close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Kentucky Privacy Law

KY

Kentucky (KCDPA)

Last updated

KCDPA Enacted, in effect

Who this affects: This page tracks Kentucky’s KCDPA, which governs controllers and processors.

Who it applies to: Persons that do business in Kentucky or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 1, 2026
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

KCDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to authenticated requests to access, correct, delete, or port data, or to opt out, within 45 days of receipt. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3615 “A controller shall comply with an authenticated consumer request to exercise the right to:” Read the statute KY-367.3615 “A controller shall respond to the consumer without undue delay, but in all cases within forty-five (45) days of receipt of the request” Read the statute KY-367.3615 “Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret” Read the statute KY-367.3615 “Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data” Read the statute KY-367.3615 “Delete personal data provided by or obtained about the consumer” Read the statute KY-367.3615 “Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. The controller shall not be required to reveal any trade secrets” Read the statute KY-367.3615 “Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer” Read the statute
  • If you decline a request, explain why and how to appeal within 45 days, and answer appeals in writing within 60 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3615 “If a controller declines to take action regarding the consumer's request, the controller shall inform the consumer without undue delay, but no later than forty-five (45) days after receipt of the request, of the justification for declining to take action and instructions on how to appeal the decision” Read the statute KY-367.3615 “Within sixty (60) days of receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal” Read the statute
  • Publish a clear privacy notice with secure request methods, and conspicuously disclose sale or targeted ads and how to opt out. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3617 “Controllers shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes:” Read the statute KY-367.3617 “A controller shall establish, and shall describe in a privacy notice, one (1) or more secure and reliable means for consumers to submit a request to exercise their consumer rights” Read the statute KY-367.3617 “the controller shall clearly and conspicuously disclose such activity, as well as the manner in which a consumer may exercise the right to opt out of processing” Read the statute KY-367.3615 “Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer” Read the statute

Can't

  • Process sensitive data without the consumer's consent, or process a known child's sensitive data other than per COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3617 “Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data collected from a known child, process the data in accordance with the federal Children's Online Privacy Protection Act, 15 U.S.C. sec. 6501 et seq.” Read the statute
  • Deny goods, charge different prices, or lower quality for exercising rights; voluntary bona fide loyalty offers are allowed. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3617 “A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in KRS 367.3615, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer. However, nothing in this paragraph shall be construed to require a controller to provide a product or service that requires the personal data of a consumer that the controller does not collect or maintain, or to prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee, if the offer is related to a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program” Read the statute
  • Require a consumer to create a new account to exercise privacy rights, though you may require use of an existing account. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3617 “Controllers shall not require a consumer to create a new account in order to exercise consumer rights pursuant to KRS 367.3615 but may require a consumer to use an existing account.” Read the statute

Should

  • Track each request against the 45-day clock and, if you need the one 45-day extension, tell the consumer why within that window. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3615 “A controller shall respond to the consumer without undue delay, but in all cases within forty-five (45) days of receipt of the request” Read the statute KY-367.3615 “The response period may be extended once by forty-five (45) additional days when reasonably necessary, taking into consideration the complexity and number of the consumer's requests, so long as the controller informs the consumer of any extension within the initial forty-five (45) day response period, together with the reason for the extension” Read the statute
  • Route AG violation notices to an owner who can cure within 30 days and send the AG an express written statement of cure. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3627 “If within the thirty (30) days the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action for damages under subsection (3) of this section shall be initiated against the controller or processor.” Read the statute
  • Use a standard processor contract setting instructions, nature and purpose, data type, duration, and each side's obligations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. KY-367.3619 “A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and shall clearly set forth instructions for processing personal data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.” Read the statute

These are the highlights we judge most important, not everything KCDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Kentucky Consumer Data Protection Act

