1 confirmed; dark-patterns and UOOM recognition status under the enacted law remain unconfirmed gaps.

Sub-modules (6)

Cookies And TrackersRed

No cookie-specific consent regime distinct from the general targeted-advertising opt-out was located.

Absence provenance: not recorded. Searched: Kentucky cookie consent law.

Dark PatternsAmber

An earlier competing bill (SB 15) defined 'dark patterns' but was abandoned; it is unconfirmed whether the enacted KCDPA (HB15) carries an equivalent express prohibition.

Claims (1):

  • Kentucky's enacted KCDPA (HB 15) framework has not been confirmed to include an explicit statutory 'dark patterns' prohibition; an earlier competing bill (SB 15) that defined 'dark patterns' was abandoned and not enacted.

Opt Out SignalsAmber

Universal opt-out mechanism recognition (e.g., GPC) was proposed in the non-enacted SB 15; it is unconfirmed whether the enacted KCDPA recognizes such signals.

Claims (1):

  • It is unconfirmed whether the enacted KCDPA (HB 15) recognizes universal opt-out mechanisms (e.g., Global Privacy Control); universal opt-out recognition was a feature proposed in the competing, non-enacted SB 15.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room rule was located under the KCDPA.

Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act data clean room.

Cross Context AdvertisingGreen

Controllers must disclose in privacy notices whether they sell data or process it for targeted advertising, and how consumers can opt out.

Claims (1):

  • The KCDPA requires controllers to disclose in their privacy notice whether they sell personal data to third parties or process it for targeted advertising, and how consumers may exercise applicable opt-out rights.

Direct MarketingRed

No direct-marketing-specific suppression regime distinct from the general sale/targeted-advertising opt-out was located.

Absence provenance: not recorded. Searched: Kentucky direct marketing consent suppression law.

Key findings (3)

  • Opt-out/notice confirmed; dark-patterns/UOOM status under enacted law unconfirmed. — source on file
  • Opt-out/notice confirmed; dark-patterns/UOOM status under enacted law unconfirmed. — source on file
  • Opt-out/notice confirmed; dark-patterns/UOOM status under enacted law unconfirmed. — source on file
Category narrative64 words

The KCDPA's primary adtech-relevant lever is the opt-out right for targeted advertising and sale of personal data, paired with privacy-notice disclosure duties. Dark-patterns prohibition and universal opt-out mechanism (UOOM/GPC) recognition were features of the earlier, non-enacted competing bill (SB 15) rather than confirmed features of the enacted HB15/KCDPA; their status under the final law could not be independently confirmed. No clean-room/data-collaboration-room rule was located.

Sources and claims (3)
  1. ConfirmedKentucky Attorney General's OfficeThe KCDPA requires controllers to disclose in their privacy notice whether they sell personal data to third parties or process it for targeted advertising, and how consumers may exercise applicable opt-out rights.observed
  2. UncertainIAPPKentucky's enacted KCDPA (HB 15) framework has not been confirmed to include an explicit statutory 'dark patterns' prohibition; an earlier competing bill (SB 15) that defined 'dark patterns' was abandoned and not enacted.observed
  3. UncertainIAPPIt is unconfirmed whether the enacted KCDPA (HB 15) recognizes universal opt-out mechanisms (e.g., Global Privacy Control); universal opt-out recognition was a feature proposed in the competing, non-enacted SB 15.observed

#

Profiling opt-out and biometric/genetic sensitive-data classification are Tier-1 confirmed; AI-risk-assessment and surveillance-carveout sub-modules rely on thinner secondary sourcing or carry no evidence.

Primary frameworkKCDPA (profiling opt-out) + Kentucky Senate Bill 4 (public-sector AI governance)
Traffic-light rationale — AmberProfiling opt-out and biometric/genetic sensitive-data classification are Tier-1 confirmed; AI-risk-assessment and surveillance-carveout sub-modules rely on thinner secondary sourcing or carry no evidence.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling in furtherance of legal or similarly significant decisions.

Claims (1):

  • Kentucky consumers have a right under the KCDPA to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, functioning as the state's analogue to a GDPR Article 22-style automated-decision-making safeguard.

Automated Decision Making TransparencyAmber

DPIA obligations attach to disparate-impact profiling, providing a risk-assessment/transparency mechanism.

Claims (1):

  • The KCDPA's DPIA obligation is triggered, among other things, by profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers, providing a risk-assessment mechanism for automated decision-making.

Ai Risk AssessmentsAmber

Senate Bill 4 establishes public-sector high-risk AI governance separate from the consumer-facing KCDPA; exact effective date unconfirmed.

