Kentucky Consumer Data Protection Act (KCDPA) Assessment

Author

Anas Baig

Product Marketing Manager at Securiti

The Kentucky Consumer Data Protection Act (KCDPA) introduces privacy obligations for certain organizations that do business in Kentucky or target Kentucky residents. This evaluation tool helps you assess whether KCDPA is likely relevant to your organization and how prepared you may be to meet its core requirements by guiding you through a series of essential questions.

The assessment considers factors such as whether your organization has a Kentucky business connection, whether it processes personal data of Kentucky consumers, whether the statutory thresholds are met, and whether exemptions may apply. By answering these questions, you will gain clarity on your organization’s position and whether KCDPA is likely to be relevant. If relevance is indicated, your organization should understand the applicable obligations and take steps to strengthen readiness. KCDPA became effective on January 1, 2026.

1. Does your organization conduct business in Kentucky or target products or services to Kentucky residents?

KCDPA applies to persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents.

2. Does your organization control or process personal data about Kentucky residents acting in an individual context?

Under KCDPA, a “consumer” is a Kentucky resident acting only in an individual context. It does not include a person acting in a commercial or employment context.

3. Does your organization meet at least one of the thresholds of KCDPA?

The KCDPA applies to you if you, in a calendar year, either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.

4. Is the relevant entity clearly exempt from KCDPA?

KCDPA does not apply to certain entities, including Kentucky state or local bodies, financial institutions and affiliates regulated under the Gramm-Leach-Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA) covered entities and business associates, nonprofits, institutions of higher education, certain insurance-related entities, and some telecom or municipal utilities.

5. Does your organization hold the data excluded from the scope of KCDPA?

KCDPA excludes several categories of data, including HIPAA-related data, health records, Fair Credit Reporting Act (FCRA) data, Family Educational Rights and Privacy Act (FERPA) data, Driver's Privacy Protection Act (DPPA) data, certain research and public health data, and employment-related data.

6. Which role best describes your organization for the relevant processing?

A controller determines the purposes and means of processing personal data. A processor processes personal data on behalf of a controller. KCDPA distinguishes between these roles.

7. Does your organization allow consumers to submit privacy rights requests, and does your organization respond within the required timeline?

KCDPA grants consumers rights such as access, correction, deletion, portability, and opt-out rights. Controllers generally must respond within 45 days, with one possible 45-day extension when reasonably necessary.

8. Does your organization provide a reasonably accessible, clear, and meaningful privacy notice containing all required disclosures?

KCDPA requires controllers to provide a reasonably accessible, clear, and meaningful privacy notice covering the categories of personal data collected, purposes, how rights are exercised including appeals, the categories of third parties receiving sold data if any, the categories of personal data shared with third parties, clear opt-out information if data is sold or is used for targeted advertisements, and description of secure method(s) to submit consumer requests.

9. If relevant, does your organization provide opt-outs for sale, targeted advertising, and certain profiling, and obtain consent before processing sensitive data?

KCDPA requires opt-out rights for sale, targeted advertising, and certain profiling, and requires consent for processing sensitive data, with Children's Online Privacy Protection Act (COPPA)-aligned handling for known children.

10. Does your organization’s processor or service-provider contracts include appropriate privacy and security terms?

KCDPA requires processor contracts to address instructions, nature and purpose of processing, type of data, duration, confidentiality, deletion or return, and related compliance support.

11. Does your organization maintain reasonable administrative, technical, and physical safeguards for the personal data covered by KCDPA?

KCDPA requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.

Turn Your Kentucky Privacy Assessment Into an Action Plan

Based on your responses, your organization may need to strengthen key areas of Kentucky Consumer Data Protection Act readiness, including consumer rights workflows, consent management, privacy notices, data protection assessments, security safeguards, and vendor governance.

Securiti helps privacy teams operationalize privacy compliance by automating data discovery, rights fulfillment, consent and preference management, assessment workflows, vendor oversight, and compliance evidence.

Get a personalized Kentucky privacy readiness walkthrough to understand where your program stands, which gaps may require attention, and how to prioritize remediation.

BOOK MY KCDPA READINESS WALKTHROUGH

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You

See the platform live

Ready to see DataAI Command Platform in action?

See how your team can discover sensitive data, reduce risk, and secure AI usage from one command center.

Book a demo
Demo BG Book a demo
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
One Unrevoked Key, 37.5 Million People: What the Coupang data breach reveals about data access
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
How to Choose the Right DSPM Platform View More
How to Choose the Right DSPM Platform
Learn how to choose the right DSPM platform by evaluating data coverage, classification accuracy, contextual risk, AI security, and automated remediation.
What is Data Stewardship? All You Need to Know View More
What is Data Stewardship? All You Need to Know
Discover what data stewardship is, types, importance, how it differs from data governance, use cases, challenges, benefits and how Securiti helps.
View More
Green-Light AI, Not Data Exposure
Learn the five critical data-layer controls enterprises need to prevent sensitive data exposure and enable secure, scalable AI agent adoption.
Agentic AI Readiness View More
Agentic AI Readiness: Why Your Enterprise Needs a New Data Security Paradigm
Learn how to secure Agentic AI by discovering sensitive data, mitigating AI risks, and building an enterprise-ready AI security strategy.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
"The Algorithm Did It" Is Now Dead in Court View More
“The Algorithm Did It” Is Now Dead in Court
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New