Kentucky — Comprehensive Law

Kentucky Privacy Law

Kentucky enacted its comprehensive law in 2024 and amended it two years later to reach something no other state in the region regulates: the pictures on a television screen. House Bill 692 of 2026, chapter 118 of the session acts, defines “automatic content recognition data” — the record of what a smart television or smart monitor displays, identified in real time by audio or video fingerprinting or watermark detection — and, from July 1, 2027, bars a controller from collecting it without consent. The Act also funds its own enforcement: KRS 367.3629 creates a non-lapsing consumer privacy fund into which every civil penalty is deposited for the Attorney General’s use, and the Office of Data Privacy that spends it has exclusive authority over the statute. Kentucky’s breach law, by contrast, is among the narrowest in the country and requires no notice to the Attorney General at all.

The Kentucky Consumer Data Protection Act (KCDPA)

Enacted as House Bill 15 in the 2024 regular session (2024 Ky. Acts ch. 72) and effective January 1, 2026, the KCDPA occupies KRS 367.3611 through 367.3629. Its exemptions are wider than most: KRS 367.3613 removes cities, state agencies and political subdivisions, financial institutions and Gramm-Leach-Bliley data, HIPAA covered entities and business associates, and — unlike Delaware or Oregon — every nonprofit organization and every institution of higher education, together with certain insurance-fraud investigative entities recognised under KRS 304.47-060(1)(e). Two features are Kentucky’s own. KRS 367.3629 establishes the consumer privacy fund, a trust and agency account administered by the Office of the Attorney General into which all civil penalties are paid, with interest accruing to the fund and any balance carried forward rather than lapsing at the close of the fiscal year. And 2026 Ky. Acts ch. 118, effective July 1, 2027, adds “automatic content recognition data” to KRS 367.3611 and a standalone consent duty at KRS 367.3617(1)(f). The chapter contains no opt-out preference signal requirement and no rulemaking authority.

Effective dateJanuary 1, 2026
CitationKy. Rev. Stat. §§ 367.3611 to 367.3629
Enforced byKentucky Attorney General, Office of Data Privacy
Maximum penaltyUp to $7,500 for each continued violation under Ky. Rev. Stat. § 367.3627(3)
Private right of actionNo, enforcement by the state only
Right to cure30 days, with no sunset date (Ky. Rev. Stat. § 367.3627(2))

Who Must Comply

The KCDPA reaches a business that conducts business in the Commonwealth or produces products or services targeted to Kentucky residents, and during a calendar year controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data.

Penalties are paid into a non-lapsing consumer privacy fund the Attorney General spends on enforcement, nonprofits and universities are exempt outright, and from July 1, 2027 smart-television content-recognition data may not be collected without consent.

Consumer Rights Under the KCDPA

Residents of Kentucky can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Kentucky

Student data and cloud computing service providers (Ky. Rev. Stat. § 365.734)

Enacted alongside the breach statute in 2014 Ky. Acts ch. 84, KRS 365.734 regulates any person other than an educational institution that operates a service marketed and designed to give a kindergarten-through-grade-twelve institution account-based access to online computing resources. Subsection (1)(f) defines “student data” expansively — any information in any medium concerning a student and created or provided by the student in the course of using the service, or by an employee or agent of the institution in connection with it, including the student’s name, e-mail address, e-mail messages, postal address, phone number, and any documents, photos or unique identifiers relating to the student. Subsection (2) confines processing to providing, improving, developing or maintaining the integrity of the service absent express parental permission, permits assistance with educational research as allowed by the Family Educational Rights and Privacy Act, and then imposes three absolute bars: the provider may not process student data to advertise or facilitate advertising, may not create or correct an individual or household profile for any advertising purpose, and may not sell, disclose or otherwise process student data for any commercial purpose. Subsection (3) requires written certification of compliance to the institution on entering an agreement, and subsection (4) authorises the Kentucky Board of Education to promulgate administrative regulations under KRS chapter 13A.

