Law note · Kentucky

Notification to affected persons of computer security breach

cite KRS 365.732 stage IN FORCE in force since 2014-07-15 reviewed 2026-08-27

An information holder must disclose a breach of the security of the system involving unencrypted personal information to any affected Kentucky resident in the most expedient time possible and without unreasonable delay, with consumer-reporting-agency notice required once more than 1,000 persons are affected at one time.

"Personally identifiable information" is limited to a name plus a Social Security, driver's license, or financial account number with access credentials, and does not reach biometric identifiers. No provision in the eight subsections read requires notice to the Kentucky Attorney General, and none establishes a private right of action; the codified text's own history note dates it to 2014 Ky. Acts ch. 84, sec. 1, effective July 15, 2014.

What it asks of an app

  • Notify an affected Kentucky resident of a breach involving unencrypted personal information in the most expedient time possible and without unreasonable delay.
  • Notify each nationwide consumer reporting agency if more than 1,000 persons are affected at one time.
  • Do not rely on this statute alone to cover a breach of biometric data with no accompanying Social Security, driver's license, or financial account number. Biometric data alone is not within this statute's definition of personally identifiable information.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Kentucky statute text, KRS section 365.732, Kentucky Legislature website

← Back to the example  ·  Lint your app →