Traffic-light rationale — GreenPrimary statute is in force with a clearly identified enforcement authority and Tier-1 (ag.ky.gov) confirmation of effective date and thresholds.
Sub-modules (5)
Regulator And AuthorityGreen
The Office of Data Privacy, created within the Kentucky AG's office, has exclusive statutory authority to enforce the KCDPA.
Claims (1):
The Kentucky Office of Data Privacy, housed within the Attorney General's office, has exclusive authority to enforce the KCDPA.
Act And InstrumentsGreen
The KCDPA is the sole comprehensive instrument; codified at KRS 367.3611–367.3629, effective January 1, 2026.
Claims (1):
The Kentucky Consumer Data Protection Act (KCDPA) went into effect on January 1, 2026 and is codified at KRS 367.3611 to 367.3629.
Material ScopeGreen
Applicability turns on a 100,000-consumer / 25,000-consumer-plus-50%-revenue threshold, with categorical entity exemptions (government, nonprofits, higher education) and data-level exemptions (HIPAA-regulated data).
Claims (2):
The KCDPA applies to controllers that control or process personal data of at least 100,000 Kentucky consumers, or that derive over 50% of gross revenue from the sale of personal data while controlling or processing the data of at least 25,000 Kentucky consumers.
The KCDPA exempts certain entities, including cities, state agencies and political subdivisions, nonprofit organizations, and institutions of higher education, from its scope.
Territorial ScopeAmber
Coverage is limited to Kentucky-resident consumers, excluding employment/commercial-context individuals; precise extraterritorial-reach statutory language was not independently retrieved from primary text.
Claims (1):
The KCDPA's definition of 'consumer' is limited to Kentucky residents, excluding individuals acting in an employment or commercial context.
Regulator Registration And FilingRed
No general controller registration or filing obligation with the Attorney General was identified for the KCDPA (unlike some states' data-broker registries).
Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act controller registration, KCDPA filing requirement Attorney General.
Key findings (3)
KCDPA in force Jan 1 2026; sole enforcer AG Office of Data Privacy. — source on file
KCDPA in force Jan 1 2026; sole enforcer AG Office of Data Privacy. — source on file
KCDPA in force Jan 1 2026; sole enforcer AG Office of Data Privacy. — source on file
Category narrative94 words
Kentucky's comprehensive consumer-privacy regime is the Kentucky Consumer Data Protection Act (KCDPA), enacted as House Bill 15 (signed April 4, 2024) and codified at KRS 367.3611–367.3629, which entered into force January 1, 2026. It is a Virginia-model, controller/processor statute enforced exclusively by a dedicated Office of Data Privacy inside the Attorney General's office (no independent DPA). Material scope is threshold-based (100,000 KY consumers, or 25,000 consumers plus 50% of revenue from data sales) with broad entity- and data-level exemptions (government bodies, nonprofits, higher-education institutions, HIPAA-regulated health data). No freestanding controller registration/filing regime was identified.
Sources and claims (5)
ConfirmedKentucky Attorney General's Office — The Kentucky Consumer Data Protection Act (KCDPA) went into effect on January 1, 2026 and is codified at KRS 367.3611 to 367.3629.observed
ConfirmedKentucky Attorney General's Office — The Kentucky Office of Data Privacy, housed within the Attorney General's office, has exclusive authority to enforce the KCDPA.observed
ConfirmedIAPP — The KCDPA applies to controllers that control or process personal data of at least 100,000 Kentucky consumers, or that derive over 50% of gross revenue from the sale of personal data while controlling or processing the data of at least 25,000 Kentucky consumers.observed
ConfirmedKentucky Attorney General's Office — The KCDPA exempts certain entities, including cities, state agencies and political subdivisions, nonprofit organizations, and institutions of higher education, from its scope.observed
ProbableIAPP — The KCDPA's definition of 'consumer' is limited to Kentucky residents, excluding individuals acting in an employment or commercial context.observed
Consent/opt-out structure is well evidenced from Tier-1 sources, but no GDPR Art.6-equivalent lawful-basis enumeration exists, and pseudonymisation/anonymisation safe-harbour detail is only lightly sourced.
Primary frameworkKCDPA, KRS 367.3611 et seq. (consent/opt-out model; no Art.6-style lawful-basis enumeration)
Traffic-light rationale — AmberConsent/opt-out structure is well evidenced from Tier-1 sources, but no GDPR Art.6-equivalent lawful-basis enumeration exists, and pseudonymisation/anonymisation safe-harbour detail is only lightly sourced.
Sub-modules (4)
Lawful BasesAmber
No enumerated lawful-basis list; processing is permitted by default, subject to notice and opt-out/consent overlays.
Claims (1):
The KCDPA does not enumerate GDPR-style Article 6 lawful bases; instead it structures processing permissions around consumer consent for sensitive data and opt-out rights for targeted advertising, sale, and certain profiling.
Consent ThresholdsGreen
Affirmative, prior consumer consent is required before processing sensitive data.
