Kansas
Kansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 24 primary sources cited on this page. How we verify our legal content

Kansas has no comprehensive consumer data privacy law as of May 2026. The Protection of Consumer Information Act (K.S.A. 50-7a01) requires businesses to notify residents of data breaches without unreasonable delay. Additional protections come from the Consumer Protection Act, student data statutes, and insurance and financial institution security laws.
Kansas takes a sectoral approach to data privacy rather than enacting a single comprehensive consumer privacy statute. While states like California, Colorado, Texas, and Virginia have passed broad data protection laws granting consumers extensive rights over their personal information, Kansas has not followed suit.
Instead, Kansas residents rely on a collection of targeted laws: a data breach notification statute, the state Consumer Protection Act, student data privacy protections, financial institution information security requirements, insurance data security requirements, and criminal identity theft provisions.
This guide covers each Kansas law that touches data privacy, explains what protections you have, what businesses must do to comply, and how enforcement works.
Protection of Consumer Information Act
The Protection of Consumer Information Act is Kansas's primary data breach notification law. Codified at K.S.A. 50-7a01 through 50-7a04, it took effect in 2006 and establishes the rules businesses and government agencies must follow when a security breach exposes personal information belonging to Kansas consumers. It is a different statute from the Wayne Owen Act (K.S.A. 50-6,139 through 50-6,139b), a Kansas Consumer Protection Act provision covering identity theft and personal-information-security requirements.

Key Definitions Under K.S.A. 50-7a01
The statute defines several critical terms that determine when the law applies and who it protects.
Personal information means a consumer's first name or first initial and last name linked to any one or more of the following data elements, when those elements are neither encrypted nor redacted:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number, alone or in combination with any required security code, access code, or password that would permit access to a consumer's financial account
This definition is narrower than what many newer state privacy laws cover. Kansas does not include biometric data, medical information, or online account credentials in its breach notification trigger, unless those elements fall under one of the categories listed above.
Security breach means the unauthorized access and acquisition of unencrypted or unredacted computerized data that compromises the security, confidentiality, or integrity of personal information. The breach must cause, or the entity must reasonably believe it has caused or will cause, identity theft to any consumer.
Encrypted means the transformation of data through an algorithmic process into a form in which there is a low probability of assigning meaning without the use of a confidential process or key, or securing the information by another method that renders the data elements unreadable or unusable.
A good-faith acquisition of personal information by an employee or agent of a business, for the purposes of that business, does not qualify as a security breach, provided the personal information is not used for or subject to further unauthorized disclosure.
Breach Notification Requirements Under K.S.A. 50-7a02
When a business or government entity that conducts business in Kansas becomes aware of a security breach, K.S.A. 50-7a02 requires it to take the following steps.
Investigation. The entity must conduct a good-faith, reasonable, and prompt investigation to determine the likelihood that personal information has been or will be misused.
Consumer notification. If the investigation determines that misuse of information has occurred or is reasonably likely to occur, the entity must notify affected Kansas residents. The notification must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Kansas does not set a specific deadline measured in days. The standard is "without unreasonable delay," which gives businesses some flexibility but also leaves room for enforcement discretion by the Attorney General.
Large-scale breach reporting. When a breach requires notification to more than 1,000 consumers at one time, the entity must also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the notices sent to consumers.
Methods of Notification
Kansas law allows notification through several channels:
- Written notice sent to the consumer's mailing address
- Electronic notice consistent with the federal Electronic Signatures in Global and National Commerce Act (15 U.S.C. Section 7001)
Substitute Notice
An entity may provide substitute notice if it demonstrates that the cost of providing standard notification would exceed $100,000, the affected class of consumers exceeds 5,000 people, or the entity does not have sufficient contact information to provide direct notice.
Substitute notice must include all of the following:
- Email notice to affected consumers for whom the entity has an email address
- Conspicuous posting of the notice on the entity's website
- Notification to major statewide media outlets
Compliance Alternatives
Businesses that maintain their own notification procedures as part of an information security policy are deemed in compliance with Kansas law, as long as those procedures are consistent with the timing requirements of K.S.A. 50-7a02 and the business follows its own policies when a breach occurs.
Entities regulated by state or federal law that maintain breach procedures under their primary regulator's rules, regulations, or guidelines are also deemed in compliance.
Enforcement and Penalties
The Kansas Attorney General has the authority to bring enforcement actions against individuals and commercial entities that violate the Protection of Consumer Information Act. The Attorney General may seek injunctive relief and civil penalties.
For violations committed by a state-licensed insurance company, the Kansas Insurance Commissioner has sole enforcement authority rather than the Attorney General.
Kansas's breach notification law does not provide a private right of action. Individual consumers cannot sue a business directly for failing to provide breach notification. Enforcement rests exclusively with the Attorney General or, for insurers, the Insurance Commissioner.
K.S.A. 50-7a03 has been repealed. K.S.A. 50-7a04 is a severability clause that preserves the remaining provisions of the Act if any single provision is found invalid.
Kansas Consumer Protection Act
The Kansas Consumer Protection Act (KCPA), codified at K.S.A. 50-623 through 50-643, is the state's general consumer protection statute. While it was not designed specifically for data privacy, the Attorney General uses it to pursue enforcement actions related to deceptive data practices.

