Kentucky Consumer Data Protection Act
KY CDPA Consumer Rights

Kentucky Consumer Data Protection Act KY-CDPA-Consumer-Rights-Section3-Access-Correction-Deletion-Portability-Object-Profiling-45-Days: Kentucky CDPA Consumer Rights + Section 3 + Right of Access + Correction + Deletion + Portability + Right to Object to Sale/Targeted Advertising/Profiling + 45-Day Response Window + Single 45-Day Extension + Free for First Request

Section 3 of Kentucky CDPA establishes the comprehensive consumer rights framework + closely modelled on VCDPA Virginia template. (1) Section 3(1) Five Consumer Rights: (a) Right of Access - confirm whether processing personal data + access copy in portable + readily usable format; (b) Right of Correction - correct inaccuracies based on consumer's request; (c) Right of Deletion - request deletion of personal data provided by or obtained about consumer; (d) Right of Portability - obtain copy of personal data previously provided to controller in portable + readily usable format (where technically feasible); (e) Right to Opt Out of (i) targeted advertising; (ii) sale of personal data; (iii) profiling for decisions that produce legal or similarly significant effects. (2) Section 3(2) Response Window: (a) Authenticated request - controller must respond within 45 CALENDAR DAYS of receipt; (b) One single 45-day extension permitted for complex requests; (c) Total maximum 90 days; (d) Notification to consumer of extension with reasons; (e) Information to be provided about request status. (3) Section 3 Free of Charge: (a) First request per consumer per 12-month period - FREE; (b) Manifestly unfounded or excessive requests - reasonable fee permitted; (c) Refusal allowed if request manifestly unfounded; (d) Refusal must be reasoned + appealable. (4) Section 3 Authenticated Request: (a) Authentication required to prevent fraudulent requests; (b) Reasonable authentication means - account login + email verification + KBA Knowledge-Based Authentication + government ID match; (c) Proportionate to risk of unauthorized access; (d) Authentication cannot be unduly burdensome; (e) Privacy-preserving authentication preferred. (5) Section 3 Rights Request Mechanism: (a) Controller must designate clear + conspicuous mechanism; (b) Web portal + email + phone number + form; (c) Mechanism in plain English; (d) Accessibility for disability per ADA + WCAG 2.2; (e) Mobile-friendly; (f) Privacy professional support. (6) Section 3 Refusal Grounds (Limited): (a) Manifestly unfounded + excessive frequency; (b) Threat to security of personal data; (c) Threat to other's rights; (d) State secret or law enforcement constraints; (e) Cannot verify consumer identity; (f) Refusal must provide reasoned response. (7) Section 3 Appeals Process: (a) Consumer right to appeal controller decision; (b) Appeals process must be conspicuously available; (c) 60-day appeal response window; (d) Reasoned response required for appeals; (e) Online mechanism for appeals encouraged; (f) Plain language explanation. (8) Section 3 Specific Rights Detailed: (a) Right of Access - all personal data + categories + sources + recipients + purposes + retention; (b) Right of Correction - factual inaccuracies + technical errors; (c) Right of Deletion - data provided BY consumer + data obtained ABOUT consumer (broader than some states); (d) Right of Portability - structured + commonly used + machine-readable + automated where feasible; (e) Right to Opt Out - immediate effect + cessation of processing. (9) Universal Opt-Out Mechanism (UOOM) (Section 4(3) emerging): (a) Recognized Universal Opt-Out Mechanism (e.g. GPC Global Privacy Control + emerging others); (b) Browser-level signal recognition; (c) Required to honor for targeted advertising + sale; (d) Required to honor for profiling (emerging); (e) Discoverability + verification requirements; (f) Updated annually with recognized mechanisms (Attorney General); (g) Reflects Colorado CPA + California CCPA UOOM models. (10) Children's Specific Rights (Under 13): (a) Parental request rights; (b) COPPA-aligned mechanisms; (c) Parental consent rescission; (d) Special considerations for minor data. (11) Multi-State Rights Request Coordination: (a) Multi-state rights request standardization; (b) Common request portal across states; (c) Per-state response timeline tracking; (d) Multi-state authentication standardization; (e) Privacy engineering for multi-state DSAR. (12) Penalties for Rights Violations: (a) Section 9 AG enforcement; (b) 30-day cure period; (c) Civil penalty up to USD 7,500 per violation. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + Tennessee TIPA + ADPPA federal proposal + GPC Global Privacy Control + IAB TCF v2.2 + COPPA + ADA + WCAG 2.2 + NIST Privacy Framework + multi-state DSAR standards. Kentucky CDPA Consumer Rights + Section 3 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 201 controls across 53 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-02 Principles of lawful processing
  • CH-FADP-04 Data subject access right
  • CH-FADP-05 Data accuracy and rectification
  • CH-FADP-09 Notification of data files to the FDPIC
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-11 Duty to Inform (Article 19)
  • FADP-12 Right of Access (Article 25)
  • FADP-13 Right to Data Portability (Article 28)
  • FADP-15 Data Breach Notification
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

GDPR · 9 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.20 Right to data portability
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.9 Processing of special categories of personal data
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 6 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

ISO/IEC 27400:2022 · 4 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.1 Network Security for IoT
  • 27400-7.3 Data minimization and purpose limitation
  • 27400-7.4 Data retention and deletion
  • PAKPDPB-3 Data Subject Rights
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27 Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • IM8-DAT.2 Data Protection
  • IM8-DAT.3 Data Sharing and Transfer
  • IM8-DAT.4 Data Retention and Disposal

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation

Turkey KVKK · 3 controls

  • TURKEYKVKK-1 VERBIS Registration and Lawful Basis
  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CPSC-CS.3 Data Protection for Safety Systems
  • CPSC-STD.4 Interoperability Safety
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • ASD37-27 Outbound data loss prevention (Very Good)
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • DIQ-1 Data Integration and Interoperability

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO8000-MDG-01 Master Data Quality

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 201 it maps to, and the evidence behind each claim, over MCP and REST.