Claims (1):
Controllers may not process a consumer's sensitive data without first obtaining the consumer's consent under the KCDPA.
Special CategoriesGreen
Sensitive data is broadly defined and subject to opt-in consent.
Claims (1):
The KCDPA defines 'sensitive data' to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used for personal identification, precise geolocation data, and data collected from a known child under 13.
Pseudonymisation And AnonymisationAmber
Kentucky's law, in common with contemporaneous state statutes, includes requirements around processing deidentified/pseudonymous data, though KY-specific statutory text was not directly retrieved.
Claims (1):
Comprehensive state privacy laws coming into effect alongside the KCDPA in 2026, including Kentucky's, include requirements for processing deidentified or pseudonymous data.
Key findings (3)
Consent/opt-out model, no Art.6-style lawful-basis list; broad sensitive-data definition. — source on file
Consent/opt-out model, no Art.6-style lawful-basis list; broad sensitive-data definition. — source on file
Consent/opt-out model, no Art.6-style lawful-basis list; broad sensitive-data definition. — source on file
Category narrative62 words
The KCDPA does not use a GDPR-style enumerated lawful-basis model; instead it is a consent/opt-out architecture: general processing is permitted by default subject to disclosure and opt-out rights (targeted advertising, sale, certain profiling), while 'sensitive data' processing requires affirmative prior consent. Sensitive data is broadly defined (race/ethnicity, religion, health diagnosis, sexual orientation, immigration status, biometric/genetic identifiers, precise geolocation, known child data <13).
Sources and claims (4)
ProbableKentucky Attorney General's Office — The KCDPA does not enumerate GDPR-style Article 6 lawful bases; instead it structures processing permissions around consumer consent for sensitive data and opt-out rights for targeted advertising, sale, and certain profiling.observed
ConfirmedKentucky Attorney General's Office — Controllers may not process a consumer's sensitive data without first obtaining the consumer's consent under the KCDPA.observed
ConfirmedKentucky Attorney General's Office — The KCDPA defines 'sensitive data' to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used for personal identification, precise geolocation data, and data collected from a known child under 13.observed
ProbableIAPP — Comprehensive state privacy laws coming into effect alongside the KCDPA in 2026, including Kentucky's, include requirements for processing deidentified or pseudonymous data.observed
Traffic-light rationale — GreenAll core rights and the response-deadline framework are confirmed directly from Tier-1 ag.ky.gov sources.
Sub-modules (5)
Access RightGreen
Consumers may confirm processing and access their data (trade secrets excluded).
Claims (1):
Kentucky consumers have the right to confirm whether a controller is processing their personal data and to access their collected personal data, without revealing trade secrets.
Rectification And ErasureGreen
Consumers may correct inaccuracies and delete personal data.
Claims (1):
Kentucky consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them.
Restriction And ObjectionGreen
Consumers may opt out of targeted advertising, sale, and significant-effect profiling.
Claims (1):
Kentucky consumers have the right to opt out of the processing of their personal data for targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.
Data PortabilityGreen
Consumers may obtain a portable copy of their data to the extent feasible.
Claims (1):
Kentucky consumers have the right to obtain a portable copy of their personal data to the extent technically feasible, without revealing trade secrets.
Deadlines And Response WindowsGreen
Controllers must respond within 45 days, free of charge, up to twice annually per consumer.
Claims (1):
Controllers must respond to KCDPA consumer requests free of charge, up to twice annually per consumer, and must respond within forty-five days.
Key findings (3)
Full Virginia-model rights bundle, 45-day response window. — source on file
Full Virginia-model rights bundle, 45-day response window. — source on file
Full Virginia-model rights bundle, 45-day response window. — source on file
Category narrative45 words
The KCDPA grants Kentucky consumers a standard Virginia-model rights bundle: confirmation of processing, access, correction, deletion, portability, and opt-out of targeted advertising/sale/certain profiling. Controllers must respond within 45 days, free of charge, up to twice annually, and must provide an appeal mechanism for denied requests.
Sources and claims (5)
ConfirmedKentucky Attorney General's Office — Kentucky consumers have the right to confirm whether a controller is processing their personal data and to access their collected personal data, without revealing trade secrets.observed
ConfirmedKentucky Attorney General's Office — Kentucky consumers have the right to correct inaccuracies in their personal data and to delete personal data provided by or obtained about them.observed
ConfirmedKentucky Attorney General's Office — Kentucky consumers have the right to opt out of the processing of their personal data for targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.observed
ConfirmedKentucky Attorney General's Office — Kentucky consumers have the right to obtain a portable copy of their personal data to the extent technically feasible, without revealing trade secrets.observed
ConfirmedKentucky Attorney General's Office — Controllers must respond to KCDPA consumer requests free of charge, up to twice annually per consumer, and must respond within forty-five days.observed
Traffic-light rationale — AmberCore duties (DPIA, contracts, breach notification) are Tier-1/Tier-3 confirmed; DPO, ROPA and retention/disposal sub-modules carry no direct evidence.
