livelaw

Guides · Kentucky

Recording Law for Voiceprints & Biometric Data in Kentucky

Kentucky’s biometric data definition under the Kentucky Consumer Data Protection Act (KCDPA)

Kentucky does not have a standalone biometric-privacy law like Illinois’ BIPA. Instead, biometric data is regulated under the Kentucky Consumer Data Protection Act (KCDPA), which takes effect January 1, 2026. Under the KCDPA, "biometric data" is defined at KRS 367.3611(3) as: "data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual. Biometric data does not include a physical or digital photograph, a video or audio recording, or data generated therefrom, unless that data is generated to identify a specific individual or information collected, used, or stored for health care treatment, payment, or operations under HIPAA." The second sentence is the important addition: a plain audio or video recording is categorically excluded from "biometric data" under Kentucky law unless it is generated to identify a specific individual. So if your smart glasses capture ambient audio that isn’t used to identify anyone, it’s not biometric data under the KCDPA. Only when the system processes that audio to create a voiceprint that identifies the wearer (or another person) does it become biometric data and trigger the KCDPA’s rules for processing sensitive data. Sensitive data includes "the processing of genetic or biometric data that is processed for the purpose of uniquely identifying a specific natural person" under KRS 367.3611(28)(b).

Under the KCDPA, you must obtain a person’s "consent" before processing their sensitive data that includes biometric data used for identification. The law defines "consent" at KRS 367.3611(6) as: "a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data relating to the consumer. Consent may include a written statement, written by electronic means or any other unambiguous affirmative action." The Attorney General enforces the KCDPA exclusively and must provide a 30-day written notice identifying the specific provisions alleged to have been or are being violated and an opportunity to cure before bringing an action. The law caps penalties at up to seven thousand five hundred dollars ($7,500) for each continued violation and does not allow private lawsuits. The KCDPA also requires reasonable data-minimization and security safeguards under KRS 367.3617(1)(a) and (1)(c), and you must post a clear, reasonably accessible, and meaningful privacy notice. There is no state-mandated retention or destruction schedule specifically for biometric data under the KCDPA.

How Kentucky’s eavesdropping statute (KRS 526.010 and KRS 526.020) governs audio capture and relates to voiceprint processing

Kentucky’s eavesdropping statute is set out in KRS 526.010 (Definition of "eavesdrop") and KRS 526.020 (Eavesdropping), Kentucky Revised Statutes, Chapter 526 "Eavesdropping and Related Offenses." KRS 526.010 defines "eavesdrop" to mean: "to overhear, record, amplify or transmit any part of a wire or oral communication of others without the consent of at least one (1) party thereto by means of any electronic, mechanical or other device." The statute applies regardless of location and does not distinguish between in-person and phone/electronic communications. The one-party consent rule means you can record any conversation you’re part of without telling the others. The eavesdropping law governs the audio capture itself and applies regardless of whether the recording is later used to create a voiceprint. Turning that audio into a voiceprint for identification is governed by the KCDPA’s separate rules for processing sensitive data that includes biometric data. So if you record a conversation with your smart glasses and then use that recording to create a voiceprint that identifies someone, the eavesdropping law covers the recording, while the KCDPA covers the voiceprint processing.

When voiceprints are and aren’t biometric data under Kentucky’s KCDPA

Under KCDPA’s definition at KRS 367.3611(3), a voiceprint becomes biometric data only if it is generated to identify a specific person. A raw audio recording of a conversation is not biometric data unless it is used to identify someone. For example, if your glasses capture audio of a meeting and then run it through a voice-enrollment feature to confirm it’s you speaking, that processed voiceprint is biometric data because it is generated to identify you. But if the system simply stores the audio without turning it into an identifier, it is not biometric data under the KCDPA. Sensitive data includes "the processing of genetic or biometric data that is processed for the purpose of uniquely identifying a specific natural person" under KRS 367.3611(28)(b), so the consent requirement applies when the voiceprint is used for identification.

