Section 4 of Kentucky CDPA establishes Privacy Notice and transparency requirements. (1) Section 4 Privacy Notice Content: (a) Controller must provide consumers with a reasonably accessible + clear + meaningful Privacy Notice; (b) Categories of personal data processed; (c) Purpose for processing personal data; (d) How consumers may exercise their consumer rights including appeals process; (e) Categories of personal data shared with third parties; (f) Categories of third parties with whom personal data shared; (g) Active email or online mechanism to contact controller for rights requests; (h) Description of process for consumer to opt out of targeted advertising + sale of personal data + profiling for decisions with legal/significant effects. (2) Privacy Notice Accessibility Requirements: (a) Reasonably accessible to consumer; (b) Clear and meaningful + plain English language; (c) Conspicuous link or button labeled - typical conventions include 'Privacy Notice' + 'Privacy Policy' + 'Notice at Collection'; (d) Mobile-friendly + responsive design; (e) Accessibility for disability accommodation per ADA + WCAG 2.2; (f) Multi-language - English primary + Spanish + other significant minority languages emerging best practice; (g) Updated when material changes occur. (3) Privacy Notice Update Notification: (a) Material changes notification to consumers; (b) Email notification for active consumers; (c) Website banner for material changes; (d) Effective date and version history; (e) Archived previous versions accessible. (4) Sale of Personal Data Disclosure: (a) Disclose whether controller sells personal data; (b) Categories of personal data sold; (c) Categories of third party recipients; (d) Method for consumer to opt out; (e) Clear and conspicuous link to opt-out mechanism. (5) Targeted Advertising Disclosure: (a) Disclose whether controller processes personal data for targeted advertising; (b) Method for consumer to opt out; (c) Clear and conspicuous link to opt-out mechanism. (6) Sensitive Data Disclosure: (a) Specific notice regarding sensitive data processing (consent required per Section 3); (b) Categories of sensitive data processed; (c) Purposes for sensitive data processing. (7) Loyalty Programs Disclosure: (a) Section 4(2) - controller may offer different prices or quality of goods/services for consumer participation in loyalty program; (b) Reasonable relationship to value provided; (c) Disclosure of bona fide loyalty program terms; (d) Distinguished from unlawful discrimination per Section 4. (8) Children's Notice (Under 13): (a) Specific COPPA-compliant notice; (b) Parental consent mechanism; (c) Categories of personal data of children processed; (d) Description of disclosure practices. (9) Notice at Collection (CCPA-equivalent emerging): (a) Just-in-time notice at point of collection; (b) Layered notice approach - short notice + detailed Privacy Notice link; (c) Mobile in-app notification; (d) Contextual notice for first-time interactions. (10) Documentation + Compliance Evidence: (a) Privacy Notice version control; (b) Effective date tracking; (c) Notification log; (d) Consumer acknowledgments where applicable; (e) Audit trail of changes; (f) Customer service training on Privacy Notice. (11) Comparable State Law Considerations: (a) Virginia VCDPA Section 59.1-578 substantially similar Privacy Notice; (b) Colorado CPA + Connecticut CTDPA + Utah UCPA similar; (c) California CCPA/CPRA Notice at Collection + Privacy Policy; (d) Multi-state notice harmonization for operators; (e) Cookie banner integration for opt-outs. (12) Penalties for Privacy Notice Failures: (a) Section 9 Attorney General enforcement; (b) 30-day cure period; (c) Civil penalty up to USD 7,500 per violation. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + Tennessee TIPA + ADA + WCAG 2.2 + COPPA Children's Online Privacy Protection Act + FTC Section 5 + Cookie banner standards (IAB TCF v2.2) + Multi-state harmonization. Kentucky CDPA Privacy Notice + Section 4 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.