Kentucky's New Privacy Law Already Has Its First Lawsuit — Here's What Sellers Should Know
Kentucky's comprehensive privacy law had barely been in effect for a week before it got tested. On January 8, 2026, just eight days after the Kentucky Consumer Data Protection Act took effect, the state's Attorney General filed suit against an AI chatbot company over how it handled children's data. That's a fast start for a brand-new law, and it's worth understanding what triggered it, and what the law actually requires of everyone else.
The Basics
The KCDPA, codified at Kentucky Revised Statutes 367.3611 through 367.3629, was signed by Governor Andy Beshear on April 4, 2024, and took effect January 1, 2026, making Kentucky the fifteenth state to adopt a comprehensive privacy law. It applies to businesses that operate in Kentucky or target its residents and, during a calendar year, control or process personal data for at least 100,000 consumers, or at least 25,000 consumers while deriving over 50% of revenue from selling personal data.
Like several of its neighbors, there's no revenue threshold standing alone. Consumer volume is what matters.
Consumer Rights, Virginia-Style
Kentucky's law closely mirrors Virginia's framework. Consumers get the right to confirm whether their data is being processed and access it, correct inaccurate data, delete it, obtain a portable copy, and opt out of targeted advertising, data sales, and profiling that produces legal or similarly significant effects. Sensitive data, health, biometric, precise location, and similar categories, requires opt-in consent before processing.
What Makes the Cure Period Notable
Businesses generally get 30 days to fix a violation before the Attorney General escalates, and unlike some other states, Kentucky's cure period is permanent rather than set to expire after a few years.
But the Character.AI case revealed a real limit to that protection. The Attorney General's office filed suit without issuing the standard 30-day cure notice at all, by pairing the KCDPA claims with other Kentucky consumer protection statutes that don't carry the same cure requirement. The complaint alleged the company collected and processed children's sensitive data without parental consent and used private emotional disclosures to train AI models.
The practical lesson isn't that the cure period is meaningless. It's that stacking a KCDPA violation with other consumer protection claims, especially anything involving children's data, can bypass the grace period Kentucky otherwise clearly intends to offer.
Enforcement Details
The Kentucky Attorney General holds exclusive enforcement authority. There's no private right of action. Civil penalties can reach up to $7,500 per violation. Additional data protection impact assessment requirements, covering higher-risk processing activities like targeted advertising and profiling, apply to processing initiated on or after June 1, 2026.
What This Means If You Sell Into Kentucky
The compliance bar here is genuinely comparable to Virginia's, not California's stricter model, and the Attorney General's office has said its early priority is education over punishment for most businesses. But the Character.AI case shows that priority doesn't extend to cases involving minors' data. If your store collects any information from users who might be under 18, that's the area worth the most careful review before assuming a general Virginia-style compliance approach covers you here too.
Check Your Kentucky Exposure
All information in this article is sourced from Kentucky Revised Statutes 367.3611–367.3629, the Kentucky Attorney General's Office of Data Privacy public statements, and independent legal analysis from Davis Wright Tremaine and Taft Law. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Kentucky as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Further Reading
Does Your Store Need to Detect a Browser Signal? A State-by-State Guide
Some states require your store to automatically recognize a consumer's opt-out preference through their browser settings, with no click required on your site at all. Here's exactly which states require it.
Four More States Are About to Get Privacy Laws — Here's Your Advance Notice
Alabama, Oklahoma, Louisiana, and Vermont have all signed comprehensive privacy laws into effect between 2027 and 2028. None are enforceable yet, but each is worth understanding well before its clock starts.