How the KCPA Applies to Data Privacy
The KCPA prohibits deceptive acts and practices, unconscionable acts, and false or misleading representations in consumer transactions. Under K.S.A. 50-623, the Act is to be construed liberally to promote its purposes, which include:
- Simplifying and modernizing the law governing consumer transactions
- Protecting consumers from suppliers who commit deceptive and unconscionable practices
- Encouraging fair and honest business dealings
When a company collects personal data from Kansas consumers and then fails to protect it as promised in its privacy policy, misrepresents how data will be used, or engages in deceptive data collection practices, the Attorney General can bring an action under the KCPA.
Penalties Under the KCPA
The Attorney General, county attorney, or district attorney may seek civil penalties of up to $10,000 per violation under K.S.A. 50-636. Willful violations of court orders may result in civil penalties up to $20,000 per violation. Each deceptive act directed at an individual consumer can constitute a separate violation, meaning penalties can accumulate rapidly in cases involving widespread data misuse.
The Attorney General may also seek injunctive relief to stop ongoing violations and obtain restitution for affected consumers.
Identity Theft as an Unconscionable Act
Kansas law explicitly links identity theft to the Consumer Protection Act. Under K.S.A. 50-6,139, conduct that constitutes identity theft under K.S.A. 21-6107 is considered an unconscionable act or practice. Any person who engages in such conduct is subject to all remedies and penalties available under the KCPA.
This provides the Attorney General with an additional enforcement tool when data breaches lead to identity theft.
AG Enforcement Under the KCPA (2023-2026)
Attorney General Kris Kobach, who took office in January 2023, has used the KCPA actively in the data and technology space. The AG's office reported over $180 million in consumer recoveries and judgments since January 2023 and more than $3 million in settlements returned to state funds in fiscal year 2025. In 2026, the AG filed suit against a Wyandotte County company for targeting vulnerable homeowners. In September 2025, Kobach's office also sued Snap Inc., the maker of Snapchat, alleging the app was deceptively marketed and designed to be addictive and harmful to Kansas teenagers, in violation of the KCPA. Kobach also sent demand letters to AI companies citing chatbot interactions harmful to Kansas children. These actions signal that the KCPA is Kansas's primary enforcement lever for technology-related consumer data abuses in the absence of a dedicated privacy statute.
Student Data Privacy Act
Kansas enacted the Student Data Privacy Act in 2014 through Senate Bill 367, now codified at K.S.A. 72-6312 through 72-6320. The law specifically protects student information held by educational agencies and their contractors.
What the Student Data Privacy Act Prohibits
The Act prohibits three categories of conduct:
- Unauthorized disclosure of student data and personally identifiable student data. Educational agencies and their operators cannot release student records without proper authorization.
- Unauthorized collection of biometric data from students. Schools and their technology vendors cannot collect fingerprints, retinal scans, or other biometric identifiers without authorization.
- Unauthorized use of devices to assess psychological or emotional state. No device or mechanism may be used to evaluate a student's psychological or emotional condition without proper consent.
Definitions of Protected Data
Student data includes information contained in a student's educational record, such as state and national assessment results, course completion and transcript information, graduation data, and dropout data.
Personally identifiable student data means student data that, alone or in combination, is linked or linkable to a specific student and would allow a reasonable person to identify the student with reasonable certainty.
Enforcement
The Kansas Attorney General or a district attorney may enforce the Student Data Privacy Act by bringing an action in court. They may seek injunctive relief to prevent any educational agency from disclosing student data in violation of the Act.
Citizens who believe a school or educational technology vendor has violated the Act can file complaints with either their district attorney or the Office of the Attorney General.
Insurance Data Security in Kansas
Kansas has not enacted a dedicated Insurance Data Security Act. K.S.A. 40-5901, sometimes mislabeled online as the source of this Act, actually governs vision care insurance contract terms and has nothing to do with cybersecurity. According to the National Association of Insurance Commissioners' own tracking of state adoption of its Insurance Data Security Model Law (Model #668), Kansas shows no current activity adopting that model.

What Applies to Kansas Insurers Instead
Because Kansas has no separate insurer-specific cybersecurity statute, licensed insurers remain subject to the state's general data breach notification law, the Protection of Consumer Information Act. Under K.S.A. 50-7a02, the Kansas Insurance Commissioner has sole authority to enforce that law against violations by a state-licensed insurance company, rather than the Attorney General.
Kansas Financial Institutions Information Security Act
In 2023, Kansas enacted the Kansas Financial Institutions Information Security Act through Senate Bill 44. This law established information security standards for financial institutions operating in the state.
Purpose and Standards
The Act aligns Kansas with federal information security requirements by establishing standards consistent with 16 C.F.R. Section 314 (the FTC's Safeguards Rule) as in effect on July 1, 2023. Covered entities must implement comprehensive information security programs to protect customer data.
Covered Entities
The Financial Institutions Information Security Act applies to:
- Credit services organizations
- Mortgage companies
- Supervised lenders
- Financial institutions engaging in money transmission
Enforcement by the State Bank Commissioner
The Kansas State Bank Commissioner implements, administers, and enforces the Act. The Commissioner may assess fines or civil penalties on a covered entity of up to $5,000 per violation and may also assess the costs of investigation, examination, or enforcement actions.
Kansas Identity Theft Criminal Statute
Kansas criminalizes identity theft under K.S.A. 21-6107. While this is a criminal law rather than a data privacy regulation, it provides important protections for Kansas residents whose personal information is stolen or misused.
Definition of Identity Theft
Identity theft in Kansas means obtaining, possessing, transferring, using, selling, or purchasing any personal identifying information or document containing the same, belonging to or issued to another person, with the intent to:
- Defraud that person or anyone else in order to receive any benefit
- Misrepresent that person in order to subject them to economic or bodily harm
Personal Identifying Information
The statute defines personal identifying information broadly. It includes:
- Financial account numbers
- Passwords that can be used to access financial resources, including checking or savings accounts
- Credit or debit card information
- Usernames or other log-in credentials that can be used to access personal electronic content
Criminal Penalties
Identity theft in Kansas carries two severity levels based on the monetary loss to victims:
- $100,000 or less: Severity level 8 nonperson felony
- More than $100,000: Severity level 5 nonperson felony
Kansas felony sentencing guidelines determine the actual prison time based on the severity level and the offender's criminal history. A severity level 5 nonperson felony can carry a presumptive prison sentence ranging from 31 to 136 months depending on prior convictions.
Credit Freeze Protections
Kansas law provides consumers with the right to place a security freeze on their credit reports under K.S.A. 50-723, a provision of the Kansas Fair Credit Reporting Act. The term security freeze itself is defined at K.S.A. 50-702, the act's definitions section, which sets out no procedure of its own.
How a Security Freeze Works
A security freeze is a notice placed on a consumer report that prohibits a consumer reporting agency from releasing the consumer's credit report or credit score for the purpose of extending credit. This prevents identity thieves from opening new accounts in a victim's name.
Placing a Freeze
Kansas consumers can request a security freeze through:
- Written request sent by certified mail or regular mail
- A secure website if the consumer reporting agency makes one available
- Telephone, if the agency does not have an available secure website
A consumer reporting agency must place the freeze within five business days of receiving the request.
Identification and Management
Within 10 business days of placing a freeze, the consumer reporting agency must provide the consumer with a unique personal identification number, password, or similar device. The agency must also explain the process for placing, removing, and temporarily lifting a security freeze.
Credit freezes in Kansas are free for all consumers, consistent with the federal Economic Growth, Regulatory Relief, and Consumer Protection Act, which made credit freezes free nationwide.
Kansas Health Information Privacy
Kansas addresses health information privacy primarily through the Kansas Health Information Technology Act, codified at K.S.A. 65-6821 through 65-6835, and through compliance with the federal Health Insurance Portability and Accountability Act (HIPAA).
State-Level Requirements
Kansas law defines health information and protected health information using the same definitions as the HIPAA Privacy Rule. Covered entities in Kansas must provide individuals or their personal representatives with access to their protected health information.
A separate Kansas records provision that sits outside the Health Information Technology Act, K.S.A. 65-6836, governs access to records themselves. It requires copies of health care records to be furnished to a patient, a patient's authorized representative, or any other person or entity authorized by law to obtain them within 30 days of receiving the authorization.
A provider may withhold copies only if providing them would cause substantial harm to the patient or another person.
Controlling Law
Where any provision of Kansas state law regarding the confidentiality, privacy, security, or privileged status of protected health information conflicts with the Kansas Health Information Technology Act, the Act's provisions control. Certain exceptions apply for peer review and risk management statutes.
Federal Laws That Apply in Kansas
Because Kansas lacks a comprehensive state-level consumer data privacy law, federal statutes play a significant role in protecting Kansas residents' personal data.
TAKE IT DOWN Act
The TAKE IT DOWN Act (Pub. L. 119-12) was signed into law on May 19, 2025. It criminalizes the publication of nonconsensual intimate visual depictions, including AI-generated deepfakes. Covered platforms must establish a notice-and-removal process and take down flagged images within 48 hours of receiving notice. FTC enforcement of the platform takedown obligations began May 19, 2026. Platforms that fail to comply face FTC enforcement action, including civil penalties of up to $53,088 per violation.
HIPAA
The Health Insurance Portability and Accountability Act governs how health care providers, insurers, and their business associates handle protected health information for Kansas residents. HIPAA establishes national standards for the security and privacy of medical records and provides patients with rights to access and request corrections to their health data.
Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and to safeguard sensitive consumer financial data. Kansas banks, credit unions, and other financial service providers must comply with GLBA's privacy notice and data security requirements.
FERPA
The Family Educational Rights and Privacy Act protects the privacy of student education records at institutions that receive federal funding. FERPA works alongside Kansas's own Student Data Privacy Act to protect student information in the state.
FTC Act Section 5
The Federal Trade Commission Act prohibits unfair or deceptive acts or practices in commerce. The FTC has used this authority to bring enforcement actions against companies nationwide, including those operating in Kansas, for data privacy and security failures.
Children's Online Privacy Protection Act
COPPA requires websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information from children. This federal law applies to all operators collecting data from Kansas children.
