Kentucky Consumer Data Protection Act
KY CDPA AG Enforcement

Kentucky Consumer Data Protection Act KY-CDPA-Attorney-General-AG-Enforcement-Sole-30-Day-Cure-Period-7500-Civil-Penalty-Per-Violation: Kentucky CDPA Attorney General Enforcement + Sole Authority + 30-Day Cure Period + USD 7,500 Civil Penalty Per Violation + No Private Right of Action + Injunctive Relief + Attorneys' Fees + Section 9 Enforcement + Children's Data + Sensitive Data Heightened

Section 9 of Kentucky CDPA establishes the Attorney General sole enforcement framework + closely modelled on VCDPA Virginia template. (1) Section 9 AG Sole Authority: (a) Attorney General exclusive enforcement; (b) NO PRIVATE RIGHT OF ACTION (PRA) - distinguishes Kentucky CDPA from California CCPA breach PRA + Illinois BIPA; (c) Reduces litigation exposure for businesses; (d) Centralised enforcement strategy; (e) AG industry-wide investigations possible. (2) Section 9 30-Day Cure Period: (a) Written notice of violation provided to controller/processor; (b) 30 calendar days from receipt to cure; (c) Cure includes remediation + restitution + procedural changes; (d) Cure notice + acceptance closes matter; (e) Cure period sunsets after specified date (typically 18-24 months after effective date - similar to VCDPA); (f) Currently expected sunset around July 2027 - 18 months after effective date. (3) Cure Period Practical Considerations: (a) Notice clarity - specific violation cited; (b) Cure scope - all similar violations or only flagged; (c) Cure documentation - what counts as cured; (d) Post-cure non-recurrence period; (e) Best practice - notify all customers of cure actions; (f) Compliance program enhancements. (4) Section 9 Civil Penalty Framework: (a) Up to USD 7,500 per violation after cure period; (b) Per consumer + per category violation potentially; (c) Aggregation possible (multiple consumers + multiple violations); (d) Pattern of violations + intentional violations increases per-violation penalty; (e) Cure of subsequent violations possible per AG discretion. (5) Section 9 Heightened Penalties: (a) Sensitive data violations - upper end of penalty range; (b) Children's data violations (COPPA-aligned) - heightened; (c) Repeat + willful violations - heightened; (d) Failure to cooperate - heightened. (6) Section 9 Other Remedies: (a) Injunctive relief; (b) Attorneys' fees + costs + investigatory expenses recoverable for AG; (c) Restitution to consumers; (d) Disgorgement of profits; (e) Public Naming on AG website. (7) AG Investigation Process: (a) Complaint receipt - consumer complaints to AG; (b) AG self-initiated investigation; (c) Civil Investigative Demand (CID) + subpoena power; (d) Document production + interview + on-site inspection; (e) Cooperation expectation; (f) Settlement discussions; (g) Consent Decree possible; (h) Final action - cure + penalty + injunction. (8) Settlement + Consent Decree: (a) Negotiated resolution; (b) Compliance commitments; (c) Monitor appointment; (d) Penalty amount agreed; (e) Public Notice; (f) Reputation considerations. (9) Multi-State AG Coordination: (a) Multi-State AG investigations common; (b) National Association of Attorneys General (NAAG); (c) State Privacy Working Group; (d) Information sharing; (e) Joint enforcement actions; (f) Cross-jurisdictional settlement. (10) Civil Penalty Calculation Considerations: (a) Number of affected consumers; (b) Number of categories of personal data; (c) Duration of violation; (d) Sophistication of controller; (e) Cooperation level; (f) Public interest; (g) Aggravating factors (sensitive data + children + repeat); (h) Mitigating factors (cure + remediation + cooperation). (11) Reputational + Litigation Exposure: (a) AG public actions create reputational risk; (b) AG settlements typically include public disclosure; (c) Class action exposure absent (no PRA) but private state law claims possible; (d) Federal class action exposure for adjacent claims (CCPA in California operations); (e) Insurance coverage considerations - cyber liability + privacy liability + D&O. (12) Compliance Program Best Practices: (a) Internal Compliance Program; (b) DPO or Privacy Officer appointment; (c) Annual privacy risk assessment; (d) Privacy Notice + DPA + Processor Contracts current; (e) Vendor management + DPA tracking; (f) Customer service training; (g) Documentation + audit trail; (h) Industry self-regulation participation; (i) Industry codes of conduct adoption. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + Tennessee TIPA + ADPPA federal proposal + NAAG National Association of Attorneys General + State Privacy Working Group + FTC Section 5 + COPPA Children's + Multi-state AG joint enforcement + Cyber + Privacy + D&O insurance + Settlement + Consent Decree templates. Kentucky CDPA AG Enforcement + Section 9 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 296 controls across 91 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-15 Cooperation with the FDPIC
  • CH-FADP-16 Record keeping and accountability
  • CH-FADP-17 Workplace and employment data
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • CH-FADP-24 Cross-border transfer safeguards
  • CH-FADP-25 Compliance monitoring and auditing
  • FADP-10 Cross-Border Disclosure (Articles 16-18)
  • FADP-15 Data Breach Notification
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

Bahrain PDPL · 7 controls

API 1164 · 6 controls

BSI IT-Grundschutz · 6 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

IEC 62443 · 6 controls

ISO 13485 · 6 controls

ISO 27799:2025 · 6 controls

ISO/IEC 27019:2024 · 6 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

ISO 27017 · 5 controls

ISO 27018 · 5 controls

ISO/IEC 27011:2024 · 5 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing

GDPR · 4 controls

South Korea ISMS-P · 4 controls

APPI · 3 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

ISO 22320:2018 · 3 controls

ISO/IEC 27010:2015 · 3 controls

ISO/IEC 27043:2015 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/SAE 21434 · 3 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls

ISO/IEC 20000-1:2018 · 2 controls

ISO/IEC 30111:2019 · 2 controls

ITIL 4 · 2 controls

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

Turkey KVKK · 2 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • CA-12 Deploys Through Policies and Procedures

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • ICP-25 Supervisory Cooperation and Coordination
  • 62351-8 Role-based access control (RBAC)

ISO 14001 · 1 control

  • ISO14001-03 Legal and regulatory compliance obligations

ISO 22000 · 1 control

ISO 26000:2010 · 1 control

ISO 45001 · 1 control

ISO/IEC 23894:2023 · 1 control

MITRE D3FEND · 1 control

  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • AC-2 Account Management
  • AC-2 Account Management
  • AC-2 Account Management
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • RUSPD-4 Special Categories, Biometric Data
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 296 it maps to, and the evidence behind each claim, over MCP and REST.