{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/kansas",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/kansas.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/kansas",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/kansas/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/kansas/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "kansas",
    "frontmatter": {
      "title": "Kansas Consumer Privacy Law",
      "description": "Kansas has no comprehensive consumer-privacy statute. The operative framework is the 2006 data-breach notification law (K.S.A. 50-7a01 and 50-7a02) plus the Kansas Consumer Protection Act, with a federal and sectoral overlay supplying the rest of a privacy program.",
      "state": "Kansas",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Kansas data-breach notification statute, K.S.A. 50-7a01 and 50-7a02, plus the Kansas Consumer Protection Act, K.S.A. 50-623 et seq. — Kansas has no comprehensive consumer-privacy law",
        "appliesTo": "The breach statute reaches any person that conducts business in Kansas and owns or licenses computerized personal information of Kansas residents; the KCPA reaches any supplier in consumer transactions — no revenue or consumer-volume thresholds",
        "privacyPolicyRequired": "No Kansas statute mandates a consumer privacy policy or fixes its contents; a policy that misstates actual practices is reachable as a deceptive act under the KCPA and FTC Act § 5, and GLBA, HIPAA, and COPPA supply notice duties where they apply",
        "privateRightOfAction": "The breach statute creates no express private remedy; the KCPA gives an aggrieved consumer an individual action for damages or a civil penalty, whichever is greater, with damages class actions sharply limited",
        "regulator": "Kansas Attorney General (the insurance commissioner has sole authority over breach violations by licensed insurers)",
        "bottomLine": "Kansas has not enacted a comprehensive consumer-privacy law, so there are no general data-rights, notice-at-collection, consent, or processor-contract duties under state law. The operative statutes are the 2006 data-breach notification law — a twice-gated, identity-theft-keyed notice duty with no fixed day-count — and the Kansas Consumer Protection Act, whose deception and unconscionability rules are what make a published privacy policy enforceable against the business that wrote it. Everything else rides the federal and sectoral overlay, so build to FTC Act § 5, GLBA, HIPAA, and COPPA and the program will be easier to adapt if Kansas later enacts an omnibus law.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Kansas consumer privacy law",
        "Kansas data breach notification K.S.A. 50-7a01",
        "Kansas Consumer Protection Act privacy",
        "Kansas no comprehensive privacy law",
        "Kansas privacy policy requirements",
        "Kansas vendor data processing contracts",
        "Kansas Attorney General privacy enforcement",
        "Kansas data breach private right of action",
        "Kansas Wayne Owen Act data security",
        "Kansas app store accountability act"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Kansas?",
        "heading": "Which privacy laws apply to your business in Kansas?",
        "answerText": "There is no comprehensive Kansas consumer-privacy law. The operative state framework is two-part: the 2006 data-breach notification statute, which applies to any person that conducts business in Kansas — or any government unit — that owns or licenses computerized data including personal information, and the Kansas Consumer Protection Act (KCPA), which is construed liberally to protect consumers from suppliers who commit deceptive and unconscionable practices. Neither statute carries a revenue or consumer-volume threshold.",
        "sources": [
          {
            "id": "stat-7a02-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02",
            "citation": "K.S.A. 50-7a02(a).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "The breach statute applies to any person that conducts business in Kansas, and to any government unit, that owns or licenses computerized data including personal information — with no revenue or volume threshold.",
            "verbatimQuote": "A person that conducts business in this state, or a government, governmental subdivision or agency that owns or licenses computerized data that includes personal information shall, when it becomes aware of any breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-scope"
          },
          {
            "id": "stat-623-purpose",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-623",
            "citation": "K.S.A. 50-623.",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0023.html",
            "proposition": "The Kansas Consumer Protection Act is construed liberally to protect consumers from suppliers who commit deceptive and unconscionable practices.",
            "verbatimQuote": "This act shall be construed liberally to promote the following policies: (a) To simplify, clarify and modernize the law governing consumer transactions; (b) to protect consumers from suppliers who commit deceptive and unconscionable practices;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-623-purpose"
          },
          {
            "id": "stat-624-consumer",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-624 (consumer)",
            "citation": "K.S.A. 50-624(b).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0024.html",
            "proposition": "A KCPA consumer includes an individual, husband and wife, sole proprietor, or family partnership acting for personal, family, household, business, or agricultural purposes — broader than most consumer-protection statutes.",
            "verbatimQuote": "\"Consumer\" means an individual, husband and wife, sole proprietor, or family partnership who seeks or acquires property or services for personal, family, household, business or agricultural purposes.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-624-consumer"
          },
          {
            "id": "stat-624-supplier",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-624 (supplier)",
            "citation": "K.S.A. 50-624(l).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0024.html",
            "proposition": "A KCPA supplier is anyone who, in the ordinary course of business, solicits, engages in, or enforces consumer transactions, whether or not dealing directly with the consumer.",
            "verbatimQuote": "\"Supplier\" means a manufacturer, distributor, dealer, seller, lessor, assignor, or other person who, in the ordinary course of business, solicits, engages in or enforces consumer transactions, whether or not dealing directly with the consumer.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-624-supplier"
          },
          {
            "id": "stat-624-transaction",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-624 (consumer transaction)",
            "citation": "K.S.A. 50-624(c).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0024.html",
            "proposition": "A KCPA consumer transaction is a disposition of property or services for value within Kansas, expressly excluding insurance contracts regulated under state law.",
            "verbatimQuote": "\"Consumer transaction\" means a sale, lease, assignment or other disposition for value of property or services within this state, except insurance contracts regulated under state law, to a consumer; or a solicitation by a supplier with respect to any of these dispositions.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-624-transaction"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Kansas privacy policy contain?",
        "heading": "What must your Kansas privacy policy contain?",
        "answerText": "No Kansas statute requires a general consumer privacy policy or fixes what it must say. The constraint that does the work is truthfulness. The KCPA forbids a supplier from engaging in any deceptive act or practice in connection with a consumer transaction, and its enumerated deceptive acts include the willful use of falsehood or ambiguity as to a material fact and the willful failure to state — or the willful concealment of — a material fact. A published privacy policy the business does not follow is the natural target of those rules, and the same conduct is independently a deceptive practice under Section 5 of the FTC Act.",
        "sources": [
          {
            "id": "stat-626-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-626",
            "citation": "K.S.A. 50-626(a).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0026.html",
            "proposition": "The KCPA prohibits a supplier from engaging in any deceptive act or practice in connection with a consumer transaction — the hook that makes a misleading privacy policy actionable.",
            "verbatimQuote": "No supplier shall engage in any deceptive act or practice in connection with a consumer transaction.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-626-deceptive"
          },
          {
            "id": "stat-626-omission",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-626(b)",
            "citation": "K.S.A. 50-626(b)(2)–(3).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0026.html",
            "proposition": "Enumerated deceptive acts include the willful use of falsehood or ambiguity as to a material fact and the willful failure to state or concealment of a material fact — the natural theories against a privacy policy that misstates or omits actual data practices.",
            "verbatimQuote": "(2) the willful use, in any oral or written representation, of exaggeration, falsehood, innuendo or ambiguity as to a material fact; (3) the willful failure to state a material fact, or the willful concealment, suppression or omission of a material fact;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-626-omission"
          },
          {
            "id": "stat-627-unconscionable",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-627",
            "citation": "K.S.A. 50-627(a).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0027.html",
            "proposition": "The KCPA separately prohibits unconscionable acts and practices, and the prohibition reaches conduct before, during, or after the consumer transaction.",
            "verbatimQuote": "No supplier shall engage in any unconscionable act or practice in connection with a consumer transaction. An unconscionable act or practice violates this act whether it occurs before, during or after the transaction.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-627-unconscionable"
          },
          {
            "id": "fed-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-fed-ftc5-deceptive"
          },
          {
            "id": "fed-glba-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA privacy notice",
            "citation": "15 U.S.C. § 6802(a).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6802",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6802#:~:text=Except%20as%20otherwise%20provided%20in,section%206803%20of%20this%20title.",
