🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-KS · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Kansas

US-KS schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM

Last updated · 10 categories · 31 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
31Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive DPA-style regulator or omnibus statute exists; oversight is fragmented across the state AG's general consumer-protection authority and federal sectoral law.

Primary frameworkKansas Consumer Protection Act (K.S.A. §50-623 et seq.) + Kansas breach notification statute (K.S.A. §50-7a01 et seq.); federal FTC Act Section 5 baseline
Traffic-light rationale — RedNo comprehensive DPA-style regulator or omnibus statute exists; oversight is fragmented across the state AG's general consumer-protection authority and federal sectoral law.

Sub-modules (5)

Regulator And AuthorityAmber

The Kansas Attorney General's Consumer Protection Division is the primary state-level authority handling privacy-adjacent consumer complaints and breach notices; there is no dedicated Kansas data-protection authority analogous to a DPA.

Claims (1):

  • The Kansas Attorney General's Consumer Protection Division is the designated point of contact for Kansas residents regarding data breach notifications and general consumer-protection enforcement.

Act And InstrumentsAmber

Instruments in force are the Kansas Consumer Protection Act and the Kansas breach-notification statute, plus applicable federal sectoral statutes (HIPAA, GLBA, COPPA, FCRA) and FTC Act Section 5.

Claims (2):

  • The FTC Act Section 5 prohibition on unfair or deceptive acts or practices constitutes a general federal privacy-and-security enforcement baseline applicable nationally, including to entities operating in Kansas.
  • Kansas has no comprehensive consumer-privacy statute equivalent to GDPR or CCPA; data-protection matters are addressed only through federal sectoral law and the state's general consumer-protection and breach-notification statutes.

Material ScopeRed

No state statute defines a general material scope for 'personal data' processing; scope is defined narrowly, per-statute, e.g., the breach law's definition of 'personal information' tied to identity-theft/financial-fraud data elements.

Claims (1):

  • The Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) defines covered 'personal information' narrowly around identity-theft/financial-fraud data elements, and, per industry analysis, does not require a credit card number to be connected to a consumer's name to trigger notification, unlike most other states' breach laws.

Territorial ScopeAmber

The breach-notification statute applies based on residency of affected Kansas individuals rather than the location of the entity, consistent with the general US state breach-law pattern, but the precise statutory territorial language was not independently verified against primary statutory text in this run.

Claims (1):

  • The Kansas breach-notification statute's territorial reach (i.e., whether it applies to any entity holding computerized personal information of Kansas residents regardless of the entity's own location) follows the common US state pattern of resident-based applicability, but exact statutory wording was not verified against the primary Kansas statute text in this research pass.

Regulator Registration And FilingRed

Kansas imposes no general controller/processor registration or filing obligation with the Attorney General or any state privacy authority.

Claims (1):

  • Kansas imposes no general controller or processor registration/filing requirement with any state authority for personal-data processing activities.
Category narrative63 words

Kansas has no comprehensive omnibus consumer-privacy statute. The operative regime is (a) federal FTC Act Section 5 unfair/deceptive-practices authority applied nationally, (b) the Kansas Consumer Protection Act (K.S.A. §50-623 et seq.) enforced by the Kansas Attorney General for deceptive/unconscionable acts, and (c) the Kansas data-breach notification statute (K.S.A. §50-7a01 et seq.), which addresses breach notification only and does not create general consumer data-rights.

Sources and claims (6)
  1. ConfirmedCalifornia Attorney General breach filing repositoryThe Kansas Attorney General's Consumer Protection Division is the designated point of contact for Kansas residents regarding data breach notifications and general consumer-protection enforcement.observed
  2. ConfirmedFederal Trade CommissionThe FTC Act Section 5 prohibition on unfair or deceptive acts or practices constitutes a general federal privacy-and-security enforcement baseline applicable nationally, including to entities operating in Kansas.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsKansas has no comprehensive consumer-privacy statute equivalent to GDPR or CCPA; data-protection matters are addressed only through federal sectoral law and the state's general consumer-protection and breach-notification statutes.observed
  4. ProbableInternational Association of Privacy ProfessionalsThe Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) defines covered 'personal information' narrowly around identity-theft/financial-fraud data elements, and, per industry analysis, does not require a credit card number to be connected to a consumer's name to trigger notification, unlike most other states' breach laws.observed
  5. UncertainOneTrust DataGuidanceThe Kansas breach-notification statute's territorial reach (i.e., whether it applies to any entity holding computerized personal information of Kansas residents regardless of the entity's own location) follows the common US state pattern of resident-based applicability, but exact statutory wording was not verified against the primary Kansas statute text in this research pass.observed
  6. ConfirmedInternational Association of Privacy ProfessionalsKansas imposes no general controller or processor registration/filing requirement with any state authority for personal-data processing activities.observed

