iQ Cookie State Law Series
Cookie & Privacy Law in Kentucky
Educational purposes only — not legal advice. This guide is intended to help you understand Kentucky’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Kentucky signed its privacy law in April 2024 but, like Indiana, gave businesses a long runway before enforcement — it did not take effect until January 1, 2026. In an unusual move, lawmakers amended the KCDPA nearly a year before it even kicked in, expanding HIPAA-related exemptions and tweaking the data protection assessment rules. It follows the familiar Virginia model, with a permanent 30-day cure period.
Kentucky does not have a separate cookie law. Cookie compliance flows from the KCDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.
Who does it apply to?
The KCDPA covers businesses that conduct business in Kentucky or target Kentucky residents, and meet at least one of these thresholds:
Controls or processes personal data of 100,000 or more Kentucky consumers during a calendar year.
Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.
Nonprofits are exempt. The 2025 amendment widened HIPAA-related exemptions to fully cover healthcare providers maintaining protected health information and data in a HIPAA-defined limited data set.
Consumer rights
Kentucky residents whose data is covered by the KCDPA have five core rights:
Businesses must respond within 45 days, extendable once by another 45. There is no private right of action — only the Attorney General can enforce.
What makes Kentucky different
Amended before it even took effect. HB 473, signed March 2025, expanded HIPAA exemptions and adjusted the profiling risk-assessment trigger — all before the original law had processed a single consumer request. Rare for a state to revise its privacy law before enforcement even starts.
Permanent 30-day cure period. Like Indiana, Kentucky’s cure period does not sunset. Businesses always get a chance to fix a violation before the AG can seek penalties.
No GPC requirement. Kentucky does not require businesses to recognize or honor Global Privacy Control or any other universal opt-out mechanism.
Minors’ protection extends to under-16. No sale or targeted advertising to anyone the business knows or reasonably should know is under 16 — broader than the 13-year cutoff federal COPPA uses.
Disparate-impact profiling gets extra scrutiny. The 2025 amendment specifically refined when a data protection assessment is required for profiling that creates a foreseeable risk of unlawful disparate impact — a more targeted standard than most peer states.
Sensitive data & children
Processing sensitive data requires express consent before any collection begins. Sensitive data includes:
Beyond the standard opt-in for known children’s sensitive data, Kentucky specifically bars selling or targeted advertising to anyone under 16 when the business knows or reasonably should know their age — treat unknown-age users conservatively if your audience could include teens.
What this means for your cookies
| Cookie type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (geolocation, biometric, health) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism for sale and targeted ads. |
| GPC / opt-out signals | Not required | No KCDPA obligation, but honoring it keeps you consistent with other states you may also serve. |
| Any cookies — users under 16 | Opt-in required | No sale or targeted-ad cookies for known or reasonably-known minors under 16. |
| Analytics & functional cookies | No specific requirement | Disclose in your privacy policy. Confirm they are not building profiles that count as "sale." |
Enforcement
The Kentucky Attorney General has exclusive enforcement authority, with penalties up to $7,500 per violation plus potential injunctive relief. The permanent 30-day cure period means businesses that respond promptly to a notice get a genuine opportunity to fix problems before facing penalties.
Your action checklist
The law took effect January 1, 2026 — here is what to have in place now:
Check your thresholds. Do you process data on 100,000+ Kentucky consumers, or 25,000+ while earning over half your revenue from data sales? If yes, you are in scope.
Audit your cookies. Identify which cookies touch sensitive data or power targeted advertising — those are the categories with specific compliance obligations.
Set up opt-in for sensitive data. Cookies collecting precise geolocation, biometric, or health data must be blocked until the user affirmatively consents.
Add a targeted advertising opt-out. A clear "Do Not Sell or Share" link or equivalent mechanism satisfies this requirement.
Treat unknown-age users conservatively. If your site could reach anyone under 16, avoid targeted-ad and sale cookies until you can confirm age or obtain consent.
Check the HIPAA exemption if relevant. If you are a covered healthcare provider or handle HIPAA limited data sets, confirm you qualify for the expanded 2025 exemption before assuming full KCDPA coverage applies.
Review vendor contracts. Any processor handling Kentucky resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site, flags gaps, and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 10 of 25 · Next: Maryland →