            "proposition": "A financial institution may not disclose nonpublic personal information to a nonaffiliated third party unless it has provided the consumer a privacy notice complying with the GLBA.",
            "verbatimQuote": "Except as otherwise provided in this subchapter, a financial institution may not, directly or through any affiliate, disclose to a nonaffiliated third party any nonpublic personal information, unless such financial institution provides or has provided to the consumer a notice that complies with section 6803 of this title.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-fed-glba-notice"
          },
          {
            "id": "fed-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520(a)(1).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-fed-hipaa-notice"
          },
          {
            "id": "fed-coppa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "COPPA",
            "citation": "15 U.S.C. § 6502(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6502",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6502#:~:text=It%20is%20unlawful%20for%20an,regulations%20prescribed%20under%20subsection%20(b).",
            "proposition": "An operator of a website or online service directed to children, or with actual knowledge it collects children's personal information, may not collect that information in violation of the COPPA notice and parental-consent regulations.",
            "verbatimQuote": "It is unlawful for an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child, to collect personal information from a child in a manner that violates the regulations prescribed under subsection (b).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-fed-coppa-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say?",
        "heading": "What must your contracts with vendors say?",
        "answerText": "Kansas imposes no general data-processing-agreement requirement — no state statute prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs for ordinary commercial contracts. The one Kansas vendor duty is breach-notice flow-up: an entity that maintains computerized personal information it does not own or license must notify the owner or licensee of the information after discovering a breach, if the personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person.",
        "sources": [
          {
            "id": "stat-7a02-vendor-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(b)",
            "citation": "K.S.A. 50-7a02(b).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "A vendor that maintains computerized personal information it does not own or license must notify the owner or licensee of the information after discovering a breach involving unauthorized access and acquisition.",
            "verbatimQuote": "An individual or a commercial entity that maintains computerized data that includes personal information that the individual or the commercial entity does not own or license shall give notice to the owner or licensee of the information of any breach of the security of the data following discovery of a breach, if the personal information was, or is reasonably believed to have been, accessed and acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-vendor-notice"
          },
          {
            "id": "fed-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Oversee%20service%20providers%2C%20by%3A%20(1),continued%20adequacy%20of%20their%20safeguards.",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers — selecting capable providers, requiring safeguards by contract, and periodically assessing them.",
            "verbatimQuote": "Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-fed-glba-safeguards"
          },
          {
            "id": "fed-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,information%20by%20the%20business%20associate.",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted and required uses and disclosures of protected health information by the business associate.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-fed-hipaa-baa"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Kansas?",
        "heading": "When must you notify people of a data breach in Kansas?",
        "answerText": "After a two-step determination, and then quickly but with no fixed day-count. When a business becomes aware of a security breach it must conduct a good-faith, reasonable, and prompt investigation into the likelihood that personal information has been or will be misused; if the investigation determines that misuse has occurred or is reasonably likely to occur, it must notify the affected Kansas residents as soon as possible, in the most expedient time possible and without unreasonable delay. The duty is also gated at the definition: a security breach means the unauthorized access and acquisition of unencrypted or unredacted computerized data that compromises personal information and that causes — or that the business reasonably believes has caused or will cause — identity theft to a Kansas consumer. If notice goes to more than 1,000 consumers at one time, the business must also notify the nationwide consumer reporting agencies without unreasonable delay.",
        "sources": [
          {
            "id": "stat-7a02-notice-trigger",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(a)",
            "citation": "K.S.A. 50-7a02(a).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "If the post-breach investigation determines that misuse of personal information has occurred or is reasonably likely, the business must notify affected Kansas residents as soon as possible, in the most expedient time possible and without unreasonable delay — with no fixed day-count.",