Claims (1):

  • Kentucky's Senate Bill 4 establishes governance and risk-assessment requirements for high-risk artificial-intelligence systems used in the state's public sector, separate from and supplementing the KCDPA's consumer-facing framework.

Biometric RegimeGreen

Biometric data used for personal identification is 'sensitive data' requiring consent.

Claims (1):

  • Biometric data used for personal identification purposes is classified as 'sensitive data' under the KCDPA, requiring consumer consent prior to processing.

Genetic DataGreen

Genetic data is 'sensitive data' requiring consent.

Claims (1):

  • Genetic data is classified as 'sensitive data' under the KCDPA and may not be processed without the consumer's consent.

State Surveillance CarveoutsRed

No state-surveillance/national-security carve-out provision was located for the KCDPA.

Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act national security exemption law enforcement.

Key findings (3)

  • Profiling opt-out and biometric/genetic sensitive-data rules confirmed; SB4 AI governance date unconfirmed. — source on file
  • Profiling opt-out and biometric/genetic sensitive-data rules confirmed; SB4 AI governance date unconfirmed. — source on file
  • Profiling opt-out and biometric/genetic sensitive-data rules confirmed; SB4 AI governance date unconfirmed. — source on file
Category narrative55 words

The KCDPA's profiling opt-out functions as Kentucky's closest analogue to a GDPR Article 22-style ADM safeguard, reinforced by a DPIA trigger for disparate-impact profiling risk. Separately, Senate Bill 4 addresses high-risk AI governance in the public sector. Biometric and genetic identifiers are treated as 'sensitive data' requiring consent. No state-surveillance carve-out provision was independently located.

Sources and claims (5)
  1. ConfirmedKentucky Attorney General's OfficeKentucky consumers have a right under the KCDPA to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, functioning as the state's analogue to a GDPR Article 22-style automated-decision-making safeguard.observed
  2. ProbableDataGuidanceThe KCDPA's DPIA obligation is triggered, among other things, by profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers, providing a risk-assessment mechanism for automated decision-making.observed
  3. ProbableDataGuidanceKentucky's Senate Bill 4 establishes governance and risk-assessment requirements for high-risk artificial-intelligence systems used in the state's public sector, separate from and supplementing the KCDPA's consumer-facing framework.observed
  4. ConfirmedKentucky Attorney General's OfficeBiometric data used for personal identification purposes is classified as 'sensitive data' under the KCDPA, requiring consumer consent prior to processing.observed
  5. ConfirmedKentucky Attorney General's OfficeGenetic data is classified as 'sensitive data' under the KCDPA and may not be processed without the consumer's consent.observed

#

The KCDPA's own under-13 sensitive-data protection is Tier-1 confirmed; the broader minors' online-safety bill landscape (Kids Code, HB12/227) rests on unconfirmed enactment status and is flagged as a gap.

Primary frameworkKCDPA (child sensitive-data provision); status of Kentucky Kids Code (HB633) and related minors' bills unconfirmed
Traffic-light rationale — AmberThe KCDPA's own under-13 sensitive-data protection is Tier-1 confirmed; the broader minors' online-safety bill landscape (Kids Code, HB12/227) rests on unconfirmed enactment status and is flagged as a gap.

Sub-modules (5)

Age VerificationAmber

House Bill 12 would introduce age-verification requirements for social-media account creation; enactment status unconfirmed.

Claims (1):

  • Kentucky's House Bill 12 seeks to enhance online protections for minors by regulating social media account creation and enforcing age verification.

Minor Profiling BansAmber

The Kentucky Kids Code (HB633) would impose stringent data-privacy requirements for online services aimed at minors; enactment status could not be confirmed.

Claims (1):

  • House Bill 633, the Kentucky Kids Code, would introduce stringent data-privacy requirements for online services targeting minors; as of the most recent tracked update, this bill's enactment status could not be independently confirmed from ag.ky.gov or verified legislative-history sources.

Education SettingsRed

No education-setting-specific children's-data provision was located.

Absence provenance: not recorded. Searched: Kentucky student data privacy education children.

Dependent AdultsRed

No dependent-adult / incapacitated-persons data-protection provision was located.

Absence provenance: not recorded. Searched: Kentucky dependent adult data privacy protection.

Key findings (3)

  • Under-13 sensitive-data rule confirmed; Kids Code/HB12/HB227 status unconfirmed. — source on file
  • Under-13 sensitive-data rule confirmed; Kids Code/HB12/HB227 status unconfirmed. — source on file
  • Under-13 sensitive-data rule confirmed; Kids Code/HB12/HB227 status unconfirmed. — source on file
Category narrative64 words

The KCDPA treats data from a known child under 13 as 'sensitive data' requiring consent, giving Kentucky a COPPA-aligned baseline. Beyond that, several bills targeting minors online (Kentucky Kids Code / HB633, HB12, HB227) and age-verification/social-media provisions were identified in secondary sources, but their enactment/effective-date status could not be independently confirmed from ag.ky.gov or verified legislative-history sources. No dependent-adult-specific or education-setting-specific provision was located.