Hypothetical example: Recording a meeting and creating a voiceprint

Imagine you’re wearing smart glasses in a client meeting. You record the conversation with your glasses’ microphone. Later, you run the recording through your company’s voice-ID system to confirm it was you speaking. Under Kentucky’s KCDPA, the voiceprint created by that system is biometric data only if it is generated to identify a specific person—here, you. The KCDPA requires your consent to process that biometric data as part of its sensitive-data rules under KRS 367.3617(1)(e), which provides: "Not process sensitive data concerning a consumer without obtaining the consumer's consent..." If you didn’t obtain consent before creating the voiceprint, you would need to stop processing it or obtain consent. The eavesdropping law covers the initial recording (since you’re a party to the conversation under KRS 526.010), but the KCDPA governs the voiceprint extraction and storage.

KCDPA enforcement, penalties, and the absence of a private right of action for biometric violations

The KCDPA is enforced exclusively by the Kentucky Attorney General under KRS 367.3627. Before suing, the Attorney General must provide a 30-day written notice identifying the specific provisions alleged to have been or are being violated and an opportunity to cure. If within 30 days the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured and that no further violations shall occur, no action for damages under subsection (3) shall be initiated. If violation continues past the cure period or the cure statement is breached, the Attorney General may initiate an action and seek damages for up to seven thousand five hundred dollars ($7,500) for each continued violation. KRS 367.3627(4) states in full: "Nothing in KRS 367.3611 to 367.3629 or any other law, regulation, or the equivalent shall be construed as providing the basis for, or give rise to, a private right of action for violations of KRS 367.3611 to 367.3629." The eavesdropping statute, by contrast, is a criminal offense—violations are Class D felonies under KRS 526.020—but that applies to unauthorized interception of communications, not to biometric processing.

KCDPA applicability thresholds: when does the law apply to voiceprint processing?

The KCDPA applies only if your processing meets its applicability thresholds set out in KRS 367.3613(1), confirmed verbatim: applies to entities conducting business in or targeting Kentucky residents that during a calendar year control or process personal data of at least "(a) One hundred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data." If your use of voiceprints falls below these thresholds, the KCDPA does not apply to that processing, regardless of whether the voiceprint is biometric data. The statute also excludes from its definition of "biometric data" at KRS 367.3611(3) any plain audio or video recording unless it is generated to identify a specific individual.

KRS 526.070 exceptions to eavesdropping liability and their limited scope

Kentucky’s eavesdropping statute includes only two narrow exceptions to liability under KRS 526.070. The first exception applies to inadvertent, non-divulged telephone party-line or extension overhearing where no party to the communication has disclosed the interception to anyone outside the overhearing party. The second exception applies to common-carrier employees acting within the necessary scope of their employment. These exceptions are not location-based and do not create a general public-place carve-out. No Kentucky case law was found extending KRS 526 eavesdropping liability to video-only capture, and the statute’s definition of "eavesdrop" is limited to audio interception of "wire or oral communication."

Easterling v. Commonwealth (Ky. 2019) and reasonable expectation of privacy under Kentucky law

In Easterling v. Commonwealth, 606 S.W.3d 129 (Ky. 2019), the Kentucky Supreme Court addressed a recording issue and held that a suspect had no reasonable expectation of privacy in a police-controlled interrogation room. The Court did not adopt or resolve a statutory reasonable-expectation-of-privacy gate for KRS 526.020, instead affirming on two independent grounds: (1) KRS 526.020 does not contain a provision, either explicitly or implicitly, that requires exclusion of evidence obtained through its violation, so suppression failed regardless of whether a statutory violation occurred; and (2) separately, Easterling had no Fourth Amendment reasonable expectation of privacy in a police interrogation room under the Katz test. The case underscores that no Kentucky appellate decision has squarely and bindingly held that KRS 526.010’s "oral communication" language carries an implicit reasonable-expectation-of-privacy threshold.