Sub-modules (7)
Accountability And DpiaAmber
DPIAs are required in specified circumstances; HB473 (effective June 1, 2026) narrows the profiling-related trigger to disparate-impact cases and adds a HIPAA-data carve-out.
Claims (2):
The KCDPA requires controllers to conduct Data Protection Impact Assessments in specified circumstances, including profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers.
House Bill 473, signed into law March 15, 2025, amends the KCDPA to narrow the DPIA trigger for profiling to cases involving disparate impact and exempts certain HIPAA-regulated health information, effective June 1, 2026.
Dpo RequirementsRed
No DPO-appointment or independence requirement was located for the KCDPA.
Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act data protection officer requirement.
Ropa RequirementsRed
No records-of-processing-activity obligation was located for the KCDPA.
Absence provenance: not recorded. Searched: KCDPA records of processing activities requirement.
Joint Controller ArrangementsGreen
The KCDPA mandates specific contractual terms between controllers and processors.
Claims (1):
The KCDPA requires that specific contractual terms be included in agreements between controllers and processors.
Security MeasuresAmber
The KCDPA imposes general data-security obligations on controllers and processors, though granular technical/organisational-measure detail was not independently retrieved from primary statutory text.
Claims (1):
The KCDPA imposes obligations on controllers and processors related to data security, as part of its consent, disclosure, and security framework.
Breach NotificationAmber
Kentucky's standalone breach-notification statute (KRS 365.732) requires notice to affected residents and, above a 1,000-resident threshold, to nationwide credit bureaus; enforcement-authority attribution under that statute is itself ambiguous per secondary sources.
Claims (2):
Kentucky's data breach notification statute, KRS 365.732, requires notification to affected Kentucky residents, and where a breach affects more than 1,000 Kentucky residents, notification to consumer reporting agencies and nationwide credit bureaus.
The KCDPA separately contains certain requirements relevant to breach notification, though KRS 365.732 does not explicitly grant the Attorney General enforcement authority over breach-notification violations.
Retention And DisposalRed
No explicit statutory retention-limitation or disposal-duty provision was located for the KCDPA.
Absence provenance: not recorded. Searched: KCDPA data retention limitation disposal requirement.
Key findings (3)
DPIA/contract/breach duties confirmed; DPO/ROPA/retention gaps; HB473 date bifurcation corrected. — source on file
DPIA/contract/breach duties confirmed; DPO/ROPA/retention gaps; HB473 date bifurcation corrected. — source on file
DPIA/contract/breach duties confirmed; DPO/ROPA/retention gaps; HB473 date bifurcation corrected. — source on file
Category narrative44 words
Controllers/processors face DPIA obligations (narrowed by HB473, effective June 1, 2026), mandatory controller-processor contract terms, general security and breach-notification duties (KRS 365.732, plus KCDPA breach-adjacent provisions), but no explicit DPO-appointment or ROPA requirement, and no explicit statutory retention/disposal duty, was located in available sources.
Sources and claims (6)
ProbableDataGuidance — The KCDPA requires controllers to conduct Data Protection Impact Assessments in specified circumstances, including profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers.observed
ConfirmedDataGuidance — House Bill 473, signed into law March 15, 2025, amends the KCDPA to narrow the DPIA trigger for profiling to cases involving disparate impact and exempts certain HIPAA-regulated health information, effective June 1, 2026.observed
ConfirmedKentucky Attorney General's Office — The KCDPA requires that specific contractual terms be included in agreements between controllers and processors.observed
ProbableDataGuidance — The KCDPA imposes obligations on controllers and processors related to data security, as part of its consent, disclosure, and security framework.observed
ConfirmedDataGuidance — Kentucky's data breach notification statute, KRS 365.732, requires notification to affected Kentucky residents, and where a breach affects more than 1,000 Kentucky residents, notification to consumer reporting agencies and nationwide credit bureaus.observed
ProbableDataGuidance — The KCDPA separately contains certain requirements relevant to breach notification, though KRS 365.732 does not explicitly grant the Attorney General enforcement authority over breach-notification violations.observed
Genuine regulatory gap: US state consumer-privacy statutes, including the KCDPA, do not contain a transfer-mechanism/adequacy/localisation regime.
Traffic-light rationale — RedGenuine regulatory gap: US state consumer-privacy statutes, including the KCDPA, do not contain a transfer-mechanism/adequacy/localisation regime.
Sub-modules (6)
Transfer MechanismsRed
No KCDPA or other Kentucky-specific cross-border transfer mechanism was located.
Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act cross-border data transfer mechanism.
Adequacy ReceivedRed
Not applicable; the US federal system, and Kentucky specifically, is not a recipient of foreign adequacy determinations at sub-federal level.
Absence provenance: not recorded. Searched: Kentucky adequacy decision received.
Adequacy GrantedRed
Kentucky, as a US state, has no independent authority to grant adequacy decisions to other regimes.
Absence provenance: not recorded. Searched: Kentucky adequacy decision granted.
Sccs And BcrsRed
No SCC/BCR uptake regime exists under the KCDPA.
Absence provenance: not recorded. Searched: KCDPA standard contractual clauses binding corporate rules.
Transfer Impact AssessmentRed
No transfer-impact-assessment obligation was located under the KCDPA.
Absence provenance: not recorded. Searched: KCDPA transfer impact assessment requirement.
Data LocalisationRed
No data-localisation mandate was located under the KCDPA.
Absence provenance: not recorded. Searched: Kentucky data localisation requirement consumer data.
Key findings (3)
No transfer/adequacy/localisation regime; structural US state-law gap. — source on file
No transfer/adequacy/localisation regime; structural US state-law gap. — source on file
No transfer/adequacy/localisation regime; structural US state-law gap. — source on file
Category narrative75 words
No cross-border transfer mechanism, adequacy determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate was located for the KCDPA or any other Kentucky state instrument. This is consistent with the general pattern of US state comprehensive consumer-privacy laws, which do not operate an adequacy or SCC framework analogous to GDPR Chapter V; cross-border data flows involving Kentucky-collected personal data are governed only indirectly, via federal sectoral regimes (e.g., export-control, CFIUS) that fall outside DP consumer-level scope.
Health and insurance overlays are reasonably well evidenced; the financial-sector exemption is inferred from a general US multi-state pattern rather than direct KCDPA statutory text, and telecoms/education sub-modules carry no direct evidence.
Primary frameworkKCDPA sectoral exemptions; Kentucky Insurance Data Security Act (KRS Ch. 304, Subtit. 3); federal HIPAA/GLBA overlays
Traffic-light rationale — AmberHealth and insurance overlays are reasonably well evidenced; the financial-sector exemption is inferred from a general US multi-state pattern rather than direct KCDPA statutory text, and telecoms/education sub-modules carry no direct evidence.
Sub-modules (7)
Financial Sector OverlayAmber
GLBA-regulated financial institutions are presumed exempted at entity level under the general state-law pattern; KY-specific statutory text was not independently retrieved.
Claims (1):
Most U.S. state comprehensive consumer privacy laws, a category that includes Kentucky's KCDPA, fully exempt financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) from coverage, with only a handful of states (California, Connecticut, Minnesota, Montana, and Oregon) instead applying a narrower data-level GLBA carve-out.
Health Sector OverlayGreen
HIPAA-regulated PHI, health records, and patient-identifying information are exempt; HB473 (effective June 1, 2026) extends the exemption to HIPAA-covered-provider data including limited data sets.
Claims (2):
The KCDPA exempts protected health information regulated under HIPAA, health records, and patient-identifying information from its scope.
House Bill 473 (effective June 1, 2026) further exempts information collected by HIPAA-covered health care providers, including information included in a limited data set, from the KCDPA.
Telecoms And EprivacyRed
No telecoms- or ePrivacy-specific overlay statute was located for Kentucky.
Absence provenance: not recorded. Searched: Kentucky telecoms ePrivacy cookie law.
Employment DataAmber
The KCDPA's consumer definition excludes individuals acting in an employment context, effectively carving employment data out of general consumer-privacy coverage.
Credit And ScoringAmber
Kentucky's breach law requires notification to nationwide consumer reporting agencies/credit bureaus for large breaches, giving a credit-reporting dimension to the state's data-security regime.
Claims (1):
Where a Kentucky data breach affects more than 1,000 residents, notification must also be made to nationwide consumer reporting agencies and credit bureaus.
EducationRed
No education-sector-specific data-privacy overlay statute was located for Kentucky.
Absence provenance: not recorded. Searched: Kentucky student data privacy law.
InsuranceAmber
Kentucky maintains a separate Insurance Data Security Act governing insurer data security independent of the KCDPA.
Claims (1):
Kentucky has a separate Insurance Data Security Act (new section of KRS Chapter 304, Subtitle 3) governing data security for the insurance sector, distinct from the KCDPA's general consumer-privacy framework.
Key findings (3)
HIPAA/GLBA overlays and separate Insurance Data Security Act. — source on file
HIPAA/GLBA overlays and separate Insurance Data Security Act. — source on file
HIPAA/GLBA overlays and separate Insurance Data Security Act. — source on file
Category narrative92 words
The KCDPA layers onto pre-existing Kentucky sectoral regimes. It exempts HIPAA-regulated health data (narrowed further by HB473 from June 1, 2026); financial institutions subject to GLBA are, per the general multi-state pattern, most likely fully exempted at the entity level (Kentucky is not among the five states that instead apply only a narrower GLBA data-level carve-out). A distinct Insurance Data Security Act (new KRS Chapter 304, Subtitle 3) governs insurer data security separately from the KCDPA. No telecoms/ePrivacy-specific, education-specific, or employment-specific overlay statute (beyond the KCDPA's employment-context consumer exclusion) was independently located.
Sources and claims (5)
ProbableIAPP — Most U.S. state comprehensive consumer privacy laws, a category that includes Kentucky's KCDPA, fully exempt financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) from coverage, with only a handful of states (California, Connecticut, Minnesota, Montana, and Oregon) instead applying a narrower data-level GLBA carve-out.observed
ConfirmedKentucky Attorney General's Office — The KCDPA exempts protected health information regulated under HIPAA, health records, and patient-identifying information from its scope.observed
ConfirmedDataGuidance — House Bill 473 (effective June 1, 2026) further exempts information collected by HIPAA-covered health care providers, including information included in a limited data set, from the KCDPA.observed
ConfirmedDataGuidance — Where a Kentucky data breach affects more than 1,000 residents, notification must also be made to nationwide consumer reporting agencies and credit bureaus.observed
ProbableDataGuidance — Kentucky has a separate Insurance Data Security Act (new section of KRS Chapter 304, Subtitle 3) governing data security for the insurance sector, distinct from the KCDPA's general consumer-privacy framework.observed
Traffic-light rationale — AmberCore opt-out/notice duties are Tier-1 confirmed; dark-patterns and UOOM recognition status under the enacted law remain unconfirmed gaps.
Sub-modules (6)
Cookies And TrackersRed
No cookie-specific consent regime distinct from the general targeted-advertising opt-out was located.
Absence provenance: not recorded. Searched: Kentucky cookie consent law.
Dark PatternsAmber
An earlier competing bill (SB 15) defined 'dark patterns' but was abandoned; it is unconfirmed whether the enacted KCDPA (HB15) carries an equivalent express prohibition.
Claims (1):
Kentucky's enacted KCDPA (HB 15) framework has not been confirmed to include an explicit statutory 'dark patterns' prohibition; an earlier competing bill (SB 15) that defined 'dark patterns' was abandoned and not enacted.
Opt Out SignalsAmber
Universal opt-out mechanism recognition (e.g., GPC) was proposed in the non-enacted SB 15; it is unconfirmed whether the enacted KCDPA recognizes such signals.
Claims (1):
It is unconfirmed whether the enacted KCDPA (HB 15) recognizes universal opt-out mechanisms (e.g., Global Privacy Control); universal opt-out recognition was a feature proposed in the competing, non-enacted SB 15.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room rule was located under the KCDPA.
Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act data clean room.
Cross Context AdvertisingGreen
Controllers must disclose in privacy notices whether they sell data or process it for targeted advertising, and how consumers can opt out.
Claims (1):
The KCDPA requires controllers to disclose in their privacy notice whether they sell personal data to third parties or process it for targeted advertising, and how consumers may exercise applicable opt-out rights.
Direct MarketingRed
No direct-marketing-specific suppression regime distinct from the general sale/targeted-advertising opt-out was located.
Absence provenance: not recorded. Searched: Kentucky direct marketing consent suppression law.
Key findings (3)
Opt-out/notice confirmed; dark-patterns/UOOM status under enacted law unconfirmed. — source on file
Opt-out/notice confirmed; dark-patterns/UOOM status under enacted law unconfirmed. — source on file
Opt-out/notice confirmed; dark-patterns/UOOM status under enacted law unconfirmed. — source on file
Category narrative64 words
The KCDPA's primary adtech-relevant lever is the opt-out right for targeted advertising and sale of personal data, paired with privacy-notice disclosure duties. Dark-patterns prohibition and universal opt-out mechanism (UOOM/GPC) recognition were features of the earlier, non-enacted competing bill (SB 15) rather than confirmed features of the enacted HB15/KCDPA; their status under the final law could not be independently confirmed. No clean-room/data-collaboration-room rule was located.
Sources and claims (3)
ConfirmedKentucky Attorney General's Office — The KCDPA requires controllers to disclose in their privacy notice whether they sell personal data to third parties or process it for targeted advertising, and how consumers may exercise applicable opt-out rights.observed
UncertainIAPP — Kentucky's enacted KCDPA (HB 15) framework has not been confirmed to include an explicit statutory 'dark patterns' prohibition; an earlier competing bill (SB 15) that defined 'dark patterns' was abandoned and not enacted.observed
UncertainIAPP — It is unconfirmed whether the enacted KCDPA (HB 15) recognizes universal opt-out mechanisms (e.g., Global Privacy Control); universal opt-out recognition was a feature proposed in the competing, non-enacted SB 15.observed
Profiling opt-out and biometric/genetic sensitive-data classification are Tier-1 confirmed; AI-risk-assessment and surveillance-carveout sub-modules rely on thinner secondary sourcing or carry no evidence.
Primary frameworkKCDPA (profiling opt-out) + Kentucky Senate Bill 4 (public-sector AI governance)
Traffic-light rationale — AmberProfiling opt-out and biometric/genetic sensitive-data classification are Tier-1 confirmed; AI-risk-assessment and surveillance-carveout sub-modules rely on thinner secondary sourcing or carry no evidence.
Sub-modules (6)
Profiling RestrictionsGreen
Consumers may opt out of profiling in furtherance of legal or similarly significant decisions.
Claims (1):
Kentucky consumers have a right under the KCDPA to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, functioning as the state's analogue to a GDPR Article 22-style automated-decision-making safeguard.
Automated Decision Making TransparencyAmber
DPIA obligations attach to disparate-impact profiling, providing a risk-assessment/transparency mechanism.
Claims (1):
The KCDPA's DPIA obligation is triggered, among other things, by profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers, providing a risk-assessment mechanism for automated decision-making.
Ai Risk AssessmentsAmber
Senate Bill 4 establishes public-sector high-risk AI governance separate from the consumer-facing KCDPA; exact effective date unconfirmed.
Claims (1):
Kentucky's Senate Bill 4 establishes governance and risk-assessment requirements for high-risk artificial-intelligence systems used in the state's public sector, separate from and supplementing the KCDPA's consumer-facing framework.
Biometric RegimeGreen
Biometric data used for personal identification is 'sensitive data' requiring consent.
Claims (1):
Biometric data used for personal identification purposes is classified as 'sensitive data' under the KCDPA, requiring consumer consent prior to processing.
Genetic DataGreen
Genetic data is 'sensitive data' requiring consent.
Claims (1):
Genetic data is classified as 'sensitive data' under the KCDPA and may not be processed without the consumer's consent.
State Surveillance CarveoutsRed
No state-surveillance/national-security carve-out provision was located for the KCDPA.
Absence provenance: not recorded. Searched: Kentucky Consumer Data Protection Act national security exemption law enforcement.
Key findings (3)
Profiling opt-out and biometric/genetic sensitive-data rules confirmed; SB4 AI governance date unconfirmed. — source on file
Profiling opt-out and biometric/genetic sensitive-data rules confirmed; SB4 AI governance date unconfirmed. — source on file
Profiling opt-out and biometric/genetic sensitive-data rules confirmed; SB4 AI governance date unconfirmed. — source on file
Category narrative55 words
The KCDPA's profiling opt-out functions as Kentucky's closest analogue to a GDPR Article 22-style ADM safeguard, reinforced by a DPIA trigger for disparate-impact profiling risk. Separately, Senate Bill 4 addresses high-risk AI governance in the public sector. Biometric and genetic identifiers are treated as 'sensitive data' requiring consent. No state-surveillance carve-out provision was independently located.
Sources and claims (5)
ConfirmedKentucky Attorney General's Office — Kentucky consumers have a right under the KCDPA to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer, functioning as the state's analogue to a GDPR Article 22-style automated-decision-making safeguard.observed
ProbableDataGuidance — The KCDPA's DPIA obligation is triggered, among other things, by profiling that presents a reasonably foreseeable risk of unfair or disparate impact on consumers, providing a risk-assessment mechanism for automated decision-making.observed
ProbableDataGuidance — Kentucky's Senate Bill 4 establishes governance and risk-assessment requirements for high-risk artificial-intelligence systems used in the state's public sector, separate from and supplementing the KCDPA's consumer-facing framework.observed
ConfirmedKentucky Attorney General's Office — Biometric data used for personal identification purposes is classified as 'sensitive data' under the KCDPA, requiring consumer consent prior to processing.observed
ConfirmedKentucky Attorney General's Office — Genetic data is classified as 'sensitive data' under the KCDPA and may not be processed without the consumer's consent.observed
The KCDPA's own under-13 sensitive-data protection is Tier-1 confirmed; the broader minors' online-safety bill landscape (Kids Code, HB12/227) rests on unconfirmed enactment status and is flagged as a gap.
Primary frameworkKCDPA (child sensitive-data provision); status of Kentucky Kids Code (HB633) and related minors' bills unconfirmed
Traffic-light rationale — AmberThe KCDPA's own under-13 sensitive-data protection is Tier-1 confirmed; the broader minors' online-safety bill landscape (Kids Code, HB12/227) rests on unconfirmed enactment status and is flagged as a gap.
Sub-modules (5)
Age VerificationAmber
House Bill 12 would introduce age-verification requirements for social-media account creation; enactment status unconfirmed.
Claims (1):
Kentucky's House Bill 12 seeks to enhance online protections for minors by regulating social media account creation and enforcing age verification.
Parental ConsentGreen
Data from a known child under 13 is 'sensitive data' requiring consent under the KCDPA, aligning with COPPA-style parental-consent norms.
Claims (1):
The KCDPA classifies personal data collected from a known child younger than 13 as 'sensitive data,' requiring consumer consent before processing, aligning with COPPA-style protections for young children.
Minor Profiling BansAmber
The Kentucky Kids Code (HB633) would impose stringent data-privacy requirements for online services aimed at minors; enactment status could not be confirmed.
