Skip to content

Evidence request lists

Kentucky Consumer Data Protection Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

KY CDPA AG Enforcement

KY-CDPA-Attorney-General-AG-Enforcement-Sole-30-Day-Cure-Period-7500-Civil-Penalty-Per-Violation
Kentucky CDPA Attorney General Enforcement + Sole Authority + 30-Day Cure Period + USD 7,500 Civil Penalty Per Violation + No Private Right of Action + Injunctive Relief + Attorneys' Fees + Section 9 Enforcement + Children's Data + Sensitive Data Heightened

Section 9 of Kentucky CDPA establishes the Attorney General sole enforcement framework + closely modelled on VCDPA Virginia template. (1) Section 9 AG Sole Authority: (a) Attorney General exclusive enforcement; (b) NO PRIVATE RIGHT OF ACTION (PRA) - distinguishes Kentucky CDPA from California CCPA breach PRA + Illinois BIPA; (c) Reduces litigation exposure for businesses; (d) Centralised enforcement strategy; (e) AG industry-wide investigations possible. (2) Section 9 30-Day Cure Period: (a) Written notice of violation provided to controller/processor; (b) 30 calendar days from receipt to cure; (c) Cure includes remediation + restitution + procedural changes; (d) Cure notice + acceptance closes matter; (e) Cure period sunsets after specified date (typically 18-24 months after effective date - similar to VCDPA); (f) Currently expected sunset around July 2027 - 18 months after effective da

Artefacts an auditor will ask for
  • AG cooperation + records + per inquiry + cure period within 30 days
  • 30-day cure procedure + records + per notice + cure documentation
  • Reasonable care defence + records + per control + audit trail + training records
  • Compliance program + internal + records + per quarter + Board reporting
  • Multi-state AG coordination + records + per investigation + counsel coordinated
Where this commonly fails
  • AG cooperation reactive (no proactive engagement)
  • 30-day cure window missed or insufficient response
  • Reasonable care defence undocumented
  • Internal compliance program absent or pro forma
  • Multi-state AG coordination uncoordinated

KY CDPA Consumer Rights

KY-CDPA-Consumer-Rights-Section3-Access-Correction-Deletion-Portability-Object-Profiling-45-Days
Kentucky CDPA Consumer Rights + Section 3 + Right of Access + Correction + Deletion + Portability + Right to Object to Sale/Targeted Advertising/Profiling + 45-Day Response Window + Single 45-Day Extension + Free for First Request

Section 3 of Kentucky CDPA establishes the comprehensive consumer rights framework + closely modelled on VCDPA Virginia template. (1) Section 3(1) Five Consumer Rights: (a) Right of Access - confirm whether processing personal data + access copy in portable + readily usable format; (b) Right of Correction - correct inaccuracies based on consumer's request; (c) Right of Deletion - request deletion of personal data provided by or obtained about consumer; (d) Right of Portability - obtain copy of personal data previously provided to controller in portable + readily usable format (where technically feasible); (e) Right to Opt Out of (i) targeted advertising; (ii) sale of personal data; (iii) profiling for decisions that produce legal or similarly significant effects. (2) Section 3(2) Response Window: (a) Authenticated request - controller must respond within 45 CALENDAR DAYS of receipt; (b)

Artefacts an auditor will ask for
  • Rights request mechanism + Section 3 + records + per mechanism + clear + accessible
  • 45-day SLA + records + per request + extension reason + audit trail
  • Authentication + proportionate + records + per request + risk-based
  • Appeals process + 60-day + records + per appeal + reasoned response + plain language
  • UOOM + GPC + records + honored + browser-level + verified
Where this commonly fails
  • Rights request mechanism buried (not conspicuous)
  • 45-day SLA frequently missed
  • Authentication overly burdensome (denial of rights)
  • Appeals process absent or poorly defined
  • UOOM not honored (GPC ignored)

KY CDPA Data Protection Assessment

KY-CDPA-Data-Protection-Assessment-DPA-Targeted-Advertising-Sale-Sensitive-Profiling-Substantial-Risk
Kentucky CDPA Data Protection Assessment (DPA) + Section 6 + Targeted Advertising + Sale + Sensitive Data + Profiling Substantial Injury + Maintained Records + Attorney General Access + 4 Categories Requiring DPA + Risk-Benefit Analysis

Section 6 of Kentucky CDPA establishes the Data Protection Assessment (DPA) requirement for high-risk processing activities. (1) Section 6 DPA Required Activities (4 Categories): (a) Processing personal data for targeted advertising; (b) Sale of personal data; (c) Processing sensitive data; (d) Processing personal data for profiling where profiling presents reasonable foreseeable risk of (i) substantial injury (including financial + reputational + physical + economic + emotional harm); (ii) deceptive practices; (iii) intrusion upon solitude or seclusion. (2) Section 6 DPA Methodology: (a) Identify processing activity; (b) Assess risks of processing including likelihood + severity; (c) Identify benefits of processing including legitimate business interests; (d) Risk-Benefit balancing analysis; (e) Identify safeguards + mitigations; (f) Document conclusions; (g) Periodic review + update; (

