Kentucky Privacy Law
Kentucky enacted its comprehensive law in 2024 and amended it two years later to reach something no other state in the region regulates: the pictures on a television screen. House Bill 692 of 2026, chapter 118 of the session acts, defines “automatic content recognition data” — the record of what a smart television or smart monitor displays, identified in real time by audio or video fingerprinting or watermark detection — and, from July 1, 2027, bars a controller from collecting it without consent. The Act also funds its own enforcement: KRS 367.3629 creates a non-lapsing consumer privacy fund into which every civil penalty is deposited for the Attorney General’s use, and the Office of Data Privacy that spends it has exclusive authority over the statute. Kentucky’s breach law, by contrast, is among the narrowest in the country and requires no notice to the Attorney General at all.
The Kentucky Consumer Data Protection Act (KCDPA)
Enacted as House Bill 15 in the 2024 regular session (2024 Ky. Acts ch. 72) and effective January 1, 2026, the KCDPA occupies KRS 367.3611 through 367.3629. Its exemptions are wider than most: KRS 367.3613 removes cities, state agencies and political subdivisions, financial institutions and Gramm-Leach-Bliley data, HIPAA covered entities and business associates, and — unlike Delaware or Oregon — every nonprofit organization and every institution of higher education, together with certain insurance-fraud investigative entities recognised under KRS 304.47-060(1)(e). Two features are Kentucky’s own. KRS 367.3629 establishes the consumer privacy fund, a trust and agency account administered by the Office of the Attorney General into which all civil penalties are paid, with interest accruing to the fund and any balance carried forward rather than lapsing at the close of the fiscal year. And 2026 Ky. Acts ch. 118, effective July 1, 2027, adds “automatic content recognition data” to KRS 367.3611 and a standalone consent duty at KRS 367.3617(1)(f). The chapter contains no opt-out preference signal requirement and no rulemaking authority.
| Effective date | January 1, 2026 |
|---|---|
| Citation | Ky. Rev. Stat. §§ 367.3611 to 367.3629 |
| Enforced by | Kentucky Attorney General, Office of Data Privacy |
| Maximum penalty | Up to $7,500 for each continued violation under Ky. Rev. Stat. § 367.3627(3) |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days, with no sunset date (Ky. Rev. Stat. § 367.3627(2)) |
Who Must Comply
The KCDPA reaches a business that conducts business in the Commonwealth or produces products or services targeted to Kentucky residents, and during a calendar year controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data.
Penalties are paid into a non-lapsing consumer privacy fund the Attorney General spends on enforcement, nonprofits and universities are exempt outright, and from July 1, 2027 smart-television content-recognition data may not be collected without consent.
Consumer Rights Under the KCDPA
Residents of Kentucky can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Kentucky
Student data and cloud computing service providers (Ky. Rev. Stat. § 365.734)
Enacted alongside the breach statute in 2014 Ky. Acts ch. 84, KRS 365.734 regulates any person other than an educational institution that operates a service marketed and designed to give a kindergarten-through-grade-twelve institution account-based access to online computing resources. Subsection (1)(f) defines “student data” expansively — any information in any medium concerning a student and created or provided by the student in the course of using the service, or by an employee or agent of the institution in connection with it, including the student’s name, e-mail address, e-mail messages, postal address, phone number, and any documents, photos or unique identifiers relating to the student. Subsection (2) confines processing to providing, improving, developing or maintaining the integrity of the service absent express parental permission, permits assistance with educational research as allowed by the Family Educational Rights and Privacy Act, and then imposes three absolute bars: the provider may not process student data to advertise or facilitate advertising, may not create or correct an individual or household profile for any advertising purpose, and may not sell, disclose or otherwise process student data for any commercial purpose. Subsection (3) requires written certification of compliance to the institution on entering an agreement, and subsection (4) authorises the Kentucky Board of Education to promulgate administrative regulations under KRS chapter 13A.
Consumer Protection Act — unlawful acts (Ky. Rev. Stat. § 367.170)
Kentucky’s general unfair-practices statute is two sentences long and one of them is a rule of construction found in few other states. KRS 367.170(1) declares unlawful “[u]nfair, false, misleading, or deceptive acts or practices in the conduct of any trade or commerce”. Subsection (2), added by 1976 Ky. Acts ch. 221, then provides that “for the purposes of this section, unfair shall be construed to mean unconscionable” — a definition that sets a higher bar for the unfairness prong than the federal substantial-injury test the FTC applies under section 5. The chapter’s remedial provisions at KRS 367.110 to 367.300 and its penalties at KRS 367.990 are the machinery behind the Attorney General’s privacy litigation, and the KCDPA sits in the same chapter.
Automatic content recognition and smart monitors (Ky. Rev. Stat. §§ 367.3611, 367.3617, eff. July 1, 2027)
House Bill 692, chapter 118 of the 2026 acts, adds two definitions and one duty. KRS 367.3611(3), as amended, defines “automatic content recognition data” as data about a consumer’s content viewing history collected through technology embedded or operated through a smart television or smart monitor that identifies, in real time, the specific content displayed by analysing audio or video fingerprints — including content received through broadcast, cable, satellite, streaming services or external inputs — through digital fingerprinting, watermark detection or similar comparison techniques. The definition excludes data about interactions with the controller’s own services, data generated in providing a feature the consumer requested, and data collected to enforce terms of service. KRS 367.3611(30) defines a “smart monitor” as a display device integrating hardware and software to enable internet connectivity, application execution and independent media streaming, excluding voice assistant devices and mobile devices. The operative duty is at KRS 367.3617(1)(f): a controller shall “[n]ot collect automatic content recognition data without a consumer’s consent.” It is a standalone controller duty rather than an addition to the sensitive-data list — the definition of sensitive data at KRS 367.3611(29) as amended still runs only to data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation or citizenship or immigration status, genetic or biometric data processed to identify a person, data collected from a known child, and precise geolocation data.
Data Breach Notification in Kentucky
KRS 365.732, created by 2014 Ky. Acts ch. 84, is narrower than most state breach statutes in three separate ways. Its definition of a breach is itself a harm test: under KRS 365.732(1)(a) an unauthorized acquisition of unencrypted and unredacted computerized data is a “breach of the security of the system” only where it “actually causes, or leads the information holder to reasonably believe has caused or will cause, identity theft or fraud” against a Kentucky resident, and only where the data was maintained as part of a database regarding multiple individuals. Its definition of personally identifiable information at KRS 365.732(1)(c) lists three data elements beside a name — a Social Security number, a driver’s license number, and an account, credit or debit card number with the code permitting access — without the medical, biometric or health-insurance categories that neighbouring states added. And it directs no notice to any state regulator: subsection (2) requires disclosure to the affected resident in the most expedient time possible and without unreasonable delay, subsection (3) requires a non-owner to tell the owner or licensee, and subsection (7) requires notice to the nationwide consumer reporting agencies and credit bureaus once more than 1,000 persons are notified at one time, but nothing in the section requires notice to the Attorney General. Substitute notice becomes available under subsection (5)(c) where the cost of notice would exceed $250,000, the affected class exceeds 500,000, or contact information is insufficient. Subsection (8) removes persons subject to Title V of the Gramm-Leach-Bliley Act or HIPAA, and state and local government bodies, from both this section and the nonaffiliated third-party requirements of KRS chapter 61.
Residents must be notified in the most expedient time possible and without unreasonable delay. No notice to the Attorney General is required of private information holders. Complaints are taken by the Kentucky Attorney General, which enforces the statute.
How the KCDPA Is Enforced
The consumer privacy fund. KRS 367.3629 creates a trust and agency account known as the consumer privacy fund, administered by the Office of the Attorney General. All civil penalties collected under KRS 367.3611 to 367.3629 are deposited into it, interest earned accrues to it, and the money is to be used by the office to enforce those sections. The section then displaces the ordinary lapse rule: notwithstanding KRS 45.229, any balance remaining at the close of the fiscal year does not lapse but is carried forward into the succeeding year for the same purpose. House Bill 15 carried the title “AN ACT relating to consumer data privacy and making an appropriation therefor”, and this section is the appropriation.
