Key Takeaways
- The Kentucky Consumer Data Protection Act (KCDPA) has been in effect since January 1, 2026. It applies to businesses that process personal data of 100,000 or more Kentucky consumers annually, or 25,000 or more if over 50% of gross revenue comes from selling personal data. There's no standalone revenue-only threshold.
- Consumer rights include access, correction, deletion, portability, and opt-out of targeted advertising, data sales, and certain profiling. Sensitive data requires opt-in consent.
- A March 2025 amendment, HB 473, expanded the law's HIPAA-related exemption to cover protected health information and HIPAA "limited data sets," and made a small technical change to one Data Protection Assessment trigger.
- The Kentucky Attorney General has exclusive enforcement authority. Penalties reach $7,500 per violation, and a permanent 30-day cure period applies. It doesn't sunset, unlike Colorado's or Montana's.
- The law is already being enforced: the AG's Office of Data Privacy filed its first KCDPA lawsuit on January 8, 2026, against an AI chatbot company over children's data practices.
- Data Protection Assessments apply only to processing activities created or generated on or after June 1, 2026, giving businesses a short runway for that specific obligation.
The Kentucky Consumer Data Protection Act (KCDPA) is Kentucky's first comprehensive consumer privacy law. Governor Andy Beshear signed it as House Bill 15 on April 4, 2024, making Kentucky the 15th state to enact this kind of legislation. It took effect January 1, 2026, alongside similar new laws in Indiana and Rhode Island, and has applied for over eight months as of this update. If you're still treating it as a future obligation, you're behind: it's a current compliance requirement, and the Attorney General's office has already brought its first enforcement action.
You'll sometimes see this law called the "Kentucky Consumer Privacy Act" or "KCPA" in vendor content. That's not the statutory name, and it's worth being careful with it: Kentucky also has a separate, older, general consumer-protection statute that's informally abbreviated the same way. This guide uses KCDPA throughout, the name the Kentucky legislature and Attorney General's office both use.
Secure Privacy is a cookie and consent management platform that generates KCDPA-compliant consent flows, rights-request workflows, and Data Protection Assessment templates, alongside GDPR, CCPA, and 55+ other privacy laws.
What Is the KCDPA?
The KCDPA is a comprehensive state consumer data privacy law built on the Virginia Consumer Data Protection Act (VCDPA) model, the same framework that shaped Indiana, Tennessee, and several other states' laws. That lineage matters for compliance planning: if your organization has already built a VCDPA-aligned privacy program, Kentucky requires incremental adjustments rather than a rebuild from scratch. If you haven't addressed any Virginia-model law yet, the infrastructure you build to satisfy Kentucky will cover most of the other Virginia-model states at the same time.
The law reflects a deliberate policy balance: meaningful consumer rights and real business accountability, paired with a framework predictable enough for the mid-market companies that make up much of Kentucky's business base. That shows up as clear applicability thresholds, a narrow definition of data sale, a permanent cure period, and no private right of action. None of that is an invitation to ignore the law. These are structural choices that make compliance more predictable than in California, Colorado, or Connecticut, not a reduction in the underlying obligations once you cross the thresholds.
Who Does the KCDPA Apply To?
The KCDPA applies to any person or entity that conducts business in Kentucky, or produces products or services targeted to Kentucky residents, and that during a calendar year meets one of two volume-based thresholds. The first is controlling or processing the personal data of 100,000 or more Kentucky consumers. The second is controlling or processing the personal data of 25,000 or more Kentucky consumers while deriving more than 50% of gross revenue from the sale of personal data.
There's no standalone revenue threshold like California's CCPA uses. Applicability is tied to data-processing volume, not company size or total revenue. A large enterprise that processes very little Kentucky consumer data may fall outside the law; a mid-sized SaaS platform with heavy behavioral-data processing likely doesn't. The question isn't "how big is our company," it's "how much Kentucky consumer data do we actually process."
"Consumer" under the KCDPA covers Kentucky residents acting in an individual or household context. It excludes people acting in an employment or commercial (B2B) capacity, so employee data, job-applicant data, and business-to-business contact data all sit outside the law's scope. That's a meaningful carve-out compared to California's CPRA, which brought much of that data into its reach. This exclusion is standard across the Virginia model and narrows the practical compliance surface for many organizations.
Who Is Exempt From the KCDPA?
Several categories of entities are exempt entirely:
- State and local government bodies
- Financial institutions and data regulated under the Gramm-Leach-Bliley Act (GLBA)
- Nonprofit organizations
- Institutions of higher education
Entities and data governed by HIPAA are also exempt, and that exemption got more specific in March 2025. A closer look at that change is below.
If your organization falls into one of these categories, the KCDPA doesn't apply to you, though you should verify the exact scope of each exemption against your actual processing activities rather than assuming a categorical pass.
What Counts as Personal Data and Sensitive Data?
Personal data under the KCDPA is any information linked to an identified or identifiable Kentucky consumer. That covers obvious identifiers such as names, email addresses, and Social Security numbers, along with data that can be traced back to a specific person, like browsing behavior, IP addresses, device fingerprints, and purchase history. De-identified data and publicly available information aren't considered personal data.
A narrower category, sensitive data, carries extra protection and requires opt-in consent before processing. It includes:
- Racial or ethnic origin, religious beliefs, mental or physical health diagnosis or condition, sex life or sexual orientation, and citizenship or immigration status
- Genetic data
- Biometric data processed to identify a specific individual
- Personal data collected from a known child
- Precise geolocation data
What Rights Do Kentucky Consumers Have?
Kentucky consumers have five core rights, all of which controllers must honor within 45 days of a verified request, with a 45-day extension available when reasonably necessary: access (confirm processing and get a copy), correction (fix inaccuracies), deletion (subject to narrow exceptions like legal obligations or an in-progress transaction), and portability (get data in a usable format). These four are standard across nearly every Virginia-model state law and broadly consistent with California's CCPA/CPRA, though mechanics differ.
The right to opt out covers three activities: targeted advertising (ads chosen based on a consumer's activity across nonaffiliated sites), the sale of personal data (narrowly defined as an exchange for monetary consideration, not California's broader "valuable consideration" standard), and profiling that produces legal or similarly significant effects.
Notably, the KCDPA doesn't require recognizing universal opt-out mechanisms such as Global Privacy Control. That's a real difference from California, Colorado, and Connecticut, which all require GPC recognition. If Kentucky is the only law you're subject to, you don't need GPC processing for it specifically; if you're also subject to those other states, one infrastructure handling GPC covers all of them.
When a controller denies a rights request, it has to explain the denial and provide an appeal process. If the appeal is also denied, the consumer can file a complaint directly with the Kentucky Attorney General's Office of Data Privacy.
What Obligations Do Businesses Have?
Controllers (the entities that decide why and how personal data gets processed) carry the primary compliance duties. Processors (the vendors that process data on a controller's behalf, like a SaaS platform or analytics tool) must operate under a written contract that spells out the scope of processing, security requirements, and the processor's duty to help the controller meet its KCDPA obligations.
Your privacy notice has to be "reasonably accessible, clear, and meaningful," disclosing the categories of personal data processed, the purposes, how consumers can exercise their rights, the categories of data shared with third parties, and which third parties receive it. A privacy notice that already satisfies California's more demanding disclosure requirements will generally cover Kentucky's as a subset.
Data minimization and purpose limitation require you to collect only what's "adequate, relevant, and reasonably necessary" for the disclosed purpose, and to avoid repurposing data for an incompatible use without disclosing that too. That has direct implications for marketing teams that collect data for one stated purpose and then route it into CRM enrichment, cross-sell targeting, or third-party sharing never disclosed at collection.
Security requires "appropriate administrative, technical, and physical" measures that protect data confidentiality and integrity and reduce foreseeable risk of harm. The KCDPA doesn't prescribe specific technical standards, but "appropriate" scales with data sensitivity, processing volume, and current industry practice.
Controllers also have to process data nondiscriminatorily: no denying goods or services, charging different prices, or providing different quality to consumers who exercise their KCDPA rights. And you can't sell the personal data of, or direct targeted advertising to, anyone under 16 when you know or reasonably should know they're a minor.
Opt-In Consent for Sensitive Data
The KCDPA's sensitive-data rules are one of its most operationally significant features because they flip the law's default. Ordinary personal data runs on an opt-out model. Sensitive data requires opt-in consent before you process it at all.
The statute defines the required consent precisely: a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process their personal data. That can be a written statement, including an electronic one, or any other unambiguous affirmative action. Passive non-objection, pre-checked boxes, or continuing to browse don't meet this bar.
The practical reach is broader than it looks: a health app that infers mental-health conditions from usage patterns, a loyalty program that infers religious affiliation from purchase history, or any system processing precise location data all need a documented, opt-in mechanism before that specific processing happens, not a general privacy-notice disclosure.
