Privacy
Kentucky Consumer Data Protection Act
The law applies to persons that conduct business in Kentucky or produce products or services targeted to Kentucky residents and that, during a calendar year, control or process personal data of at least 100,000 consumers. It also applies to persons that control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. Cities, state agencies, political subdivisions, financial institutions subject to the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofit organizations, and institutions of higher education are exempt.
What the website needs
- A covered controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purpose of processing, how consumers can exercise their rights and appeal a decision, the categories of personal data shared with third parties, and the categories of third parties with whom personal data is shared.
- A controller that sells personal data or processes it for targeted advertising must clearly and conspicuously disclose that activity and how a consumer can opt out.
- A controller must establish one or more secure and reliable means for consumers to submit requests, must describe them in the privacy notice, and may not require a consumer to create a new account.
- A controller may not process sensitive data without the consumer's consent, and sensitive data collected from a known child must be processed under the federal Children's Online Privacy Protection Act.