Exclusive authority and the cure period. KRS 367.3627(1) gives the Attorney General exclusive authority to enforce the KCDPA, exercisable in the name of the Commonwealth or on behalf of residents, with all the powers and duties granted under KRS chapter 15 to investigate and prosecute, and the power to demand information, documentary material or physical evidence from any controller or processor believed to be engaged in or about to engage in a violation. Subsection (2) requires 30 days’ written notice identifying the specific provisions alleged to have been violated; a controller that cures within that window and provides an express written statement that the violation has been cured and that no further violations will occur is not subject to an action for damages. Unlike the cure periods in Connecticut, Delaware, Minnesota, Montana, New Hampshire and Oregon, this one carries no sunset date. Subsection (4) forecloses a private right of action; subsection (5) allows recovery of investigative expenses, court costs and fees.
Recent Enforcement in Kentucky
Commonwealth v. PDD Holdings and Whaleco (Temu) — Woodford Circuit Court, July 2025. On July 17, 2025 the Attorney General filed suit in Woodford Circuit Court, case number 25-CI-00232, against PDD Holdings Inc., formerly Pinduoduo Inc., and Whaleco Inc. doing business as Temu. The complaint is brought under the Kentucky Consumer Protection Act, KRS 367.110 et seq., and count one is pleaded as “unfair and deceptive acts and practices in violation of Kentucky Consumer Protection Act (KCPA) — privacy harms” under KRS 367.170, with a second count following. The Commonwealth alleges that the Temu application collected users’ sensitive personally identifiable information without their knowledge or consent, that it exploited vulnerabilities in mobile operating systems to obtain access to data stored on the device, and that it was designed to recompile itself after installation in a way that frustrated detection. The complaint also pleads counterfeiting claims involving Kentucky marks. It demands a jury trial and seeks the penalties available for willful violations of KRS 367.170.
Pending Privacy Legislation
The 2026 regular session produced the first substantive amendment to the KCDPA since its enactment. House Bill 692, chapter 118 of the 2026 acts, amends KRS 367.3611 to define automatic content recognition data and the smart monitors that generate it, and amends KRS 367.3617 to add the consent duty at subsection (1)(f); both take effect July 1, 2027, which is why the codified chapter currently carries two versions of KRS 367.3611 and KRS 367.3617, one effective until that date and one effective from it. The 2026 session separately created KRS 367.367 to 367.369 governing proxy advisors, effective July 15, 2026, which routes non-compliance through the same KRS 367.170 unlawful-acts provision the privacy statutes rely on but is not itself a privacy measure. Nothing in either session altered KRS 365.732, which has stood unamended since 2014 Ky. Acts ch. 84.
Federal Privacy Laws That Apply in Kentucky
Federal privacy law applies in Kentucky by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The KCDPA sits alongside those rules rather than displacing them: the Kentucky Attorney General, Office of Data Privacy enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Consumer Protection Act — unlawful acts (Ky. Rev. Stat. § 367.170), which the Kentucky Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Kentucky Privacy Law FAQ
What is “automatic content recognition data” under Kentucky law?
Is smart-television viewing data treated as sensitive data in Kentucky?
Does Kentucky require breach notice to the Attorney General?
How narrow is Kentucky’s definition of a data breach?
What happens to civil penalties collected under the KCDPA?
Are nonprofits and universities covered by the KCDPA?
What may a Kentucky cloud provider do with K-12 student data?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Ky. Rev. Stat. § 367.3611 — Definitions (effective until July 1, 2027) statute
- Ky. Rev. Stat. § 367.3611 — Definitions (effective July 1, 2027) statute
- Ky. Rev. Stat. § 367.3613 — Application, limitations and exemptions statute
- Ky. Rev. Stat. § 367.3617 — Controller limitations (effective July 1, 2027) statute
- Ky. Rev. Stat. § 367.3627 — Enforcement authority of the Attorney General statute
- Ky. Rev. Stat. § 367.3629 — Consumer privacy fund statute
- Ky. Rev. Stat. § 365.732 — Notification of computer security breach statute
- Ky. Rev. Stat. § 365.734 — Student information and cloud computing providers statute
- Ky. Rev. Stat. § 367.170 — Unlawful acts statute
- 2026 Ky. Acts ch. 118 (House Bill 692) — automatic content recognition legislation
- House Bill 15 (2024) — Kentucky Consumer Data Protection Act as engrossed legislation
- Kentucky Attorney General — Office of Data Privacy agency
- Commonwealth v. PDD Holdings and Whaleco (Temu), Woodford Cir. Ct. No. 25-CI-00232 (complaint) docket
- Kentucky Attorney General — Temu lawsuit announcement agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.