KCDPA (HB 15) is Kentucky’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read …ural or legal person, public authority, agency, or body other than the consumer, controller, processor, or an affiliate of the processor or the controller; and (32) "Trade secret" has the same meaning as in KRS 365.880. Effective: January 1, 2026 History: Created 2024 Ky. Acts ch. 72, sec. 1, effective January 1, 2026. Legislative Research Commission Note (1/1/2026). Under the authority of KRS 7.136, the reviser of statutes has renumbered the subsections in this… Archived from source — captured 2026-08-03 · snapshot b6399f97 Verify at the source
Effective
January 1, 2026
Archived excerpt — the text we read Section 12. This Act takes effect January 1, 2026. Signed by Governor April 4, 2024. Archived from source — captured 2026-08-14 · snapshot 04bef675 Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Signed
April 4, 2024
Archived excerpt — the text we read Section 12. This Act takes effect January 1, 2026. Signed by Governor April 4, 2024. Archived from source — captured 2026-08-14 · snapshot 04bef675 Verify at the source

Corroborated by Legislative record

Enforced by
Attorney General
Archived excerpt — the text we read 367.3627 Enforcement authority of Attorney General -- Written notice of violation -- Civil action -- Damages -- Recovery of expenses. (1) (2) (3) (4) (5) The Attorney General shall have exclusive authority to enforce violations of KRS 367.3611 to 367.3629. The Attorney General may enforce KRS 367.3611 to 367.3629 by bringing an action in the name of the Commonwealth of Kentucky or on behalf of persons residing in this Commonwealth. The Attorney General shall have all powe… Archived from source — captured 2026-08-03 · snapshot 7a875795 Verify at the source
Maximum penalty per violation
$7,500
The AG may also recover investigation costs, court costs and attorney's fees. No private right of action. “the Attorney General may initiate an action and seek damages for up to seven thousand five hundred dollars ($7,500) for each continued violation” View the statute
Right to cure
30 days
Archived excerpt — the text we read …he Attorney General shall provide a controller or processor thirty (30) days' written notice identifying the specific provisions of KRS 367.3611 to 367.3629, the Attorney General alleges have been or are being violated. If within the thirty (30) days the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action for damages under subsection (3) of this section shall be initiated against the controller or processor. If a controller or processor continues to violate KRS 367.3611 to 367.3629 following the cure period in subsection (2) of this section or breaches an express written statement provided to the Attorney General under subs… Archived from source — captured 2026-08-03 · snapshot 7a875795 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …eral under subsection (2) of this section, the Attorney General may initiate an action and seek damages for up to seven thousand five hundred dollars ($7,500) for each continued violation under KRS 367.3611 to 367.3629. Nothing in KRS 367.3611 to 367.3629 or any other law, regulation, or the equivalent shall be construed as providing the basis for, or give rise to, a private right of action for violations of KRS 367.3611 to 367.3629. The Attorney General may recover reasonable expenses incurred in investigating and preparing the case, court costs, attorney's fees, and any other relief ordered by the court of any action initiated under KRS 367.3611 t… Archived from source — captured 2026-08-03 · snapshot 7a875795 Verify at the source
Universal opt-out signal
Not required

Corroborated by Privacy-law tracker

Who it applies to

Persons that do business in Kentucky or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data