#

Absence of any state lawful-basis, consent, or special-category regime outside narrow federal sectoral overlays.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedAbsence of any state lawful-basis, consent, or special-category regime outside narrow federal sectoral overlays.

Sub-modules (4)

Lawful BasesRed

No Kansas statute enumerates lawful bases for processing analogous to GDPR Art 6; processing is governed by general contract/consumer-protection principles and federal sectoral rules only.

Claims (1):

  • Kansas has no state statute enumerating lawful bases for the processing of personal data equivalent to GDPR Article 6.

Special CategoriesRed

Kansas has no state-level sensitive/special-category data regime; heightened protection for health or financial data arises solely from federal HIPAA/GLBA sectoral law.

Claims (1):

  • Kansas has no state-level special/sensitive-category data statute; sensitive data protections apply only through federal sectoral overlays such as HIPAA for health data and GLBA for financial data.

Pseudonymisation And AnonymisationRed

No Kansas statutory definition or safe-harbour for pseudonymised or anonymised data was identified.

Category narrative34 words

Kansas has no state-enumerated lawful-basis framework, no general consent-threshold statute, and no state-level special/sensitive-category regime for commercial data processing. These matters are addressed only where a federal sectoral statute (HIPAA, GLBA, COPPA) independently applies.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsKansas has no state statute enumerating lawful bases for the processing of personal data equivalent to GDPR Article 6.observed
  2. ConfirmedOneTrust DataGuidanceNo general Kansas consent-threshold statute governs commercial data collection outside of the federal COPPA parental-consent regime for children under 13.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsKansas has no state-level special/sensitive-category data statute; sensitive data protections apply only through federal sectoral overlays such as HIPAA for health data and GLBA for financial data.observed

#

No comprehensive data-subject-rights framework exists in Kansas; only breach notification rights apply.

Traffic-light rationale — RedNo comprehensive data-subject-rights framework exists in Kansas; only breach notification rights apply.

Sub-modules (5)

Access RightRed

No general right of access to personal data held by private businesses exists under Kansas law.

Claims (1):

  • Kansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data held by private-sector businesses.

Rectification And ErasureRed

No state right to correct or delete personal data held by private-sector businesses exists in Kansas.

Claims (1):

  • Kansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data held by private-sector businesses.

Restriction And ObjectionRed

No state right to restrict processing or object to processing/profiling exists in Kansas.

Claims (1):

  • Kansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data held by private-sector businesses.

Data PortabilityRed

No state data-portability right exists in Kansas.

Claims (1):

  • Kansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data held by private-sector businesses.

Deadlines And Response WindowsAmber

The only statutory deadline identified is the breach-notification obligation, generally described as requiring notice without unreasonable delay; the precise numeric day-count in the Kansas statute was not independently verified against primary text in this pass.

Claims (1):

  • The Kansas breach-notification statute requires notice to affected individuals following discovery of a breach, consistent with the general US state pattern of a 'without unreasonable delay' standard, though the exact numeric deadline was not independently confirmed against primary statutory text in this research pass.
Category narrative43 words

Kansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability on consumers with respect to personal data held by private-sector businesses. The only individual-facing right operative at state level is receipt of breach notification under K.S.A. §50-7a01 et seq.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsKansas confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data held by private-sector businesses.observed
  2. UncertainNational Association of Attorneys GeneralThe Kansas breach-notification statute requires notice to affected individuals following discovery of a breach, consistent with the general US state pattern of a 'without unreasonable delay' standard, though the exact numeric deadline was not independently confirmed against primary statutory text in this research pass.observed

#

No omnibus controller/processor obligations exist in Kansas outside breach notification and narrow federal sectoral overlays.

