Kentucky
Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Kentucky has no standalone biometric privacy statute. The Kentucky Consumer Data Protection Act, which took effect January 1, 2026, classifies biometric data as sensitive data and requires businesses to obtain opt-in consent before processing it for identification. The Kentucky Attorney General has exclusive enforcement authority; individual consumers have no private right of action.
Kentucky does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, biometric data protections in the state come primarily from the Kentucky Consumer Data Protection Act (KCDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent.
Governor Andy Beshear signed House Bill 15 into law on April 4, 2024, making Kentucky the 16th state to enact a comprehensive consumer data privacy law. The KCDPA took effect on January 1, 2026.
For an overview of Kentucky's broader privacy framework, see the parent guide to Kentucky Data Privacy Laws.
How the KCDPA Defines Biometric Data
The KCDPA defines biometric data under KRS 367.3611 as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The law draws a clear boundary around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data unless that data is specifically generated to identify a specific individual.
This definition follows the approach used in Connecticut's privacy law and several other state comprehensive privacy statutes. It is narrower than the definition used in Illinois's BIPA, which covers a broader set of biometric identifiers without the same exclusions.
The KCDPA also excludes information collected, used, or stored for health care treatment, payment, or operations under HIPAA from the biometric data definition.

Sensitive Data Classification and Consent
Under the KCDPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data." This is the highest protection category in the law.
Other categories of sensitive data under KRS 367.3611 include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnoses
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Precise geolocation data
- Personal data collected from a known child under 13
Consent requirement. Controllers must obtain a consumer's opt-in consent before processing sensitive data, including biometric data. This means a business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without first asking for and receiving your affirmative agreement.
This consent must be freely given, specific, informed, and unambiguous. A buried clause in a terms-of-service agreement does not meet this standard.
Who Must Comply
The KCDPA applies to entities that conduct business in Kentucky or produce products or services targeted to Kentucky residents and meet one of these thresholds:
- Process personal data of 100,000 or more Kentucky consumers during a calendar year, or
- Process personal data of 25,000 or more Kentucky consumers and derive over 50% of gross revenue from the sale of personal data
The term "sale" under the KCDPA covers only exchanges for monetary consideration. This is a narrower definition than laws in states like California, which also cover non-monetary exchanges.
Key Exemptions
The KCDPA carves out several categories of entities and data types from coverage:
Entity exemptions:
- HIPAA-covered entities and their business associates
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Nonprofit organizations
- Higher education institutions
- Government agencies
Data exemptions:
- Data regulated under HIPAA
- Data governed by the Fair Credit Reporting Act (FCRA)
- Data covered by the Family Educational Rights and Privacy Act (FERPA)
- Data under the Driver's Privacy Protection Act (DPPA)
- Data regulated under the Farm Credit Act

Employee data exemption. The KCDPA excludes persons acting in a commercial or employment context from the definition of "consumer." Data processed about an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party is exempt when used in the context of that role.
This means that if your employer collects your fingerprints for a timekeeping system or uses facial recognition for building access, the KCDPA does not apply to that collection. Kentucky does not have a separate law regulating employer use of biometric data.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal data under the KCDPA, Kentucky consumers have these access, correction, deletion, portability, and opt-out rights under KRS 367.3615, plus a separate non-discrimination protection under the KCDPA:
Right to confirm and access. You can ask any covered business whether it is processing your biometric data and request access to that data.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your biometric data in a portable and readily usable format.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Right to non-discrimination. Businesses cannot penalize you for exercising any of these rights by denying goods or services, charging different prices, or providing a different quality of service.
Businesses must respond to consumer rights requests within 45 days. They can extend this period by an additional 45 days when reasonably necessary, but must notify the consumer of the extension and the reason for it.
Data Protection Assessments
Controllers that process sensitive data, including biometric data, must conduct data protection assessments under the KCDPA. These assessments apply to processing activities created or generated on or after June 1, 2026.
A data protection assessment must weigh the benefits of the processing against the potential risks to the consumer, including risks of:
- Unfair or deceptive treatment or unlawful disparate impact
- Financial, physical, or reputational injury
- Intrusion upon solitude or seclusion
- Other substantial injury
The Kentucky Attorney General can request these assessments during an investigation. They are considered confidential and exempt from public inspection under the Kentucky Open Records Act.
Breach Notification and Biometric Data
Separate from the KCDPA, Kentucky's breach notification law at KRS 365.732 requires businesses to notify affected individuals when a security breach compromises their unencrypted personal information.
Kentucky's breach notification law for private businesses (KRS 365.732) defines personal information as a name combined with a Social Security number, driver's license number, or financial account number; it does not include biometric or genetic data. A separate statute, KRS 61.933, requires government agencies, not private businesses, to notify residents when a breach involves biometric or genetic data, as defined under KRS 61.931. This means a breach that exposes only biometric data linked to your name does not, by itself, trigger a notification duty for a private business under Kentucky's breach law.
The notification obligation applies to any entity that conducts business in Kentucky and owns or licenses computerized data containing personal information of Kentucky residents. There is no minimum size threshold for this requirement.
Kentucky law does not specify an exact timeline for notification. Instead, it requires notification in the most expedient time possible, without unreasonable delay, consistent with the needs of law enforcement and any investigation.
Enforcement and Penalties

The Kentucky Attorney General has exclusive enforcement authority over the KCDPA. There is no private right of action, which means individual consumers cannot file lawsuits against businesses for KCDPA violations.
The enforcement process works as follows:
- The Attorney General's Office of Data Privacy identifies a potential violation
- The office notifies the business in writing, identifying the specific provisions believed to have been violated
- The business has 30 days to cure the alleged violation
- If the business cures the violation and provides a written statement that it will not engage in further violations, the Attorney General takes no action
- If the business fails to cure, the Attorney General can bring a civil action with penalties of up to $7,500 per violation
The 30-day cure period is permanent. Unlike privacy laws in some other states, the KCDPA's cure provision does not sunset, giving businesses an ongoing opportunity to correct violations before facing penalties.
Consumers can file complaints with the Kentucky Attorney General's Office of Data Privacy. The office can be reached at (502) 892-8538.

How Kentucky Compares to Other States
Kentucky's approach to biometric privacy falls in the middle of the spectrum among U.S. states:
Stronger than states with no protections. Many states still lack any specific biometric data protections. Kentucky's classification of biometric data as sensitive data requiring consent puts it ahead of states like Georgia, which has no dedicated biometric privacy statute and no comprehensive privacy law in effect.
Weaker than dedicated biometric privacy laws. States like Illinois, Texas, and Washington have standalone biometric privacy statutes with specific requirements for notice, consent, retention schedules, and data destruction. Illinois's BIPA includes a private right of action that has produced significant litigation and settlements.
Similar to other comprehensive privacy law states. Kentucky's approach closely mirrors states like Connecticut, Indiana, Montana, and Tennessee, which all classify biometric data as sensitive data within their comprehensive consumer privacy frameworks and require opt-in consent for processing.
Sources and References
This article references Kentucky statutes and official state government publications. For the full text of the KCDPA, visit the Kentucky Legislature website. For guidance on consumer rights and filing complaints, visit the Kentucky Attorney General's Office of Data Privacy.
This article provides general legal information about Kentucky biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Kentucky government sources.
More Kentucky Laws
Frequently Asked Questions
Does Kentucky have a standalone biometric privacy law like Illinois?
No. Kentucky does not have a dedicated biometric privacy statute. Instead, the Kentucky Consumer Data Protection Act (KCDPA), effective January 1, 2026, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The KCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention, destruction, and private right of action provisions found in Illinois BIPA.
Can I sue a company in Kentucky for collecting my fingerprints without consent?
Not under the KCDPA. The Kentucky Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint with the Kentucky Attorney General's Office of Data Privacy at (502) 892-8538. The AG can investigate and pursue civil penalties of up to $7,500 per violation.
Does the KCDPA protect my biometric data at work?
No. The KCDPA exempts data collected in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the KCDPA does not regulate that activity. Kentucky does not have a separate law governing employer use of biometric data, and the general breach notification law (KRS 365.732) does not cover biometric data, since its definition of personal information is limited to a Social Security number, driver's license number, or financial account number.
What biometric data does the KCDPA cover?
The KCDPA covers data generated by automatic measurements of biological characteristics used to identify a specific individual. This includes fingerprints, voiceprints, eye retinas, irises, and other unique biological patterns. Photographs, video recordings, and audio recordings are not covered unless they are specifically used to identify a particular individual. Data collected for health care treatment, payment, or operations under HIPAA is also excluded.
What happens if a company ignores a biometric data deletion request in Kentucky?
If a covered business fails to respond to your deletion request within 45 days (or 90 days with a valid extension), you can file a complaint with the Kentucky Attorney General. The AG will notify the business and provide 30 days to cure the violation. If the business still does not comply, the AG can pursue civil penalties of up to $7,500 per violation. Repeatedly ignoring consumer rights requests could result in multiple violation counts.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected: Verified against the mirrored statutes: KRS 61.
