EnglishEspañol
Kansas flag

Kansas

Kansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 24 primary sources cited on this page. How we verify our legal content

Kansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does Kansas have a comprehensive data privacy law?

No. Kansas does not have a comprehensive consumer data privacy law similar to the California Consumer Privacy Act or the Texas Data Privacy and Security Act. As of May 2026, the Kansas legislature has not passed broad consumer privacy legislation. Kansas relies on a patchwork of targeted statutes covering data breach notification, consumer protection, student data privacy, insurance data security, and financial institution security. Federal laws including HIPAA, GLBA, COPPA, and the FTC Act fill additional gaps.

What are my rights if a company experiences a data breach involving my information in Kansas?

Under the Protection of Consumer Information Act (K.S.A. 50-7a02), any business or government entity that conducts business in Kansas must notify you without unreasonable delay if a security breach has compromised your personal information and misuse has occurred or is reasonably likely to occur. Personal information includes your name linked to your Social Security number, driver's license number, or financial account numbers. You also have the right to place a free security freeze on your credit reports.

Can I sue a company in Kansas for a data breach?

Kansas's breach notification law does not provide a private right of action. You cannot sue a company directly under K.S.A. 50-7a01 through 50-7a04 for failing to notify you of a breach. Enforcement is handled by the Kansas Attorney General or the Insurance Commissioner for insurance companies. However, you may have claims under the Kansas Consumer Protection Act if a company engaged in deceptive practices related to your data, and you may have common-law claims depending on the circumstances.

How does Kansas protect student data privacy?

The Kansas Student Data Privacy Act (K.S.A. 72-6312 through 72-6320) prohibits unauthorized disclosure of student data, unauthorized collection of biometric data from students, and unauthorized use of devices to assess a student's psychological or emotional state. The Attorney General and district attorneys can enforce the Act. Parents and students can file complaints with the Attorney General's office if they believe a school or educational technology vendor has violated these protections.

What penalties do businesses face for violating Kansas data privacy laws?

Penalties depend on which statute is violated. Under the Kansas Consumer Protection Act (K.S.A. 50-636), the Attorney General may seek civil penalties up to $10,000 per violation, with willful court-order violations subject to up to $20,000 per violation. Under the Financial Institutions Information Security Act, the State Bank Commissioner can assess fines up to $5,000 per violation. Identity theft is a felony with presumptive sentences up to 136 months depending on monetary loss. The Attorney General can also seek injunctive relief and restitution under multiple statutes.

Does the TAKE IT DOWN Act apply in Kansas?

Yes. The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that applies in all states including Kansas. It criminalizes the publication of nonconsensual intimate visual depictions, including AI-generated deepfake images. Covered online platforms were required to implement notice-and-removal processes by May 19, 2026, and must remove flagged images within 48 hours. The FTC enforces the platform obligations and may impose civil penalties up to $53,088 per violation.

Is Kansas a one-party consent state for recording?

Yes. Kansas is a one-party consent state under K.S.A. 21-6101. Recording a phone call or in-person conversation is lawful as long as one party to the conversation consents, and that party can be you. Secretly recording a conversation in which you are not a participant is unlawful. Penalties for illegal interception include up to one year in jail and fines, plus civil liability under K.S.A. 22-2518. For full details, see the Kansas Recording Laws page.

Does the Kansas Insurance Data Security Act affect policyholders?

Kansas has not enacted an Insurance Data Security Act modeled on the NAIC's model law. K.S.A. 40-5901, which is sometimes cited for this claim, actually covers vision care insurance contracts. Kansas-licensed insurers are instead subject to the state's general data breach notification law, the Protection of Consumer Information Act. If a breach affects your insurance data, the insurer must notify you under K.S.A. 50-7a02, and the Kansas Insurance Commissioner has sole authority to enforce that law against insurers, rather than the Attorney General.

Updates

Corrected the Kansas Health Information Technology Act's statutory range to K.S.A. 65-6821 through 65-6835, clarified that the 30-day medical records copy rule in K.S.A. 65-6836 is a separate provision outside that Act, and grounded the credit freeze section in K.S.A. 50-723, the operative security freeze statute, rather than the definitions section.

