summary
Introduced
02/12/2025
02/12/2025
In Committee
03/06/2025
03/06/2025
Crossed Over
02/26/2025
02/26/2025
Passed
03/12/2025
03/12/2025
Dead
Signed/Enacted/Adopted
03/15/2025
03/15/2025
Introduced Session
2025 Regular Session
Bill Summary
Amend KRS 367.3613 to exempt information collected by a health care provider that maintains protected health information in accordance with HIPAA and information included in a limited data set as described in 45 C.F.R. sec.164.514(e); amend KRS 367.3621 to make a technical change to include a data protection impact assessment of processing of personal data for the purposes of profiling where the profiling presents a foreseeable risk of an unlawful disparate impact on consumers.
AI Summary
This bill amends Kentucky's consumer data privacy law to make two key changes. First, it expands exemptions to the state's data privacy regulations for health care-related information, specifically adding protections for information collected by health care providers that maintain protected health information under HIPAA (the Health Insurance Portability and Accountability Act) and information included in a limited data set as defined by federal regulations. Second, the bill modifies requirements for data protection impact assessments, particularly for profiling activities, by explicitly including an assessment of potential "unlawful disparate impact" on consumers. The bill requires controllers (organizations that determine the purposes and means of processing personal data) to conduct and document impact assessments for various data processing activities, including targeted advertising, selling personal data, and profiling. These assessments must weigh the benefits of data processing against potential risks to consumer rights, considering factors like de-identified data, consumer expectations, and the context of data processing. The assessments remain confidential and can be requested by the Attorney General during investigations, with the bill specifying that such a request does not waive attorney-client privilege. The changes will take effect on June 1, 2026, providing businesses time to adapt to the new requirements.
Committee Categories
Business and Industry
Sponsors (2)
Last Action
signed by Governor (Acts Ch. 13) (on 03/15/2025)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
Document Type | Source Location |
---|---|
State Bill Page | https://apps.legislature.ky.gov/record/25RS/hb473.html |
BillText | https://apps.legislature.ky.gov/law/acts/25RS/documents/0013.pdf |
BillText | https://apps.legislature.ky.gov/recorddocuments/bill/25RS/hb473/bill.pdf |
Vote History for HB473 | https://apps.legislature.ky.gov/record/25RS/hb473/vote_history.pdf |
BillText | https://apps.legislature.ky.gov/recorddocuments/bill/25RS/hb473/orig_bill.pdf |
Loading...