What the law gives consumers

  • Right to access Archived excerpt — the text we read …l guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the child. A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right to correct Archived excerpt — the text we read …right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technicall… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right to delete For data obtained from another source, a controller complies by keeping a minimal deletion record or by opting the consumer out of all non-exempt processing (367.3615(3)(e)). Archived excerpt — the text we read …nd access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to tran… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right to data portability Archived excerpt — the text we read …Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. The controller shall not be required to reveal any trade secrets; and (e) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concernin… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …at that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. The controller shall not be required to reveal any trade secrets; and (e) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. Except as otherwise provided in KRS 367.3611 to 367.3629, a controller shall comply with a request by a consumer to exercise the consumer rights pursuant to this section as follows: (a) A controller shall respond to th… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …at that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. The controller shall not be required to reveal any trade secrets; and (e) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. Except as otherwise provided in KRS 367.3611 to 367.3629, a controller shall comply with a request by a consumer to exercise the consumer rights pursuant to this section as follows: (a) A controller shall respond to th… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …at that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. The controller shall not be required to reveal any trade secrets; and (e) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. Except as otherwise provided in KRS 367.3611 to 367.3629, a controller shall comply with a request by a consumer to exercise the consumer rights pursuant to this section as follows: (a) A controller shall respond to th… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …to a consumer, including offering goods or services for no fee, if the offer is related to a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program; and (e) Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data collected from a known child, process the data in accordance with the federal Children's Online Privacy Protection Act, 15 U.S.C. sec. 6501 et seq. Any provision of a… Archived from source — captured 2026-08-03 · snapshot 87ab88cc Verify at the source
  • Right to appeal Archived excerpt — the text we read …data for any other purpose pursuant to the provisions of KRS 367.3611 to 367.3629; or 2. Opting the consumer out of the processing of the personal data for any purpose except for those exempted pursuant to KRS 367.3613. A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision pursuant to subsection (3)(b) of this section. The appeal process shall be conspicuously available and similar to the process for submittin… Archived from source — captured 2026-08-03 · snapshot 71eb4ded Verify at the source
  • Right against discrimination Archived excerpt — the text we read …curity practices shall be appropriate to the volume and nature of the personal data at issue; (d) Not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in KRS 367.3615, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer. However, nothing in this paragraph shall b… Archived from source — captured 2026-08-03 · snapshot 87ab88cc Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …eral under subsection (2) of this section, the Attorney General may initiate an action and seek damages for up to seven thousand five hundred dollars ($7,500) for each continued violation under KRS 367.3611 to 367.3629. Nothing in KRS 367.3611 to 367.3629 or any other law, regulation, or the equivalent shall be construed as providing the basis for, or give rise to, a private right of action for violations of KRS 367.3611 to 367.3629. The Attorney General may recover reasonable expenses incurred in investigating and preparing the case, court costs, attorney's fees, and any other relief ordered by the court of any action initiated under KRS 367.3611 t… Archived from source — captured 2026-08-03 · snapshot 7a875795 Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read … (7) "Consumer" means a natural person who is a resident of the Commonwealth of Kentucky acting only in an individual context. Consumer does not include a natural person acting in a commercial or employment context; (8) "Controller" means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing personal data; (9) "Covered entity" has the same meaning as established in 45 C.F.R. sec. 160.103 pursuant to HIPAA; (10) "Decisions that produce legal or similarly significant effects concerning a consumer" means a decision made by … Archived from source — captured 2026-08-03 · snapshot b6399f97 Verify at the source
  • Processors Archived excerpt — the text we read …rmed, whether by manual or automated means, on personal data or on sets of personal data, including but not limited to the collection, use, storage, disclosure, analysis, deletion, or modification of personal data; (22) "Processor" means a natural or legal entity that processes personal data on behalf of a controller; (23) "Profiling" means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person's economic situation, health,… Archived from source — captured 2026-08-03 · snapshot b6399f97 Verify at the source

