Get emailed when this bill changes status, is amended, or advances.
Disclaimer: This page provides general informational summaries only and does not constitute legal advice. AI-generated content may contain errors. Always consult a qualified attorney for guidance specific to your situation.
Read full disclaimer →
Kentucky's SB345 aims to enhance protections for children using the internet by requiring covered entities to implement stringent data privacy measures. It mandates data protection impact assessments and high default privacy settings for minors. This bill will significantly affect online service providers and their data handling practices.
Key Provisions
Require Data Protection Impact Assessments before new product releases.
Mandate high default privacy settings for children's online accounts.
Prohibit the use of children's data in high-risk scenarios.
Restrict profiling and unnecessary data collection of children.
Require tools for parents to manage children's privacy.
Establish penalties for non-compliance.
Latest Legislative Action
to Economic Development, Tourism, & Labor (S)
Bill Sponsors
Name
Role
B. Storm
Primary
G. Neal
Primary
J. Adams
Primary
R. Thomas
Primary
Compliance Checklist
Conduct Data Protection Impact Assessments before launching new products. Who: Covered entities Penalty: Penalties for violations
Configure default privacy settings for children at a high level. Who: Covered entities Penalty: Penalties for violations
Full Legal Analysis
SB345 introduces new regulations aimed at protecting children's online privacy in Kentucky. It requires covered entities to conduct Data Protection Impact Assessments (DPIAs) before launching new products or services, ensuring that potential risks to children's data are evaluated. Additionally, these entities must make DPIAs available to the Attorney General upon request, enhancing oversight and accountability. The bill also mandates that default privacy settings for children be configured to a high level of privacy, thereby safeguarding their personal information from unnecessary exposure.
Covered entities are prohibited from using children's personal information in ways that are likely to result in high risk, as identified in DPIAs. This includes restrictions on profiling children and collecting or retaining their precise geolocation data without necessity. The bill outlines penalties for violations, although specific amounts are not detailed in the provided text. Compliance will be crucial for online service providers targeting children, as failure to adhere to these regulations could result in significant legal repercussions.
The bill's provisions align with growing trends in data privacy legislation across the United States, reflecting a broader movement towards protecting minors in the digital space. Similar laws have been enacted in other states, emphasizing the importance of safeguarding children's data from exploitation and misuse.
We use cookies for analytics to understand how visitors use this site. We also use essential cookies for site functionality.
See our Privacy Policy for details.