{
 "jurisdiction_id": "US-KS",
 "jurisdiction": "United States – Kansas",
 "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 31,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "red",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No comprehensive DPA-style regulator or omnibus statute exists; oversight is fragmented across the state AG's general consumer-protection authority and federal sectoral law.",
   "claims": [
    {
     "statement": "The Kansas Attorney General's Consumer Protection Division is the designated point of contact for Kansas residents regarding data breach notifications and general consumer-protection enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Attorney General breach filing repository",
     "source_url": "https://oag.ca.gov/system/files/BRG%20Notice%20Letter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC Act Section 5 prohibition on unfair or deceptive acts or practices constitutes a general federal privacy-and-security enforcement baseline applicable nationally, including to entities operating in Kansas.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kansas has no comprehensive consumer-privacy statute equivalent to GDPR or CCPA; data-protection matters are addressed only through federal sectoral law and the state's general consumer-protection and breach-notification statutes.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) defines covered 'personal information' narrowly around identity-theft/financial-fraud data elements, and, per industry analysis, does not require a credit card number to be connected to a consumer's name to trigger notification, unlike most other states' breach laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/examining-the-presidents-proposed-national-data-breach-notification-standard-against-existing-legislation",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Kansas breach-notification statute's territorial reach (i.e., whether it applies to any entity holding computerized personal information of Kansas residents regardless of the entity's own location) follows the common US state pattern of resident-based applicability, but exact statutory wording was not verified against the primary Kansas statute text in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/%C2%A750-7a01-et-seq-article-7a-chapter-50-kansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kansas imposes no general controller or processor registration/filing requirement with any state authority for personal-data processing activities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Absence of any state lawful-basis, consent, or special-category regime outside narrow federal sectoral overlays.",
   "claims": [
    {
     "statement": "Kansas has no state statute enumerating lawful bases for the processing of personal data equivalent to GDPR Article 6.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No general Kansas consent-threshold statute governs commercial data collection outside of the federal COPPA parental-consent regime for children under 13.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/usa-data-protection-education-sector-part-one",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kansas has no state-level special/sensitive-category data statute; sensitive data protections apply only through federal sectoral overlays such as HIPAA for health data and GLBA for financial data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No comprehensive data-subject-rights framework exists in Kansas; only breach notification rights apply.",
   "claims": [
    {
     "statement": "Kansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data held by private-sector businesses.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Kansas breach-notification statute requires notice to affected individuals following discovery of a breach, consistent with the general US state pattern of a 'without unreasonable delay' standard, though the exact numeric deadline was not independently confirmed against primary statutory text in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "National Association of Attorneys General",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "red",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "No omnibus controller/processor obligations exist in Kansas outside breach notification and narrow federal sectoral overlays.",
   "claims": [
    {
     "statement": "Kansas imposes no statutory accountability principle, DPIA trigger, DPO appointment threshold, ROPA obligation, or joint-controller framework applicable to private-sector data processing generally.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Insurance entities and financial institutions operating in Kansas remain subject to the federal Gramm-Leach-Bliley Act's affirmative obligation to protect the security and confidentiality of customers' non-public personal information, absent a confirmed Kansas-specific insurance data-security statute mirroring the NAIC Insurance Data Security Model Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/new-cybersecurity-regulatory-guidance-for-the-insurance-industry",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) requires entities that own or license computerized data including personal information to notify affected Kansas residents following a security breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Association of Attorneys General",
     "source_url": "https://www.naag.org/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Cross-border transfer governance is not a state-level competency in the US federal system; no Kansas-specific mechanism exists.",
   "claims": [
    {
     "statement": "Kansas has no state-specific cross-border data-transfer mechanism; Kansas-based entities engaged in international data flows rely on federal or counterpart-jurisdiction mechanisms such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Adequacy decisions are federal/international-level determinations; Kansas as a US state neither receives nor grants adequacy status independently.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kansas imposes no data-localisation requirement, partial or absolute, on personal data processing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sector coverage exists but only via federal law; no state-specific sectoral overlay confirmed.",
   "claims": [
    {
     "statement": "Financial institutions operating in Kansas are subject to the federal Gramm-Leach-Bliley Act's privacy and safeguards requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/new-cybersecurity-regulatory-guidance-for-the-insurance-industry",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Covered entities and business associates in Kansas are subject to the federal HIPAA Privacy and Security Rules; no additional comprehensive Kansas-specific health-privacy statute was confirmed in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/usa-data-protection-education-sector-part-one",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Credit-scoring and consumer-report data involving Kansas residents is governed by the federal Fair Credit Reporting Act; no Kansas-specific credit-scoring statute was identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Student data in Kansas is governed by the federal FERPA, COPPA, and PPRA frameworks; no dedicated Kansas student-data-privacy statute analogous to California's Student Online Personal Information Protection Act was confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/usa-data-protection-education-sector-part-one",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No state adtech/commercial-privacy regime exists; only generic federal deception and marketing-communications law applies.",
   "claims": [
    {
     "statement": "Kansas has no cookie/tracker consent regime, dark-pattern prohibition, mandated opt-out-signal recognition, or cross-context-advertising 'sale'/'share' framework of the kind found in states with comprehensive privacy laws.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Direct-marketing communications targeting Kansas residents remain subject to federal telemarketing (TCPA) and email (CAN-SPAM) suppression rules in the absence of a Kansas-specific direct-marketing consent statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No state algorithmic, biometric, or AI-governance statute exists in Kansas.",
   "claims": [
    {
     "statement": "Kansas has enacted no profiling-restriction, automated-decision-making transparency, or AI-specific risk-assessment statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Among US states, only Illinois, Texas, and Washington have enacted biometric-specific privacy legislation; Kansas has no dedicated biometric-data statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/how-should-we-regulate-facial-recognition-technology",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Federal COPPA/FERPA provide baseline child protections; no Kansas-specific enhancement exists.",
   "claims": [
    {
     "statement": "Children's online personal information collected from Kansas residents under age 13 is governed by the federal COPPA parental-consent requirement; Kansas has no additional state-level age-of-consent or parental-consent statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/usa-data-protection-education-sector-part-one",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Kansas has no statutory ban on profiling or targeted advertising directed at minors, unlike several states with comprehensive privacy laws.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-kansas/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement exists but is narrow (AG consumer-protection powers plus federal FTC authority); no dedicated privacy regulator or comprehensive penalty regime.",
   "claims": [
    {
     "statement": "The Kansas Attorney General has authority under the Kansas Consumer Protection Act to bring enforcement actions for deceptive or unconscionable acts, including privacy-related misrepresentations, and can enforce the breach-notification statute; the FTC retains concurrent federal Section 5 authority over the same conduct.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/kansas-consumer-protection-act-%C2%A750-623-et-seq",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Recent US state privacy-enforcement activity has concentrated in states with comprehensive privacy statutes (e.g., California, Colorado, Oregon, Texas); no comparable Kansas-specific privacy enforcement action was confirmed in this research pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "US state breach-notification statutes, including Kansas's, generally reserve enforcement to the state Attorney General rather than conferring a private right of action, though a minority of states' statutes do allow private suits.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No new comprehensive Kansas consumer-privacy legislation, adequacy determination, or major case law development was identified in the 180 days preceding this research run (i.e., since approximately February 2026).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}