Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Kentucky · Consumer Data Protection Act

Data minimization & assessments.

Applies to: Controllers under Kentucky's KCDPA. Built · effective 1 Jan 2026

What the signed record shows

Security records, 45-day consumer-request signals, and assessment references.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: KRS 367.3615/3617/3621

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Kentucky Consumer Data Protection Act (KCDPA), KRS 367.3611 to 367.3629 (HB 15, 2024 Reg. Session; 2024 Ky. Acts ch. 72). Provisions addressed:

KRS 367.3617
Controller duties; data minimization; reasonable administrative, technical and physical data security practices; non-discrimination; sensitive-data consent.
KRS 367.3615
Consumer rights request; controller responds within 45 days (one 45-day extension).
KRS 367.3621
Data protection (impact) assessment; disclosure to the Attorney General; confidentiality. Effective 1 January 2026.

Taken from the Regulayer entry for this instrument, which is built against the primary text.