Kentucky Consumer Privacy Protection Act (KPPA)
Overview
The Kentucky Consumer Privacy Protection Act (KPPA), codified as KRS §367.401 through §367.445, was signed into law on April 4, 2024 (HB 15), and becomes effective January 1, 2026. Kentucky follows the Virginia/Connecticut model with five consumer rights, controller-processor framework, sensitive data opt-in consent, and AG-only enforcement.
Applicability (§367.405)
The KPPA applies to persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents AND during a calendar year:
- Control or process personal data of at least 100,000 Kentucky consumers; OR
- Control or process personal data of at least 25,000 Kentucky consumers AND derive more than 50% of gross revenue from the sale of personal data.
Exemptions (§367.407):
- State and local government entities
- GLBA-covered financial institutions (entity-level)
- HIPAA covered entities and business associates (entity-level)
- Nonprofit organizations
- Institutions of higher education
- Covered entities under FERPA
- Data governed by GLBA, HIPAA, FERPA, FCRA, DPPA, COPPA, Farm Credit Act
Liberty Commerce Inc. Assessment:
Liberty Commerce Inc. processes personal data of approximately 68,000 Kentucky consumers. It does not meet either threshold but monitors as the law becomes effective January 1, 2026.
Consumer Rights (§367.415)
Five Consumer Rights
- Right to Access (§367.415(1)(a)): Confirm processing and access personal data
- Right to Correct (§367.415(1)(b)): Correct inaccuracies
- Right to Delete (§367.415(1)(c)): Delete personal data
- Right to Portability (§367.415(1)(d)): Obtain data in portable format
- Right to Opt Out (§367.415(1)(e)):
- Targeted advertising
- Sale of personal data
- Profiling in furtherance of decisions producing legal or similarly significant effects
Response Requirements (§367.417)
- Respond within 45 days
- Extension: up to 45 additional days (90 total) with notice
- At least one free response per 12 months per right
- Appeal: controller must respond within 60 days
Sensitive Data (§367.401(27), §367.413(5))
Categories
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic or biometric data for identification
- Personal data of a known child
- Precise geolocation data
Consent Requirement
Processing requires opt-in consent before processing. The KPPA follows the Virginia model requiring affirmative, freely given consent.
Controller Obligations (§367.413)
- Purpose limitation: Adequate, relevant, and reasonably necessary
- Data minimization: Not excessive relative to purposes
- Data security: Appropriate technical and organizational measures
- Non-discrimination: No processing in violation of antidiscrimination laws
- Sensitive data consent: Opt-in before processing
- Transparency: Clear and reasonably accessible privacy notice
Privacy Notice Requirements (§367.413(2))
- Categories of personal data processed
- Purposes for processing each category
- Consumer rights and how to exercise them
- Categories of data shared with third parties
- Categories of third parties
- Active email or online contact mechanism
Data Protection Assessments (§367.419)
Required for:
- Targeted advertising
- Sale of personal data
- Profiling with significant effects
- Sensitive data processing
- High-risk processing activities
DPIAs must be made available to the AG upon request.
Processor Requirements (§367.421)
Processing must be governed by a contract that includes:
- Instructions for processing
- Nature, purpose, and duration
- Type of data and categories of consumers
- Controller and processor rights and obligations
- Confidentiality duty for persons processing data
- Return or deletion upon end of services
- Cooperation with compliance assessments
- Sub-processor contract requirements with equivalent protections
Enforcement (§367.435)
Attorney General Authority
- Exclusive enforcement — no private right of action
- Enforcement under KRS §367.990 (Kentucky Consumer Protection Act)
Cure Period (§367.437)
- AG must provide written notice of alleged violation
- Controller has 30 days to cure
- If cured and express written statement provided: AG may not bring action
- No sunset provision — 30-day cure period is permanent
Penalties
- Civil penalties up to $7,500 per violation
- Injunctive relief
- Costs and attorney fees
Implementation Timeline
| Milestone |
Date |
Action |
| Law enacted |
April 4, 2024 |
HB 15 signed by Governor |
| Compliance planning |
April 2024 - December 2025 |
Gap analysis, privacy notice updates, consent mechanisms |
| Data protection assessments |
July - December 2025 |
Complete DPIAs for applicable processing activities |
| Technical implementation |
September - December 2025 |
Deploy consumer rights portal, opt-out mechanisms |
| Staff training |
November - December 2025 |
Train privacy team and customer service |
| Effective date |
January 1, 2026 |
Full compliance required |
Key Regulatory References
- KRS §367.401 through §367.445 (KPPA)
- KRS §367.990 (Kentucky Consumer Protection Act — enforcement penalties)
- KRS §365.732 (Kentucky Data Breach Notification)