The Outlook for Comprehensive Privacy Legislation in Kansas
As of May 2026, Kansas has not enacted a comprehensive consumer data privacy law. The 2025-2026 legislative session did not produce a comprehensive privacy bill granting consumers broad rights to access, delete, or opt out of the sale of their personal data. The Kansas legislature advanced SB 372, an app store age-verification and parental consent bill, which passed the Senate in early 2026 but did not advance through the House before the session closed.
Kansas currently has no statute providing residents with:
- The right to request a copy of all personal data a company holds about them
- The right to demand deletion of their personal data
- The right to opt out of the sale or sharing of their personal data
- The right to opt out of targeted advertising based on their data
- The right to correct inaccurate personal data held by a business
These rights exist in states with comprehensive privacy laws (California, Texas, Virginia, Colorado, and roughly 20 others as of mid-2026) but are not available under current Kansas statutes.
Residents and businesses should monitor the Kansas Legislature for future privacy bills, as the national trend toward comprehensive state privacy laws continues to accelerate.
More Kansas Laws
Frequently Asked Questions
Does Kansas have a comprehensive data privacy law?
No. Kansas does not have a comprehensive consumer data privacy law similar to the California Consumer Privacy Act or the Texas Data Privacy and Security Act. As of May 2026, the Kansas legislature has not passed broad consumer privacy legislation. Kansas relies on a patchwork of targeted statutes covering data breach notification, consumer protection, student data privacy, insurance data security, and financial institution security. Federal laws including HIPAA, GLBA, COPPA, and the FTC Act fill additional gaps.
What are my rights if a company experiences a data breach involving my information in Kansas?
Under the Protection of Consumer Information Act (K.S.A. 50-7a02), any business or government entity that conducts business in Kansas must notify you without unreasonable delay if a security breach has compromised your personal information and misuse has occurred or is reasonably likely to occur. Personal information includes your name linked to your Social Security number, driver's license number, or financial account numbers. You also have the right to place a free security freeze on your credit reports.
Can I sue a company in Kansas for a data breach?
Kansas's breach notification law does not provide a private right of action. You cannot sue a company directly under K.S.A. 50-7a01 through 50-7a04 for failing to notify you of a breach. Enforcement is handled by the Kansas Attorney General or the Insurance Commissioner for insurance companies. However, you may have claims under the Kansas Consumer Protection Act if a company engaged in deceptive practices related to your data, and you may have common-law claims depending on the circumstances.
How does Kansas protect student data privacy?
The Kansas Student Data Privacy Act (K.S.A. 72-6312 through 72-6320) prohibits unauthorized disclosure of student data, unauthorized collection of biometric data from students, and unauthorized use of devices to assess a student's psychological or emotional state. The Attorney General and district attorneys can enforce the Act. Parents and students can file complaints with the Attorney General's office if they believe a school or educational technology vendor has violated these protections.
What penalties do businesses face for violating Kansas data privacy laws?
Penalties depend on which statute is violated. Under the Kansas Consumer Protection Act (K.S.A. 50-636), the Attorney General may seek civil penalties up to $10,000 per violation, with willful court-order violations subject to up to $20,000 per violation. Under the Financial Institutions Information Security Act, the State Bank Commissioner can assess fines up to $5,000 per violation. Identity theft is a felony with presumptive sentences up to 136 months depending on monetary loss. The Attorney General can also seek injunctive relief and restitution under multiple statutes.
Does the TAKE IT DOWN Act apply in Kansas?
Yes. The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that applies in all states including Kansas. It criminalizes the publication of nonconsensual intimate visual depictions, including AI-generated deepfake images. Covered online platforms were required to implement notice-and-removal processes by May 19, 2026, and must remove flagged images within 48 hours. The FTC enforces the platform obligations and may impose civil penalties up to $53,088 per violation.
Is Kansas a one-party consent state for recording?
Yes. Kansas is a one-party consent state under K.S.A. 21-6101. Recording a phone call or in-person conversation is lawful as long as one party to the conversation consents, and that party can be you. Secretly recording a conversation in which you are not a participant is unlawful. Penalties for illegal interception include up to one year in jail and fines, plus civil liability under K.S.A. 22-2518. For full details, see the Kansas Recording Laws page.
Does the Kansas Insurance Data Security Act affect policyholders?
Kansas has not enacted an Insurance Data Security Act modeled on the NAIC's model law. K.S.A. 40-5901, which is sometimes cited for this claim, actually covers vision care insurance contracts. Kansas-licensed insurers are instead subject to the state's general data breach notification law, the Protection of Consumer Information Act. If a breach affects your insurance data, the insurer must notify you under K.S.A. 50-7a02, and the Kansas Insurance Commissioner has sole authority to enforce that law against insurers, rather than the Attorney General.
Updates
Corrected the Kansas Health Information Technology Act's statutory range to K.S.A. 65-6821 through 65-6835, clarified that the 30-day medical records copy rule in K.S.A. 65-6836 is a separate provision outside that Act, and grounded the credit freeze section in K.S.A. 50-723, the operative security freeze statute, rather than the definitions section.
