iQ Cookie  State Law Series

State 10 of 25 · Kentucky

Cookie & Privacy Law in Kentucky

Published August 2026
Law in effect
Since January 1, 2026

Educational purposes only — not legal advice. This guide is intended to help you understand Kentucky’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
KCDPA
HB 15
SIGNED
Apr 4, 2024
Amended Mar 2025
EFFECTIVE
Jan 1, 2026
Brand new this year
STATE RANK
#16
To enact a law

The short version

Kentucky signed its privacy law in April 2024 but, like Indiana, gave businesses a long runway before enforcement — it did not take effect until January 1, 2026. In an unusual move, lawmakers amended the KCDPA nearly a year before it even kicked in, expanding HIPAA-related exemptions and tweaking the data protection assessment rules. It follows the familiar Virginia model, with a permanent 30-day cure period.

Kentucky does not have a separate cookie law. Cookie compliance flows from the KCDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

Kentucky General Assembly — Official Text
Kentucky Consumer Data Protection Act, HB 15 (as amended by HB 473)

Who does it apply to?

The KCDPA covers businesses that conduct business in Kentucky or target Kentucky residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more Kentucky consumers during a calendar year.

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.

Nonprofits are exempt. The 2025 amendment widened HIPAA-related exemptions to fully cover healthcare providers maintaining protected health information and data in a HIPAA-defined limited data set.

Consumer rights

Kentucky residents whose data is covered by the KCDPA have five core rights:

Access
Confirm whether their data is being processed and receive a copy
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Targeted ads, data sales, and profiling

Businesses must respond within 45 days, extendable once by another 45. There is no private right of action — only the Attorney General can enforce.

What makes Kentucky different

Amended before it even took effect. HB 473, signed March 2025, expanded HIPAA exemptions and adjusted the profiling risk-assessment trigger — all before the original law had processed a single consumer request. Rare for a state to revise its privacy law before enforcement even starts.

Permanent 30-day cure period. Like Indiana, Kentucky’s cure period does not sunset. Businesses always get a chance to fix a violation before the AG can seek penalties.

No GPC requirement. Kentucky does not require businesses to recognize or honor Global Privacy Control or any other universal opt-out mechanism.

Minors’ protection extends to under-16. No sale or targeted advertising to anyone the business knows or reasonably should know is under 16 — broader than the 13-year cutoff federal COPPA uses.

Disparate-impact profiling gets extra scrutiny. The 2025 amendment specifically refined when a data protection assessment is required for profiling that creates a foreseeable risk of unlawful disparate impact — a more targeted standard than most peer states.

Sensitive data & children

Processing sensitive data requires express consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health information
Biometric identifiers
Precise geolocation
Children’s data

Beyond the standard opt-in for known children’s sensitive data, Kentucky specifically bars selling or targeted advertising to anyone under 16 when the business knows or reasonably should know their age — treat unknown-age users conservatively if your audience could include teens.

What this means for your cookies

Cookie typeRequirementWhat to do
Sensitive data cookies (geolocation, biometric, health)Opt-in requiredGate these behind affirmative consent before they fire.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism for sale and targeted ads.
GPC / opt-out signalsNot requiredNo KCDPA obligation, but honoring it keeps you consistent with other states you may also serve.
Any cookies — users under 16Opt-in requiredNo sale or targeted-ad cookies for known or reasonably-known minors under 16.
Analytics & functional cookiesNo specific requirementDisclose in your privacy policy. Confirm they are not building profiles that count as "sale."

Enforcement

$7,500
Max penalty per violation
30 days
Cure period — permanent, no sunset
AG only
No private right of action

The Kentucky Attorney General has exclusive enforcement authority, with penalties up to $7,500 per violation plus potential injunctive relief. The permanent 30-day cure period means businesses that respond promptly to a notice get a genuine opportunity to fix problems before facing penalties.

Your action checklist

The law took effect January 1, 2026 — here is what to have in place now:

1

Check your thresholds. Do you process data on 100,000+ Kentucky consumers, or 25,000+ while earning over half your revenue from data sales? If yes, you are in scope.

2

Audit your cookies. Identify which cookies touch sensitive data or power targeted advertising — those are the categories with specific compliance obligations.

3

Set up opt-in for sensitive data. Cookies collecting precise geolocation, biometric, or health data must be blocked until the user affirmatively consents.

4

Add a targeted advertising opt-out. A clear "Do Not Sell or Share" link or equivalent mechanism satisfies this requirement.

5

Treat unknown-age users conservatively. If your site could reach anyone under 16, avoid targeted-ad and sale cookies until you can confirm age or obtain consent.

6

Check the HIPAA exemption if relevant. If you are a covered healthcare provider or handle HIPAA limited data sets, confirm you qualify for the expanded 2025 exemption before assuming full KCDPA coverage applies.

7

Review vendor contracts. Any processor handling Kentucky resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Kentucky?

iQ Cookie scans your site, flags gaps, and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 10 of 25  ·  Next: Maryland →