{"data":{"id":"us-ky/krs-380.070","jurisdiction":"us-ky","citation":"KRS 380.070","heading":"Debt adjuster to take reasonable measures to protect debtor's personal","body":"information.\n(1) A debt adjuster shall take reasonable measures to:\n(a) Ensure the security and confidentiality of a debtor's personal information;\n(b) Protect against any anticipated threats or hazards to the security or integrity of\na debtor's personal information; and\n(c) Protect against unauthorized access to or use of a debtor's personal\ninformation.\n(2) The reasonable measures required by this section shall include, at a minimum:\n(a) Design and implementation of a comprehensive information security program\nthat:\n1. Is written in one (1) or more readily accessible parts;\n2. Contains administrative, technical, and physical safeguards that are\nappropriate to the size and complexit y of the debt adjuster, the nature\nand scope of the debt adjuster's activities, and the sensitivity of any\npersonal information at issue;\n3. Designates one (1) or more employees to coordinate compliance with\nthe information security program; and\n4. Identifies reasonably foreseeable internal and external risks to the\nsecurity, confidentiality, and integrity of the personal information of a\ndebtor that could result in the unauthorized access to or use of the\ninformation, and assesses the sufficiency of any sa feguards in place to\ncontrol these risks. At a minimum, the risk assessment required by this\nsubparagraph shall include consideration of risks in each relevant area of\nthe debt adjuster's operation, including employee training and\nmanagement, information s ystems, information processing, information\nstorage, information transmission, information disposal, and detecting,\npreventing, and responding to failures to comply with the information\nsecurity program.\n(b) Design and implementation of information safegua rds to control the risks\nidentified by the risk assessment required by this subsection, as well as regular\ntesting or other monitoring of the effectiveness of the safeguards of key\ncontrols, systems, and procedures;\n(c) Requirements for regular training of  employees who will or may have access\nto records containing personal information of debtors regarding compliance\nwith the information security program required by this subsection;\n(d) Oversight of service providers to whom personal information of a debtor  will\nbe disclosed, by taking reasonable steps to select and retain service providers\nthat are capable of maintaining appropriate safeguards for the personal\ninformation at issue, as well as requiring service providers, by contract, to\nimplement and maintain those safeguards;\n(e) Evaluation and adjustment of the information security program in light of the\nresults of testing and monitoring, any material changes to the operation or\nbusiness arrangements of the debt adjuster, or any other circumstances that the\ndebt adjuster knows or has reason to know may have a material impact on\ncompliance with the information security program; and\n(f) A requirement that when records containing personal information of a debtor\nare disposed of the records shall be shredded, erased, or otherwise modified so\nthe personal information is made unreadable or indecipherable through any\nmeans.","path":["KRS Chapter 380"],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=35384","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:59:09Z","sha256":"68e207798e40ffadc0107c767477ed3dcee224869dc904a2fcd7eaa10b37c9e1","source_id":"us-ky","stale":false,"prev":"us-ky/krs-380.060","next":"us-ky/krs-380.080"},"notice":"GroundRules: Original legal text. Not legal advice."}
