Kentucky Consumer Data Protection Act (KCDPA)

Kentucky’s privacy law lays out a host of requirements for controllers related to how data is handled, along with security, consent, and privacy policy requirements, and how they should handle consumer rights requests.

Is Complying with KCDPA Mandatory?

The law applies toto any person who conducts business in Kentucky or who produces products or services that target residents of the state, and during a calendar year controls or processes data of at least:

  • 100,000 consumers; or

  • 25,000 consumers and derives over 50 percent of gross revenue from the sale of personal data.

What are the penalties for not complying with KCDPA?

The penalty for violating the KCDPA is up to $7,500 for each violation. Penalties paid will be put into a fund the Office of the Attorney General can use to enforce the KCDPA.