            "verbatimQuote": "If the investigation determines that the misuse of information has occurred or is reasonably likely to occur, the person or government, governmental subdivision or agency shall give notice as soon as possible to the affected Kansas resident. Notice must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-notice-trigger"
          },
          {
            "id": "stat-7a01-breach-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a01(h)",
            "citation": "K.S.A. 50-7a01(h).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0001.html",
            "proposition": "A security breach requires unauthorized access and acquisition of unencrypted or unredacted computerized data that compromises personal information and causes, or is reasonably believed to have caused or will cause, identity theft to a Kansas consumer.",
            "verbatimQuote": "\"Security breach\" means the unauthorized access and acquisition of unencrypted or unredacted computerized data that compromises the security, confidentiality or integrity of personal information maintained by an individual or a commercial entity and that causes, or such individual or entity reasonably believes has caused or will cause, identity theft to any consumer.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a01-breach-def"
          },
          {
            "id": "stat-7a01-pi-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a01(g)",
            "citation": "K.S.A. 50-7a01(g).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0001.html",
            "proposition": "Personal information is a consumer's name linked to an unencrypted, unredacted Social Security number, driver's license or state ID number, or financial-account or card number with any code permitting account access.",
            "verbatimQuote": "\"Personal information\" means a consumer's first name or first initial and last name linked to any one or more of the following data elements that relate to the consumer, when the data elements are neither encrypted nor redacted: (1) Social security number; (2) driver's license number or state identification card number; or (3) financial account number, or credit or debit card number, alone or in combination with any required security code, access code or password that would permit access to a consumer's financial account.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a01-pi-def"
          },
          {
            "id": "stat-7a02-cra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(f)",
            "citation": "K.S.A. 50-7a02(f).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "When more than 1,000 consumers must be notified at one time, the business must also notify the nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution, and content of the notices.",
            "verbatimQuote": "In the event that a person discovers circumstances requiring notification pursuant to this section of more than 1,000 consumers at one time, the person shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined by 15 U.S.C. § 1681a(p), of the timing, distribution and content of the notices.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-cra"
          },
          {
            "id": "stat-7a01-substitute",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a01(c)",
            "citation": "K.S.A. 50-7a01(c)(3).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0001.html",
            "proposition": "Substitute notice is permitted where the cost of notice would exceed $100,000, the affected class exceeds 5,000 consumers, or the business lacks sufficient contact information.",
            "verbatimQuote": "substitute notice, if the individual or the commercial entity required to provide notice demonstrates that the cost of providing notice will exceed $100,000, or that the affected class of consumers to be notified exceeds 5,000, or that the individual or the commercial entity does not have sufficient contact information to provide notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a01-substitute"
          },
          {
            "id": "stat-7a01-substitute-methods",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a01(e)",
            "citation": "K.S.A. 50-7a01(e).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0001.html",
            "proposition": "Substitute notice means email notice where email addresses are available, conspicuous website posting where the business maintains a website, and notification to major statewide media.",
            "verbatimQuote": "\"Substitute notice\" means: (1) E-mail notice if the individual or the commercial entity has e-mail addresses for the affected class of consumers; (2) conspicuous posting of the notice on the web site page of the individual or the commercial entity if the individual or the commercial entity maintains a web site; and (3) notification to major statewide media.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a01-substitute-methods"
          },
          {
            "id": "stat-7a02-law-delay",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(c)",
            "citation": "K.S.A. 50-7a02(c).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "Breach notice may be delayed if a law-enforcement agency determines that notice will impede a criminal investigation.",
            "verbatimQuote": "Notice required by this section may be delayed if a law enforcement agency determines that the notice will impede a criminal investigation. Notice required by this section shall be made in good faith, without unreasonable delay and as soon as possible after the law enforcement agency determines that notification will no longer impede the investigation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-law-delay"