Sources and claims (3)
  1. UncertainDataGuidanceKentucky's House Bill 12 seeks to enhance online protections for minors by regulating social media account creation and enforcing age verification.observed
  2. ConfirmedKentucky Attorney General's OfficeThe KCDPA classifies personal data collected from a known child younger than 13 as 'sensitive data,' requiring consumer consent before processing, aligning with COPPA-style protections for young children.observed
  3. UncertainDataGuidanceHouse Bill 633, the Kentucky Kids Code, would introduce stringent data-privacy requirements for online services targeting minors; as of the most recent tracked update, this bill's enactment status could not be independently confirmed from ag.ky.gov or verified legislative-history sources.observed

#

Enforcement powers, penalty caps, and recent enforcement activity are corroborated by primary AG court filings and Tier-1 AG guidance pages.

Primary frameworkKCDPA, KRS 367.3611 et seq.; Kentucky Consumer Protection Act, KRS 367.110 et seq.
Traffic-light rationale — GreenEnforcement powers, penalty caps, and recent enforcement activity are corroborated by primary AG court filings and Tier-1 AG guidance pages.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AG has exclusive KCDPA enforcement authority, a 30-day cure requirement, and can seek civil penalties up to $7,500 per uncured violation plus injunctive relief and fees.

Claims (1):

  • The Kentucky Attorney General's Office of Data Privacy has exclusive authority to enforce the KCDPA and may seek injunctive relief, civil penalties, and reasonable attorneys' fees and investigative costs; violators that fail to cure within 30 days of notice face civil penalties of up to $7,500 per violation.

Enforcement Activity IndexGreen

Recent AG enforcement activity includes suits against Temu (2025) and Character Technologies (2026), both brought under general consumer-protection authority rather than the KCDPA itself.

Claims (2):

  • In January 2026, the Kentucky Attorney General filed a parens patriae enforcement action against Character Technologies, Inc. alleging AI chatbot safety and data-protection violations.
  • In July 2025, the Kentucky Attorney General filed a lawsuit against Temu (PDD Holdings/Whaleco) under the Kentucky Consumer Protection Act alleging unlawful collection of sensitive personal information without consent, among other data-practice violations.

Regulator Funding And CapacityRed

No specific funding/headcount data for the Office of Data Privacy was located.

Absence provenance: not recorded. Searched: Kentucky Office of Data Privacy budget staffing headcount.

Collective Redress And Class ActionsAmber

The Kentucky Consumer Protection Act, used separately from the KCDPA in recent AG suits, does not appear from available sources to provide a distinct private class-action mechanism beyond AG enforcement.

Claims (1):

  • Separately from the KCDPA, Kentucky's general Consumer Protection Act (KRS 367.110 et seq.) has been used by the Attorney General to bring data-practice-related enforcement actions (e.g., against Temu), but this statute likewise does not appear to provide a private class-action mechanism distinct from AG enforcement based on available sources.

Private Right Of ActionGreen

The KCDPA provides no private right of action; enforcement is exclusive to the Attorney General.

Claims (1):

  • The KCDPA does not provide Kentucky consumers with a private right of action; enforcement runs exclusively through the Attorney General's Office of Data Privacy.

Recent Developments 180DGreen

Within roughly the last 180 days: HB473's KCDPA amendments (HIPAA/DPIA narrowing) took effect June 1, 2026; HB692 (automatic content recognition / smart monitor consent amendment) was signed in 2026 for a July 1, 2027 effective date.

Claims (2):

  • House Bill 473, effective June 1, 2026, amended the KCDPA to exempt certain HIPAA-regulated health information and to narrow the profiling-related DPIA trigger to cases involving disparate impact.
  • House Bill 692, signed into law in 2026, amends the KCDPA to define 'automatic content recognition' and 'smart monitor' and to require consumer consent for data collection via such technologies, with an effective date of July 1, 2027.

Key findings (3)

  • Sole AG enforcement, no PRA, active enforcement (Temu, Character Technologies). — source on file
  • Sole AG enforcement, no PRA, active enforcement (Temu, Character Technologies). — source on file
  • Sole AG enforcement, no PRA, active enforcement (Temu, Character Technologies). — source on file
Category narrative96 words

Enforcement runs exclusively through the AG's Office of Data Privacy, with a non-sunsetting 30-day cure period and civil penalties up to $7,500 per uncured violation; there is no private right of action. The AG has also used its general Consumer Protection Act authority (not the KCDPA itself) to bring recent high-profile data-practice suits against Temu (July 2025) and Character Technologies (January 2026), evidencing active enforcement posture ahead of and following KCDPA's January 1, 2026 effective date. HB473 (effective June 1, 2026) and HB692 (signed 2026, effective July 1, 2027) represent recent legislative developments amending the KCDPA.

Sources and claims (7)
  1. ConfirmedKentucky Attorney General's OfficeThe Kentucky Attorney General's Office of Data Privacy has exclusive authority to enforce the KCDPA and may seek injunctive relief, civil penalties, and reasonable attorneys' fees and investigative costs; violators that fail to cure within 30 days of notice face civil penalties of up to $7,500 per violation.observed
  2. ConfirmedKentucky Attorney General's Office / Franklin Circuit CourtIn January 2026, the Kentucky Attorney General filed a parens patriae enforcement action against Character Technologies, Inc. alleging AI chatbot safety and data-protection violations.observed
  3. ConfirmedKentucky Attorney General's Office / Woodford Circuit CourtIn July 2025, the Kentucky Attorney General filed a lawsuit against Temu (PDD Holdings/Whaleco) under the Kentucky Consumer Protection Act alleging unlawful collection of sensitive personal information without consent, among other data-practice violations.observed
  4. UncertainKentucky Attorney General's Office / Woodford Circuit CourtSeparately from the KCDPA, Kentucky's general Consumer Protection Act (KRS 367.110 et seq.) has been used by the Attorney General to bring data-practice-related enforcement actions (e.g., against Temu), but this statute likewise does not appear to provide a private class-action mechanism distinct from AG enforcement based on available sources.observed
  5. ConfirmedKentucky Attorney General's OfficeThe KCDPA does not provide Kentucky consumers with a private right of action; enforcement runs exclusively through the Attorney General's Office of Data Privacy.observed
  6. ConfirmedDataGuidanceHouse Bill 473, effective June 1, 2026, amended the KCDPA to exempt certain HIPAA-regulated health information and to narrow the profiling-related DPIA trigger to cases involving disparate impact.observed
  7. ProbableDataGuidanceHouse Bill 692, signed into law in 2026, amends the KCDPA to define 'automatic content recognition' and 'smart monitor' and to require consumer consent for data collection via such technologies, with an effective date of July 1, 2027.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Kentucky
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 14 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacytransfer mechanisms
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, and enforcement_and_redress rest primarily on Tier-1 ag.ky.gov guidance and primary court filings (Temu, Character Technologies complaints), giving high confidence. lawful_processing_and_special_data and algorithmic_biometric_and_surveillance_governance mix Tier-1 (sensitive-data definitions) with Tier-3 secondary commentary (DPIA/ADM framing). controller_processor_duties is partially confirmed (DPIA, contracts, breach law) but has genuine gaps on DPO/ROPA/retention. sectoral_watch and adtech_and_commercial_privacy rely more heavily on Tier-3/Tier-4 secondary sources and general multi-state pattern-matching (GLBA exemption, dark patterns, UOOM) rather than direct KCDPA statutory text. children_and_vulnerable_groups is confirmed for the under-13 sensitive-data rule but the broader minors' bill landscape (Kids Code HB633, HB12, HB227) has unconfirmed enactment status. cross_border_and_adequacy is a genuine, well-evidenced regulatory gap (no US state-level transfer/adequacy/localisation regime).

Unresolved questions (7):

  • Exact KCDPA statutory text (KRS 367.3611–367.3629) was not directly parsed; all thresholds/exemptions are drawn from AG-published summaries and secondary legal commentary rather than the codified text itself.
  • Whether the KCDPA's GLBA/financial-institution exemption is entity-level or data-level was not directly confirmed from KY statutory text.
  • Enactment/effective-date status of the Kentucky Kids Code (HB633), HB12 (social media age verification), and HB227 (addictive platforms) could not be confirmed.
  • Exact signing date and full provisions of HB692 (automatic content recognition / smart monitor) beyond its July 1, 2027 effective date were not confirmed.
  • Whether the KCDPA recognizes universal opt-out mechanisms (e.g., Global Privacy Control) or contains an explicit dark-patterns prohibition was not confirmed.
  • DPO-appointment, ROPA, and data-retention/disposal obligations under the KCDPA could not be confirmed or disconfirmed from available sources.
  • Exact effective date and full scope of Senate Bill 4 (public-sector AI governance) and the Kentucky Insurance Data Security Act were not independently confirmed.

Escalate to primary-source review: yes