Exemptions

  • State and local government agencies Archived excerpt — the text we read …dred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data. KRS 367.3611 to 367.3629 shall not apply to any: (a) City, state agency, or any political subdivision of the state; (b) Financial institutions, their affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. sec. 6801 et seq.; (c) Covered entity or business associate governed by the privacy, security, a… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • GLBA: financial institutions, their affiliates, and data subject to Title V Entity- and data-level Archived excerpt — the text we read …000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data. KRS 367.3611 to 367.3629 shall not apply to any: (a) City, state agency, or any political subdivision of the state; (b) Financial institutions, their affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. sec. 6801 et seq.; (c) Covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established purs… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • HIPAA covered entities and business associates Archived excerpt — the text we read …to any: (a) City, state agency, or any political subdivision of the state; (b) Financial institutions, their affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. sec. 6801 et seq.; (c) Covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Nonprofit organizations operating for religious, charitable, or educational purposes With no net earnings to insiders; other nonprofits are not exempt as nonprofits. KRS 367.3611 definition. Archived excerpt — the text we read …y or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder of the entity; and 2. Is an… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Institutions of higher education Archived excerpt — the text we read …rned by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder of the entity; and 2. Is an entity such as those recognized unde… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Insurance fraud/first responder investigative nonprofit organizations Archived excerpt — the text we read …each notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. pts. 160 and 164 established pursuant to HIPAA; (d) Nonprofit organization; (e) Institution of higher education; (f) Organization that: 1. Does not provide net earnings to, or operate in any manner that inures to the benefit of, any officer, employee, or shareholder of the entity; and 2. Is an entity such as those recognized under KRS 304.47-060(1)(e), so long as the entity collects, processes, uses, or shares data solely in relation to identifying, investigating, or assisting: a. Law enforcement agencies in connection with suspected insurance-related criminal or fraudulent acts; or b. First responders in connection with catastrophic events; or (g) Small telephone utility as defined in KRS 278.516, a Tier III CMRS provider as defined in KRS 65.7621, or a municipally owned utility that does not sell or share personal data with any third-party. The following… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Small telephone utilities, Tier III CMRS providers, and others Small telephone utilities, Tier III CMRS providers, and municipally owned utilities that do not sell or share personal data with any third party. Archived excerpt — the text we read … to identifying, investigating, or assisting: a. Law enforcement agencies in connection with suspected insurance-related criminal or fraudulent acts; or b. First responders in connection with catastrophic events; or (g) Small telephone utility as defined in KRS 278.516, a Tier III CMRS provider as defined in KRS 65.7621, or a municipally owned utility that does not sell or share personal data with any third-party. The following information and data are exempt from KRS 367.3611 to 367.3629: (a) Protected health information under HIPAA; (b) Health records; (c) Patient identifying information for purposes of 42 C.F.R. sec. 2.11; (d… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Protected health information under HIPAA Archived excerpt — the text we read …II CMRS provider as defined in KRS 65.7621, or a municipally owned utility that does not sell or share personal data with any third-party. The following information and data are exempt from KRS 367.3611 to 367.3629: (a) Protected health information under HIPAA; (b) Health records; (c) Patient identifying information for purposes of 42 C.F.R. sec. 2.11; (d) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. … Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Health records Archived excerpt — the text we read … a municipally owned utility that does not sell or share personal data with any third-party. The following information and data are exempt from KRS 367.3611 to 367.3629: (a) Protected health information under HIPAA; (b) Health records; (c) Patient identifying information for purposes of 42 C.F.R. sec. 2.11; (d) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46; identifiable… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Patient identifying information under 42 C.F.R. 2.11 Archived excerpt — the text we read … utility that does not sell or share personal data with any third-party. The following information and data are exempt from KRS 367.3611 to 367.3629: (a) Protected health information under HIPAA; (b) Health records; (c) Patient identifying information for purposes of 42 C.F.R. sec. 2.11; (d) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46; identifiable private information that is otherwise information collected as part of h… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Human subjects research information Archived excerpt — the text we read …The following information and data are exempt from KRS 367.3611 to 367.3629: (a) Protected health information under HIPAA; (b) Health records; (c) Patient identifying information for purposes of 42 C.F.R. sec. 2.11; (d) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonisation of Tec… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read ….F.R. pts. 50 and 56; or personal data used or shared in research conducted in accordance with the requirements set forth in KRS 367.3611 to 367.3629, or other research conducted in accordance with applicable law; (e) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. sec. 11101 et seq.; (f) Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act, 42 U.S.C. sec. 299b-21 et seq.; (g) Information derived from any of the health care-related information listed in … Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Patient Safety and