Kentucky · verified official-source register

Kentucky Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Kentucky case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Experian Data Corp.

Date
November 7, 2022
Amount
$1,000,000 total payable to the ATTORNEYS GENERAL; $20,000.00 payable to the Commonwealth of Kentucky for the Attorney General’s reasonable costs of investigation and litigation
Legal basis
KRS 367.230; Kentucky Consumer Protection Act, KRS §§ 367.110-.300, 367.990; KRS 365.732; STATE CONSUMER PROTECTION ACTS, STATE PERSONAL INFORMATION PROTECTION ACTS, and STATE DATA BREACH NOTIFICATION ACTS listed in Appendices A and B, including: Alaska Unfair Trade Practices Act, AS 45.50.471 et seq.; Personal Information Protection Act, AS §§ 45.48.010 et seq.; Arizona Consumer Fraud Act, A.R.S. §§ 44-1521 et seq.; Ariz. Rev. Stat. § 18-552; Arkansas Deceptive Trade Practices Act, Ark. Code Ann. §§ 4-88-101 et seq.; Personal Information Protection Act, Ark. Code Ann. §§ 4-110-101 et seq.; Colorado Consumer Protection Act, C.R.S. §§ 6-1-101 et seq.; Personal Information Protection, C.R.S. § 6-1-713.5; Security Breach Notification, C.R.S. § 6-1-716; Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. §§ 42-110b et seq.; Safeguarding of Personal Information, Conn. Gen. Stat. § 42-471; Breach of Security, Conn. Gen. Stat. § 36a-701b; Consumer Fraud Act, 6 Del. C. §§ 2511 et seq.; Delaware Data Breach Notification Law, 6 Del. C. § 12B-100 et seq.; Consumer Protection Procedures Act, D.C. Code §§ 28-3901 et seq.; District of Columbia Consumer Security Breach Notification Act, D.C. Code §§ 28-3851 et seq.; Florida Deceptive and Unfair Trade Practices Act, Chapter 501, Part II, Florida Statutes; Florida Information Protection Act, Section 501.171, Florida Statutes; Uniform Deceptive Trade Practice Act, Haw. Rev. Stat. Chpt. 481A and Haw. Rev. Stat. Sect. 480-2; Personal Information Protection, Haw. Rev. Stat. Chpt. 487J; Security Breach of Personal Information, Haw. Rev. Stat. Chpt. 487N; Idaho Consumer Protection Act, Idaho Code §§ 48-601 et seq.; Identity Theft, Idaho Code §§ 28-51-104 et seq.; Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505/1 et seq.; Illinois Personal Information Protection Act, 815 ILCS 530/1 et seq.; Deceptive Consumer Sales Act, Ind. Code §§ 24-5-0.5 et seq.; Disclosure of Security Breach Act, Indiana Code §§ 24-4.9 et seq.; Iowa Consumer Fraud Act, Iowa Code § 714.16; Personal Information Security Breach Protection Act, Iowa Code § 715C; Kansas Consumer Protection Act, K.S.A §§ 50-623 et seq.; The Wayne Owen Act, K.S.A. § 50-6,139b; Security Breach Notification Act, K.S.A. §§ 50-7a01 et seq.; Maine Unfair Trade Practices Act, 5 M.R.S.A. §§ 205-A et seq.; Maine Notice of Risk to Personal Data Act, 10 M.R.S.A. §§ 1346 et seq.; Maryland Consumer Protection Act, Md. Code Ann., Com. Law §§ 13-101 et seq.; Maryland Personal Information Protection Act, Md. Code Ann., Com. Law § 14-3501 et seq.; Mass. Gen. Laws ch. 93A; Mass. Gen. Laws ch. 93H; 201 Code Mass. Regs. 17.00 et seq.; Michigan Consumer Protection Act, MCL §§ 445.901 et seq.; Identity Theft Protection Act, MCL §§ 445.61 et seq.; The Uniform Deceptive Trade Practices Act, Minn. Stat. §§ 325D.43–.48; Consumer Fraud Act, Minn. Stat. §§ 325F.68-.694; Minnesota Data Breach Notification Statute, Minn. Stat. § 325E.61; Missouri Merchandising Practices Act, Mo. Rev. Stat. §§ 407.010 et seq.; Mo. Rev. Stat. § 407.1500; Montana Unfair Trade Practices and Consumer Protection Act, Mont. Code Ann. §§ 30-14-101 et seq.; Montana Impediment of Identity Theft Act, Mont. Code Ann. §§ 30-14-1701 et seq.; Nebraska Consumer Protection Act, Neb. Rev. Stat. §§ 59-1601 et seq.; Nebraska Uniform Deceptive Trade Practices Act, Neb. Rev. Stat. § 87-301 et seq.; Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, Neb. Rev. Stat. § 87-801 et seq.; Nevada Deceptive Trade Practices Act; Nev. Rev. Stat. §§ 598.0903 et seq.; Nevada Security and Privacy of Personal Information Act; Nev. Rev. Stat. §§ 603A.010 et seq.; New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 et seq.; New Jersey Identity Theft Prevention Act, N.J.S.A. 56:8-161 to -166; The New Mexico Unfair Practices Act, NMSA 1978, §§ 57-12-1 to -26; The New Mexico Data Breach Notification Act, NMSA 1978, §§ 57-12C-1 to -12; North Carolina Unfair and Deceptive Trade Practices Act, N.C.G.S. §§ 75-1.1 et seq.; North Carolina Identity Theft Protection Act, N.C.G.S. §§ 75-60 et seq.; Unlawful Sales or Advertising Practices, N.D.C.C. §§ 51-15-01 et seq.; Notice of Security Breach for Personal Information, N.D.C.C. §§ 51-30-01 et seq.; Ohio Consumer Sales Practices Act, R.C. §§ 1345.01 et seq.; Security Breach Notification Act, R.C. §§ 1349.19 et seq.; Oregon Unlawful Trade Practices Act, ORS 646.605 et seq.; Oregon Consumer Information Protection Act, ORS 646A.600 et seq.; Pennsylvania Unfair Trade Practices and Consumer Protection Law, 73 P.S. §§ 201-1 et seq.; Breach of Personal Information Notification Act, 73 P.S. §§ 2301 et seq.; Rhode Island Deceptive Trade Practices Act, R.I. Gen. Laws §§ 6-13.1-1 et seq.; Rhode Island Identity Theft Protection Act, R.I. Gen. Laws §§ 11-49.3-1 et seq.; South Carolina Unfair Trade Practices Act, S.C. Code Ann. §§ 39-5-10 et seq.; Data Breach Notification, S.C. Code Ann., § 39-1-90; SDCL 37-24; Data Breach Notification SDCL 22-40-19 through 22-40-26; Tennessee Consumer Protection Act of 1977, Tenn. Code Ann. §§ 47-18-101 to -134; Tennessee Identity Theft Deterrence Act of 1999, Tenn. Code Ann. §§ 47-18-2101 to -2111; Texas Deceptive Trade Practices – Consumer Protection Act, Tex. Bus. & Com. Code Ann. §§ 17.41–17.63; Identity Theft Enforcement and Protection Act, Tex. Bus. & Com. Code Ann. § 521.001–152; Utah Consumer Sales Practices Act, Utah Code §§ 13-11-1 et seq.; Utah Protection of Personal Information Act, Utah Code §§ 13-44-101 et seq.; Vermont Consumer Protection Act, 9 V.S.A. §§ 2451 et seq.; Vermont Security Breach Notice Act, 9 V.S.A. § 2435; Washington Consumer Protection Act, RCW 19.86.020; Washington Data Breach Notification Law, RCW 19.255.010; Fraudulent Representations, Wis. Stat. § 100.18(1); Notice of Unauthorized Acquisition of Personal Information, Wis. Stat. § 134.98