Consumer Protection Act — unlawful acts (Ky. Rev. Stat. § 367.170)

Kentucky’s general unfair-practices statute is two sentences long and one of them is a rule of construction found in few other states. KRS 367.170(1) declares unlawful “[u]nfair, false, misleading, or deceptive acts or practices in the conduct of any trade or commerce”. Subsection (2), added by 1976 Ky. Acts ch. 221, then provides that “for the purposes of this section, unfair shall be construed to mean unconscionable” — a definition that sets a higher bar for the unfairness prong than the federal substantial-injury test the FTC applies under section 5. The chapter’s remedial provisions at KRS 367.110 to 367.300 and its penalties at KRS 367.990 are the machinery behind the Attorney General’s privacy litigation, and the KCDPA sits in the same chapter.

Automatic content recognition and smart monitors (Ky. Rev. Stat. §§ 367.3611, 367.3617, eff. July 1, 2027)

House Bill 692, chapter 118 of the 2026 acts, adds two definitions and one duty. KRS 367.3611(3), as amended, defines “automatic content recognition data” as data about a consumer’s content viewing history collected through technology embedded or operated through a smart television or smart monitor that identifies, in real time, the specific content displayed by analysing audio or video fingerprints — including content received through broadcast, cable, satellite, streaming services or external inputs — through digital fingerprinting, watermark detection or similar comparison techniques. The definition excludes data about interactions with the controller’s own services, data generated in providing a feature the consumer requested, and data collected to enforce terms of service. KRS 367.3611(30) defines a “smart monitor” as a display device integrating hardware and software to enable internet connectivity, application execution and independent media streaming, excluding voice assistant devices and mobile devices. The operative duty is at KRS 367.3617(1)(f): a controller shall “[n]ot collect automatic content recognition data without a consumer’s consent.” It is a standalone controller duty rather than an addition to the sensitive-data list — the definition of sensitive data at KRS 367.3611(29) as amended still runs only to data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation or citizenship or immigration status, genetic or biometric data processed to identify a person, data collected from a known child, and precise geolocation data.

Data Breach Notification in Kentucky

KRS 365.732, created by 2014 Ky. Acts ch. 84, is narrower than most state breach statutes in three separate ways. Its definition of a breach is itself a harm test: under KRS 365.732(1)(a) an unauthorized acquisition of unencrypted and unredacted computerized data is a “breach of the security of the system” only where it “actually causes, or leads the information holder to reasonably believe has caused or will cause, identity theft or fraud” against a Kentucky resident, and only where the data was maintained as part of a database regarding multiple individuals. Its definition of personally identifiable information at KRS 365.732(1)(c) lists three data elements beside a name — a Social Security number, a driver’s license number, and an account, credit or debit card number with the code permitting access — without the medical, biometric or health-insurance categories that neighbouring states added. And it directs no notice to any state regulator: subsection (2) requires disclosure to the affected resident in the most expedient time possible and without unreasonable delay, subsection (3) requires a non-owner to tell the owner or licensee, and subsection (7) requires notice to the nationwide consumer reporting agencies and credit bureaus once more than 1,000 persons are notified at one time, but nothing in the section requires notice to the Attorney General. Substitute notice becomes available under subsection (5)(c) where the cost of notice would exceed $250,000, the affected class exceeds 500,000, or contact information is insufficient. Subsection (8) removes persons subject to Title V of the Gramm-Leach-Bliley Act or HIPAA, and state and local government bodies, from both this section and the nonaffiliated third-party requirements of KRS chapter 61.

Residents must be notified in the most expedient time possible and without unreasonable delay. No notice to the Attorney General is required of private information holders. Complaints are taken by the Kentucky Attorney General, which enforces the statute.

How the KCDPA Is Enforced

The consumer privacy fund. KRS 367.3629 creates a trust and agency account known as the consumer privacy fund, administered by the Office of the Attorney General. All civil penalties collected under KRS 367.3611 to 367.3629 are deposited into it, interest earned accrues to it, and the money is to be used by the office to enforce those sections. The section then displaces the ordinary lapse rule: notwithstanding KRS 45.229, any balance remaining at the close of the fiscal year does not lapse but is carried forward into the succeeding year for the same purpose. House Bill 15 carried the title “AN ACT relating to consumer data privacy and making an appropriation therefor”, and this section is the appropriation.

