Kentucky Consumer Data Protection Act

HB 15

Enacted
2024-04-04
Effective
2026-01-01
Status
enacted
Verified
2026-03-18

Regulatory Snapshot: Kentucky Consumer Data Protection Act

Kentucky Consumer Data Protection Act (HB 15) is an enacted law in Kentucky under the Data Privacy category. It was enacted on 2024-04-04 and becomes effective on 2026-01-01. Kentucky currently reports 2 tracked regulations with 2 already in force, giving the state a regulatory strictness score of 31/100 relative to the national baseline. PlainRegWatch last verified this entry on 2026-03-18.

Nationally, 21 states have enacted data privacy statutes and 0 additional bills remain pending — 21 distinct jurisdictions have codified rules in this area so far. That places Kentucky within a mature and broadly adopted data privacy landscape where compliance programs typically hinge on definitions in HB 15 itself.

Applicability under Kentucky Consumer Data Protection Act: 100K+ consumers, or 25K+ with 50%+ data sale revenue. Penalty exposure is documented as: $7,500/violation. AG with 30-day cure. Notable exemptions: Government, HIPAA, GLBA, nonprofits, higher ed..

Summary

Virginia model privacy law.

Key Requirements

Full rights. Data protection assessments. Sensitive data consent.

Penalties

$7,500/violation. AG with 30-day cure.

Applicability

100K+ consumers, or 25K+ with 50%+ data sale revenue.

Exemptions

Government, HIPAA, GLBA, nonprofits, higher ed.

Frequently Asked Questions

Which states have data privacy regulations?

As of the last verification, 21 states have enacted data privacy regulations, with 0 additional bills pending across other states. Kentucky is among the states that has enacted such legislation. Browse all data privacy regulations at plainregwatch.com for the complete state-by-state comparison.

When was Kentucky Consumer Data Protection Act enacted?

Kentucky Consumer Data Protection Act was enacted on 2024-04-04 and became effective on 2026-01-01. It was introduced as HB 15.

What are the penalties for violating Kentucky Consumer Data Protection Act?

$7,500/violation. AG with 30-day cure. Note that enforcement mechanisms and penalty structures may vary. Consult the official statute and qualified legal counsel for specific compliance requirements.

Does Kentucky Consumer Data Protection Act apply to small businesses?

100K+ consumers, or 25K+ with 50%+ data sale revenue. Many state regulations include thresholds or exemptions for smaller organizations. Review the full applicability criteria and consult legal counsel to determine your obligations.

How does Kentucky compare to other states on data privacy?

Kentucky has a regulatory strictness score of 31/100, based on 2 enacted regulations out of 2 tracked. Nationally, 21 states have enacted data privacy laws. Visit our state comparison page for a full ranking.

Where can I read the full text of Kentucky Consumer Data Protection Act?

The official text of Kentucky Consumer Data Protection Act (HB 15) is available from the Kentucky legislature. PlainRegWatch links to the official source for every tracked regulation. We recommend reviewing the full statute alongside qualified legal counsel for compliance planning.

Regulation Guides

Plain-language guides to help you understand the broader regulatory landscape.

Disclaimer: This summary is provided for informational purposes only and does not constitute legal advice. Regulation details may have changed since last verification (2026-03-18). Always consult official sources and qualified legal counsel for compliance guidance.

More Kentucky Regulations

Related

Data sourced from official state legislatures, IAPP, NCSL, and federal regulatory trackers. See our methodology for details. Retrieved and formatted by PlainRegWatch Editorial

Verify with EPA →