EnglishEspañol
Kentucky flag

Kentucky

What Is the KCDPA? Kentucky Consumer Data Privacy

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 9 primary sources cited on this page. How we verify our legal content

What Is the KCDPA? Kentucky Consumer Data Privacy

Frequently Asked Questions

What is the KCDPA?

The KCDPA, or Kentucky Consumer Data Protection Act, is Kentucky's comprehensive consumer data privacy law codified at KRS 367.3611 to 367.3629. It was enacted as House Bill 15, signed by Governor Andy Beshear on April 4, 2024, and takes effect January 1, 2026. It gives Kentucky residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and disclose it.

When did the KCDPA take effect?

The KCDPA takes effect January 1, 2026, more than a year and a half after it was signed on April 4, 2024. The long runway gave covered businesses time to build privacy programs before their obligations began. As of 2026, the effective date has arrived and every covered business is fully subject to the law.

Who has to comply with the KCDPA?

Under KRS 367.3613, the KCDPA applies to a business that conducts business in Kentucky or targets Kentucky residents and that, in a calendar year, controls or processes the personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data. There is no separate revenue-only trigger.

Is the KCDPA the same as Virginia's privacy law?

Nearly. Kentucky's legislature modeled the KCDPA closely on Virginia's Consumer Data Protection Act, sharing the same definitions, the same rights set in KRS 367.3615, the same opt-in rule for sensitive data, and the same Attorney-General-only enforcement with a cure period. A business already aligned with Virginia's framework will find Kentucky's obligations familiar.

Does the KCDPA require consent for sensitive data?

Yes. Under KRS 367.3617(1)(e), a controller may not process sensitive data without first obtaining the consumer's consent, an opt-in model. Sensitive data under KRS 367.3611 includes data revealing racial or ethnic origin, religious beliefs, a health diagnosis, sexual orientation, or immigration status, plus genetic or biometric data used to identify a person, a known child's data, and precise geolocation.

Does the KCDPA require honoring a universal opt-out signal?

No. The KCDPA does not mandate that controllers recognize a universal opt-out mechanism such as the Global Privacy Control browser signal. KRS 367.3617 requires controllers to disclose and provide their own opt-out methods, but the statute contains no requirement to honor a global opt-out signal, matching the Virginia model it was based on.

How is the KCDPA different from the CCPA?

The KCDPA keys on consumer volume and data-sale revenue share rather than offering a revenue-only trigger like California's $25 million floor. It uses an opt-in model for sensitive data, while California uses a right to limit. It does not require honoring universal opt-out signals, while California does. And it has no private right of action, while California allows a limited one for certain breaches.

Is the KCDPA being amended after 2026?

Yes. House Bill 692, signed April 13, 2026 as 2026 Ky. Acts ch. 118, amends KRS 367.3611 and KRS 367.3617 but does not take effect until July 1, 2027. It defines automatic content recognition data and smart monitor, and adds KRS 367.3617(1)(f), which bars a controller from collecting automatic content recognition data without a consumer's consent. Until July 1, 2027, the controller duties described on this page are the operative set.

Who enforces the KCDPA?

The Kentucky Attorney General has exclusive enforcement authority under KRS 367.3627. There is no private right of action. Before suing, the Attorney General must give a 30-day written notice and cure opportunity, and that cure period is permanent with no sunset. Under KRS 367.3627(3) the Attorney General may then seek damages of up to $7,500 for each continued violation, meaning a violation that continues after the cure period or that breaches the written cure statement. Civil penalties collected are deposited into the consumer privacy fund under KRS 367.3629.

Updates

Corrected the KCDPA penalty measure to $7,500 for each continued violation under KRS 367.3627(3), restated the KRS 367.3613(2)(g) utility exemption to match the statute including the Tier III CMRS carve-out, and added the enacted 2026 amendment (House Bill 692, 2026 Ky. Acts ch. 118) that bars collecting automatic content recognition data without consent starting July 1, 2027.

Independently fact-checked against the cited primary sources

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Kentucky HB 15 (2024): Kentucky Consumer Data Protection Act (Enrolled Bill Text)(apps.legislature.ky.gov).gov
  2. Kentucky General Assembly: HB 15 Bill Page (2024 Regular Session)(apps.legislature.ky.gov).gov
  3. KRS 367.3611: Definitions for KRS 367.3611 to 367.3629(apps.legislature.ky.gov).gov
  4. KRS 367.3613: Application, Limitations, and Exemptions(apps.legislature.ky.gov).gov
  5. KRS 367.3615: Consumer Rights Request and Appeal Process(apps.legislature.ky.gov).gov
  6. KRS 367.3617: Controller Limitations and Sensitive Data Consent(apps.legislature.ky.gov).gov
  7. KRS 367.3627: Attorney General Enforcement, Cure Period, and Civil Penalties(apps.legislature.ky.gov).gov
  8. KRS 367.3629: Consumer Privacy Fund(apps.legislature.ky.gov).gov
  9. Kentucky Attorney General: Rights of Kentuckians under the Kentucky Consumer Data Protection Act(ag.ky.gov).gov
  10. Kentucky General Assembly: HB 692 Bill Page (2026 Regular Session), signed April 13, 2026 as Acts ch. 118(apps.legislature.ky.gov)
  11. Kentucky HB 692 (2026): Enrolled Bill Text amending KRS 367.3611 and KRS 367.3617, effective July 1, 2027(apps.legislature.ky.gov)
  12. KRS 367.3627: Attorney General Enforcement, Written Notice of Violation, Cure Period, and Damages(apps.legislature.ky.gov)
  13. KRS 367.3617: Limitations on the Collection and Use of Personal Data by a Controller(apps.legislature.ky.gov)
  14. KRS 367.3615: Consumer Rights Request, Controller Compliance, and Appeal Process(apps.legislature.ky.gov)
  15. KRS 367.3629: Consumer Privacy Fund(apps.legislature.ky.gov)
Share: