Law note · Kentucky
Kentucky Consumer Data Protection Act, sensitive data and biometric data definitions
KCDPA classifies genetic or biometric data processed to uniquely identify a person as sensitive data, requiring opt-in consent under KRS 367.3617.
"Biometric data" means data from automatic measurement of a biological characteristic, such as a fingerprint, voiceprint, or eye retina or iris, used to identify a specific individual; a photograph, video, or audio recording, or data generated from one, is excluded only until that data is generated to identify a specific individual or is health care information governed by HIPAA, at which point the general exclusion lifts. A 2026 amendment effective July 1, 2027 leaves this definition's operative text unchanged.
What it asks of an app
- Obtain a Kentucky consumer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual.
- Treat a voiceprint or faceprint you deliberately extract from a photograph, video, or audio recording to identify a specific individual as covered biometric data. Kentucky's exclusion for recording-derived data does not reach data generated for that purpose.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice, crawls_web, trains_models
Primary source: official Kentucky statute text, KRS chapter 367, Kentucky Legislature website