Sixth Circuit uncertainty on First Amendment right to record on-duty police in public

KRS Chapter 526 contains no specific statutory law-enforcement exception governing a citizen’s recording of an on-duty police officer; the general one-party-consent audio rule governs, so a wearer who is a direct party to (or present and participating in) an encounter with police may lawfully audio-record it. Kentucky sits in the U.S. Court of Appeals for the Sixth Circuit (KY, OH, MI, TN). The Sixth Circuit has NOT squarely recognized (nor rejected) a general First Amendment right of ordinary citizens to record on-duty police performing their public duties in public places — unlike several other circuits (e.g., 1st, 3rd, 5th, 7th, 9th, 11th) that have recognized such a right. The closest recent Sixth Circuit authority, Hils v. Davis, 52 F.4th 997 (6th Cir. 2022), held that police officers themselves have no First Amendment right to record their own misconduct-investigation interviews conducted by a citizen complaint authority — a narrower, distinguishable context (non-public internal investigation, officer-as-recorder) rather than a citizen bystander recording police performing public duties in public. Because the Sixth Circuit right-to-record question remains open/undecided as applied to ordinary citizens filming police in public, this is an area of legal uncertainty in Kentucky — practitioners should not assume a clearly-established constitutional right exists in a Sixth-Circuit qualified-immunity posture, even though the underlying eavesdropping statute itself does not bar the recording.

Frequently asked questions

Does Kentucky’s one-party consent rule for recording conversations under KRS 526.010/.020 also cover creating voiceprints from those recordings?

No. Kentucky’s eavesdropping law (KRS 526.010/.020) covers the audio capture and requires only one-party consent because you are a party to the conversation. Creating a voiceprint from that recording is governed by the KCDPA, which requires separate consent for processing sensitive data that includes biometric data used for identification under KRS 367.3617(1)(e). So one-party consent covers the recording, but you still need consent under the KCDPA to create and store the voiceprint if it is used to identify someone.

If I’m in a meeting and record it with my smart glasses, then use the recording to create a voiceprint that identifies me, what law applies?

The eavesdropping law applies to the recording because you are a party to the conversation and the one-party consent rule under KRS 526.010 permits the recording. The KCDPA applies to the voiceprint only if it is biometric data processed to uniquely identify a specific person—here, you—under KRS 367.3611(28)(b). You must have consent to process that biometric data under KRS 367.3617(1)(e), even though the recording itself was lawful under the eavesdropping statute.

Can someone sue me in Kentucky for violating biometric privacy if I create a voiceprint without their consent?

No. Kentucky’s KCDPA does not allow private lawsuits for biometric-privacy violations. KRS 367.3627(4) states in full: "Nothing in KRS 367.3611 to 367.3629 or any other law, regulation, or the equivalent shall be construed as providing the basis for, or give rise to, a private right of action for violations of KRS 367.3611 to 367.3629." Only the Attorney General can enforce the law, and they must give a 30-day notice-and-cure period before taking action under KRS 367.3627(2). So a person cannot sue you directly for biometric violations under the KCDPA.

Does Kentucky have a law requiring me to delete voiceprints after a certain time?

No. Kentucky’s KCDPA does not impose specific retention or destruction timelines for biometric data. It requires reasonable data-minimization and security safeguards under KRS 367.3617(1)(a) and (1)(c), and a clear privacy notice under KRS 367.3617(3), but does not set a fixed deletion schedule for voiceprints.

If my smart glasses capture audio but don’t use it to identify anyone, does the KCDPA apply?

No. The KCDPA excludes plain audio recordings from the definition of "biometric data" unless they are generated to identify a specific person under KRS 367.3611(3). If your glasses simply capture and store ambient audio without using it for identification, the KCDPA does not apply to that audio.

Want a lawyer already lined up before you need one?

live.law connects your smartglasses to a real attorney, live. Join the waitlist to be first in line.

Join the waitlist

live.law is not a law firm and does not provide legal advice. This page is general information, not legal advice for your specific situation — for that, talk to a licensed attorney in your state.