Kentucky Consumer Data Protection Act
KCDPA · Normalized Research Card v2.1
IN FORCELAST VERIFIED · AUG 26 2026At a glance
Who must comply?
Applicability model: Numerical threshold.
Core threshold: 100,000 consumers; or 25,000 consumers and >50% gross revenue from sale
Applicability remains subject to statutory entity, data-level and activity-specific exemptions. Employment/B2B treatment and federal-law carve-outs should be read together with the official statute linked below.
Consumer rights
| Right / protection | Status |
|---|---|
| Confirmation / access | ✓ Included / qualified by statute |
| Correction | ✓ Included / qualified by statute |
| Deletion | ✓ Included / qualified by statute |
| Portability | ✓ Included / qualified by statute |
| Opt-out targeted advertising | ✓ Included / qualified by statute |
| Opt-out sale | ✓ Included / qualified by statute |
| Opt-out qualifying profiling | ✓ Included / qualified by statute |
Sensitive data & minors
Sensitive-data standard: Consent required
Known-child data receives COPPA-linked treatment.
Business obligations
Privacy notice, consumer requests and appeals, processor contracts, security, sensitive-data consent and assessments.
Enforcement
Authority: Kentucky Attorney General — Office of Data Privacy
Private right of action: No
Penalty / remedy baseline: Up to $7,500 per violation after the statutory cure process
What makes Kentucky different?
Kentucky created a dedicated Office of Data Privacy inside the Attorney General's office. That institutional enforcement structure is notable for a newer state privacy law.
Developments to watch
KCDPA is in force and the Office of Data Privacy now provides consumer and business guidance.
Editorial rule: future-effective, proposed and pending measures are kept separate from current law.
Primary sources & verification
Last verified: August 26, 2026
Research standard: primary official sources prioritized; official guidance used to explain operational requirements.