{"data":{"id":"us-ky/krs-61.933","jurisdiction":"us-ky","citation":"KRS 61.933","heading":"Notification of personal information security breach -- Investigation --","body":"Notice to affected individuals of result of investigation -- Personal information\nnot subject to requirements -- Injunctive relief by Attorney General.\n(1) (a) Any agency that c ollects, maintains, or stores personal information that\ndetermines or is notified of a security breach relating to personal information\ncollected, maintained, or stored by the agency or by a nonaffiliated third party\non behalf of the agency shall as soon a s possible, but within seventy -two (72)\nhours of determination or notification of the security breach:\n1. Notify the commissioner of the Kentucky State Police, the Auditor of\nPublic Accounts, and the Attorney General. In addition, an agency shall\nnotify the secretary of the Finance and Administration Cabinet or his or\nher designee if an agency is an organizational unit of the executive\nbranch of state government; notify the commissioner of the Department\nfor Local Government if the agency is a unit of gover nment listed in\nKRS 61.931(1)(b) or (c) that is not an organizational unit of the\nexecutive branch of state government; notify the commissioner of the\nKentucky Department of Education if the agency is a public school\ndistrict listed in KRS 61.931(1)(d); an d notify the president of the\nCouncil on Postsecondary Education if the agency is an educational\nentity listed under KRS 61.931(1)(e). Notification shall be in writing on\na form developed by the Commonwealth Office of Technology. The\nCommonwealth Office of  Technology shall promulgate administrative\nregulations under KRS 61.931 to 61.934 regarding the contents of the\nform; and\n2. Begin conducting a reasonable and prompt investigation in accordance\nwith the security and breach investigation procedures and pra ctices\nreferenced in KRS 61.932(1)(b) to determine whether the security\nbreach has resulted in or is likely to result in the misuse of the personal\ninformation.\n(b) Upon conclusion of the agency's investigation:\n1. If the agency determined that a security breach has occurred and that the\nmisuse of personal information has occurred or is reasonably likely to\noccur, the agency shall:\na. Within forty -eight (48) hours of completion of the investigation,\nnotify in writing all officers listed in paragraph (a)1. o f this\nsubsection, and the commissioner of the Department for Libraries\nand Archives, unless the provisions of subsection (3) of this\nsection apply;\nb. Within thirty-five (35) days of providing the notifications required\nby subdivision a. of this subparagr aph, notify all individuals\nimpacted by the security breach as provided in subsection (2) of\nthis section, unless the provisions of subsection (3) of this section\napply; and\nc. If the number of individuals to be notified exceeds one thousand\n(1,000), the a gency shall notify, at least seven (7) days prior to\nproviding notice to individuals under subdivision b. of this\nsubparagraph, the Commonwealth Office of Technology if the\nagency is an organizational unit of the executive branch of state\ngovernment, the Department for Local Government if the agency is\na unit of government listed under KRS 61.931(1)(b) or (c) that is\nnot an organizational unit of the executive branch of state\ngovernment, the Kentucky Department of Education if the agency\nis a public school district listed under KRS 61.931(1)(d), or the\nCouncil on Postsecondary Education if the agency is an\neducational entity listed under KRS 61.931(1)(e); and notify all\nconsumer credit reporting agencies included on the list maintained\nby the Office of the A ttorney General that compile and maintain\nfiles on consumers on a nationwide basis, as defined in 15 U.S.C.\nsec. 1681a(p), of the timing, distribution, and content of the notice;\nor\n2. If the agency determines that the misuse of personal information has no t\noccurred and is not likely to occur, the agency is not required to give\nnotice, but shall maintain records that reflect the basis for its decision for\na retention period set by the State Archives and Records Commission as\nestablished by KRS 171.420. The agency shall notify the appropriate\nentities listed in paragraph (a)1. of this subsection that the misuse of\npersonal information has not occurred.