Corrected the name and citation of the Wayne Owen Act (it is K.S.A. 50-6,139, a separate Kansas Consumer Protection Act provision, not the data breach notification statute), fixed the citation for the identity-theft-as-unconscionable-act rule (K.S.A. 50-6,139, not 50-6,139b), corrected the Student Data Privacy Act's statutory range (K.S.A. 72-6312 through 72-6320, not 72-6311), and fixed the year and target of a cited Kansas AG social-media enforcement action (Snap Inc./Snapchat, September 2025).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the identity theft criminal penalty table (K.S.A. 21-6107 sets only two severity tiers, not four) and removed the fabricated Kansas Insurance Data Security Act, which does not exist under Kansas law (K.S.A. 40-5901 is the vision care insurance contract statute; NAIC's own model-law tracker lists Kansas as having no current activity adopting the Insurance Data Security Model Law).
Updated a stale May 2026 changelog entry that still described a 'Kansas Insurance Data Security Act' section as if it were a real statute, contradicting the corrected article body, which explains Kansas has not enacted that act.
Governing law re-checked for recent changes
May 2026 refresh: Added an insurance section describing a purported Kansas Insurance Data Security Act citing K.S.A. 40-5901 et seq.; a later review found Kansas has not enacted such an act and that K.S.A. 40-5901 actually governs vision care insurance contracts, so that section was corrected on 2026-08-07. Corrected KCPA civil penalty figure from $500-$1,000 per violation to the accurate up to $10,000 per violation under K.S.A. 50-636 for AG enforcement actions. Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) to federal overlay section with FTC enforcement status effective May 19, 2026. Added AG Kobach enforcement context (2023-2026 KCPA enforcement, $180M+ in recoveries, social media and AI company actions). Updated legislative outlook to reflect no comprehensive privacy bill passed in 2025 or 2026 sessions; SB 372 (app store bill) passed Senate but did not advance in House. Added two new FAQ entries on TAKE IT DOWN Act applicability and one-party consent recording law. Added K.S.A. 21-6101 (wiretap/recording) and K.S.A. 50-636 (civil penalties) to SourcesList.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Kansas Statutes Annotated, Chapter 50: UNFAIR TRADE AND CONSUMER PROTECTION
§ 50-7a02Security breach; requirements.In forcecited in 3 of our articles
(a) A person that conducts business in this state, or a government, governmental subdivision or agency that owns or licenses computerized data that includes personal information shall, when it becomes aware of any breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused. If the investigation determines that the misuse of information has occurred or is reasonably likely to occur, the person or government, governmental subdivision or agency shall give notice as soon as possible to the affected Kansas resident. Notice must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at ksrevisor.gov
Also relied on in: Kansas Biometric Privacy Laws: What You Need to Know (2026), Kansas Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 50-7a01Consumer information; security breach; definitions.In forcecited in 3 of our articles
As used in K.S.A. 50-7a01 and 50-7a02, and amendments thereto: (a) "Consumer" means an individual who is a resident of this state. (b) "Encrypted" means transformation of data through the use of algorithmic process into a form in which there is a low probability of assigning meaning without the use of a confidential process or key, or securing the information by another method that renders the data elements unreadable or unusable. (c) "Notice" means: (1) Written notice; (2) electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or (3) substitute notice, if the individual or the commercial entity required to provide notice demonstrates that the cost of providing notice will exceed $100,000, or that the affected class of consumers to be notified exceeds 5,000, or that the individual or the commercial entity does not have sufficient contact information to provide notice.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
§ 50-7a04Severability clause.In forcecited in 2 of our articles
If any provision of this act or its application to any person or circumstance is held invalid, the invalidity shall not affect any other provision or application of the act which can be given effect without the invalid provision or application. To this end the provisions of this act are severable.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
§ 50-623Kansas consumer protection act; purpose; construction.In forcecited in 4 of our articles
This act shall be construed liberally to promote the following policies: (a) To simplify, clarify and modernize the law governing consumer transactions; (b) to protect consumers from suppliers who commit deceptive and unconscionable practices; (c) to protect consumers from unbargained for warranty disclaimers; and (d) to provide consumers with a three-day cancellation period for door-to-door sales.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 214 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Unruh v. PURINA MILLS, LLC (Supreme Court of Kansas 2009, 289 Kan. 1185)“…a supplier under the Kansas Consumer Protection Act (KCPA), K.S.A. 50-623 et seq. As the majority correctly n…”
- Williamson v. Amrani (Supreme Court of Kansas 2007, 283 Kan. 227)“…stion of whether the Kansas Consumer Protection Act (KCPA), K.S.A. 50-623 et seq., applies to a physician s pro…”
- Stair v. Gaylord (Supreme Court of Kansas 1983, 232 Kan. 765)“…chantability, breach of contract and violation of the KCPA, K.S.A. 50-623 et seq. He also alleged ac…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Kansas AI Laws and Regulation (2026)
§ 50-636Civil penalties.In forcecited in 3 of our articles
(a) The commission of any act or practice declared to be a violation of this act shall render the violator liable to the aggrieved consumer, or the state or a county as provided in subsection (c), for the payment of a civil penalty, recoverable in an individual action, including an action brought by the attorney general or county attorney or district attorney, in a sum set by the court of not more than $10,000 for each violation. An aggrieved consumer is not a required party in actions brought by the attorney general or a county or district attorney pursuant to this section. (b) Any supplier who willfully violates the terms of any court order issued pursuant to this act shall forfeit and pay a civil penalty of not more than $20,000 per violation, in addition to other penalties that may be imposed by the court, as the court shall deem necessary and proper. For the purposes of this section, the district court issuing an order shall retain jurisdiction, and in such cases, the attorney general, acting in the name of the state, or the appropriate county attorney or district attorney may petition for recovery of civil penalties.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 39 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State Ex Rel. Morrison v. Oshman Sporting Goods Co. Kansas (Supreme Court of Kansas 2003, 275 Kan. 763)“…not the failed inspection. Oshman also argues, that K.S.A. 50-636(d) should have been considered by the t…”
