Kentucky
Kentucky Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Under KRS 365.732, Kentucky businesses that own or license computerized personal information must notify affected residents after a breach involving unencrypted data, but only when the breach is reasonably likely to cause identity theft or fraud. Notification must occur without unreasonable delay. Encrypted data is exempt.
If your business handles personal data belonging to Kentucky residents, you need to understand the state's data breach notification rules. A single breach affecting thousands of people can trigger notification obligations that carry legal consequences for businesses that fail to act promptly.
Kentucky's breach notification framework operates through two separate statutes: one for private-sector entities and one for government agencies. Both require notification without unreasonable delay, but the government rules impose stricter requirements, including mandatory reporting to multiple state agencies.
For an overview of Kentucky's broader privacy framework, see the parent guide to Kentucky Data Privacy Laws.
Who Must Comply With KRS 365.732
Kentucky's primary data breach notification law, KRS 365.732, applies to any person or business entity that conducts business in Kentucky and owns or licenses computerized data that includes personal information.
The statute covers a broad range of entities. If you maintain computerized records containing personal information about Kentucky residents, regardless of where your business is physically located, KRS 365.732 applies to you.
There are two key exemptions. Entities regulated under the Health Insurance Portability and Accountability Act (HIPAA) are exempt, as are financial institutions subject to the Gramm-Leach-Bliley Act (GLBA). These entities follow their own federal breach notification frameworks instead.
State agencies and local governments are also excluded from KRS 365.732 because they are covered under the separate government breach notification statutes at KRS 61.931 through 61.934.
What Qualifies as Personal Information
Under KRS 365.732, personal information means an individual's first name or first initial and last name in combination with one or more of these data elements:
- Social Security number
- Driver's license number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the account
The data must be in computerized (electronic) form. Paper records are not covered by this statute.
Publicly available information lawfully made available to the general public from government records does not count as personal information under this law.
What Triggers a Notification Obligation
A breach occurs when there is an unauthorized acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality, or integrity of personal information.
Kentucky adds an important qualifier. Notification is required only when the breach actually causes, or the entity reasonably believes it has caused or will cause, identity theft or fraud against the affected residents. If the entity determines through its investigation that no harm is reasonably likely, notification is not required.
This risk-of-harm threshold gives businesses some discretion. However, that discretion comes with responsibility. If a business incorrectly assesses the risk and does not notify, it could face legal exposure.
Good faith exception. The law provides that acquisition of personal information by an employee or agent of the entity does not constitute a breach, as long as the information is not actually misused or further disclosed without authorization.
Encryption Safe Harbor
Kentucky's statute does not apply to information that is encrypted or redacted. This is a straightforward safe harbor: if you encrypt personal information and a breach occurs, you are not required to send notifications under KRS 365.732.
This incentivizes businesses to adopt encryption as a standard data protection practice. If your organization stores personal information electronically, encryption removes one of the most significant legal risks associated with a breach.
Notification Timing and Method
When notification is required, businesses must act in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Kentucky does not set a specific deadline in days. The "without unreasonable delay" standard gives businesses time to investigate, but it also means that unnecessary foot-dragging could be considered a violation.
Law enforcement delay. If a law enforcement agency determines that notification would impede a criminal investigation, the business may delay notification until law enforcement authorizes it.
Methods of Notice

Businesses may provide notice through:
- Written notice sent to the affected individual's last known address
- Electronic notice consistent with the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act)
Substitute Notice
If direct notification would cost more than $250,000, affect more than 500,000 people, or the entity lacks sufficient contact information, substitute notice is available. Substitute notice requires all three of the following:
- Email notification to all affected individuals for whom the entity has an email address
- Conspicuous posting on the entity's website
- Notification to major statewide media outlets

Credit Reporting Agency Notification
When a breach affects more than 1,000 Kentucky residents, the entity must also notify all nationwide consumer reporting agencies and credit bureaus without unreasonable delay. This notification must describe the timing, distribution, and content of the notices sent to affected individuals.
Third-Party Data Holders
If an entity maintains personal information on behalf of another business (the data owner or licensee), the maintaining entity must notify the data owner or licensee of the breach as soon as reasonably practicable after discovering it. The data owner or licensee then becomes responsible for notifying affected individuals.

Government Entity Requirements (KRS 61.931 Through 61.934)
Kentucky holds government agencies to a different and more detailed standard through KRS 61.931 through 61.934, effective January 1, 2015.
Broader Definition of Personal Information
The government statutes define personal information more broadly than the private-sector law. Under KRS 61.931, personal information includes an individual's first name or first initial and last name, personal mark, or unique biometric or genetic print or image, in combination with:
- Social Security number
- Taxpayer identification number that incorporates a Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number with required security codes or passwords
- Other individual identification number
This definition is broader than KRS 365.732 in two ways: it includes biometric and genetic identifiers as qualifying name elements, and it adds taxpayer identification numbers as a covered data element.
Mandatory Multi-Agency Notification
When a government agency experiences a breach, it must notify multiple state entities:
- The Attorney General
- The Auditor of Public Accounts
- The Finance and Administration Cabinet
- The Kentucky State Police
- The Kentucky Department of Library and Archives
- The Commonwealth Office of Technology
This multi-agency notification requirement reflects the heightened accountability expected of government entities handling citizen data.
Third-Party Contractor Obligations
Private companies that contract with Kentucky state agencies and handle personal information face specific obligations under KRS 61.932.
For contracts executed or amended on or after January 1, 2015, contractors must implement security and breach investigation procedures at least as stringent as those required of the government agency itself.
When a contractor discovers a breach, it must notify the contracting agency in the most expedient time possible and without unreasonable delay, but no later than 72 hours after determining the breach occurred. The contracting agency then takes responsibility for notifying affected individuals and the Attorney General.
AG-Approved Delays
If a government agency determines that measures necessary to restore the integrity of its data system cannot be implemented within the required notification timeframe, the agency may request a delay. That delay must be approved in writing by the Office of the Attorney General.
Injunctive Relief
Under KRS 61.933, the Attorney General may seek injunctive relief against entities that fail to comply with government breach notification requirements.
Enforcement and Penalties
Private Sector (KRS 365.732)
KRS 365.732 does not contain specified penalties or a dedicated enforcement mechanism. The statute also does not create an explicit private right of action.
However, injured parties may have recourse through KRS 446.070, Kentucky's general remedy statute. KRS 446.070 provides that a person injured by the violation of any statute may recover damages from the offender through a civil action. This creates a potential, though untested in many data breach contexts, pathway for affected individuals to seek damages.
The Attorney General may also pursue enforcement through Kentucky's general consumer protection statutes.
Government Entities (KRS 61.931 Through 61.934)
The Attorney General has explicit authority to seek injunctive relief against government entities and their contractors that violate the breach notification requirements. This gives the AG power to compel compliance through court orders.
The KCDPA's Impact on Data Breach Response

The Kentucky Consumer Data Protection Act (KCDPA), which took effect on January 1, 2026, does not replace the existing breach notification statutes. However, it adds a new layer of data protection obligations that affect how businesses handle personal information before, during, and after a breach.
Under the KCDPA, codified at KRS 367.3611 through 367.3629, businesses that meet the applicability thresholds must:
- Implement reasonable data security practices proportional to the volume and sensitivity of the data they process
- Classify biometric data, genetic data, precise geolocation data, and other sensitive categories as requiring opt-in consent
- Respond to consumer deletion and access requests within 45 days
- Conduct data protection assessments for high-risk processing activities
The KCDPA gives the Attorney General exclusive enforcement authority with penalties of up to $7,500 per violation after a 30-day cure period. While the KCDPA does not directly modify KRS 365.732, a data breach that results from inadequate security practices could trigger enforcement actions under both frameworks.
