Key Facts
Overview
Kentucky's KCDPA closely follows the Virginia VCDPA template, with a permanent 30-day cure period and standard applicability thresholds. It takes effect January 1, 2026, with data protection impact assessments applying to processing from June 2026. HB 473 (March 2025) refined healthcare and DPIA provisions.
What This Means for Your Website
- Opt-in consent is required for sensitive data of Kentucky visitors
- Consumer rights include access, correction, deletion, portability, and opt-out
- A permanent 30-day cure period applies
- No requirement to honor GPC/UOOM signals
- Data protection impact assessments apply from June 1, 2026
Key Requirements
The Kentucky AG enforces the KCDPA with penalties up to $7,500 per violation. Consumer requests must be fulfilled within 45 days. The VCDPA template provides a familiar framework for businesses already complying with Virginia law.
How ConsentStack Handles This
ConsentStack detects Kentucky visitors and applies the KCDPA opt-out model with opt-in for sensitive data when the law takes effect in January 2026.
Penalties
Up to $7,500 per violation.
Key Requirements
- Opt-in consent for sensitive data
- Consumer rights: access, correct, delete, portability, opt-out
- Data protection assessments from June 2026
- Privacy notice with required disclosures
- Data minimization obligations
Notable Provisions
- Virginia VCDPA template
- Permanent 30-day cure period
- No UOOM requirement
- DPIAs from June 2026
- HB 473 (March 2025) refined healthcare and DPIA provisions
US State Specifics
Other North America Regulations
Frequently Asked Questions
When does Kentucky's privacy law take effect?
January 1, 2026. Data protection impact assessments apply to processing from June 1, 2026.
Does Kentucky require GPC signal honoring?
No. The KCDPA does not require honoring GPC/UOOM signals, unlike many other recent US state privacy laws.
What are the KCDPA penalties?
Up to $7,500 per violation with a permanent 30-day cure period.
Stay compliant with KCDPA
ConsentStack helps you implement Opt-out consent for Kentucky, United States automatically.