- Finstad v. Washburn University (Supreme Court of Kansas 1993, 252 Kan. 465)“…civil penalty, ... whichever is greater.” K.S.A. 50-634(b). K.S.A. 50-636(a) provides, in pertinent part:…”
- Alenco, Inc. v. Warrington (Court of Appeals of Kansas 2024)“…ng act or practice, whichever is greater. K.S.A. 50-634(b); K.S.A. 50-636(a). Suppliers who willfully violate the…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Kansas Age Verification Law: SB 394 Requirements Explained
§ 50-702Definitions and rules of construction.In force
The following words and phrases when used in the fair credit reporting act shall have the meanings ascribed to them in this section: (a) The term "person" means any individual, partnership, corporation, trust, estate, cooperative, association, government or governmental subdivision or agency, or other entity. (b) The term "consumer" means an individual. (c) The term "consumer report" means any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer's eligibility for credit or insurance to be used primarily for personal, family, or household purposes, or employment purposes, or other purposes authorized under K.S.A. 50-703, and amendments thereto.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 1990
Opinions citing this section in our collection:
- Peasley v. Telecheck of Kansas, Inc. (Court of Appeals of Kansas 1981, 6 Kan. App. 2d 990)“…service of TeleCheck distribute “consumer reports?” K.S.A. 50-702(e) provides: “(e) The term ‘cons…”
- McKown v. Dun & Bradstreet, Inc. (District Court, D. Kansas 1990, 744 F. Supp. 1046)“…purpose of preparing or furnishing consumer reports. K.S.A. 50-702(e); see 15 U.S.C. § 1681a(…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Kansas Statutes Annotated, Chapter 21: CRIMES AND PUNISHMENTS
§ 21-6107Identity theft; identity fraud.In forcecited in 3 of our articles
(a) Identity theft is obtaining, possessing, transferring, using, selling or purchasing any personal identifying information, or document containing the same, belonging to or issued to another person, with the intent to: (1) Defraud that person, or anyone else, in order to receive any benefit; or (2) misrepresent that person in order to subject that person to economic or bodily harm. (b) Identity fraud is: (1) Using or supplying information the person knows to be false in order to obtain a document containing any personal identifying information; or (2) altering, amending, counterfeiting, making, manufacturing or otherwise replicating any document containing personal identifying information with the intent to deceive; (c) (1) Identity theft is a: (A) Severity level 8, nonperson felony, except as provided in subsection (c)(1)(B); and (B) severity level 5, nonperson felony if the monetary loss to the victim or victims is more than $100,000. (2) Identity fraud is a severity level 8, nonperson felony.
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 10 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):State v. Valdiviezo-Martinez (2021) held an employee can commit identity theft under K.S.A. 21-6107 by deceiving an employer with another’s Social Security number to obtain employment and its benefits, that the offense is continuing, and that the statute is not unconstitutionally vague. Warsame (2025) applied those elements.
Opinions citing this section in our collection:
- State v. Valdiviezo-Martinez (Supreme Court of Kansas 2021, 486 P.3d 1256)✓A restaurant worker used another man's Social Security number on his W-4 and drew paychecks for years; the court held he obtained a benefit by deceiving his employer even though he earned the wages, called 21-6107 a continuing offense, and affirmed.
- In re Wrongful Conviction of Warsame (Supreme Court of Kansas 2025, 563 P.3d 1281)✓Warsame used stolen credit cards to buy gift cards, and his identity theft convictions were vacated for naming the wrong victim; the court held wrongful conviction compensation turns on the statutory elements of 21-6107, which he admitted meeting, so his claim failed.
- State v. Garcia (Supreme Court of Kansas 2017)✓Garcia used another person's Social Security number on tax forms when hired at a restaurant; the Kansas Supreme Court reversed his 21-6107 conviction as expressly preempted because that number also appeared on his federal I-9, a holding the U.S. Supreme Court reversed in 2020.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Identity Theft Laws: Federal Rules and State Penalties, Kansas Identity Theft Laws
§ 21-6101Breach of privacy.In forcecited in 26 of our articles
(a) Breach of privacy is knowingly and without lawful authority: (1) Intercepting, without the consent of the sender or receiver, a message by telephone, telegraph, letter or other means of private communication; (2) divulging, without the consent of the sender or receiver, the existence or contents of such message if such person knows that the message was illegally intercepted, or if such person illegally learned of the message in the course of employment with an agency in transmitting such message; (3) entering with intent to listen surreptitiously to private conversations in a private place or to observe the personal conduct of any other person or persons entitled to privacy therein; (4) installing or using outside or inside a private place any device for hearing, recording, amplifying or broadcasting sounds originating in such place, which sounds would not ordinarily be audible or comprehensible without the use of such device, without the consent of the person or persons entitled to privacy therein; (5) installing or using any device or equipment for the interception of any telephone, telegraph or other wire or wireless communication without the consent of the person in…
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 8 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Recent Kansas decisions construe the image-dissemination subsection, K.S.A. 21-6101(a)(8), not the interception subsections. State v. Ivy (2025) held a reasonable expectation of privacy under that subsection has a subjective and an objective component. State v. Jamil (2026), unpublished, found disseminating needs no jury definition.