Artefacts an auditor will ask for
  • DPA conducted + 4 categories + records + per processing + audit trail
  • Risk-benefit analysis + records + per DPA + documented decision + safeguards
  • AG access + confidentiality + records + per request + privilege awareness
  • Multi-state DPA + harmonization + records + per state + per activity
  • Periodic review + annual + records + per DPA + update audit
Where this commonly fails
  • DPA not conducted for qualifying activities
  • Risk-benefit analysis pro forma
  • AG access not prepared (no DPA ready)
  • Multi-state DPAs fragmented
  • DPA periodic review not scheduled

KY CDPA Privacy Notice

KY-CDPA-Privacy-Notice-Transparency-Reasonably-Accessible-Categories-Purposes-Rights-Sharing
Kentucky CDPA Privacy Notice + Transparency + Reasonably Accessible + Categories Processed + Purposes + Consumer Rights + Sharing Practices + Sale Disclosure + Targeted Advertising Disclosure + Section 4 Notice Requirements

Section 4 of Kentucky CDPA establishes Privacy Notice and transparency requirements. (1) Section 4 Privacy Notice Content: (a) Controller must provide consumers with a reasonably accessible + clear + meaningful Privacy Notice; (b) Categories of personal data processed; (c) Purpose for processing personal data; (d) How consumers may exercise their consumer rights including appeals process; (e) Categories of personal data shared with third parties; (f) Categories of third parties with whom personal data shared; (g) Active email or online mechanism to contact controller for rights requests; (h) Description of process for consumer to opt out of targeted advertising + sale of personal data + profiling for decisions with legal/significant effects. (2) Privacy Notice Accessibility Requirements: (a) Reasonably accessible to consumer; (b) Clear and meaningful + plain English language; (c) Conspic

Artefacts an auditor will ask for
  • Privacy Notice + Section 4 + records + per update + version control
  • Categories + purposes + rights + records + per disclosure + audit
  • Sale + targeted advertising + opt-out + records + clear mechanism + working link
  • Sensitive data notice + records + per category + consent linked
  • Multi-state harmonization + records + per state + per privacy notice
Where this commonly fails
  • Privacy Notice not reasonably accessible (buried link)
  • Categories generic or vague
  • Sale opt-out absent or broken
  • Sensitive data not separately addressed
  • Multi-state notices fragmented (compliance gaps)

KY CDPA Processor Contracts

KY-CDPA-Processor-Contracts-Section5-Confidentiality-Subprocessor-Authorisation-Audits-Sub-Processor
Kentucky CDPA Processor Contracts + Section 5 + Confidentiality + Subprocessor Authorisation + Audits + Sub-Processor Flow-Down + Documented Instructions + Data Deletion + Cooperation + Mandatory Contract Terms

Section 5 of Kentucky CDPA establishes the Processor Contract framework + closely modelled on VCDPA Virginia + GDPR Article 28. (1) Section 5 Processor Definition: (a) Person processing personal data on behalf of controller; (b) Includes vendors + service providers + sub-processors; (c) Contractually bound; (d) Subject to controller direction + obligations. (2) Section 5(1) Controller-Processor Contract Required: (a) Binding written contract; (b) Cannot rely on oral or implied arrangements; (c) Must precede processing activity; (d) Must specifically address personal data processing. (3) Section 5(2) Mandatory Contract Terms: (a) Nature + purpose + scope of processing; (b) Type of personal data processed; (c) Duration of processing; (d) Rights + obligations of both parties; (e) Confidentiality - processor and personnel maintain confidentiality; (f) Documented instructions - processor proc

Artefacts an auditor will ask for
  • Processor contracts + Section 5 + records + per vendor + mandatory terms
  • Subprocessor authorisation + flow-down + records + per sub + due diligence
  • Audit rights + SOC 2/ISO/Independent + records + per engagement + reasonable
  • Data deletion + return + records + end of contract + certification
  • Multi-state harmonization + records + per state + per vendor + template
Where this commonly fails
  • Processor contracts missing Section 5 mandatory terms
  • Subprocessor chain undisclosed
  • Audit rights contractual but never exercised
  • End of contract deletion not enforced
  • Multi-state contracts fragmented

KY CDPA Scope + Applicability

KY-CDPA-Scope-Applicability-Threshold-HB15-KRS-Chapter-367-Effective-1-January-2026-100000-25000
Kentucky CDPA Scope + Applicability + Thresholds + HB 15 + KRS Chapter 367 + Effective 1 January 2026 + 100,000 Consumers OR 25,000 Consumers + 50% Revenue from Sale + Attorney General Enforcement + VCDPA Template + Commonwealth of Kentucky

Kentucky Consumer Data Protection Act (CDPA) enacted via House Bill 15 (HB 15) signed by Governor 4 April 2024 + codified at KRS Chapter 367 Sections 1-10 + effective 1 January 2026. Kentucky becomes the 17th (approximately) US state to enact a comprehensive consumer privacy law + 4th state of 2024 enactments + follows VCDPA Virginia template common to majority of US state laws. (1) Statutory Framework: (a) HB 15 enacted 2024 Regular Session of Kentucky General Assembly; (b) Senate Bill 15 (SB 15) parallel version; (c) Signed by Governor Andy Beshear 4 April 2024; (d) Codified at Kentucky Revised Statutes (KRS) Chapter 367 (Consumer Protection); (e) Effective 1 January 2026; (f) Attorney General sole enforcement authority - NO PRIVATE RIGHT OF ACTION. (2) Section 1 Applicability and Thresholds: (a) Applies to legal entities (controllers and processors) that conduct business in Kentucky O