The Kentucky Attorney General's Office of Data Privacy, created to enforce the KCDPA, can be reached at (502) 892-8538.
Insurance Data Security Law
Kentucky also enacted an insurance-specific data security law at KRS 304.3-750 through 304.3-768. Licensed insurers, agents, and other insurance entities must notify the Commissioner of Insurance of cybersecurity events as promptly as possible, but no later than three business days after the event, when the breach affects 250 or more Kentucky residents or materially harms operations.
Penalties under the insurance data security law can reach $10,000 per violation for insurers and $1,000 to $2,000 for individual agents and adjusters.
Steps to Take After a Breach in Kentucky
If your business experiences a data breach involving Kentucky residents' personal information, consider these steps:
- Contain the breach and secure your systems to prevent further unauthorized access
- Investigate the scope to determine what data was compromised and how many individuals are affected
- Assess the risk of harm to determine whether the breach is reasonably likely to cause identity theft or fraud
- Notify affected individuals in the most expedient time possible if harm is likely
- Notify credit reporting agencies if more than 1,000 Kentucky residents are affected
- Document your response including the investigation findings and notification timeline
- Contact law enforcement if the breach involves criminal activity
If you are a government contractor, remember the 72-hour notification window to the contracting agency.
Sources and References
This article references Kentucky statutes and official state government publications. For the full text of the breach notification statutes, visit the Kentucky Legislature website. For consumer guidance on data breaches and identity theft, visit the Kentucky Attorney General website. For information about the KCDPA and the Office of Data Privacy, see the AG's KCDPA page.
This article provides general legal information about Kentucky data breach notification laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Kentucky government sources.
More Kentucky Laws
Frequently Asked Questions
How quickly must a business notify Kentucky residents of a data breach?
Kentucky law requires notification in the most expedient time possible and without unreasonable delay. The state does not set a specific deadline in days. The timeline must account for any measures necessary to determine the scope of the breach and restore the integrity of the data system. Notification may also be delayed if law enforcement determines it would impede a criminal investigation.
Does Kentucky require businesses to notify the Attorney General after a data breach?
No. The private-sector breach notification law (KRS 365.732) does not require businesses to notify the Attorney General. However, government agencies must notify the AG, along with the Auditor of Public Accounts, Kentucky State Police, and other state entities, under KRS 61.933. Businesses may still face AG scrutiny through consumer protection enforcement.
What is Kentucky's encryption safe harbor for data breaches?
Kentucky's breach notification law does not apply to information that was encrypted or redacted at the time of the breach. If you encrypt personal information and an unauthorized party gains access, you are not required to send breach notifications under KRS 365.732. This safe harbor provides a strong incentive for businesses to encrypt stored personal data.
Can individuals sue for damages after a data breach in Kentucky?
KRS 365.732 does not create an explicit private right of action. However, individuals may seek damages under KRS 446.070, Kentucky's general remedy statute, which allows a person injured by any statutory violation to recover damages. The Kentucky Consumer Data Protection Act (KCDPA) also does not provide a private right of action. The Attorney General has exclusive enforcement authority under the KCDPA.
How does the Kentucky Consumer Data Protection Act affect data breach obligations?
