Obtainer
Use case

Kentucky Consumer Data Protection Act (KCDPA) Compliance: Handle Kentucky Data Privacy Law Requests on the 45-Day Deadline

The Kentucky Consumer Data Protection Act took effect on January 1, 2026 and gives Kentucky residents the right to access, correct, delete, and port their personal data and to opt out of its sale, targeted advertising, and profiling. A request starts a 45-day clock. Kentucky amended the statute a year before it switched on, which changed who is exempt, so a compliance plan written in 2024 is now out of date. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The Kentucky Consumer Data Protection Act (KCDPA), House Bill 15, codified at KRS 367.3611 to 367.3629, was signed by Governor Andy Beshear on April 4, 2024 and took effect on January 1, 2026. It applies to a person that conducts business in Kentucky or produces products or services targeted to Kentucky residents and, in a calendar year, either controls or processes the personal data of at least 100,000 Kentucky consumers, or controls or processes the personal data of at least 25,000 Kentucky consumers while deriving more than 50 percent of gross revenue from the sale of personal data. Kentucky switched on the same day as Indiana and Rhode Island, so a company operating nationally picked up three jurisdictions in one morning.

Kentucky consumers can confirm whether you are processing their personal data and access it, correct inaccuracies, delete personal data provided by or obtained about them, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. You have 45 days from receipt to respond, extendable once by another 45 days when reasonably necessary if you notify the consumer inside the first window. A refusal has to explain itself and tell the consumer how to appeal, and you have 60 days to answer that appeal in writing. If you deny the appeal, you have to give the consumer a way to submit a complaint to the Attorney General.

Two details separate Kentucky from the Virginia template it otherwise copies. First, it was amended before it ever applied to anyone: House Bill 473, signed March 15, 2025, exempted information collected by health care providers acting as HIPAA covered entities and maintained in accordance with HIPAA, exempted information maintained in limited data sets under HIPAA, and narrowed the profiling assessment trigger by requiring a reasonably foreseeable risk of unlawful disparate impact rather than disparate impact generally. Second, Kentucky defines the sale of personal data as an exchange for monetary consideration only, which is the narrower of the two definitions US states use. Enforcement rests solely with the Kentucky Attorney General at up to $7,500 per violation, there is no private right of action, and the 30-day right to cure is permanent rather than a grace window that expires.

Obtainer handles the operational half of a Kentucky request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock and the 60-day appeal. Nothing is disclosed or erased automatically. A human reviews, redacts, and approves before anything goes out. Obtainer helps you comply. It is not legal advice, so scope calls, exemptions, and any refusal stay with your team. Self-serve from a planned $49/mo.

Last updated September 2026

// THE FIT

Why it fits

Kentucky businesses, plus out-of-state SaaS, ecommerce, retail, healthcare adjacent, and B2C firms that target Kentucky residents and cross the 100,000 consumer threshold, that want discovery, drafting, appeal handling, and 45-day deadline tracking for a data subject request in one place.

The law you read in 2024 is not the law that took effect

Kentucky is the rare state that amended its privacy act before the act ever applied to anybody. House Bill 473 landed in March 2025 and moved two things that matter operationally: health care providers acting as HIPAA covered entities got a data-level exemption for protected health information maintained under HIPAA, along with limited data sets, and the profiling assessment trigger was narrowed to unlawful disparate impact. If your Kentucky readiness memo predates March 2025, its exemption analysis is stale and its assessment list is longer than the statute now requires.

45 days to respond, then 60 more on appeal

The clock starts when the request arrives, not when somebody opens the ticket, and the appeal is a second deadline most teams have never run. Obtainer stamps the arrival date, starts the countdown, finds the data, drafts the reply, and keeps the appeal on its own 60-day timer, because a denial in Kentucky ends with a documented route for the consumer to complain to the Attorney General.

The 30-day cure is permanent, and records are what earn it

Kentucky kept its right to cure with no sunset date, which puts it alongside Texas, Virginia, Utah, Iowa, Indiana, and Nebraska while Colorado, Connecticut, Delaware, Montana, Minnesota, and New Jersey have let theirs lapse. The Attorney General has to give you written notice and 30 days before seeking $7,500 per violation, and cannot proceed if you cure and confirm it in writing. Writing that confirmation honestly means showing what was searched, what was found, what was redacted, and what went out. Obtainer keeps that record as a by-product of doing the work. Self-serve from a planned $49/mo, with no five-figure floor before your first request.

// THE TABLE

Reference

Where the Kentucky Consumer Data Protection Act differs from the state laws you already handle

Kentucky copied Virginia and then amended itself before the effective date. The rights and the clocks will look familiar. The differences are concentrated in what counts as a sale, who is exempt, and how much room the Attorney General has to give you. Each row is a place the KCDPA departs from the template, and what that departure changes in your request workflow.

