Law note · Kentucky
Kentucky Consumer Data Protection Act (KCDPA), general applicability and controller and processor duties
KCDPA applies to a person that conducts business in Kentucky, or produces a product or service targeted to Kentucky residents, and that during a calendar year controls or processes personal data of at least 100,000 consumers, or 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data.
It exempts city and state government, GLBA-covered financial institutions, HIPAA covered entities and business associates, nonprofits, higher-education institutions, certain insurance-fraud investigative organizations, and small telephone, CMRS, or municipal utilities that do not sell personal data. Controllers must limit collection to disclosed purposes and processors act on the controller's instructions under a written contract. The enacting session law is 2024 Ky. Acts ch. 72, sec. 1, not the ch. 89 the corpus carried.
What it asks of an app
- Determine whether you conduct business in Kentucky, or produce a product or service targeted to Kentucky residents, and control or process personal data of at least 100,000 consumers, or 25,000 consumers while deriving over 50 percent of gross revenue from selling personal data, before relying on any KCDPA exemption.
- Confirm whether a sector exemption applies. KCDPA excludes city and state government, GLBA-covered financial institutions, HIPAA covered entities and business associates, nonprofits, and higher-education institutions.
- Limit collection to the purposes disclosed to the consumer, and use a written contract to bind any processor to your instructions.
When LexLint raises it
Declared activities: automated_outreach, crawls_web, deploys_chatbot, processes_biometrics, processes_voice, trains_models
Primary source: official Kentucky statute text, KRS chapter 367, Kentucky Legislature website