Kansas Privacy Law
Kansas has not enacted a comprehensive consumer privacy law. What Kansas does have is a breach-notification statute with an unusual split enforcement clause, a consumer-protection act that lets the injured consumer sue for the same civil penalty the Attorney General would seek, and a pair of student-data provisions that reach beyond record disclosure into the surveys schools may administer at all.
Sector-Specific Privacy Laws in Kansas
Kansas Consumer Protection Act (K.S.A. 50-623 et seq.)
K.S.A. 50-626(a) forbids a supplier to engage in any deceptive act or practice in connection with a consumer transaction, and subsection (b) lists specific practices that violate the Act “whether or not any consumer has in fact been misled.” The penalty provision is unusual in who may invoke it: K.S.A. 50-636(a) makes a violation render the violator liable for a civil penalty of up to $10,000 per violation “recoverable in an individual action,” including one brought by the Attorney General, a county attorney or a district attorney, and states that an aggrieved consumer is not a required party to a government action. Subsection (b) raises the penalty to $20,000 per violation for willfully violating a court order issued under the Act, and subsection (d) treats a continuing practice not tied to an identifiable transaction as a separate violation each day it exists.
Student data disclosure — K.S.A. 72-6314
K.S.A. 72-6314 restricts how an educational agency may disclose student data held in the statewide longitudinal student data system and requires annual written notice to each student’s parent or legal guardian, signed by the parent and kept on file with the district. Disclosure to authorized personnel of an educational agency, of the state board of regents, and to the student and parent is permitted at any time. Disclosure to other state agencies or to a service provider engaged for instruction, assessment or longitudinal reporting requires a data-sharing agreement that states the purpose, scope and duration of the agreement and limits the recipient to the specified purposes.
Nonacademic surveys of students — K.S.A. 72-6316
K.S.A. 72-6316 bars administering to a K–12 student, during the school day, any nonacademic test, questionnaire, survey or examination containing questions about the personal and private attitudes, values, beliefs or practices of the student or the student’s family, friends or peers, unless the parent was notified in writing no more than four months in advance and gave separate written consent for each instrument. The notice must include a copy of the instrument, the name of the company or entity providing it, and whether the school will receive or maintain the resulting data and how it intends to use it. Subsection (b) gives the student a right to refuse at any time without adverse consequences.
Data Breach Notification in Kansas
K.S.A. 50-7a02(a) requires a person conducting business in Kansas, or a government body, that owns or licenses computerized data containing personal information to conduct a good-faith, reasonable and prompt investigation on becoming aware of a breach, and to notify affected Kansas residents only if that investigation determines misuse has occurred or is reasonably likely to occur. K.S.A. 50-7a01(c)(3) sets the substitute-notice thresholds at a notice cost exceeding $100,000 or an affected class exceeding 5,000 consumers, and subsection (d) defines redaction as leaving no more than five digits of a Social Security number or the last four digits of a driver’s licence, state identification card or account number. Subsection (f) of § 50-7a02 adds notice to the nationwide consumer reporting agencies where more than 1,000 consumers are notified at one time. Enforcement is split: under subsection (g) the Attorney General may bring an action in law or equity for violations, but subsection (h) gives the Insurance Commissioner sole authority over insurance companies licensed to do business in Kansas. Subsections (d) and (e) deem an entity in compliance where it follows its own consistent notice procedures or the procedures set by its primary or functional state or federal regulator.
Residents must be notified as soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely. No Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 consumers are notified at one time. Complaints are taken by the Kansas Attorney General, which enforces the statute.
Pending Privacy Legislation
Senate Bill 234 of the 2025 session, referred from the Committee on Federal and State Affairs, would prohibit medical and research facilities that receive state money from using genetic sequencers or genetic-analysis software produced in or by a foreign adversary, a term the bill defines by naming seven states and allowing the Governor, in consultation with the adjutant general, to designate others. The Legislature’s subject index for the 2025–26 biennium lists Senate Bill 205 and House Bills 2183, 2479 and 2518 under “breach of privacy,” the criminal offence rather than data-security regulation. No comprehensive consumer-privacy statute has been enacted in Kansas.
Federal Privacy Laws That Apply in Kansas
Federal privacy law applies in Kansas by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Kansas Consumer Protection Act (K.S.A. 50-623 et seq.), which the Kansas Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Kansas Businesses
With no comprehensive state statute, most privacy obligations on a Kansas business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Kansas businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Kansas itself has none, and any business holding personal information about Kansas residents is subject to the state’s breach-notification statute described above.
Kansas Privacy Law FAQ
Does Kansas require notice to the Attorney General after a data breach?
Who enforces the Kansas breach-notification law against an insurance company?
Can a Kansas consumer recover the civil penalty under the Consumer Protection Act?
What counts as personal information under the Kansas breach statute?
When may a Kansas entity use substitute notice instead of contacting people directly?
Do Kansas schools need parental consent before surveying students about their beliefs?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- K.S.A. 50-7a01 — Consumer information; security breach; definitions statute
- K.S.A. 50-7a02 — Security breach; requirements statute
- K.S.A. 50-626 — Deceptive acts and practices statute
- K.S.A. 50-636 — Civil penalties statute
- K.S.A. 72-6314 — Disclosure of student data statute
- K.S.A. 72-6316 — Nonacademic tests, questionnaires and surveys statute
- Senate Bill 234 (2025) — Genetic sequencers produced by a foreign adversary legislation
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.