RequirementKentucky (KCDPA)Typical state lawWhat it changes for you
Applicability threshold100,000 Kentucky consumers, or 25,000 plus more than 50 percent of gross revenue from selling personal dataOften 100,000, but the revenue prong is commonly 25 percent, and Connecticut cut its main trigger to 35,000 in July 2026Fewer companies are in scope in Kentucky than in Connecticut or Colorado. Count residents per state, not once for the country.
Definition of a saleExchange of personal data for monetary consideration onlyColorado, Connecticut, Oregon, Delaware, and New Jersey reach exchanges for monetary or other valuable consideration, and California adds a separate concept of sharingA data-for-data swap with an ad partner can be outside the Kentucky sale definition and inside five other states. Scope the opt-out per state or apply the broadest rule everywhere.
Health data exemptionEntity-level for HIPAA covered entities, plus data-level exemptions added in 2025 for provider-held protected health information and for HIPAA limited data setsHIPAA carve-outs are standard, but the limited data set exemption is notA hospital system or a provider-adjacent vendor may be further out of scope in Kentucky than elsewhere. Confirm against the amended text, not the 2024 bill.
Response deadline45 days, extendable once by 45 days with notice inside the first window45 days plus a 45-day extension in most states. Iowa runs 90 days, Florida caps the extension at 15Same clock you already run for twenty other states. The failure mode is intake, not drafting.
AppealRequired, 60 days to respond in writing, and a denial must give the consumer a route to the Attorney GeneralRequired in most states, usually 45 or 60 daysA denial creates a second deadline. Track it separately from the original request.
Universal opt-out signalNot required. Kentucky joins Virginia, Iowa, Utah, and Indiana in declining to mandate oneColorado, Connecticut, Texas, Montana, New Jersey, Delaware, Oregon, Minnesota, and Maryland require honoring an opt-out preference signalYou still need Global Privacy Control handling for the states that mandate it, so build it once and apply it everywhere.
Cure period and penalty30 days, permanent, and the Attorney General may not proceed if you cure and confirm compliance in writing. Up to $7,500 per violation, AG only, no private right of actionCommonly 30 or 60 days with a sunset, and six states have already let theirs lapseYou get a warning in Kentucky, but you have to sign for it. Producing a complete request record fast is what turns that notice into a closed file.
// FAQ

Questions

Common questions about this

Who has to comply with the Kentucky Consumer Data Protection Act?

A person that conducts business in Kentucky or produces products or services targeted to Kentucky residents and, during a calendar year, either controls or processes the personal data of at least 100,000 Kentucky consumers, or controls or processes the personal data of at least 25,000 Kentucky consumers and derives more than 50 percent of gross revenue from the sale of personal data. State agencies, financial institutions subject to the Gramm-Leach-Bliley Act, HIPAA covered entities, nonprofits, and higher education institutions are exempt at the entity level, and data regulated by HIPAA, the Fair Credit Reporting Act, FERPA, the Driver's Privacy Protection Act, and the Farm Credit Act is exempt at the data level. If you are unsure which statutes reach you, start with which state privacy laws apply to your business.

When did the Kentucky Consumer Data Protection Act take effect?

January 1, 2026. House Bill 15 passed the legislature on March 27, 2024 and was signed on April 4, 2024, giving businesses a runway of about twenty months. Kentucky took effect the same day as the Indiana Consumer Data Protection Act and the Rhode Island Data Transparency and Privacy Protection Act, so a national company added three jurisdictions at once on that date. If you scoped Indiana already, most of the operational build carries over.

What is the penalty for violating the Kentucky Consumer Data Protection Act?

Up to $7,500 per violation, sought by the Kentucky Attorney General, who holds exclusive enforcement authority. There is no private right of action, so consumers cannot sue you directly. Before filing, the Attorney General must give you written notice of the alleged violation and 30 days to cure it. If you cure the violation and provide a written statement that it has been addressed and will not recur, the Attorney General may not proceed. That cure period is permanent, not a temporary grace window, and you can compare it against the rest of the country in our rundown of state privacy law cure periods.

How long do I have to respond to a Kentucky data subject request?

Forty-five days from receipt of the request. You can take one additional 45-day extension when reasonably necessary, as long as you tell the consumer inside the first 45 days why you need it. If you decline to act, you have to explain why within that same window and tell the consumer how to appeal, and you then have 60 days to answer the appeal in writing. Obtainer starts both clocks at intake and works the DSAR process against them. The full state-by-state picture sits in our data subject request deadlines by state guide.

Does Kentucky require honoring Global Privacy Control?

No. The KCDPA does not require controllers to recognize a universal opt-out mechanism, which puts Kentucky alongside Virginia, Iowa, Utah, and Indiana. That is the minority position: Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, and Maryland all require it. If you operate nationally, honor the signal everywhere rather than maintaining a state-by-state exception in your consent layer, because the exception costs more to run than the compliance does.

What changed when Kentucky amended the KCDPA in 2025?

House Bill 473, signed on March 15, 2025, made three changes before the act ever took effect. It exempted information collected by health care providers acting as covered entities under HIPAA and maintained in accordance with HIPAA. It exempted information maintained in limited data sets under HIPAA. And it narrowed the data protection assessment trigger for profiling so that an assessment is required where the profiling presents a reasonably foreseeable risk of unlawful disparate impact on consumers, rather than disparate impact generally. The practical effect is that a Kentucky plan drafted from the 2024 bill overstates both the exemption boundary and the assessment workload. The broader picture of how health data is carved out of state law is in our note on the HIPAA exemption in state privacy laws.

Is Kentucky the same as Virginia's privacy law?

Structurally, close to it. Kentucky copied the Virginia Consumer Data Protection Act model: the same rights, the same 45-day clock, the same appeal, the same $7,500 per violation ceiling, the same absence of a private right of action, and the same decision not to mandate a universal opt-out signal. Where it departs is at the edges that show up in operations rather than in policy: the 2025 HIPAA amendments, the narrowed profiling assessment trigger, and a permanent cure period. If you already run Virginia requests, the delta is small enough to handle inside the same workflow rather than as a separate program.

Do I need Kentucky-specific software to handle a KCDPA request?

No, and buying per state is how privacy budgets get wasted. What you need is one workflow that intakes a request, verifies who is asking, searches every system that could hold that person's data, produces a manifest a human can review and redact, drafts the response, and tracks the statutory clock and any appeal. Kentucky then becomes a configuration detail: a 45-day timer, a 60-day appeal timer, and the state's narrower sale definition applied to your opt-out logic. That is what subject access request software is for, and the part that actually takes the time is personal data discovery, which is state agnostic.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.