Data Protection Assessments
Controllers must conduct and document Data Protection Assessments (DPAs) for certain high-risk processing: targeted advertising, selling personal data, processing sensitive data, and profiling that carries a foreseeable risk of unfair or deceptive treatment, injury to consumers, or intrusion on their privacy.
There's an important timing detail: the DPA requirement applies only to processing activities created or generated on or after June 1, 2026, five months after the law's own effective date. Processing that predates that threshold isn't retroactively captured, though assessing existing high-risk processing is still sound governance, since regulators will expect risk-assessment discipline regardless of the technical trigger date. A single DPA can cover comparable processing operations, reducing the documentation load for organizations with consistent patterns across product lines.
Assessments have to weigh the benefits of the processing against the risks to consumer privacy, with the analysis documented. Unlike California, which requires CPPA submission, you don't file DPAs with any Kentucky authority, but you must keep them available if the Attorney General requests them during an investigation.
The March 2025 HB 473 Amendment
Governor Beshear signed HB 473 on March 15, 2025, amending the KCDPA before it had even taken effect. The amendment became effective January 1, 2026, the same date as the base law, so businesses never operated under the pre-amendment version.
HB 473 made three changes. Most significantly, it expanded the law's HIPAA-related exemption: the original KCDPA exempted HIPAA-covered entities and business associates in general terms, and HB 473 added explicit exemptions for (1) information collected by a health care provider acting as a HIPAA covered entity that maintains protected health information per HIPAA, and (2) information held in HIPAA "limited data sets." This resolved ambiguity about which health data fell outside the KCDPA's scope. It's worth being precise about direction here: this amendment broadened what's exempt, it didn't restrict an existing one. It also made a technical adjustment to one DPA trigger (adding an unlawfulness element to the profiling-related disparate-impact trigger) and narrowed a small-utility exclusion to utilities that share no data with third parties.
If your organization handles health data adjacent to HIPAA, or read an earlier version of this law's exemptions and assumed HIPAA coverage was murky, HB 473 is the update that resolved it. The practical effect for most non-healthcare businesses is minimal.
Enforcement, Penalties, and the Cure Period
The Kentucky Attorney General has exclusive authority to enforce the KCDPA. Consumers don't have a private right of action; they can't sue directly for violations. Instead, they file complaints with the AG's Office of Data Privacy, which investigates and determines whether a violation occurred.
If the Office finds a violation, it notifies the controller or processor, who then has 30 days to cure the violation and provide a written statement confirming it's been remedied and won't recur. If the controller doesn't cure within that window, the AG can sue for civil penalties of up to $7,500 per violation plus injunctive relief.
The cure period is permanent. It doesn't sunset, and no future legislative action is required to keep it in place. That's a meaningfully different posture from Colorado, where the cure right expired January 1, 2025, or Montana, where SB 297 eliminated the cure period entirely in 2025. Kentucky's is one of the most business-friendly enforcement designs among current state comprehensive privacy laws.
Enforcement isn't just theoretical. On January 8, 2026, eight days after the KCDPA took effect, the AG's Office of Data Privacy filed its first enforcement action, against Character Technologies, Inc., an AI chatbot company, alleging KCDPA violations tied to a lack of verifiable parental consent for users under 13, alongside separate claims under other Kentucky and constitutional theories. The AG sought injunctive relief on the KCDPA count, consistent with the law's no-private-damages structure. The Office's early public posture has leaned toward education, but this filing shows it will act quickly on a clear-cut violation, and that shouldn't be read as a promise that enforcement stays light indefinitely.
How the KCDPA Compares to Other State Privacy Laws
The KCDPA's Virginia-model DNA makes it predictable for any organization that has already worked through VCDPA compliance. The consumer rights, applicability thresholds, entity-level exemptions, and narrow monetary-consideration-only definition of "sale" are effectively the same. AG-only enforcement with no private right of action is shared too.
Where it diverges from more demanding state laws comes down to three points. It doesn't require GPC or other universal opt-out signal recognition, unlike California, Colorado, and Connecticut. Its permanent 30-day cure period is more business-friendly than most states offer: California eliminated its cure period for intentional violations, Colorado's sunset in 2024, and Rhode Island (also effective January 1, 2026) has no cure period at all. And it doesn't require the legitimate-interests balancing assessments GDPR demands or Colorado's more complex risk-based framework.
Compared to California's CCPA/CPRA, the KCDPA is narrower on every dimension: lower thresholds, a narrower sale definition, no employee-data coverage, no revenue-only trigger, no GPC requirement, no private right of action, and no rulemaking authority that can expand obligations through regulation. If you've already built a CCPA-compliant program, KCDPA compliance mostly means confirming that program meets Kentucky's specific requirements and that opt-in consent covers sensitive-data processing involving Kentucky consumers.