Opinions citing this section in our collection:
- State v. Ivy (Court of Appeals of Kansas 2025)✓Ivy posted on Snapchat a sexual video his ex-girlfriend had recorded and texted him during their relationship; the court applied a subjective and objective two-part test and held a jury could find she kept a reasonable expectation of privacy, affirming the conviction.
- In re Belcher (Supreme Court of Kansas 2024, 552 P.3d 1213)“…deotape, photograph, film or image obtained in violation of K.S.A. 21-6101(a)(6) or (a)(8), and amendments…”
- State v. Jamil (Court of Appeals of Kansas 2026)✓Jamil secretly filmed a woman undressed and unconscious at his home, then sent the videos to her boyfriend; the court held that sharing with a single recipient can be disseminating under K.S.A. 21-6101(a)(8) and that intent to harass could be inferred from his conduct.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Kansas Audio Recording Laws, Kansas Dashcam Laws: Mounting Rules, Audio Recording, and Evidence (2026), Kansas Phone Call Recording Laws
Kansas Statutes Annotated, Chapter 72: SCHOOLS
§ 72-6312Student data privacy act; citation of act.In forcecited in 2 of our articles
K.S.A. 72-6312 through 72-6320, and amendments thereto, shall be known and may be cited as the student data privacy act.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Baker v. Blue Valley School Board (Court of Appeals of Kansas 2024)“…right of action under the Kansas Student Data Privacy Act, K.S.A. 72-6312 et seq. (KSDPA). On appeal, Ap…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 72-6311Right of privacy policies; definitions.In forcecited in 2 of our articles
(a) As used in this section, the following terms shall have the meanings respectively ascribed to them unless the context requires otherwise: (1) "Board" means the state board of regents, the state board of education, the board of trustees of any public community college, the board of regents of any municipal university, the governing board of any technical college and the board of education of any school district. (2) "Student" means a person who has attained 18 years of age, or is attending an institution of postsecondary education. (3) "Pupil" means a person who has not attained 18 years of age and is attending an educational institution below the postsecondary level. (b) Every board shall adopt a policy in accordance with the student data privacy act and applicable federal laws and regulations to protect the right of privacy of any student, or pupil and such pupil's family regarding personally identifiable records, files and data directly related to such student or pupil. The board shall adopt and implement procedures to effectuate such policy by January 1, 1977.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Kansas Statutes Annotated, Chapter 40: INSURANCE
§ 40-5901Vision care services act; prohibited contract provisions.In force
No contract issued or renewed on or after the effective date of this act between any insurer, health insurer or any other entity that writes vision care insurance or a vision care discount plan and a vision care provider shall contain any provisions which requires the vision care provider to: (a) Provide services or materials to an insured under such vision care insurance or health benefit plan or to a subscriber to a vision care discount plan at a fee limited or set by such vision care insurance plan or health benefit plan or vision care discount plan unless the services or materials are reimbursed as covered services under the contract; or (b) participate in a vision care insurance or a vision care discount plan as a condition to participate in any other health benefit plan or vision care plan, regardless of whether such vision care plan is a plan of insurance or a vision care discount program which is not an insurance plan.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Kansas Statutes Annotated, Chapter 9: BANKS AND BANKING; TRUST COMPANIES
§ 9-554Powers and duties of the commissioner; enforcement and review.In force
(a) The Kansas financial institutions information security act shall be implemented, administered and enforced by the commissioner. (b) (1) The commissioner may conduct: (A) Routine examinations of the operations of a covered entity; or (B) investigations of the operations of the covered entity if the commissioner has reason to believe that the covered entity has been engaged or is engaging in any conduct in violation of the Kansas financial institutions information security act.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Kansas Statutes Annotated, Chapter 65: PUBLIC HEALTH
§ 65-6821Kansas health information technology act.In force
K.S.A. 65-6821 through 65-6834 and 65-6835, and amendments thereto, shall be known and may be cited as the Kansas health information technology act.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
§ 65-6822Same; definitions.In force