Quality Improvement Act work product Archived excerpt — the text we read …o 367.3629, or other research conducted in accordance with applicable law; (e) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. sec. 11101 et seq.; (f) Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act, 42 U.S.C. sec. 299b-21 et seq.; (g) Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (h) Information origi… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • HIPAA de-identified health information Archived excerpt — the text we read …eral Health Care Quality Improvement Act of 1986, 42 U.S.C. sec. 11101 et seq.; (f) Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act, 42 U.S.C. sec. 299b-21 et seq.; (g) Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (h) Information originating from, and intermingled to be indistinguishable from, or information treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business … Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Information intermingled with exempt health information Archived excerpt — the text we read …. 299b-21 et seq.; (g) Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (h) Information originating from, and intermingled to be indistinguishable from, or information treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business associate, or a program or qualified service organization as defined by 42 C.F.R. sec. 2.11; (i) Information collected by a health care provider who is a covered entity that maintains protected health information in accordance with HIPAA and related regulations, 45 C.F.R. sec. pts. 160, 162, and 164; (j) Infor… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Information collected by HIPAA-covered health care providers Archived excerpt — the text we read … treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business associate, or a program or qualified service organization as defined by 42 C.F.R. sec. 2.11; (i) Information collected by a health care provider who is a covered entity that maintains protected health information in accordance with HIPAA and related regulations, 45 C.F.R. sec. pts. 160, 162, and 164; (j) Information included in a limited data set as described in 45 C.F.R. sec. 164.514(e), to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. sec. 164.514(e); (k) Information used… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • HIPAA limited data sets Archived excerpt — the text we read … 2.11; (i) Information collected by a health care provider who is a covered entity that maintains protected health information in accordance with HIPAA and related regulations, 45 C.F.R. sec. pts. 160, 162, and 164; (j) Information included in a limited data set as described in 45 C.F.R. sec. 164.514(e), to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. sec. 164.514(e); (k) Information used only for public health activities and purposes as authorized by HIPAA; (l) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's c… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • HIPAA public health activities information Archived excerpt — the text we read …60, 162, and 164; (j) Information included in a limited data set as described in 45 C.F.R. sec. 164.514(e), to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. sec. 164.514(e); (k) Information used only for public health activities and purposes as authorized by HIPAA; (l) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal c… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • FCRA-regulated data (only to the extent regulated by and authorized under the FCRA) Archived excerpt — the text we read …ec. 164.514(e), to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. sec. 164.514(e); (k) Information used only for public health activities and purposes as authorized by HIPAA; (l) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, furnisher, or user that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act, 15 U.S.C. sec. 1681 et seq.; (m) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. sec. 2721 et seq.; (n) Personal data regulated by the federal Family Educatio… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …on for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act, 15 U.S.C. sec. 1681 et seq.; (m) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. sec. 2721 et seq.; (n) Personal data regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. sec. 1232g et seq.; (o) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit … Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …Fair Credit Reporting Act, 15 U.S.C. sec. 1681 et seq.; (m) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. sec. 2721 et seq.; (n) Personal data regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. sec. 1232g et seq.; (o) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U.S.C. sec. 2001 et seq.; (p) Data processed or maintained: 1. In the course of an individual applying to, e… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …n compliance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. sec. 2721 et seq.; (n) Personal data regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. sec. 1232g et seq.; (o) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U.S.C. sec. 2001 et seq.; (p) Data processed or maintained: 1. In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is c… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Employment-context data Archived excerpt — the text we read …and Privacy Act, 20 U.S.C. sec. 1232g et seq.; (o) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U.S.C. sec. 2001 et seq.; (p) Data processed or maintained: 1. In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; 2. As the emergency contact information of an individual used for emergency contact purposes; or 3. That is necessary to retain to administer benefits for another individual (4) relating to the individual under subp… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Emergency contact information Archived excerpt — the text we read …f an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; 2. As the emergency contact information of an individual used for emergency contact purposes; or 3. That is necessary to retain to administer benefits for another individual (4) relating to the individual under subparagraph 1. of this paragraph and used for the purposes of administering those benefits; (q) D… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Benefits administration data Archived excerpt — the text we read …ntroller, processor, or third party, to the extent that the data is collected and used within the context of that role; 2. As