\n(2) (a) The provisions of this subsection establish the requirements for providing\nnotice to individuals und er subsection (1)(b)1.b. of this section. Notice shall\nbe provided as follows:\n1. Conspicuous posting of the notice on the Web site of the agency;\n2. Notification to regional or local media if the security breach is localized,\nand also to major statewide media if the security breach is widespread,\nincluding broadcast media, such as radio and television; and\n3. Personal communication to individuals whose  data has been breached\nusing the method listed in subdivision a., b., or c. of this subparagraph\nthat the agency believes is most likely to result in actual notification to\nthose individuals, if the agency has the information available:\na. In writing, sen t to the most recent address for the individual as\nreflected in the records of the agency;\nb. By electronic mail, sent to the most recent electronic mail address\nfor the individual as reflected in the records of the agency, unless\nthe individual has communicated to the agency in writing that they\ndo not want email notification; or\nc. By telephone, to the most recent telephone number for the\nindividual as reflected in the records of the agency.\n(b) The notice shall be clear and conspicuous, and shall include:\n1. To the extent possible, a description of the categories of information that\nwere subject to the security breach, including the elements of personal\ninformation that were or were believed to be acquired;\n2. Contact information for the notifying agency,  including the address,\ntelephone number, and toll -free number if a toll -free number is\nmaintained;\n3. A description of the general acts of the agency, excluding disclosure of\ndefenses used for the protection of information, to protect the personal\ninformation from further security breach; and\n4. The toll-free numbers, addresses, and Web site addresses, along with a\nstatement that the individual can obtain information from the following\nsources about steps the individual may take to avoid identity theft, for:\na. The major consumer credit reporting agencies;\nb. The Federal Trade Commission; and\nc. The Office of the Kentucky Attorney General.\n(c) The agency providing notice pursuant to this subsection shall cooperate with\nany investigation conducted by the age ncies notified under subsection (1)(a)\nof this section and with reasonable requests from the Office of Consumer\nProtection of the Office of the Attorney General, consumer credit reporting\nagencies, and recipients of the notice, to verify the authenticity of the notice.\n(3) (a) The notices required by subsection (1) of this section shall not be made if,\nafter consultation with a law enforcement agency, the agency receives a\nwritten request from a law enforcement agency for a delay in notification\nbecause the notice may impede a criminal investigation. The written request\nmay apply to some or all of the required notifications, as specified in the\nwritten request from the law enforcement agency. Upon written notification\nfrom the law enforcement agency that the  criminal investigation has been\ncompleted, or that the sending of the required notifications will no longer\nimpede a criminal investigation, the agency shall send the notices required by\nsubsection (1)(b)1. of this section.\n(b) The notice required by subs ection (1)(b)1.b. of this section may be delayed if\nthe agency determines that measures necessary to restore the reasonable\nintegrity of the data system cannot be implemented within the timeframe\nestablished by subsection (1)(b)1.b. of this section, and th e delay is approved\nin writing by the Office of the Attorney General. If notice is delayed pursuant\nto this subsection, notice shall be made immediately after actions necessary to\nrestore the integrity of the data system have been completed.\n(4) Any waiver of the provisions of this section is contrary to public policy and shall be\nvoid and unenforceable.\n(5) This section shall not apply to:\n(a) Personal information that has been redacted;\n(b) Personal information disclosed to a federal, state, or local gove rnment entity,\nincluding a law enforcement agency or court, or their agents, assigns,\nemployees, or subcontractors, to investigate or conduct criminal investigations\nand arrests or delinquent tax assessments, or to perform any other statutory\nduties and responsibilities;\n(c) Personal information that is publicly and lawfully made available to the\ngeneral public from federal, state, or local government records;\n(d) Personal information that an individual has consented to have publicly\ndisseminated or listed; or\n(e) Any document recorded in the records of either a county clerk or circuit clerk\nof a county, or in the records of a United States District Court.\n(6) The Office of the Attorney General may bring an action in the Franklin Circuit\nCourt against an agency or a nonaffiliated third party that is not an agency, or both,\nfor injunctive relief, and for other legal remedies against a nonaffiliated third party\nthat is not an agency to enforce the provisions of KRS 61.931 to 61.934. Nothing in\nKRS 61.931 to 61.934 shall create a private right of action.","path":["KRS Chapter 61"],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43577","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:49:17Z","sha256":"09af309042a1d0fab9fcb3b13931931b58ea984d1f868808a3f6329117d406e6","source_id":"us-ky","stale":false,"prev":"us-ky/krs-61.932","next":"us-ky/krs-61.934"},"notice":"GroundRules: Original legal text. Not legal advice."}
