Destruction of Customer Records Containing Personally Identifiable Information
KY Records Disposal
Data security
Requires businesses that discard customer records they no longer need to keep to take reasonable steps to destroy the personally identifiable information in them. Personally identifiable information is defined broadly and includes contact details, SSNs, government ID numbers, and medical, financial, tax, and disability information.
- Where
- Kentucky
- Citation
- KRS 365.720 to 365.730 (enacted 2006 Ky. Acts ch. 42)
- Status
- In force
- In force since
- 2006-07-12
- Enforced by
- Injured customers via civil action; injunctive relief available
- People can sue
- Yes
- Penalties
- Any customer injured by a violation may sue for damages, and a violating business may be enjoined; remedies are cumulative with other law.
- Applies to
- Businesses of any form, for-profit or not, including entities that destroy records for others
- Excludes banks, credit unions, savings associations, and savings and loan associations
Security duties
- When disposing of customer records not required to be retained, take reasonable steps to destroy the personally identifiable information by shredding, erasing, or otherwise making it unreadable or indecipherable.KRS 365.725
Other duties
- Injured customers may sue for damages, and violations may be enjoined.KRS 365.730
Sources
- Official text
- KRS 365.720 definitions (Kentucky Legislature)
- KRS 365.725 (Kentucky Legislature)
- KRS 365.730 (Kentucky Legislature)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.