| name | kentucky-kppa |
| title | Kentucky Consumer Privacy Protection Act (KPPA) |
| description | Kentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consumers, sensitive data processing consent, cure period provisions, and AG enforcement framework. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/kentucky-kppa |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | data-protection |
| language | en |
Kentucky Consumer Privacy Protection Act (KPPA)
Overview
The Kentucky Consumer Privacy Protection Act (KPPA), codified as KRS §367.401 through §367.445, was signed into law on April 4, 2024 (HB 15), and becomes effective January 1, 2026. Kentucky follows the Virginia/Connecticut model with five consumer rights, controller-processor framework, sensitive data opt-in consent, and AG-only enforcement.
Applicability (§367.405)
The KPPA applies to persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents AND during a calendar year:
- Control or process personal data of at least 100,000 Kentucky consumers; OR
- Control or process personal data of at least 25,000 Kentucky consumers AND derive more than 50% of gross revenue from the sale of personal data.
Exemptions (§367.407):
- State and local government entities
- GLBA-covered financial institutions (entity-level)
- HIPAA covered entities and business associates (entity-level)
- Nonprofit organizations
- Institutions of higher education
- Covered entities under FERPA
- Data governed by GLBA, HIPAA, FERPA, FCRA, DPPA, COPPA, Farm Credit Act
Liberty Commerce Inc. Assessment:
Liberty Commerce Inc. processes personal data of approximately 68,000 Kentucky consumers. It does not meet either threshold but monitors as the law becomes effective January 1, 2026.
Consumer Rights (§367.415)
Five Consumer Rights
- Right to Access (§367.415(1)(a)): Confirm processing and access personal data
- Right to Correct (§367.415(1)(b)): Correct inaccuracies
- Right to Delete (§367.415(1)(c)): Delete personal data
- Right to Portability (§367.415(1)(d)): Obtain data in portable format
- Right to Opt Out (§367.415(1)(e)):
- Targeted advertising
- Sale of personal data
- Profiling in furtherance of decisions producing legal or similarly significant effects
Response Requirements (§367.417)
- Respond within 45 days
- Extension: up to 45 additional days (90 total) with notice
- At least one free response per 12 months per right
- Appeal: controller must respond within 60 days
Sensitive Data (§367.401(27), §367.413(5))
Categories
- Racial or ethnic origin