Artefacts an auditor will ask for
  • Threshold assessment + 100K or 25K + records + annual + per state
  • Applicability + Kentucky consumers + records + per business unit + per service
  • Exemption documentation + GLBA/HIPAA/Non-Profit + records + per processing
  • 1 Jan 2026 compliance + records + status + audit trail
  • AG cooperation + 30-day cure + records + per AG inquiry
Where this commonly fails
  • Threshold assessment not conducted (silent applicability)
  • Applicability scope too narrow (B2C only)
  • Exemption claimed without basis
  • 1 January 2026 compliance not achieved
  • Cure period not utilised (missing 30-day window)

KY CDPA Sensitive Data + Consent

KY-CDPA-Sensitive-Data-Affirmative-Consent-Race-Religious-Health-Genetic-Biometric-Children-Citizenship
Kentucky CDPA Sensitive Data + Affirmative Consent + Race/Ethnicity + Religious + Mental/Physical Health + Sexual Orientation + Citizenship/Immigration + Genetic + Biometric + Children's Data + Precise Geolocation (1,750 ft) + Section 4 Heightened Consent Standard

Section 4(4)(a) of Kentucky CDPA establishes the heightened consent requirement for sensitive data processing. (1) Section 2 Sensitive Data Definition - 8 Categories: (a) Racial or ethnic origin; (b) Religious beliefs; (c) Mental or physical health diagnosis; (d) Sexual orientation; (e) Citizenship or immigration status; (f) Genetic or biometric data processed for identification purposes; (g) Children's data (data of consumers known to be under 13); (h) Precise geolocation data - within 1,750 feet (approximately 1/3 mile - critical for location tracking + connected vehicles + retail analytics). (2) Section 4(4) Heightened Consent Standard: (a) Affirmative consent required BEFORE processing sensitive data; (b) Clear affirmative act + specific + informed + unambiguous; (c) Written or electronic equivalent; (d) Withdrawable at any time; (e) Documented + audit trail; (f) Reaffirmation for ne

Artefacts an auditor will ask for
  • Sensitive data inventory + 8 categories + records + per system + classification
  • Affirmative consent + Section 4(4) + records + per subject + per category + withdrawal
  • Children's consent + COPPA + parental verification + records + per child
  • Precise geolocation + 1,750 ft + records + per service + consent
  • Genetic/biometric + identification purpose + records + GINA/HIPAA awareness
Where this commonly fails
  • Sensitive data uncategorised (8 categories not separately addressed)
  • Affirmative consent same as general consent
  • Children's data without COPPA verification
  • Precise geolocation without affirmative consent
  • Genetic/biometric ID without sensitive treatment

KY CDPA Universal Opt-Out

KY-CDPA-Universal-Opt-Out-Mechanism-Recognized-Browser-Level-GPC-Global-Privacy-Control
Kentucky CDPA Universal Opt-Out Mechanism + Section 3 + Section 4 + Recognized + Browser-Level + GPC Global Privacy Control + UOOM + Honored for Targeted Advertising + Sale + Profiling + Annual List of Recognized Mechanisms

Section 4(3) of Kentucky CDPA establishes the Universal Opt-Out Mechanism (UOOM) requirement + reflects converging US state privacy law standards for browser-level opt-out signals. (1) Section 4(3) UOOM Recognition: (a) Controller must honor a recognized universal opt-out mechanism; (b) Recognized via Attorney General published list (updated annually); (c) Currently includes GPC Global Privacy Control + emerging others; (d) Reflects Colorado CPA + California CCPA UOOM frameworks; (e) Convergence with multi-state privacy law standards. (2) GPC Global Privacy Control: (a) Browser-level signal (HTTP header Sec-GPC + JavaScript navigator.globalPrivacyControl); (b) Developed by Public Privacy + EFF + Disconnect + Brave + DuckDuckGo + Mozilla collaboration; (c) Indicates consumer opt-out preference; (d) Enabled by user in browser settings; (e) Must be honored when received; (f) Cannot require

Artefacts an auditor will ask for
  • UOOM recognition + AG list + records + per mechanism + annual update
  • GPC honor + browser-level + records + per signal + audit trail
  • UOOM scope + targeted/sale/profiling + records + per opt-out class
  • Vendor flow-down + processor + records + per vendor + per agreement
  • Audit trail + signal log + records + per quarter + bug bounty
Where this commonly fails
  • UOOM not honored (GPC ignored)
  • GPC implementation incomplete (frontend only)
  • UOOM scope too narrow (advertising only, not sale)
  • Vendor flow-down absent (downstream UOOM lost)
  • Audit trail absent (UOOM compliance unverifiable)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Kentucky Consumer Data Protection Act framework page.