{"data":{"id":"us-ky/krs-61.931","jurisdiction":"us-ky","citation":"KRS 61.931","heading":"Definitions for KRS 61.931 to 61.934.","body":"As used in KRS 61.931 to 61.934:\n(1) \"Agency\" means:\n(a) The executive branch of state government of the Commonwealth of Kentucky;\n(b) Every county, city, municipal corporation, urban -county government, charter\ncounty government, consolidated local government, and unified local\ngovernment;\n(c) Every organizational unit, department, division, branch, section, unit, office,\nadministrative body, program cabinet, bureau, board, commission, committee,\nsubcommittee, ad hoc committee, council, authority, public agency,\ninstrumentality, interagency b ody, special purpose governmental entity, or\npublic corporation of an entity specified in paragraph (a) or (b) of this\nsubsection or created, established, or controlled by an entity specified in\nparagraph (a) or (b) of this subsection;\n(d) Every public school district in the Commonwealth of Kentucky; and\n(e) Every public institution of postsecondary education, including every public\nuniversity in the Commonwealth of Kentucky and public college of the entire\nKentucky Community and Technical College System;\n(2) \"Commonwealth Office of Technology\" means the office established by KRS\n42.724;\n(3) \"Encryption\" means the conversion of data using technology that:\n(a) Meets or exceeds the level adopted by the National Institute of Standards\nTechnology as part of the Federal Information Processing Standards: and\n(b) Renders the data indecipherable without the associated cryptographic key to\ndecipher the data;\n(4) \"Law enforcement agency\" means any lawfully organized investigative agency,\nsheriff's office, police unit, or police force of federal, state, county, urban -county\ngovernment, charter county, city, consolidated local government, unified local\ngovernment, or any combination of these entities, responsible for the detection of\ncrime and the enforcement of the general criminal federal and state laws;\n(5) \"Nonaffiliated third party\" means any person that:\n(a) Has a contract or agreement with an agency; and\n(b) Receives personal information from the agency pursuant to the contract or\nagreement;\n(6) \"Personal information\" means an individual's first name or first initial and last\nname; personal mark; or unique biometric or genetic print or image, in combination\nwith one (1) or more of the following data elements:\n(a) An account number, credit card num ber, or debit card number that, in\ncombination with any required security code, access code, or password, would\npermit access to an account;\n(b) A Social Security number;\n(c) A taxpayer identification number that incorporates a Social Security number;\n(d) A driver's license number, state identification card number, or other individual\nidentification number issued by any agency;\n(e) A passport number or other identification number issued by the United States\ngovernment; or\n(f) Individually identifiable healt h information as defined in 45 C.F.R. sec.\n160.103, except for education records covered by the Family Educational\nRights and Privacy Act, as amended, 20 U.S.C. sec. 1232g;\n(7) (a) \"Public record or record,\" as established by KRS 171.410, means all books,\npapers, maps, photographs, cards, tapes, disks, diskettes, recordings, and other\ndocumentary materials, regardless of physical form or characteristics, which\nare prepared, owned, used, in the possession of, or retained by a public\nagency.\n(b) \"Public recor d\" does not include any records owned by a private person or\ncorporation that are not related to functions, activities, programs, or operations\nfunded by state or local authority;\n(8) \"Reasonable security and breach investigation procedures and practices\" means data\nsecurity procedures and practices developed in good faith and set forth in a written\nsecurity information policy; and\n(9) (a) \"Security breach\" means:\n1. The unauthorized acquisition, distribution, disclosure, destruction,\nmanipulation, or relea se of unencrypted or unredacted records or data\nthat compromises or the agency or nonaffiliated third party reasonably\nbelieves may compromise the security, confidentiality, or integrity of\npersonal information and result in the likelihood of harm to one ( 1) or\nmore individuals; or\n2. The unauthorized acquisition, distribution, disclosure, destruction,\nmanipulation, or release of encrypted records or data containing personal\ninformation along with the confidential process or key to unencrypt the\nrecords or data that compromises or the agency or nonaffiliated third\nparty reasonably believes may compromise the security, confidentiality,\nor integrity of personal information and result in the likelihood of harm\nto one (1) or more individuals.\n(b) \"Security breac h\" does not include the good -faith acquisition of personal\ninformation by an employee, agent, or nonaffiliated third party of the agency\nfor the purposes of the agency if the personal information is used for a\npurpose related to the agency and is not subject to unauthorized disclosure.","path":["KRS Chapter 61"],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43575","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:49:17Z","sha256":"17eea3a36f1e50944be48b0c25540f48611d042b2da7825ed2ad26e1d7515e87","source_id":"us-ky","stale":false,"prev":"us-ky/krs-61.9307","next":"us-ky/krs-61.932"},"notice":"GroundRules: Original legal text. Not legal advice."}