Corrected the name and citation of the Wayne Owen Act (it is K.S.A. 50-6,139, a separate Kansas Consumer Protection Act provision, not the data breach notification statute), fixed the citation for the identity-theft-as-unconscionable-act rule (K.S.A. 50-6,139, not 50-6,139b), corrected the Student Data Privacy Act's statutory range (K.S.A. 72-6312 through 72-6320, not 72-6311), and fixed the year and target of a cited Kansas AG social-media enforcement action (Snap Inc./Snapchat, September 2025).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the identity theft criminal penalty table (K.S.A. 21-6107 sets only two severity tiers, not four) and removed the fabricated Kansas Insurance Data Security Act, which does not exist under Kansas law (K.S.A. 40-5901 is the vision care insurance contract statute; NAIC's own model-law tracker lists Kansas as having no current activity adopting the Insurance Data Security Model Law).

Updated a stale May 2026 changelog entry that still described a 'Kansas Insurance Data Security Act' section as if it were a real statute, contradicting the corrected article body, which explains Kansas has not enacted that act.

Governing law re-checked for recent changes

May 2026 refresh: Added an insurance section describing a purported Kansas Insurance Data Security Act citing K.S.A. 40-5901 et seq.; a later review found Kansas has not enacted such an act and that K.S.A. 40-5901 actually governs vision care insurance contracts, so that section was corrected on 2026-08-07. Corrected KCPA civil penalty figure from $500-$1,000 per violation to the accurate up to $10,000 per violation under K.S.A. 50-636 for AG enforcement actions. Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) to federal overlay section with FTC enforcement status effective May 19, 2026. Added AG Kobach enforcement context (2023-2026 KCPA enforcement, $180M+ in recoveries, social media and AI company actions). Updated legislative outlook to reflect no comprehensive privacy bill passed in 2025 or 2026 sessions; SB 372 (app store bill) passed Senate but did not advance in House. Added two new FAQ entries on TAKE IT DOWN Act applicability and one-party consent recording law. Added K.S.A. 21-6101 (wiretap/recording) and K.S.A. 50-636 (civil penalties) to SourcesList.

Reviewed and approved by an editor

Sources and References

  1. K.S.A. 50-7a01 - Consumer Information; Security Breach; Definitions(ksrevisor.gov).gov
  2. K.S.A. 50-7a02 - Security Breach; Requirements(ksrevisor.gov).gov
  3. K.S.A. 50-7a04 - Severability(ksrevisor.gov).gov
  4. K.S.A. 50-623 - Kansas Consumer Protection Act; Purpose(ksrevisor.gov).gov
  5. K.S.A. 50-636 - Kansas Consumer Protection Act; Civil Penalties(ksrevisor.gov).gov
  6. Kansas AG - Your Identity / Consumer Protection(ag.ks.gov).gov
  7. Kansas AG - Student Data Privacy(ag.ks.gov).gov
  8. K.S.A. 21-6107 - Identity Theft(ksrevisor.gov).gov
  9. K.S.A. 50-702 - Kansas Fair Credit Reporting Act(ksrevisor.gov).gov
  10. Kansas Financial Institutions Information Security Act - SB 44 Summary(kslegislature.gov).gov
  11. K.S.A. 65-6822 - Kansas Health Information Technology Act(ksrevisor.gov).gov
  12. K.S.A. 65-6836 - Health Care Records(ksrevisor.gov).gov
  13. K.S.A. 72-6312 - Student Data Privacy Act; Citation of Act(ksrevisor.gov).gov
  14. K.S.A. 9-554 - Financial Institutions Information Security(ksrevisor.gov).gov
  15. K.S.A. 21-6101 - Breach of Privacy (Wiretap/Recording)(ksrevisor.gov).gov
  16. TAKE IT DOWN Act (Pub. L. 119-12) - FTC(ftc.gov).gov
  17. FTC: TAKE IT DOWN Act Enforcement Starts Now (May 2026)(ftc.gov).gov
  18. HHS - HIPAA(hhs.gov).gov
  19. FTC - Gramm-Leach-Bliley Act(ftc.gov).gov
  20. FERPA(www2.ed.gov).gov
  21. FTC Act(ftc.gov).gov
  22. COPPA Rule(ftc.gov).gov
  23. FTC Safeguards Rule - 16 C.F.R. Section 314(ecfr.gov).gov
  24. Kansas Legislature(kslegislature.gov).gov
  25. K.S.A. 50-723 - Security Freeze on Consumer Report; Requirements; Procedure; Damages(ksrevisor.gov)
  26. K.S.A. 65-6821 - Citation of the Kansas Health Information Technology Act(ksrevisor.gov)
Share: