Kentucky Consumer Data Protection Act
KY CDPA Processor Contracts

Kentucky Consumer Data Protection Act KY-CDPA-Processor-Contracts-Section5-Confidentiality-Subprocessor-Authorisation-Audits-Sub-Processor: Kentucky CDPA Processor Contracts + Section 5 + Confidentiality + Subprocessor Authorisation + Audits + Sub-Processor Flow-Down + Documented Instructions + Data Deletion + Cooperation + Mandatory Contract Terms

Section 5 of Kentucky CDPA establishes the Processor Contract framework + closely modelled on VCDPA Virginia + GDPR Article 28. (1) Section 5 Processor Definition: (a) Person processing personal data on behalf of controller; (b) Includes vendors + service providers + sub-processors; (c) Contractually bound; (d) Subject to controller direction + obligations. (2) Section 5(1) Controller-Processor Contract Required: (a) Binding written contract; (b) Cannot rely on oral or implied arrangements; (c) Must precede processing activity; (d) Must specifically address personal data processing. (3) Section 5(2) Mandatory Contract Terms: (a) Nature + purpose + scope of processing; (b) Type of personal data processed; (c) Duration of processing; (d) Rights + obligations of both parties; (e) Confidentiality - processor and personnel maintain confidentiality; (f) Documented instructions - processor processes only on controller's documented instructions; (g) Deletion or return of personal data at end of contract; (h) Demonstration of compliance + cooperation; (i) Reasonable assistance with controller's obligations - data subject rights + DPA + breach response; (j) Cooperation with consumer rights requests; (k) Engagement of subprocessors subject to processor's compliance + flow-down obligations. (4) Section 5(3) Subprocessor Authorisation: (a) Processor must obtain prior specific or general written authorisation; (b) For general authorisation - processor informs controller of intended changes + controller may object; (c) Processor remains fully liable for subprocessor performance; (d) Sub-processor flow-down of contractual obligations; (e) Sub-processor due diligence required. (5) Section 5(4) Audit + Compliance Demonstration: (a) Processor allows controller-conducted audit or controller-engaged third-party audit; (b) Reasonable frequency + scope; (c) Confidentiality protections; (d) SOC 2 + ISO/IEC 27001 + ISO/IEC 27701 + similar certifications may demonstrate compliance; (e) Independent third-party assurance reports; (f) Penetration testing + vulnerability assessment reports. (6) Data Deletion + Return: (a) End of contract - processor must delete or return all personal data; (b) Choice between deletion and return at controller's option; (c) Reasonable transition period; (d) Deletion certification; (e) Backup deletion considerations; (f) Anonymisation as alternative possible. (7) Cooperation with Controller Obligations: (a) Data subject rights - access + correction + deletion + portability + opt-out; (b) DPA Data Protection Assessment cooperation; (c) Breach response + notification; (d) AG investigation cooperation; (e) Audit support; (f) Reasonable cooperation expected. (8) Processor Becoming Controller: (a) Processor processing beyond controller instructions becomes joint controller for that processing; (b) Liability shifts; (c) Section 5 joint controller status may apply. (9) Standard Processor Contract Considerations: (a) Multi-state processor contract template possible; (b) VCDPA + Colorado CPA + Connecticut + Tennessee + Iowa + Indiana + Texas similar requirements; (c) Single multi-state DPA approach; (d) Cross-state compliance evidence. (10) Cloud Service Provider Specific: (a) Hyperscaler cloud (AWS + Azure + GCP) as processors; (b) Shared Responsibility Model; (c) Sub-processor chain visibility (cloud sub-services); (d) Geographic region considerations; (e) Encryption + customer-managed keys; (f) AWS Data Processing Agreement + Microsoft DPA + Google Cloud DPA standardised. (11) International Processor Considerations: (a) Foreign processor data flow; (b) EU GDPR Article 28 alignment; (c) UK DPA 2018 processor requirements; (d) Cross-border data transfer mechanisms; (e) US processor data sovereignty. (12) Penalties for Processor Contract Failures: (a) Section 9 AG enforcement; (b) 30-day cure period; (c) Civil penalty up to USD 7,500 per violation; (d) Controller liability for processor failures in some circumstances; (e) Failed audits + non-cooperation increase exposure. Coordinates with VCDPA Virginia + Indiana CDPA + Iowa ICDPA + Connecticut CTDPA + Colorado CPA + Utah UCPA + CCPA/CPRA California + EU GDPR Article 28 + UK DPA 2018 + ISO/IEC 27701 PIMS + SOC 2 + Cloud Security Alliance + Cloud Provider DPAs (AWS + Azure + GCP) + IAB TCF v2.2 + Multi-state processor contract harmonization. Kentucky CDPA Processor Contracts + Section 5 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 28 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 3 controls

  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

ISO/IEC 23894:2023 · 2 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • AL-DPA-7 Right of Access
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • AIGF-1.3 Data Management

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.