          },
          {
            "id": "stat-7a02-safe-harbors",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(d)–(e)",
            "citation": "K.S.A. 50-7a02(d)–(e).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "A business that follows its own consistent breach-notification procedures, or the breach procedures established by its primary or functional state or federal regulator, is deemed to comply with the notice requirements.",
            "verbatimQuote": "Notwithstanding any other provision in this section, an individual or a commercial entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and whose procedures are otherwise consistent with the timing requirements of this section, is deemed to be in compliance with the notice requirements of this section if the individual or the commercial entity notifies affected consumers in accordance with its policies in the event of a breach of security of the system. (e) An individual or a commercial entity that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-safe-harbors"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in Kansas over privacy?",
        "heading": "Can a consumer sue your business in Kansas over privacy?",
        "answerText": "It depends on the statute. The breach-notification law creates no express private remedy — it empowers the Attorney General to bring an action in law or equity, while providing that the section is not exclusive and does not relieve a business from complying with all other applicable law. The KCPA, by contrast, carries a real private right of action: an aggrieved consumer may recover, in an individual action but not in a class action, damages or a civil penalty, whichever is greater.",
        "sources": [
          {
            "id": "stat-7a02-ag-action",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(g)",
            "citation": "K.S.A. 50-7a02(g).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "The breach statute names the Attorney General as enforcer (in law or equity) and creates no express private remedy, while providing that the section is not exclusive of other applicable law.",
            "verbatimQuote": "For violations of this section, except as to insurance companies licensed to do business in this state, the attorney general is empowered to bring an action in law or equity to address violations of this section and for other relief that may be appropriate. The provisions of this section are not exclusive and do not relieve an individual or a commercial entity subject to this section from compliance with all other applicable provisions of law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-ag-action"
          },
          {
            "id": "stat-634-individual",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-634(b)",
            "citation": "K.S.A. 50-634(b).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0034.html",
            "proposition": "An aggrieved consumer may recover, in an individual action but not a class action, damages or a civil penalty, whichever is greater.",
            "verbatimQuote": "A consumer who is aggrieved by a violation of this act may recover, but not in a class action, damages or a civil penalty as provided in subsection (a) of K.S.A. 50-636 and amendments thereto, whichever is greater.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-634-individual"
          },
          {
            "id": "stat-634-class-injunctive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-634(c)",
            "citation": "K.S.A. 50-634(c).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0034.html",
            "proposition": "Consumers may bring a class action for declaratory judgment, an injunction, and appropriate ancillary relief — but not damages — against an act or practice that violates the KCPA.",
            "verbatimQuote": "Whether a consumer seeks or is entitled to recover damages or has an adequate remedy at law, a consumer may bring a class action for declaratory judgment, an injunction and appropriate ancillary relief, except damages, against an act or practice that violates this act.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-634-class-injunctive"
          },
          {
            "id": "stat-634-class-damages",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-634(d)",
            "citation": "K.S.A. 50-634(d).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0034.html",
            "proposition": "A damages class action is available only for acts or practices specifically proscribed by the deceptive-acts, unconscionable-acts, or door-to-door provisions, declared unlawful by a prior published final judgment, or prohibited by a prior consent judgment.",
            "verbatimQuote": "A consumer who suffers loss as a result of a violation of this act may bring a class action for the damages caused by an act or practice: (1) Violating any of the acts or practices specifically proscribed in K.S.A. 50-626, 50-627 and 50-640, and amendments thereto, or (2) declared to violate K.S.A. 50-626 or 50-627, and amendments thereto, by a final judgment of any district court or the supreme court of this state that was either officially reported or made available for public dissemination under subsection (a)(3) of K.S.A. 50-630 and amendments thereto by the attorney general 10 days before the consumer transactions on which the action is based, or (3) with respect to a supplier who agreed to it, was prohibited specifically by the terms of a consent judgment which became final before the consumer transactions on which the action is based.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-634-class-damages"