The KCDPA, effective January 1, 2026, does not replace the existing breach notification statutes. It adds obligations for businesses to implement reasonable data security practices, obtain consent before processing sensitive data like biometric identifiers, and respond to consumer rights requests. A breach resulting from inadequate security could trigger enforcement under both the KCDPA (up to $7,500 per violation) and the existing breach notification law. The Attorney General's Office of Data Privacy enforces the KCDPA.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 8 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Kentucky Revised Statutes, Chapter 304: INSURANCE CODE
§ 304.3-760Notification to commissioner of cybersecurity event -- ProceduresIn force
(1) Each licensee shall notify the commissioner of a cybersecurity event involving nonpublic information that is in the possession of the licensee as promptly as possible, but in no event later than three (3) business days from a determination that a cybersecurity event has occurred, if: (a) In the case of an insurer, this state is the licensee's state of domicile and the cybersecurity event has a reasonable likelihood of harming any material part of normal operations of the licensee; (b) In the case of an insurance producer, this state is the licensee's home state, as those terms are defined in KRS 304.9-020; or (c) The licensee reasonably believes that: 1. The nonpublic information involved in the cybersecurity event is related to two hundred fifty (250) or more consumers residing in this state; and 2. The cybersecurity event is either of the following: a. A cybersecurity event requiring the licensee to provide notice to any governmental body, self-regulatory agency, or any other supervisory body pursuant to any state or federal law; or b. A cybersecurity event that has a reasonable likelihood of materially harming any: i. Consumer residing in this state; or ii.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Kentucky Revised Statutes, Chapter 365: TRADE PRACTICES
§ 365.732Notification to affected persons of computer security breach involving their unencrypted personally identifiable informationIn forcecited in 3 of our articles
(1) As used in this section, unless the context otherwise requires: (a) "Breach of the security of the system" means unauthorized acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality, or integrity of personally identifiable information maintained by the information holder as part of a database regarding multiple individuals that actually causes, or leads the information holder to reasonably believe has caused or will cause, identity theft or fraud against any resident of the Commonwealth of Kentucky. Good-faith acquisition of personally identifiable information by an employee or agent of the information holder for the purposes of the information holder is not a breach of the security of the system if the personally identifiable information is not used or subject to further unauthorized disclosure; (b) "Information holder" means any person or business entity that conducts business in this state; and (c) "Personally identifiable information" means an individual's first name or first initial and last name in combination with any one (1) or more of the following data elements, when the name or data element is not redacted: 1.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Also relied on in: Kentucky Data Privacy Laws: Consumer Rights Guide (2026), Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION
§ 367.3611Definitions for KRS 367.3611 to 367.3629. (Effective until July 1, 2027)In forcecited in 6 of our articles
As used in KRS 367.3611 to 367.3629: (1) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company; (2) "Authenticate" means verifying through reasonable means that the consumer entitled to exercise his or her consumer rights in KRS 367.3615 is the same consumer exercising such consumer rights with respect to the personal data at issue; (3) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Also relied on in: KCDPA Consumer Rights: Kentucky Privacy Rights Guide, KCDPA Compliance Checklist: Kentucky Privacy Law, What Is the KCDPA? Kentucky Consumer Data Privacy
Kentucky Revised Statutes, Chapter 446: CONSTRUCTION OF STATUTES
§ 446.070Penalty no bar to civil recoveryIn forcecited in 2 of our articles
A person injured by the violation of any statute may recover from the offender such damages as he sustained by reason of the violation, although a penalty or forfeiture is imposed for such violation.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Kentucky Revised Statutes, Chapter 61: GENERAL PROVISIONS AS TO OFFICES AND OFFICERS -- SOCIAL SECURITY FOR PUBLIC EMPLOYEES -- EMPLOYEES RETIREMENT SYSTEM
§ 61.931Definitions for KRS 61.931 to 61.934In forcecited in 3 of our articles
