Law / United States / Kentucky

Kentucky Consumer Data Protection Act, Attorney General enforcement

KRS 367.3627

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 9 months, effective 1 January 2026.

An enforcement supervision rule binding private bodies.

As of 27 August 2026.

What it requires

  • Expect KCDPA violations to be enforced exclusively by the Kentucky Attorney General, never by a private plaintiff.
  • Cure a noticed violation and confirm the cure in writing within 30 days of Attorney General notice to avoid damages of up to $7,500 per continued violation.

If you get it wrong

Private right of actionNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Kentucky Attorney General has exclusive authority to enforce KCDPA. Before suing, the Attorney General must give a controller or processor 30 days' written notice; curing the violation and confirming the cure in writing bars an action, and this 30-day cure period is permanent, unlike New Hampshire's and Rhode Island's time-limited or absent versions. An uncured, continuing violation is subject to damages of up to $7,500 per violation, and the statute creates no private right of action.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app