Governing law re-checked for recent changes
Corrected a contradiction between the article and KRS 365.732: Kentucky's private-sector breach notification law covers only Social Security number, driver's license number, or financial account number, not biometric or genetic data (that broader definition applies only to government agencies under a separate statute). Also fixed a misattributed non-discrimination right that isn't part of KRS 367.3615's enumerated consumer rights.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 5 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Kentucky Revised Statutes, Chapter 365: TRADE PRACTICES
§ 365.732Notification to affected persons of computer security breach involving their unencrypted personally identifiable informationIn forcecited in 3 of our articles
(1) As used in this section, unless the context otherwise requires: (a) "Breach of the security of the system" means unauthorized acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality, or integrity of personally identifiable information maintained by the information holder as part of a database regarding multiple individuals that actually causes, or leads the information holder to reasonably believe has caused or will cause, identity theft or fraud against any resident of the Commonwealth of Kentucky. Good-faith acquisition of personally identifiable information by an employee or agent of the information holder for the purposes of the information holder is not a breach of the security of the system if the personally identifiable information is not used or subject to further unauthorized disclosure; (b) "Information holder" means any person or business entity that conducts business in this state; and (c) "Personally identifiable information" means an individual's first name or first initial and last name in combination with any one (1) or more of the following data elements, when the name or data element is not redacted: 1.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Also relied on in: Kentucky Data Privacy Laws: Consumer Rights Guide (2026), Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION
§ 367.3611Definitions for KRS 367.3611 to 367.3629. (Effective until July 1, 2027)In forcecited in 6 of our articles
As used in KRS 367.3611 to 367.3629: (1) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company; (2) "Authenticate" means verifying through reasonable means that the consumer entitled to exercise his or her consumer rights in KRS 367.3615 is the same consumer exercising such consumer rights with respect to the personal data at issue; (3) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Also relied on in: KCDPA Consumer Rights: Kentucky Privacy Rights Guide, KCDPA Compliance Checklist: Kentucky Privacy Law, What Is the KCDPA? Kentucky Consumer Data Privacy
§ 367.3613Application -- Limitations -- Information and data exemptions -- Compliance with federal children's online privacy lawsIn forcecited in 3 of our articles
(1) KRS 367.3611 to 367.3629 apply to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that during a calendar year control or process personal data of at least: (a) One hundred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data. (2) KRS 367.3611 to 367.3629 shall not apply to any: (a) City, state agency, or any political subdivision of the state; (b) Financial institutions, their affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. sec. 6801 et seq.; (c) Covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder of the entity; and 2.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
§ 367.3615Consumer rights request -- Controller compliance -- Requirements -- Appeal processIn forcecited in 5 of our articles
(1) A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to a controller, via the means specified by the controller pursuant to KRS 367.3617, specifying the consumer rights the consumer wishes to invoke. A child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller…
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Kentucky Revised Statutes, Chapter 61: GENERAL PROVISIONS AS TO OFFICES AND OFFICERS -- SOCIAL SECURITY FOR PUBLIC EMPLOYEES -- EMPLOYEES RETIREMENT SYSTEM
§ 61.931Definitions for KRS 61.931 to 61.934In forcecited in 3 of our articles
As used in KRS 61.931 to 61.934: (1) "Agency" means: (a) The executive branch of state government of the Commonwealth of Kentucky; (b) Every county, city, municipal corporation, urban-county government, charter county government, consolidated local government, and unified local government; (c) Every organizational unit, department, division, branch, section, unit, office, administrative body, program cabinet, bureau, board, commission, committee, subcommittee, ad hoc committee, council, authority, public agency, instrumentality, interagency body, special purpose governmental entity, or public corporation of an entity specified in paragraph (a) or (b) of this subsection or created, established, or controlled by an entity specified in paragraph (a) or (b) of this subsection; (d) Every public school district in the Commonwealth of Kentucky; and (e) Every public institution of postsecondary education, including every public university in the Commonwealth of Kentucky and public college of the entire Kentucky Community and Technical College System; (2) "Commonwealth Office of Technology" means the office established by KRS 42.724; (3) "Encryption" means the conversion of data…
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Kentucky Consumer Data Protection Act (HB 15)(apps.legislature.ky.gov).gov
- KRS 367.3611 - KCDPA Definitions(apps.legislature.ky.gov).gov
- KRS 367.3615 - Consumer Rights(apps.legislature.ky.gov).gov
- KRS 365.732 - Breach Notification(apps.legislature.ky.gov).gov
- KCDPA Chapter 72 Acts (Enrolled Bill)(apps.legislature.ky.gov).gov
- Kentucky AG - Consumer Rights Under KCDPA(ag.ky.gov).gov
- Kentucky AG - Office of Data Privacy(ag.ky.gov).gov
- KRS 367.3613 - Application and Limitations(apps.legislature.ky.gov).gov