Section 5 of Kentucky CDPA establishes the Processor Contract framework + closely modelled on VCDPA Virginia + GDPR Article 28. (1) Section 5 Processor Definition: (a) Person processing personal data on behalf of controller; (b) Includes vendors + service providers + sub-processors; (c) Contractually bound; (d) Subject to controller direction + obligations. (2) Section 5(1) Controller-Processor Contract Required: (a) Binding written contract; (b) Cannot rely on oral or implied arrangements; (c) Must precede processing activity; (d) Must specifically address personal data processing. (3) Section 5(2) Mandatory Contract Terms: (a) Nature + purpose + scope of processing; (b) Type of personal data processed; (c) Duration of processing; (d) Rights + obligations of both parties; (e) Confidentiality - processor and personnel maintain confidentiality; (f) Documented instructions - processor processes only on controller's documented instructions; (g) Deletion or return of personal data at end of contract; (h) Demonstration of compliance + cooperation; (i) Reasonable assistance with controller's obligations - data subject rights + DPA + breach response; (j) Cooperation with consumer rights requests; (k) Engagement of subprocessors subject to processor's compliance + flow-down obligations. (4) Section 5(3) Subprocessor Authorisation: (a) Processor must obtain prior specific or general written authorisation; (b) For general authorisation - processor informs controller of intended changes + controller may object; (c) Processor remains fully liable for subprocessor performance; (d) Sub-processor flow-down of contractual obligations; (e) Sub-processor due diligence required. (5) Section 5(4) Audit + Compliance Demonstration: (a) Processor allows controller-conducted audit or controller-engaged third-party audit; (b) Reasonable frequency + scope; (c) Confidentiality protections; (d) SOC 2 + ISO/IEC 27001 + ISO/IEC 27701 + similar certifications may demonstrate compliance; (e) Independent third-party assurance reports; (f) Penetration testing + vulnerability assessment reports. (6) Data Deletion + Return: (a) End of contract - processor must delete or return all personal data; (b) Choice between deletion and return at controller's option; (c) Reasonable transition period; (d) Deletion certification; (e) Backup deletion considerations; (f) Anonymisation as alternative possible. (7) Cooperation with Controller Obligations: (a) Data subject rights - access + correction + deletion + portability + opt-out; (b) DPA Data Protection Assessment cooperation; (c) Breach response + notification; (d) AG investigation cooperation; (e) Audit support; (f) Reasonable cooperation expected. (8) Processor Becoming Controller: (a) Processor processing beyond controller instructions becomes joint controller for that processing; (b) Liability shifts; (c) Section 5 joint controller status may apply. (9) Standard Processor Contract Considerations: (a) Multi-state processor contract template possible; (b) VCDPA + Colorado CPA + Connecticut + Tennessee + Iowa + Indiana + Texas similar requirements; (c) Single multi-state DPA approach; (d) Cross-state compliance evidence. (10) Cloud Service Provider Specific: (a) Hyperscaler cloud (AWS + Azure + GCP) as processors; (b) Shared Responsibility Model; (c) Sub-processor chain visibility (cloud sub-services); (d) Geographic region considerations; (e) Encryption + customer-managed keys; (f) AWS Data Processing Agreement + Microsoft DPA + Google Cloud DPA standardised. (11) International Processor Considerations: (a) Foreign processor data flow; (b) EU GDPR Article 28 alignment; (c) UK DPA 2018 processor requirements; (d) Cross-border data transfer mechanisms; (e) US processor data sovereignty. (12) Penalties for Processor Contract Failures: (a) Section 9 AG enforcement; (b) 30-day cure period; (c) Civil penalty up to USD 7,500 per violation; (d) Controller liability for processor failures in some circumstances; (e) Failed audits + non-cooperation increase exposure. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + EU GDPR Article 28 + UK DPA 2018 + ISO/IEC 27701 PIMS + SOC 2 + Cloud Security Alliance + Cloud Provider DPAs (AWS + Azure + GCP) + IAB TCF v2.2 + Multi-state processor contract harmonization. Kentucky CDPA Processor Contracts + Section 5 applies.
This control maps to 28 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.