As used in KRS 61.931 to 61.934: (1) "Agency" means: (a) The executive branch of state government of the Commonwealth of Kentucky; (b) Every county, city, municipal corporation, urban-county government, charter county government, consolidated local government, and unified local government; (c) Every organizational unit, department, division, branch, section, unit, office, administrative body, program cabinet, bureau, board, commission, committee, subcommittee, ad hoc committee, council, authority, public agency, instrumentality, interagency body, special purpose governmental entity, or public corporation of an entity specified in paragraph (a) or (b) of this subsection or created, established, or controlled by an entity specified in paragraph (a) or (b) of this subsection; (d) Every public school district in the Commonwealth of Kentucky; and (e) Every public institution of postsecondary education, including every public university in the Commonwealth of Kentucky and public college of the entire Kentucky Community and Technical College System; (2) "Commonwealth Office of Technology" means the office established by KRS 42.724; (3) "Encryption" means the conversion of data…
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
§ 61.932Personal information security and breach investigation procedures and practices for certain public agencies and nonaffiliated third partiesIn force
(1) (a) An agency or nonaffiliated third party that maintains or otherwise possesses personal information, regardless of the form in which the personal information is maintained, shall implement, maintain, and update security procedures and practices, including taking any appropriate corrective action, to protect and safeguard against security breaches. (b) Reasonable security and breach investigation procedures and practices established and implemented by organizational units of the executive branch of state government shall be in accordance with relevant enterprise policies established by the Commonwealth Office of Technology. Reasonable security and breach investigation procedures and practices established and implemented by units of government listed under KRS 61.931(1)(b) and (c) that are not organizational units of the executive branch of state government shall be in accordance with policies established by the Department for Local Government.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
§ 61.933Notification of personal information security breach -- Investigation -- Notice to affected individuals of result of investigation -- Personal information not subject to requirements -- Injunctive relief by Attorney GeneralIn force
(1) (a) Any agency that collects, maintains, or stores personal information that determines or is notified of a security breach relating to personal information collected, maintained, or stored by the agency or by a nonaffiliated third party on behalf of the agency shall as soon as possible, but within seventy-two (72) hours of determination or notification of the security breach: 1. Notify the commissioner of the Kentucky State Police, the Auditor of Public Accounts, and the Attorney General. In addition, an agency shall notify the secretary of the Finance and Administration Cabinet or his or her designee if an agency is an organizational unit of the executive branch of state government; notify the commissioner of the Department for Local Government if the agency is a unit of government listed in KRS 61.931(1)(b) or (c) that is not an organizational unit of the executive branch of state government; notify the commissioner of the Kentucky Department of Education if the agency is a public school district listed in KRS 61.931(1)(d); and notify the president of the Council on Postsecondary Education if the agency is an educational entity listed under KRS 61.931(1)(e).
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
§ 61.934Personal information security and breach investigation procedures and practices for legislative and judicial branches -- Personal information disposal or destruction proceduresIn force
(1) The legislative and judicial branches of state government shall implement, maintain, and update reasonable security and breach investigation procedures and practices, including taking any appropriate corrective action, to protect and safeguard against security breaches consistent with KRS 61.931 to 61.934. (2) The Department for Libraries and Archives shall establish procedures for the appropriate disposal or destruction of records that include personal information pursuant to the authority granted the Department for Libraries and Archives under KRS 171.450.
Official text (excerpt) · as of 2026-07-29 · Read the full section at apps.legislature.ky.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- KRS 365.732 - Notification to affected persons of computer security breach(apps.legislature.ky.gov).gov
- KRS 61.931 - Definitions for government breach notification(apps.legislature.ky.gov).gov
- KRS 61.932 - Government agency breach investigation procedures(apps.legislature.ky.gov).gov
- KRS 61.933 - Government breach notification requirements(apps.legislature.ky.gov).gov
- KRS 61.934 - Legislative and judicial branch breach procedures(apps.legislature.ky.gov).gov
- Kentucky Consumer Data Protection Act (KCDPA) - AG guidance(ag.ky.gov).gov
- Kentucky Office of Data Privacy(ag.ky.gov).gov
- Kentucky AG Identity Theft Resources(ag.ky.gov).gov
- KRS 446.070 - Penalty no bar to civil recovery(apps.legislature.ky.gov).gov
- HIPAA Information - HHS.gov(hhs.gov).gov
- Gramm-Leach-Bliley Act - FTC(ftc.gov).gov
- E-SIGN Act - FTC(ftc.gov).gov
- KRS Chapter 365 - Commerce and Trade(apps.legislature.ky.gov).gov
- KRS 304.3-760 - Insurance cybersecurity event notification(apps.legislature.ky.gov).gov
- HB 15 - Kentucky Consumer Data Protection Act bill text(apps.legislature.ky.gov).gov