As used in the Kansas health information technology act: (a) "Act" means the Kansas health information technology act. (b) "Approved health information organization" means a health information organization operating in the state under a valid certificate of authority issued by the department. (c) "Authorization" means a document that permits a covered entity to use or disclose protected health information for purposes other than to carry out treatment, payment or health care operations, and that complies with the requirements of 45 C.F.R. § 164.508. (d) "Covered entity" [means] a covered entity as the term is defined in 45 C.F.R. § 160.103. (e) "Department" means the Kansas department of health and environment. (f) "Disclosure" means disclosure as that term is defined by the HIPAA privacy rule. (g) "Health care" means health care as that term is defined by the HIPAA privacy rule. (h) "Health care provider" means a health care provider, as that term is defined by the HIPAA privacy rule. (i) "Health information" means health information as that term is defined by the HIPAA privacy rule.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
§ 65-6836Health care records; provision of copies; enforcement of act; costs; definitions.In forcecited in 2 of our articles
(a) As used in this section: (1) "Health care provider" means any person licensed by the state board of healing arts. (2) "Authorized representative" means the person designated in writing by the patient to obtain the health care records of the patient or the person otherwise authorized by law to obtain the health care records of the patient. (3) "Authorization" means a written or printed document signed by a patient or a patient's authorized representative containing: (A) A description of the health care records a health care provider is authorized to produce; (B) the patient's name, address and date of birth; (C) a designation of the person or entity authorized to obtain copies of the health care records; (D) a date or event upon which the force of the authorization shall expire which shall not exceed one year; (E) if signed by a patient's authorized representative, the authorized representative's name, address, telephone number and relationship or capacity to the patient; and (F) a statement setting forth the right of the person signing the authorization to revoke it in writing. (b) Subject to K.S.A.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Also relied on in: Kansas Medical Records Retention Laws (2026 Guide)
Kansas Statutes Annotated, Chapter 22: CRIMINAL PROCEDURE
§ 22-2518Same; civil action for damages; defense available in civil and criminal actions.In forcecited in 11 of our articles
(1) Any person whose wire, oral or electronic communication is intercepted, disclosed or used in violation of this act shall have a civil cause of action against any person who intercepts, discloses or uses, or procures any other person to intercept, disclose or use, such communications, and shall be entitled to recover from any such person: (a) Actual damages, but not less than liquidated damages computed at the rate of $100 a day for each day of violation or $1,000, whichever is greater; (b) punitive damages; and (c) reasonable attorneys' fees and other litigation costs reasonably incurred. (2) A good faith reliance by any person on a court order authorizing the interception of any wire, oral or electronic communication shall constitute a complete defense in any civil or criminal action brought against such person based upon such interception.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ksrevisor.gov
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- State v. Gibson (Supreme Court of Kansas 1994, 255 Kan. 474)“…f unlawfully intercepted *481 wire or oral communications. K.S.A. 22-2518 establishes a civil cause of action for…”
- Fields v. Atchison, Topeka, & Santa Fe Railway Co. (District Court, D. Kansas 1997, 985 F. Supp. 1308)“…18 U.S.C. § 2510 et seq., and the Kansas Wiretap Act, K.S.A. 22-2518, and invaded their privacy by intercept…”
- Banks v. Opat (District Court, D. Kansas 2021)“…ete defense against any civil action. 18 U.S.C. § 2520(d); K.S.A. § 22-2518(2). “To be in good faith, the officers’…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Kansas Landlord-Tenant Recording Laws, Kansas Security Camera Laws, Kansas Video Recording Laws
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- K.S.A. 50-7a01 - Consumer Information; Security Breach; Definitions(ksrevisor.gov).gov
- K.S.A. 50-7a02 - Security Breach; Requirements(ksrevisor.gov).gov
- K.S.A. 50-7a04 - Severability(ksrevisor.gov).gov
- K.S.A. 50-623 - Kansas Consumer Protection Act; Purpose(ksrevisor.gov).gov
- K.S.A. 50-636 - Kansas Consumer Protection Act; Civil Penalties(ksrevisor.gov).gov
- Kansas AG - Your Identity / Consumer Protection(ag.ks.gov).gov
- Kansas AG - Student Data Privacy(ag.ks.gov).gov
- K.S.A. 21-6107 - Identity Theft(ksrevisor.gov).gov
- K.S.A. 50-702 - Kansas Fair Credit Reporting Act(ksrevisor.gov).gov
- Kansas Financial Institutions Information Security Act - SB 44 Summary(kslegislature.gov).gov
- K.S.A. 65-6822 - Kansas Health Information Technology Act(ksrevisor.gov).gov
- K.S.A. 65-6836 - Health Care Records(ksrevisor.gov).gov
- K.S.A. 72-6312 - Student Data Privacy Act; Citation of Act(ksrevisor.gov).gov
- K.S.A. 9-554 - Financial Institutions Information Security(ksrevisor.gov).gov
- K.S.A. 21-6101 - Breach of Privacy (Wiretap/Recording)(ksrevisor.gov).gov
- TAKE IT DOWN Act (Pub. L. 119-12) - FTC(ftc.gov).gov
- FTC: TAKE IT DOWN Act Enforcement Starts Now (May 2026)(ftc.gov).gov
- HHS - HIPAA(hhs.gov).gov
- FTC - Gramm-Leach-Bliley Act(ftc.gov).gov
- FERPA(www2.ed.gov).gov
- FTC Act(ftc.gov).gov
- COPPA Rule(ftc.gov).gov
- FTC Safeguards Rule - 16 C.F.R. Section 314(ecfr.gov).gov
- Kansas Legislature(kslegislature.gov).gov
- K.S.A. 50-723 - Security Freeze on Consumer Report; Requirements; Procedure; Damages(ksrevisor.gov)
- K.S.A. 65-6821 - Citation of the Kansas Health Information Technology Act(ksrevisor.gov)