Claims (1):
House Bill 633, the Kentucky Kids Code, would introduce stringent data-privacy requirements for online services targeting minors; as of the most recent tracked update, this bill's enactment status could not be independently confirmed from ag.ky.gov or verified legislative-history sources.
Education SettingsRed
No education-setting-specific children's-data provision was located.
Absence provenance: not recorded. Searched: Kentucky student data privacy education children.
Dependent AdultsRed
No dependent-adult / incapacitated-persons data-protection provision was located.
Absence provenance: not recorded. Searched: Kentucky dependent adult data privacy protection.
Key findings (3)
Under-13 sensitive-data rule confirmed; Kids Code/HB12/HB227 status unconfirmed. — source on file
Under-13 sensitive-data rule confirmed; Kids Code/HB12/HB227 status unconfirmed. — source on file
Under-13 sensitive-data rule confirmed; Kids Code/HB12/HB227 status unconfirmed. — source on file
Category narrative64 words
The KCDPA treats data from a known child under 13 as 'sensitive data' requiring consent, giving Kentucky a COPPA-aligned baseline. Beyond that, several bills targeting minors online (Kentucky Kids Code / HB633, HB12, HB227) and age-verification/social-media provisions were identified in secondary sources, but their enactment/effective-date status could not be independently confirmed from ag.ky.gov or verified legislative-history sources. No dependent-adult-specific or education-setting-specific provision was located.
Sources and claims (3)
UncertainDataGuidance — Kentucky's House Bill 12 seeks to enhance online protections for minors by regulating social media account creation and enforcing age verification.observed
ConfirmedKentucky Attorney General's Office — The KCDPA classifies personal data collected from a known child younger than 13 as 'sensitive data,' requiring consumer consent before processing, aligning with COPPA-style protections for young children.observed
UncertainDataGuidance — House Bill 633, the Kentucky Kids Code, would introduce stringent data-privacy requirements for online services targeting minors; as of the most recent tracked update, this bill's enactment status could not be independently confirmed from ag.ky.gov or verified legislative-history sources.observed
Traffic-light rationale — GreenEnforcement powers, penalty caps, and recent enforcement activity are corroborated by primary AG court filings and Tier-1 AG guidance pages.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
AG has exclusive KCDPA enforcement authority, a 30-day cure requirement, and can seek civil penalties up to $7,500 per uncured violation plus injunctive relief and fees.
Claims (1):
The Kentucky Attorney General's Office of Data Privacy has exclusive authority to enforce the KCDPA and may seek injunctive relief, civil penalties, and reasonable attorneys' fees and investigative costs; violators that fail to cure within 30 days of notice face civil penalties of up to $7,500 per violation.
Enforcement Activity IndexGreen
Recent AG enforcement activity includes suits against Temu (2025) and Character Technologies (2026), both brought under general consumer-protection authority rather than the KCDPA itself.
Claims (2):
In January 2026, the Kentucky Attorney General filed a parens patriae enforcement action against Character Technologies, Inc. alleging AI chatbot safety and data-protection violations.
In July 2025, the Kentucky Attorney General filed a lawsuit against Temu (PDD Holdings/Whaleco) under the Kentucky Consumer Protection Act alleging unlawful collection of sensitive personal information without consent, among other data-practice violations.
Regulator Funding And CapacityRed
No specific funding/headcount data for the Office of Data Privacy was located.
Absence provenance: not recorded. Searched: Kentucky Office of Data Privacy budget staffing headcount.
Collective Redress And Class ActionsAmber
The Kentucky Consumer Protection Act, used separately from the KCDPA in recent AG suits, does not appear from available sources to provide a distinct private class-action mechanism beyond AG enforcement.
Claims (1):
Separately from the KCDPA, Kentucky's general Consumer Protection Act (KRS 367.110 et seq.) has been used by the Attorney General to bring data-practice-related enforcement actions (e.g., against Temu), but this statute likewise does not appear to provide a private class-action mechanism distinct from AG enforcement based on available sources.
Private Right Of ActionGreen
The KCDPA provides no private right of action; enforcement is exclusive to the Attorney General.
Claims (1):
The KCDPA does not provide Kentucky consumers with a private right of action; enforcement runs exclusively through the Attorney General's Office of Data Privacy.
Recent Developments 180DGreen
Within roughly the last 180 days: HB473's KCDPA amendments (HIPAA/DPIA narrowing) took effect June 1, 2026; HB692 (automatic content recognition / smart monitor consent amendment) was signed in 2026 for a July 1, 2027 effective date.
Claims (2):
House Bill 473, effective June 1, 2026, amended the KCDPA to exempt certain HIPAA-regulated health information and to narrow the profiling-related DPIA trigger to cases involving disparate impact.
House Bill 692, signed into law in 2026, amends the KCDPA to define 'automatic content recognition' and 'smart monitor' and to require consumer consent for data collection via such technologies, with an effective date of July 1, 2027.
