Framework overlap

Does AWS Well-Architected Security Pillar cover Kentucky Consumer Data Protection Act?

You hold AWS Well-Architected Security Pillar and have been told to do Kentucky Consumer Data Protection Act. Here is how much overlaps, control by control.

63% of Kentucky Consumer Data Protection Act you already have

AWS Well-Architected Security Pillar already covers about 63% of Kentucky Consumer Data Protection Act, leaving 3 of 8 controls as genuinely new work.

Already covered 4 Likely covered 1 New work 3

What is genuinely new work

Nothing in AWS Well-Architected Security Pillar reaches these. This is the list to scope.

KY-CDPA-Privacy-Notice-Transparency-Reasonably-Accessible-Categories-Purposes-Rights-Sharing
Kentucky CDPA Privacy Notice + Transparency + Reasonably Accessible + Categories Processed + Purposes + Consumer Rights + Sharing Practices + Sale Disclosure + Targeted Advertising
KY-CDPA-Scope-Applicability-Threshold-HB15-KRS-Chapter-367-Effective-1-January-2026-100000-25000
Kentucky CDPA Scope + Applicability + Thresholds + HB 15 + KRS Chapter 367 + Effective 1 January 2026 + 100,000 Consumers OR 25,000 Consumers + 50% Revenue from Sale + Attorney Gen
KY-CDPA-Universal-Opt-Out-Mechanism-Recognized-Browser-Level-GPC-Global-Privacy-Control
Kentucky CDPA Universal Opt-Out Mechanism + Section 3 + Section 4 + Recognized + Browser-Level + GPC Global Privacy Control + UOOM + Honored for Targeted Advertising + Sale + Profi
Show the 5 you already have
KY-CDPA-Attorney-General-AG-Enforcement-Sole-30-Day-Cure-Period-7500-Civil-Penalty-Per-Violation
Kentucky CDPA Attorney General Enforcement + Sole Authority + 30-Day Cure Period + USD 7,500 Civil Penalty Per Violation + No Private Right of Action + Injunctive Relief + Attorney
KY-CDPA-Consumer-Rights-Section3-Access-Correction-Deletion-Portability-Object-Profiling-45-Days
Kentucky CDPA Consumer Rights + Section 3 + Right of Access + Correction + Deletion + Portability + Right to Object to Sale/Targeted Advertising/Profiling + 45-Day Response Window
KY-CDPA-Data-Protection-Assessment-DPA-Targeted-Advertising-Sale-Sensitive-Profiling-Substantial-Risk
Kentucky CDPA Data Protection Assessment (DPA) + Section 6 + Targeted Advertising + Sale + Sensitive Data + Profiling Substantial Injury + Maintained Records + Attorney General Acc
KY-CDPA-Sensitive-Data-Affirmative-Consent-Race-Religious-Health-Genetic-Biometric-Children-Citizenship
Kentucky CDPA Sensitive Data + Affirmative Consent + Race/Ethnicity + Religious + Mental/Physical Health + Sexual Orientation + Citizenship/Immigration + Genetic + Biometric + Chil
KY-CDPA-Processor-Contracts-Section5-Confidentiality-Subprocessor-Authorisation-Audits-Sub-Processor
Kentucky CDPA Processor Contracts + Section 5 + Confidentiality + Subprocessor Authorisation + Audits + Sub-Processor Flow-Down + Documented Instructions + Data Deletion + Cooperat

How this is calculated

Already covered means a mapping runs from a control in AWS Well-Architected Security Pillar to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition