Kentucky Consumer Data Protection Act KY-CDPA-Attorney-General-AG-Enforcement-Sole-30-Day-Cure-Period-7500-Civil-Penalty-Per-Violation: Kentucky CDPA Attorney General Enforcement + Sole Authority + 30-Day Cure Period + USD 7,500 Civil Penalty Per Violation + No Private Right of Action + Injunctive Relief + Attorneys' Fees + Section 9 Enforcement + Children's Data + Sensitive Data Heightened
Section 9 of Kentucky CDPA establishes the Attorney General sole enforcement framework + closely modelled on VCDPA Virginia template. (1) Section 9 AG Sole Authority: (a) Attorney General exclusive enforcement; (b) NO PRIVATE RIGHT OF ACTION (PRA) - distinguishes Kentucky CDPA from California CCPA breach PRA + Illinois BIPA; (c) Reduces litigation exposure for businesses; (d) Centralised enforcement strategy; (e) AG industry-wide investigations possible. (2) Section 9 30-Day Cure Period: (a) Written notice of violation provided to controller/processor; (b) 30 calendar days from receipt to cure; (c) Cure includes remediation + restitution + procedural changes; (d) Cure notice + acceptance closes matter; (e) Cure period sunsets after specified date (typically 18-24 months after effective date - similar to VCDPA); (f) Currently expected sunset around July 2027 - 18 months after effective date. (3) Cure Period Practical Considerations: (a) Notice clarity - specific violation cited; (b) Cure scope - all similar violations or only flagged; (c) Cure documentation - what counts as cured; (d) Post-cure non-recurrence period; (e) Best practice - notify all customers of cure actions; (f) Compliance program enhancements. (4) Section 9 Civil Penalty Framework: (a) Up to USD 7,500 per violation after cure period; (b) Per consumer + per category violation potentially; (c) Aggregation possible (multiple consumers + multiple violations); (d) Pattern of violations + intentional violations increases per-violation penalty; (e) Cure of subsequent violations possible per AG discretion. (5) Section 9 Heightened Penalties: (a) Sensitive data violations - upper end of penalty range; (b) Children's data violations (COPPA-aligned) - heightened; (c) Repeat + willful violations - heightened; (d) Failure to cooperate - heightened. (6) Section 9 Other Remedies: (a) Injunctive relief; (b) Attorneys' fees + costs + investigatory expenses recoverable for AG; (c) Restitution to consumers; (d) Disgorgement of profits; (e) Public Naming on AG website. (7) AG Investigation Process: (a) Complaint receipt - consumer complaints to AG; (b) AG self-initiated investigation; (c) Civil Investigative Demand (CID) + subpoena power; (d) Document production + interview + on-site inspection; (e) Cooperation expectation; (f) Settlement discussions; (g) Consent Decree possible; (h) Final action - cure + penalty + injunction. (8) Settlement + Consent Decree: (a) Negotiated resolution; (b) Compliance commitments; (c) Monitor appointment; (d) Penalty amount agreed; (e) Public Notice; (f) Reputation considerations. (9) Multi-State AG Coordination: (a) Multi-State AG investigations common; (b) National Association of Attorneys General (NAAG); (c) State Privacy Working Group; (d) Information sharing; (e) Joint enforcement actions; (f) Cross-jurisdictional settlement. (10) Civil Penalty Calculation Considerations: (a) Number of affected consumers; (b) Number of categories of personal data; (c) Duration of violation; (d) Sophistication of controller; (e) Cooperation level; (f) Public interest; (g) Aggravating factors (sensitive data + children + repeat); (h) Mitigating factors (cure + remediation + cooperation). (11) Reputational + Litigation Exposure: (a) AG public actions create reputational risk; (b) AG settlements typically include public disclosure; (c) Class action exposure absent (no PRA) but private state law claims possible; (d) Federal class action exposure for adjacent claims (CCPA in California operations); (e) Insurance coverage considerations - cyber liability + privacy liability + D&O. (12) Compliance Program Best Practices: (a) Internal Compliance Program; (b) DPO or Privacy Officer appointment; (c) Annual privacy risk assessment; (d) Privacy Notice + DPA + Processor Contracts current; (e) Vendor management + DPA tracking; (f) Customer service training; (g) Documentation + audit trail; (h) Industry self-regulation participation; (i) Industry codes of conduct adoption. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + Tennessee TIPA + ADPPA federal proposal + NAAG National Association of Attorneys General + State Privacy Working Group + FTC Section 5 + COPPA Children's + Multi-state AG joint enforcement + Cyber + Privacy + D&O insurance + Settlement + Consent Decree templates. Kentucky CDPA AG Enforcement + Section 9 applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 296 controls across 91 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.