Law / Kentucky

Kentucky

age

Kentucky has required age verification for adult websites since 2024, enforceable only through private civil action since the statute bars government enforcement. A bill requiring age verification, parental consent, and default restrictions on addictive features for minors on social media and AI companion platforms passed the House unanimously in March 2026 but died in the Senate Judiciary Committee when the session ended. No app store accountability or design code bill has advanced past committee.

privacy

Kentucky's comprehensive privacy law, the Kentucky Consumer Data Protection Act (KCDPA, KRS 367.3611 to 367.3629), took effect January 1, 2026. This document corrects the corpus's session-law citation: the statute's own codification note reads "Created 2024 Ky. Acts ch. 72, sec. 1," not the ch. 89 the corpus carried.

KCDPA requires opt-in consent for sensitive data, including genetic or biometric data processed to uniquely identify a person, and gives consumers access, correction, deletion, portability, and opt-out rights, enforced exclusively by the Attorney General with a permanent 30-day cure period and no private right of action.

A separate breach-notification statute, KRS 365.732, covers only name plus a Social Security, driver's license, or financial account number, and does not reach biometric identifiers or establish a private right of action in the text read. A 2026 amendment to KRS 367.3611, effective July 1, 2027, leaves the biometric-data definition unchanged.

11 instruments named 7 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

Breach notification

Notification to affected persons of computer security breach

cite KRS 365.732 stage IN FORCE in force since 2014-07-15 source official Kentucky statute text, KRS section 365.732, Kentucky Legislature website

An information holder must disclose a breach of the security of the system involving unencrypted personal information to any affected Kentucky resident in the most expedient time possible and without unreasonable delay, with consumer-reporting-agency notice required once more than 1,000 persons are affected at one time.

"Personally identifiable information" is limited to a name plus a Social Security, driver's license, or financial account number with access credentials, and does not reach biometric identifiers. No provision in the eight subsections read requires notice to the Kentucky Attorney General, and none establishes a private right of action; the codified text's own history note dates it to 2014 Ky. Acts ch. 84, sec. 1, effective July 15, 2014.

What it asks of an app

Comprehensive regime

Kentucky Consumer Data Protection Act (KCDPA), general applicability and controller and processor duties

cite KRS 367.3611, 367.3613, 367.3617, 367.3619 stage RECENT in force 8 months effective 2026-01-01 source official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

KCDPA applies to a person that conducts business in Kentucky, or produces a product or service targeted to Kentucky residents, and that during a calendar year controls or processes personal data of at least 100,000 consumers, or 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data.

It exempts city and state government, GLBA-covered financial institutions, HIPAA covered entities and business associates, nonprofits, higher-education institutions, certain insurance-fraud investigative organizations, and small telephone, CMRS, or municipal utilities that do not sell personal data. Controllers must limit collection to disclosed purposes and processors act on the controller's instructions under a written contract. The enacting session law is 2024 Ky. Acts ch. 72, sec. 1, not the ch. 89 the corpus carried.

What it asks of an app

Data subject rights

Kentucky Consumer Data Protection Act, consumer rights

cite KRS 367.3615 stage RECENT in force 8 months effective 2026-01-01 source official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

KCDPA gives a Kentucky consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and significant-effect profiling.

A controller must respond without undue delay and in all cases within 45 days of receipt, with one 45-day extension available when reasonably necessary, and must decide an appeal of a denial within 60 days, after which the consumer may complain to the Attorney General.

What it asks of an app

Enforcement supervision

Kentucky Consumer Data Protection Act, Attorney General enforcement

cite KRS 367.3627 stage RECENT in force 8 months effective 2026-01-01 source official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

The Kentucky Attorney General has exclusive authority to enforce KCDPA. Before suing, the Attorney General must give a controller or processor 30 days' written notice; curing the violation and confirming the cure in writing bars an action, and this 30-day cure period is permanent, unlike New Hampshire's and Rhode Island's time-limited or absent versions. An uncured, continuing violation is subject to damages of up to $7,500 per violation, and the statute creates no private right of action.

What it asks of an app

Sensitive categories

Kentucky Consumer Data Protection Act, sensitive data and biometric data definitions

cite KRS 367.3611(28), 367.3611(3), 367.3617 stage RECENT in force 8 months effective 2026-01-01 source official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

KCDPA classifies genetic or biometric data processed to uniquely identify a person as sensitive data, requiring opt-in consent under KRS 367.3617.

"Biometric data" means data from automatic measurement of a biological characteristic, such as a fingerprint, voiceprint, or eye retina or iris, used to identify a specific individual; a photograph, video, or audio recording, or data generated from one, is excluded only until that data is generated to identify a specific individual or is health care information governed by HIPAA, at which point the general exclusion lifts. A 2026 amendment effective July 1, 2027 leaves this definition's operative text unchanged.

What it asks of an app

Social media and minors

HB 227, addictive online platforms and minor protections

cite House Bill No. 227 (2026 Regular Session), died in Senate committee stage PROPOSED draft date not recorded source official Kentucky Legislature bill text and vote history

Would require social media and AI companion platforms to estimate user age, place users under 15 into default child safety settings and disable addictive features such as autoplay absent parental consent, and give parents account monitoring tools. Passed the House 96 to 0 on March 9, 2026, received two readings in the Senate, but died in the Senate Judiciary Committee when the 2026 session ended in April.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.