KCDPA Compliance Checklist
For organizations that meet the KCDPA thresholds, the operational work breaks down into five workstreams:
- Data mapping. Know what personal data you collect, where it comes from, how it's used, who it's shared with, and how long it's retained. Flag which activities involve Kentucky consumers and which touch sensitive-data categories for the opt-in consent audit.
- Privacy notice updates. Your notice must accurately describe data categories, purposes, consumer rights, data-sharing relationships, and third-party categories. A gap between the notice and your data map is both a compliance problem and an enforcement risk.
- Rights-request infrastructure. Build intake, verification, and fulfillment for access, correction, deletion, portability, and opt-out requests, with a documented appeals process for denials, inside the 45-day response window.
- Vendor contract review. Confirm processors handling KCDPA-covered data have written agreements meeting the law's requirements. Existing GDPR DPAs or CCPA service-provider agreements usually cover most of it.
- Data Protection Assessments. Template and schedule DPAs for any new targeted-advertising, sale, sensitive-data, or profiling activity launching on or after June 1, 2026.
FAQ
What is the Kentucky Consumer Data Protection Act?
The Kentucky Consumer Data Protection Act (KCDPA) is Kentucky's first comprehensive consumer data privacy law, effective January 1, 2026. It grants Kentucky consumers rights over their personal data and imposes obligations on businesses that meet the law's applicability thresholds. It's sometimes informally called the "Kentucky Consumer Privacy Act" or "KCPA" in vendor content, but that's not its statutory name.
When did the KCDPA take effect?
January 1, 2026. It has been in force since that date. Data Protection Assessments apply to processing activities created on or after June 1, 2026, a separate, later trigger date for that one specific obligation.
Who has to comply with the KCDPA?
Businesses that conduct business in Kentucky or target Kentucky residents with products or services, and that annually process personal data of 100,000 or more Kentucky consumers, or 25,000 or more if over 50% of gross revenue comes from selling personal data.
Does the KCDPA require consent?
It requires opt-in consent for processing sensitive data categories, including health, genetic, biometric, precise geolocation, and known children's data. For non-sensitive data, it follows an opt-out model: you can process it unless a consumer opts out.
What did the 2025 HB 473 amendment change?
Signed March 15, 2025 and effective January 1, 2026, HB 473 expanded the KCDPA's HIPAA-related exemption to explicitly cover protected health information held by HIPAA-covered health care providers and HIPAA "limited data sets." It also made a minor technical change to one Data Protection Assessment trigger and narrowed a small-utility exclusion.
How is the KCDPA different from the CCPA?
The KCDPA is narrower: no standalone revenue threshold, coverage limited to consumer (not employee) data, a monetary-consideration-only sale definition, no GPC signal recognition requirement, a permanent 30-day cure period, and no private right of action. California's CCPA/CPRA is considerably more expansive across all of these dimensions.
Has Kentucky actually enforced the KCDPA yet?
Yes. The Attorney General's Office of Data Privacy filed its first KCDPA enforcement action on January 8, 2026, against an AI chatbot company, over children's data practices. The law is active, not just nominally in effect.
The KCDPA is in effect now and actively enforced. If your organization already runs a VCDPA-aligned compliance program, the incremental work here is modest. If you haven't addressed any Virginia-model state law yet, Kentucky's arrival, alongside Indiana and Rhode Island in January 2026, is a sign that reactive, one-state-at-a-time compliance no longer works.
See how Secure Privacy's consent management and privacy operations platform helps businesses implement KCDPA-compliant rights workflows, notice management, and Data Protection Assessments across all applicable US state privacy laws.
Sources
- Kentucky General Assembly, HB 15 (2024 Regular Session) bill record
- Kentucky General Assembly, HB 473 (2025 Regular Session) bill record
- Kentucky Attorney General, Office of Data Privacy: Rights of Kentuckians under the KCDPA
- IAPP US State Privacy Legislation Tracker
- National Law Review: Kentucky Amends KCDPA to Exempt HIPAA-Covered Data
- Hunton Andrews Kurth: Kentucky Attorney General Announces First Enforcement Action Under New Privacy Law
- Troutman Pepper Privacy Blog: Kentucky AG Files Lawsuit Against AI Chatbot, Including Claim It Violated New Data Privacy Law
- Koley Jessen: New State Privacy Laws Effective January 1, 2026: Indiana, Kentucky, and Rhode Island



