Section 5 of Kentucky CDPA establishes the Processor Contract framework + closely modelled on VCDPA Virginia + GDPR Article 28. (1) Section 5 Processor Definition: (a) Person processing personal data on behalf of controller; (b) Includes vendors + service providers + sub-processors; (c) Contractually bound; (d) Subject to controller direction + obligations. (2) Section 5(1) Controller-Processor Contract Required: (a) Binding written contract; (b) Cannot rely on oral or implied arrangements; (c) Must precede processing activity; (d) Must specifically address personal data processing. (3) Section 5(2) Mandatory Contract Terms: (a) Nature + purpose + scope of processing; (b) Type of personal data processed; (c) Duration of processing; (d) Rights + obligations of both parties; (e) Confidentiality - processor and personnel maintain confidentiality; (f) Documented instructions - processor processes only on controller's documented instructions; (g) Deletion or return of personal data at end of contract; (h) Demonstration of compliance + cooperation; (i) Reasonable assistance with controller's obligations - data subject rights + DPA + breach response; (j) Cooperation with consumer rights requests; (k) Engagement of subprocessors subject to processor's compliance + flow-down obligations. (4) Section 5(3) Subprocessor Authorisation: (a) Processor must obtain prior specific or general written authorisation; (b) For general authorisation - processor informs controller of intended changes + controller may object; (c) Processor remains fully liable for subprocessor performance; (d) Sub-processor flow-down of contractual obligations; (e) Sub-processor due diligence required. (5) Section 5(4) Audit + Compliance Demonstration: (a) Processor allows controller-conducted audit or controller-engaged third-party audit; (b) Reasonable frequency + scope; (c) Confidentiality protections; (d) SOC 2 + ISO/IEC 27001 + ISO/IEC 27701 + similar certifications may demonstrate compliance; (e) Independent third-party assurance reports; (f) Penetration testing + vulnerability assessment reports. (6) Data Deletion + Return: (a) End of contract - processor must delete or return all personal data; (b) Choice between deletion and return at controller's option; (c) Reasonable transition period; (d) Deletion certification; (e) Backup deletion considerations; (f) Anonymisation as alternative possible. (7) Cooperation with Controller Obligations: (a) Data subject rights - access + correction + deletion + portability + opt-out; (b) DPA Data Protection Assessment cooperation; (c) Breach response + notification; (d) AG investigation cooperation; (e) Audit support; (f) Reasonable cooperation expected. (8) Processor Becoming Controller: (a) Processor processing beyond controller instructions becomes joint controller for that processing; (b) Liability shifts; (c) Section 5 joint controller status may apply. (9) Standard Processor Contract Considerations: (a) Multi-state processor contract template possible; (b) VCDPA + Colorado CPA + Connecticut + Tennessee + Iowa + Indiana + Texas similar requirements; (c) Single multi-state DPA approach; (d) Cross-state compliance evidence. (10) Cloud Service Provider Specific: (a) Hyperscaler cloud (AWS + Azure + GCP) as processors; (b) Shared Responsibility Model; (c) Sub-processor chain visibility (cloud sub-services); (d) Geographic region considerations; (e) Encryption + customer-managed keys; (f) AWS Data Processing Agreement + Microsoft DPA + Google Cloud DPA standardised. (11) International Processor Considerations: (a) Foreign processor data flow; (b) EU GDPR Article 28 alignment; (c) UK DPA 2018 processor requirements; (d) Cross-border data transfer mechanisms; (e) US processor data sovereignty. (12) Penalties for Processor Contract Failures: (a) Section 9 AG enforcement; (b) 30-day cure period; (c) Civil penalty up to USD 7,500 per violation; (d) Controller liability for processor failures in some circumstances; (e) Failed audits + non-cooperation increase exposure. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + EU GDPR Article 28 + UK DPA 2018 + ISO/IEC 27701 PIMS + SOC 2 + Cloud Security Alliance + Cloud Provider DPAs (AWS + Azure + GCP) + IAB TCF v2.2 + Multi-state processor contract harmonization. Kentucky CDPA Processor Contracts + Section 5 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.