Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Kentucky Consumer Data Protection Act (KCDPA) Assessment

Author

Anas Baig

Product Marketing Manager at Securiti

The Kentucky Consumer Data Protection Act (KCDPA) introduces privacy obligations for certain organizations that do business in Kentucky or target Kentucky residents. This evaluation tool helps you assess whether KCDPA is likely relevant to your organization and how prepared you may be to meet its core requirements by guiding you through a series of essential questions.

The assessment considers factors such as whether your organization has a Kentucky business connection, whether it processes personal data of Kentucky consumers, whether the statutory thresholds are met, and whether exemptions may apply. By answering these questions, you will gain clarity on your organization’s position and whether KCDPA is likely to be relevant. If relevance is indicated, your organization should understand the applicable obligations and take steps to strengthen readiness. KCDPA became effective on January 1, 2026.

1. Does your organization conduct business in Kentucky or target products or services to Kentucky residents?

KCDPA applies to persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents.

2. Does your organization control or process personal data about Kentucky residents acting in an individual context?

Under KCDPA, a “consumer” is a Kentucky resident acting only in an individual context. It does not include a person acting in a commercial or employment context.

3. Does your organization meet at least one of the thresholds of KCDPA?

The KCDPA applies to you if you, in a calendar year, either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.

4. Is the relevant entity clearly exempt from KCDPA?

KCDPA does not apply to certain entities, including Kentucky state or local bodies, financial institutions and affiliates regulated under the Gramm-Leach-Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA) covered entities and business associates, nonprofits, institutions of higher education, certain insurance-related entities, and some telecom or municipal utilities.

5. Does your organization hold the data excluded from the scope of KCDPA?

KCDPA excludes several categories of data, including HIPAA-related data, health records, Fair Credit Reporting Act (FCRA) data, Family Educational Rights and Privacy Act (FERPA) data, Driver's Privacy Protection Act (DPPA) data, certain research and public health data, and employment-related data.

6. Which role best describes your organization for the relevant processing?

A controller determines the purposes and means of processing personal data. A processor processes personal data on behalf of a controller. KCDPA distinguishes between these roles.

7. Does your organization allow consumers to submit privacy rights requests, and does your organization respond within the required timeline?

KCDPA grants consumers rights such as access, correction, deletion, portability, and opt-out rights. Controllers generally must respond within 45 days, with one possible 45-day extension when reasonably necessary.

8. Does your organization provide a reasonably accessible, clear, and meaningful privacy notice containing all required disclosures?

KCDPA requires controllers to provide a reasonably accessible, clear, and meaningful privacy notice covering the categories of personal data collected, purposes, how rights are exercised including appeals, the categories of third parties receiving sold data if any, the categories of personal data shared with third parties, clear opt-out information if data is sold or is used for targeted advertisements, and description of secure method(s) to submit consumer requests.

9. If relevant, does your organization provide opt-outs for sale, targeted advertising, and certain profiling, and obtain consent before processing sensitive data?

KCDPA requires opt-out rights for sale, targeted advertising, and certain profiling, and requires consent for processing sensitive data, with Children's Online Privacy Protection Act (COPPA)-aligned handling for known children.

10. Does your organization’s processor or service-provider contracts include appropriate privacy and security terms?

KCDPA requires processor contracts to address instructions, nature and purpose of processing, type of data, duration, confidentiality, deletion or return, and related compliance support.

11. Does your organization maintain reasonable administrative, technical, and physical safeguards for the personal data covered by KCDPA?

KCDPA requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.

Turn Your Kentucky Privacy Assessment Into an Action Plan

Based on your responses, your organization may need to strengthen key areas of Kentucky Consumer Data Protection Act readiness, including consumer rights workflows, consent management, privacy notices, data protection assessments, security safeguards, and vendor governance.

Securiti helps privacy teams operationalize privacy compliance by automating data discovery, rights fulfillment, consent and preference management, assessment workflows, vendor oversight, and compliance evidence.

Get a personalized Kentucky privacy readiness walkthrough to understand where your program stands, which gaps may require attention, and how to prioritize remediation.

BOOK MY KCDPA READINESS WALKTHROUGH

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer View More
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
DSPM in 2026: Why It Matters More Than Ever View More
DSPM in 2026: Why It Matters More Than Ever
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
An Overview of Bangladesh’s Personal Data Protection Act, 2026
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
Stop Letting Data Risk Stall Your Copilot Rollout View More
Stop Letting Data Risk Stall Your Copilot Rollout
Learn how to safely scale Microsoft 365 Copilot with data labeling, ROT data minimization, and governance using Securiti's DataAI Command Platform.
View More
DPDPA Compliance: A Practical Guide for Enterprises
Learn how to operationalize compliance with India's Digital Personal Data Protection Act (DPDPA) using automation for consent, data governance, security, vendor management, and data...
"The Algorithm Did It" Is Now Dead in Court View More
“The Algorithm Did It” Is Now Dead in Court
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
View More
EU’s Transparency Code of Practice: Watermark To Warning Label
This infographic breaks down the key transparency obligations for both deployers and providers under the AI Act’s Article 50 Code of Practice. Access it...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New