Why the action was brought

Experian continued providing portal access to a database containing consumers’ personal information, including social security numbers, after acquiring Court Ventures. An identity thief used credentials obtained through false representations and enabled more than 3 million queries. After discovering the unauthorized access, Experian notified the database provider but did not notify affected consumers or the Attorneys General.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Google, LLC

Date
11/9/2022
Amount
$391,500,000.00 total; Kentucky share: $7,282,184.49; $1,820,546.12 retained by the Kentucky Attorney General’s Office pursuant to KRS 48.005(4)
Legal basis
KRS 367.110-990 et seq.; KRS 367.230; Kentucky Consumer Protection Act

Why the action was brought

Google allegedly misrepresented and omitted material information about its collection, storage, retention, and use of users’ location information through Location History and Web & App Activity. Disabling settings did not prevent collection or use, and location data continued supporting advertising, including personalized ads, leaving users unable to reasonably avoid Google’s access to their location information.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Residual Pumpkin Entity, LLC (formerly known as CafePress LLC)

Date
2020-12-11
Amount
$2,000,000 total, of which $1,250,000 is suspended; Kentucky amount payable: $58,484.65, including $14,621.16 for the Attorney General’s reasonable costs of investigation and litigation
Legal basis
KRS 367.230; Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. §§ 42-110b et seq.; Safeguarding of Personal Information, Conn. Gen. Stat. § 42-471; Breach of Security, Conn. Gen. Stat. § 36a-701b; Michigan Consumer Protection Act, MC 445.901 et seq.; Identity Theft Protection Act, MCL §§ 445.61 et seq.; Deceptive Consumer Sales Act, Ind. Code §§ 24-5-0.5 et seq.; Disclosure of Security Breach Act, Indiana Code §§ 24-4.9 et seq.; Kentucky Consumer Protection Act, KRS §§ 367.110-.300, 367.990; KRS 365.732; New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 et seq.; New Jersey Identity Theft Prevention Act, N.J.S.A. 56:8-161 to -166; Executive Law 63(12); General Business Law 349/350; General Business Law 899-aa and 899-bb; Oregon Unlawful Trade Practices Act, ORS 646.605 et seq.; Oregon Consumer Information Protection Act, ORS 646A.600 et seq.

Why the action was brought

An unidentified attacker obtained names, email addresses, passwords, physical addresses, phone numbers, partial payment-card information, and Social Security or tax identification numbers from a CafePress database containing approximately 22 million accounts, including 186,179 with Social Security or tax identification numbers. CafePress did not detect the intrusion, investigated only later, and customer information was offered for sale on the dark web.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.