the emergency contact information of an individual used for emergency contact purposes; or 3. That is necessary to retain to administer benefits for another individual relating to the individual under subparagraph 1. of this paragraph and used for the purposes of administering those benefits; (q) Data processed by a utility, an affiliate of a utility, or a holding company system organized specifically for the purpose of providing goods or services to a utility as defined in KRS 278.010. For purposes of this… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Utility and utility holding company data Archived excerpt — the text we read …s; or 3. That is necessary to retain to administer benefits for another individual (4) relating to the individual under subparagraph 1. of this paragraph and used for the purposes of administering those benefits; (q) Data processed by a utility, an affiliate of a utility, or a holding company system organized specifically for the purpose of providing goods or services to a utility as defined in KRS 278.010. For purposes of this paragraph, "holding company system" means two (2) or more affiliated persons, one (1) or more of which is a utility; and (r) Personal data collected and used for purposes of federal policy under th… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Combat Methamphetamine Epidemic Act data Archived excerpt — the text we read …se of providing goods or services to a utility as defined in KRS 278.010. For purposes of this paragraph, "holding company system" means two (2) or more affiliated persons, one (1) or more of which is a utility; and (r) Personal data collected and used for purposes of federal policy under the Combat Methamphetamine Epidemic Act of 2005. Controllers and processors that comply with the verifiable parental consent requirements of the Children's Online Privacy Protection Act, 15 U.S.C. sec. 6501 et seq., shall be deemed compliant with any obligation to ob… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read …rocessors that adversely affects the privacy or other rights or freedoms of any persons, including but not limited to the right of free speech pursuant to the First Amendment to the Constitution of the United States, or applies to the processing of personal data by a person in the course of a purely personal or household activity. Personal data processed by a controller pursuant to this section shall not be processed for any purpose other than those expressly listed in this section unless otherwise allowed by KRS 367.3611 to 367.3629. Personal d… Archived from source — captured 2026-08-03 · snapshot 1f207b2a Verify at the source
  • Human subjects research data Human subjects research data under ICH good clinical practice guidelines or 21 C.F.R. pts. 50 and 56. Archived excerpt — the text we read …alth records; (c) Patient identifying information for purposes of 42 C.F.R. sec. 2.11; (d) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use; the protection of human subjects under 21 C.F.R. pts. 50 and 56; or personal data used or shared in research conducted in accordance with the requirements set forth in KRS 367.3611 to 367.3629, or other research conducted in accordance with applicable law; (e) Information and docu… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Personal data used or shared in research conducted under the Act or other applicable law Archived excerpt — the text we read …he good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use; the protection of human subjects under 21 C.F.R. pts. 50 and 56; or personal data used or shared in research conducted in accordance with the requirements set forth in KRS 367.3611 to 367.3629, or other research conducted in accordance with applicable law; (e) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. sec. 11101 et seq.; (f) Patient safety work product for purposes of the federal Patient Safety an… Archived from source — captured 2026-08-03 · snapshot 960b24fd Verify at the source
  • Evidentiary privilege (compliance would violate a Kentucky evidentiary privilege) Archived excerpt — the text we read …provision of a product or service specifically requested by a consumer or a parent or guardian of a known child or the performance of a contract to which the consumer or a parent or guardian of a known child is a party. The obligations imposed on controllers or processors under KRS 367.3611 to 367.3629 shall not apply to a controller or processor if compliance under KRS 367.3611 to 367.3629 would violate an evidentiary privilege under the laws of this Commonwealth. Nothing in KRS 367.3611 to 367.3629 shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this Comm… Archived from source — captured 2026-08-03 · snapshot 1f207b2a Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …trollers or processors under KRS 367.3611 to 367.3629 shall not apply to a controller or processor if compliance under KRS 367.3611 to 367.3629 would violate an evidentiary privilege under the laws of this Commonwealth. Nothing in KRS 367.3611 to 367.3629 shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this Commonwealth as part of a privileged communication. A controller or processor that discloses personal data to a third-party controller or processor, in compliance with the requirements of KRS 367.3611 to 367.3629, is not in violation of KRS 367.3611 to 367.3629 if the th… Archived from source — captured 2026-08-03 · snapshot 1f207b2a Verify at the source
  • Rights and freedoms of others, including free speech Archived excerpt — the text we read …r in compliance with the requirements of KRS 367.3611 to 367.3629 is likewise not in violation of KRS 367.3611 to 367.3629 for the transgressions of the controller or processor from which it receives such personal data. Nothing in KRS 367.3611 to 367.3629 shall be construed as an obligation imposed on controllers and processors that adversely affects the privacy or other rights or freedoms of any persons, including but not limited to the right of free speech pursuant to the First Amendment to the Constitution of the United States, or applies to the processing of personal data by a person in the course of a purely personal or household activity. Personal data processed by a controller pursuant to this section shall not be processed for any purpos… Archived from source — captured 2026-08-03 · snapshot 1f207b2a Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

KCDPA milestones

This state currently has one dated milestone on the books.

Enforcement January 1, 2026

KCDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026