Exclusive authority and the cure period. KRS 367.3627(1) gives the Attorney General exclusive authority to enforce the KCDPA, exercisable in the name of the Commonwealth or on behalf of residents, with all the powers and duties granted under KRS chapter 15 to investigate and prosecute, and the power to demand information, documentary material or physical evidence from any controller or processor believed to be engaged in or about to engage in a violation. Subsection (2) requires 30 days’ written notice identifying the specific provisions alleged to have been violated; a controller that cures within that window and provides an express written statement that the violation has been cured and that no further violations will occur is not subject to an action for damages. Unlike the cure periods in Connecticut, Delaware, Minnesota, Montana, New Hampshire and Oregon, this one carries no sunset date. Subsection (4) forecloses a private right of action; subsection (5) allows recovery of investigative expenses, court costs and fees.

Recent Enforcement in Kentucky

Commonwealth v. PDD Holdings and Whaleco (Temu) — Woodford Circuit Court, July 2025. On July 17, 2025 the Attorney General filed suit in Woodford Circuit Court, case number 25-CI-00232, against PDD Holdings Inc., formerly Pinduoduo Inc., and Whaleco Inc. doing business as Temu. The complaint is brought under the Kentucky Consumer Protection Act, KRS 367.110 et seq., and count one is pleaded as “unfair and deceptive acts and practices in violation of Kentucky Consumer Protection Act (KCPA) — privacy harms” under KRS 367.170, with a second count following. The Commonwealth alleges that the Temu application collected users’ sensitive personally identifiable information without their knowledge or consent, that it exploited vulnerabilities in mobile operating systems to obtain access to data stored on the device, and that it was designed to recompile itself after installation in a way that frustrated detection. The complaint also pleads counterfeiting claims involving Kentucky marks. It demands a jury trial and seeks the penalties available for willful violations of KRS 367.170.

Pending Privacy Legislation

The 2026 regular session produced the first substantive amendment to the KCDPA since its enactment. House Bill 692, chapter 118 of the 2026 acts, amends KRS 367.3611 to define automatic content recognition data and the smart monitors that generate it, and amends KRS 367.3617 to add the consent duty at subsection (1)(f); both take effect July 1, 2027, which is why the codified chapter currently carries two versions of KRS 367.3611 and KRS 367.3617, one effective until that date and one effective from it. The 2026 session separately created KRS 367.367 to 367.369 governing proxy advisors, effective July 15, 2026, which routes non-compliance through the same KRS 367.170 unlawful-acts provision the privacy statutes rely on but is not itself a privacy measure. Nothing in either session altered KRS 365.732, which has stood unamended since 2014 Ky. Acts ch. 84.

Federal Privacy Laws That Apply in Kentucky

Federal privacy law applies in Kentucky by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The KCDPA sits alongside those rules rather than displacing them: the Kentucky Attorney General, Office of Data Privacy enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Consumer Protection Act — unlawful acts (Ky. Rev. Stat. § 367.170), which the Kentucky Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Kentucky Privacy Law FAQ

What is “automatic content recognition data” under Kentucky law?
KRS 367.3611(3), as amended by 2026 Ky. Acts ch. 118 effective July 1, 2027, defines it as data about a consumer’s content viewing history collected through technology embedded or operated through a smart television or smart monitor that identifies, in real time, the specific content displayed by analysing audio or video fingerprints — including content received through broadcast, cable, satellite, streaming services or external inputs — using digital fingerprinting, watermark detection or similar comparison techniques. It excludes data about a consumer’s interactions with the controller’s own services, data generated in providing a feature the consumer requested, and data collected to enforce terms of service.
Is smart-television viewing data treated as sensitive data in Kentucky?
No, and the distinction matters because the two categories carry different duties. The consent requirement sits in KRS 367.3617(1)(f), which provides that a controller shall not collect automatic content recognition data without a consumer’s consent. The sensitive-data definition at KRS 367.3611(29), as amended by the same 2026 act, still lists only data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation or citizenship or immigration status; genetic or biometric data processed to identify a specific person; data collected from a known child; and precise geolocation data.
Does Kentucky require breach notice to the Attorney General?
KRS 365.732 imposes no such duty on private information holders. Subsection (2) requires disclosure to the affected Kentucky resident, subsection (3) requires a holder of data it does not own to notify the owner or licensee, and subsection (7) requires notice to the nationwide consumer reporting agencies and credit bureaus where more than 1,000 persons are notified at one time. No subsection directs notice to the Attorney General or to any other state office.
How narrow is Kentucky’s definition of a data breach?
The harm test is built into the definition rather than added as a separate trigger. Under KRS 365.732(1)(a) an unauthorized acquisition of unencrypted and unredacted computerized data qualifies only where it compromises the security, confidentiality or integrity of personally identifiable information maintained as part of a database regarding multiple individuals and “actually causes, or leads the information holder to reasonably believe has caused or will cause, identity theft or fraud” against a Kentucky resident. Good-faith acquisition by an employee or agent is excluded where the information is not used or further disclosed.
What happens to civil penalties collected under the KCDPA?
They stay with the enforcer. KRS 367.3629 creates the consumer privacy fund as a trust and agency account administered by the Office of the Attorney General, requires all civil penalties collected under KRS 367.3611 to 367.3629 to be deposited into it, provides that interest accrues to the fund, and directs that the money be used to enforce those sections. Notwithstanding KRS 45.229, any balance at the close of a fiscal year is carried forward rather than lapsing.
Are nonprofits and universities covered by the KCDPA?
No. KRS 367.3613 exempts nonprofit organizations and institutions of higher education outright, alongside cities, state agencies and political subdivisions, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, and certain entities recognised under KRS 304.47-060(1)(e) that handle data solely to identify or investigate suspected insurance fraud. That is a wider entity-level carve-out than Delaware, Oregon or Montana adopted.
What may a Kentucky cloud provider do with K-12 student data?
KRS 365.734(2) confines processing to providing, improving, developing or maintaining the integrity of the cloud computing service, unless the provider has express permission from the student’s parent, and permits assistance with educational research as allowed by the Family Educational Rights and Privacy Act. It then bars processing student data to advertise or to facilitate advertising, barring creation or correction of an individual or household profile for any advertising purpose, and bars selling, disclosing or otherwise processing student data for any commercial purpose. Subsection (3) requires the provider to certify compliance in writing to the educational institution.

Sources

This guide describes what these documents say. Follow them to check the description against the source.

  1. Ky. Rev. Stat. § 367.3611 — Definitions (effective until July 1, 2027) statute
  2. Ky. Rev. Stat. § 367.3611 — Definitions (effective July 1, 2027) statute
  3. Ky. Rev. Stat. § 367.3613 — Application, limitations and exemptions statute
  4. Ky. Rev. Stat. § 367.3617 — Controller limitations (effective July 1, 2027) statute
  5. Ky. Rev. Stat. § 367.3627 — Enforcement authority of the Attorney General statute
  6. Ky. Rev. Stat. § 367.3629 — Consumer privacy fund statute
  7. Ky. Rev. Stat. § 365.732 — Notification of computer security breach statute
  8. Ky. Rev. Stat. § 365.734 — Student information and cloud computing providers statute
  9. Ky. Rev. Stat. § 367.170 — Unlawful acts statute
  10. 2026 Ky. Acts ch. 118 (House Bill 692) — automatic content recognition legislation
  11. House Bill 15 (2024) — Kentucky Consumer Data Protection Act as engrossed legislation
  12. Kentucky Attorney General — Office of Data Privacy agency
  13. Commonwealth v. PDD Holdings and Whaleco (Temu), Woodford Cir. Ct. No. 25-CI-00232 (complaint) docket
  14. Kentucky Attorney General — Temu lawsuit announcement agency
  15. 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
  16. 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
  17. 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
  18. 15 U.S.C. 1681 — Fair Credit Reporting Act statute
  19. 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
  20. Section 5 of the FTC Act, 15 U.S.C. 45 statute

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.