Key findings (3)
Sole AG enforcement, no PRA, active enforcement (Temu, Character Technologies). — source on file
Sole AG enforcement, no PRA, active enforcement (Temu, Character Technologies). — source on file
Sole AG enforcement, no PRA, active enforcement (Temu, Character Technologies). — source on file
Category narrative96 words
Enforcement runs exclusively through the AG's Office of Data Privacy, with a non-sunsetting 30-day cure period and civil penalties up to $7,500 per uncured violation; there is no private right of action. The AG has also used its general Consumer Protection Act authority (not the KCDPA itself) to bring recent high-profile data-practice suits against Temu (July 2025) and Character Technologies (January 2026), evidencing active enforcement posture ahead of and following KCDPA's January 1, 2026 effective date. HB473 (effective June 1, 2026) and HB692 (signed 2026, effective July 1, 2027) represent recent legislative developments amending the KCDPA.
Sources and claims (7)
ConfirmedKentucky Attorney General's Office — The Kentucky Attorney General's Office of Data Privacy has exclusive authority to enforce the KCDPA and may seek injunctive relief, civil penalties, and reasonable attorneys' fees and investigative costs; violators that fail to cure within 30 days of notice face civil penalties of up to $7,500 per violation.observed
ConfirmedKentucky Attorney General's Office / Franklin Circuit Court — In January 2026, the Kentucky Attorney General filed a parens patriae enforcement action against Character Technologies, Inc. alleging AI chatbot safety and data-protection violations.observed
ConfirmedKentucky Attorney General's Office / Woodford Circuit Court — In July 2025, the Kentucky Attorney General filed a lawsuit against Temu (PDD Holdings/Whaleco) under the Kentucky Consumer Protection Act alleging unlawful collection of sensitive personal information without consent, among other data-practice violations.observed
UncertainKentucky Attorney General's Office / Woodford Circuit Court — Separately from the KCDPA, Kentucky's general Consumer Protection Act (KRS 367.110 et seq.) has been used by the Attorney General to bring data-practice-related enforcement actions (e.g., against Temu), but this statute likewise does not appear to provide a private class-action mechanism distinct from AG enforcement based on available sources.observed
ConfirmedKentucky Attorney General's Office — The KCDPA does not provide Kentucky consumers with a private right of action; enforcement runs exclusively through the Attorney General's Office of Data Privacy.observed
ConfirmedDataGuidance — House Bill 473, effective June 1, 2026, amended the KCDPA to exempt certain HIPAA-regulated health information and to narrow the profiling-related DPIA trigger to cases involving disparate impact.observed
ProbableDataGuidance — House Bill 692, signed into law in 2026, amends the KCDPA to define 'automatic content recognition' and 'smart monitor' and to require consumer consent for data collection via such technologies, with an effective date of July 1, 2027.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Kentucky
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 14 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
regulator_and_framework, data_subject_rights, and enforcement_and_redress rest primarily on Tier-1 ag.ky.gov guidance and primary court filings (Temu, Character Technologies complaints), giving high confidence. lawful_processing_and_special_data and algorithmic_biometric_and_surveillance_governance mix Tier-1 (sensitive-data definitions) with Tier-3 secondary commentary (DPIA/ADM framing). controller_processor_duties is partially confirmed (DPIA, contracts, breach law) but has genuine gaps on DPO/ROPA/retention. sectoral_watch and adtech_and_commercial_privacy rely more heavily on Tier-3/Tier-4 secondary sources and general multi-state pattern-matching (GLBA exemption, dark patterns, UOOM) rather than direct KCDPA statutory text. children_and_vulnerable_groups is confirmed for the under-13 sensitive-data rule but the broader minors' bill landscape (Kids Code HB633, HB12, HB227) has unconfirmed enactment status. cross_border_and_adequacy is a genuine, well-evidenced regulatory gap (no US state-level transfer/adequacy/localisation regime).
Unresolved questions (7):
Exact KCDPA statutory text (KRS 367.3611–367.3629) was not directly parsed; all thresholds/exemptions are drawn from AG-published summaries and secondary legal commentary rather than the codified text itself.
Whether the KCDPA's GLBA/financial-institution exemption is entity-level or data-level was not directly confirmed from KY statutory text.
Enactment/effective-date status of the Kentucky Kids Code (HB633), HB12 (social media age verification), and HB227 (addictive platforms) could not be confirmed.
Exact signing date and full provisions of HB692 (automatic content recognition / smart monitor) beyond its July 1, 2027 effective date were not confirmed.
Whether the KCDPA recognizes universal opt-out mechanisms (e.g., Global Privacy Control) or contains an explicit dark-patterns prohibition was not confirmed.
DPO-appointment, ROPA, and data-retention/disposal obligations under the KCDPA could not be confirmed or disconfirmed from available sources.
Exact effective date and full scope of Senate Bill 4 (public-sector AI governance) and the Kentucky Insurance Data Security Act were not independently confirmed.