          },
          {
            "id": "q5-stat-624-transaction",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-624 (consumer transaction)",
            "citation": "K.S.A. 50-624(c).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0024.html",
            "proposition": "A KCPA consumer transaction is a disposition of property or services for value within Kansas, expressly excluding insurance contracts regulated under state law.",
            "verbatimQuote": "\"Consumer transaction\" means a sale, lease, assignment or other disposition for value of property or services within this state, except insurance contracts regulated under state law, to a consumer; or a solicitation by a supplier with respect to any of these dispositions.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-q5-stat-624-transaction"
          }
        ]
      },
      {
        "slug": "enforcement-penalties",
        "label": "Who enforces Kansas privacy law, and what are the penalties?",
        "heading": "Who enforces Kansas privacy law, and what are the penalties?",
        "answerText": "The Kansas Attorney General, with one carve-out: for breach-notification violations by an insurance company licensed in Kansas, the insurance commissioner has the sole enforcement authority. Under the KCPA, any violation exposes the business to a civil penalty of up to $10,000 per violation, recoverable by the aggrieved consumer, the Attorney General, or a county or district attorney — and a continuing practice not tied to a specific transaction counts as a separate violation each day it exists.",
        "sources": [
          {
            "id": "stat-7a02-enforcement-split",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-7a02(g)–(h)",
            "citation": "K.S.A. 50-7a02(g)–(h).",
            "url": "https://www.ksrevisor.gov/statutes/chapters/ch50/050_007a_0002.html",
            "proposition": "Breach-statute enforcement belongs to the Attorney General, except that the insurance commissioner has sole authority over violations by insurance companies licensed in Kansas.",
            "verbatimQuote": "For violations of this section, except as to insurance companies licensed to do business in this state, the attorney general is empowered to bring an action in law or equity to address violations of this section and for other relief that may be appropriate. The provisions of this section are not exclusive and do not relieve an individual or a commercial entity subject to this section from compliance with all other applicable provisions of law. (h) For violations of this section by an insurance company licensed to do business in this state, the insurance commissioner shall have the sole authority to enforce the provisions of this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-7a02-enforcement-split"
          },
          {
            "id": "stat-636-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-636(a)",
            "citation": "K.S.A. 50-636(a).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0036.html",
            "proposition": "Any KCPA violation renders the violator liable for a civil penalty of up to $10,000 per violation, recoverable in an individual action including one brought by the Attorney General or a county or district attorney.",
            "verbatimQuote": "The commission of any act or practice declared to be a violation of this act shall render the violator liable to the aggrieved consumer, or the state or a county as provided in subsection (c), for the payment of a civil penalty, recoverable in an individual action, including an action brought by the attorney general or county attorney or district attorney, in a sum set by the court of not more than $10,000 for each violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-636-penalty"
          },
          {
            "id": "stat-636-willful",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-636(b)",
            "citation": "K.S.A. 50-636(b).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0036.html",
            "proposition": "A supplier that willfully violates a court order issued under the KCPA forfeits a civil penalty of up to $20,000 per violation, in addition to other penalties.",
            "verbatimQuote": "Any supplier who willfully violates the terms of any court order issued pursuant to this act shall forfeit and pay a civil penalty of not more than $20,000 per violation, in addition to other penalties that may be imposed by the court, as the court shall deem necessary and proper.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-636-willful"
          },
          {
            "id": "stat-636-daily",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "K.S.A. 50-636(d)",
            "citation": "K.S.A. 50-636(d).",
            "url": "https://ksrevisor.gov/statutes/chapters/ch50/050_006_0036.html",
            "proposition": "A continuing violation not tied to a specific identifiable consumer transaction is deemed a separate violation for each day the act or practice exists.",
            "verbatimQuote": "Any act or practice declared to be a violation of this act not identified to be in connection with a specific identifiable consumer transaction but which is continuing in nature shall be deemed a separate violation each day such act or practice exists.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/kansas#src-stat-636-daily"
          }
        ]
      }
    ]
  }
}