1---2name: kentucky-kppa3description: Kentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consumers, sensitive data processing consent, cure period provisions, and AG enforcement framework.4license: Apache-2.05---67# Kentucky Consumer Privacy Protection Act (KPPA)89## Overview1011The Kentucky Consumer Privacy Protection Act (KPPA), codified as KRS §367.401 through §367.445, was signed into law on April 4, 2024 (HB 15), and becomes effective **January 1, 2026**. Kentucky follows the Virginia/Connecticut model with five consumer rights, controller-processor framework, sensitive data opt-in consent, and AG-only enforcement.1213## Applicability (§367.405)1415The KPPA applies to persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents AND during a calendar year:16171. Control or process personal data of at least **100,000** Kentucky consumers; OR182. Control or process personal data of at least 25,000 Kentucky consumers AND derive more than **50%** of gross revenue from the sale of personal data.1920**Exemptions (§367.407):**21- State and local government entities22- GLBA-covered financial institutions (entity-level)23- HIPAA covered entities and business associates (entity-level)24- Nonprofit organizations25- Institutions of higher education26- Covered entities under FERPA27- Data governed by GLBA, HIPAA, FERPA, FCRA, DPPA, COPPA, Farm Credit Act2829**Liberty Commerce Inc. Assessment:**30Liberty Commerce Inc. processes personal data of approximately 68,000 Kentucky consumers. It does not meet either threshold but monitors as the law becomes effective January 1, 2026.3132## Consumer Rights (§367.415)3334### Five Consumer Rights35361. **Right to Access** (§367.415(1)(a)): Confirm processing and access personal data372. **Right to Correct** (§367.415(1)(b)): Correct inaccuracies383. **Right to Delete** (§367.415(1)(c)): Delete personal data394. **Right to Portability** (§367.415(1)(d)): Obtain data in portable format405. **Right to Opt Out** (§367.415(1)(e)):41 - Targeted advertising42 - Sale of personal data43 - Profiling in furtherance of decisions producing legal or similarly significant effects4445### Response Requirements (§367.417)46- Respond within 45 days47- Extension: up to 45 additional days (90 total) with notice48- At least one free response per 12 months per right49- Appeal: controller must respond within 60 days5051## Sensitive Data (§367.401(27), §367.413(5))5253### Categories541. Racial or ethnic origin552. Religious beliefs563. Mental or physical health diagnosis574. Sexual orientation585. Citizenship or immigration status596. Genetic or biometric data for identification607. Personal data of a known child618. Precise geolocation data6263### Consent Requirement64Processing requires opt-in consent before processing. The KPPA follows the Virginia model requiring affirmative, freely given consent.6566## Controller Obligations (§367.413)67681. **Purpose limitation**: Adequate, relevant, and reasonably necessary692. **Data minimization**: Not excessive relative to purposes703. **Data security**: Appropriate technical and organizational measures714. **Non-discrimination**: No processing in violation of antidiscrimination laws725. **Sensitive data consent**: Opt-in before processing736. **Transparency**: Clear and reasonably accessible privacy notice7475### Privacy Notice Requirements (§367.413(2))76- Categories of personal data processed77- Purposes for processing each category78- Consumer rights and how to exercise them79- Categories of data shared with third parties80- Categories of third parties81- Active email or online contact mechanism8283### Data Protection Assessments (§367.419)84Required for:85- Targeted advertising86- Sale of personal data87- Profiling with significant effects88- Sensitive data processing89- High-risk processing activities9091DPIAs must be made available to the AG upon request.9293## Processor Requirements (§367.421)9495Processing must be governed by a contract that includes:96- Instructions for processing97- Nature, purpose, and duration98- Type of data and categories of consumers99- Controller and processor rights and obligations100- Confidentiality duty for persons processing data101- Return or deletion upon end of services102- Cooperation with compliance assessments103- Sub-processor contract requirements with equivalent protections104105## Enforcement (§367.435)106107### Attorney General Authority108- Exclusive enforcement — no private right of action109- Enforcement under KRS §367.990 (Kentucky Consumer Protection Act)110111### Cure Period (§367.437)112- AG must provide written notice of alleged violation113- Controller has **30 days** to cure114- If cured and express written statement provided: AG may not bring action115- **No sunset provision** — 30-day cure period is permanent116117### Penalties118- Civil penalties up to $7,500 per violation119- Injunctive relief120- Costs and attorney fees121122## Implementation Timeline123124| Milestone | Date | Action |125|-----------|------|--------|126| Law enacted | April 4, 2024 | HB 15 signed by Governor |127| Compliance planning | April 2024 - December 2025 | Gap analysis, privacy notice updates, consent mechanisms |128| Data protection assessments | July - December 2025 | Complete DPIAs for applicable processing activities |129| Technical implementation | September - December 2025 | Deploy consumer rights portal, opt-out mechanisms |130| Staff training | November - December 2025 | Train privacy team and customer service |131| **Effective date** | **January 1, 2026** | **Full compliance required** |132133## Key Regulatory References134135- KRS §367.401 through §367.445 (KPPA)136- KRS §367.990 (Kentucky Consumer Protection Act — enforcement penalties)137- KRS §365.732 (Kentucky Data Breach Notification)