Primary frameworkKansas breach notification statute (K.S.A. §50-7a01 et seq.)
Traffic-light rationale — RedNo omnibus controller/processor obligations exist in Kansas outside breach notification and narrow federal sectoral overlays.

Sub-modules (7)

Accountability And DpiaRed

No Kansas DPIA or general accountability-principle statute exists.

Claims (1):

  • Kansas imposes no statutory accountability principle, DPIA trigger, DPO appointment threshold, ROPA obligation, or joint-controller framework applicable to private-sector data processing generally.

Dpo RequirementsRed

Kansas imposes no DPO appointment threshold or independence requirement.

Claims (1):

  • Kansas imposes no statutory accountability principle, DPIA trigger, DPO appointment threshold, ROPA obligation, or joint-controller framework applicable to private-sector data processing generally.

Ropa RequirementsRed

No records-of-processing (ROPA) obligation exists under Kansas law.

Claims (1):

  • Kansas imposes no statutory accountability principle, DPIA trigger, DPO appointment threshold, ROPA obligation, or joint-controller framework applicable to private-sector data processing generally.

Joint Controller ArrangementsRed

Kansas has no statutory joint-controller framework; GLBA vendor-management obligations apply only to covered financial institutions.

Claims (1):

  • Kansas imposes no statutory accountability principle, DPIA trigger, DPO appointment threshold, ROPA obligation, or joint-controller framework applicable to private-sector data processing generally.

Security MeasuresAmber

Kansas has no freestanding 'reasonable security' statute of general application; security duties arise from the breach-notification statute's remedial trigger and from federal sectoral rules (GLBA Safeguards Rule, HIPAA Security Rule) where applicable.

Claims (1):

  • Insurance entities and financial institutions operating in Kansas remain subject to the federal Gramm-Leach-Bliley Act's affirmative obligation to protect the security and confidentiality of customers' non-public personal information, absent a confirmed Kansas-specific insurance data-security statute mirroring the NAIC Insurance Data Security Model Law.

Breach NotificationAmber

The Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) requires notification to affected Kansas residents following a breach of unencrypted computerized personal information.

Claims (1):

  • The Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) requires entities that own or license computerized data including personal information to notify affected Kansas residents following a security breach.

Retention And DisposalRed

No general Kansas data-retention-limit or disposal-duty statute of broad application was identified.

Category narrative43 words

Kansas imposes no general accountability, DPIA, DPO, ROPA, or joint-controller framework. The only affirmative duty at state level is breach notification under K.S.A. §50-7a01 et seq.; broader security/retention duties arise only via federal sectoral law (GLBA Safeguards Rule, HIPAA Security Rule) where applicable.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsKansas imposes no statutory accountability principle, DPIA trigger, DPO appointment threshold, ROPA obligation, or joint-controller framework applicable to private-sector data processing generally.observed
  2. ProbableInternational Association of Privacy ProfessionalsInsurance entities and financial institutions operating in Kansas remain subject to the federal Gramm-Leach-Bliley Act's affirmative obligation to protect the security and confidentiality of customers' non-public personal information, absent a confirmed Kansas-specific insurance data-security statute mirroring the NAIC Insurance Data Security Model Law.observed
  3. ConfirmedNational Association of Attorneys GeneralThe Kansas breach-notification statute (K.S.A. §50-7a01 et seq.) requires entities that own or license computerized data including personal information to notify affected Kansas residents following a security breach.observed

#

Cross-border transfer governance is not a state-level competency in the US federal system; no Kansas-specific mechanism exists.

Traffic-light rationale — RedCross-border transfer governance is not a state-level competency in the US federal system; no Kansas-specific mechanism exists.

Sub-modules (6)

Transfer MechanismsAmber

No Kansas-specific transfer mechanism exists; multinational entities based in Kansas rely on federal/EU-side mechanisms (e.g., EU-U.S. Data Privacy Framework, SCCs) where relevant to international data flows.

Claims (1):

  • Kansas has no state-specific cross-border data-transfer mechanism; Kansas-based entities engaged in international data flows rely on federal or counterpart-jurisdiction mechanisms such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.

Adequacy ReceivedRed

Adequacy determinations are made at the federal/EU level, not by individual US states; Kansas has no independent adequacy status.

Claims (1):

  • Adequacy decisions are federal/international-level determinations; Kansas as a US state neither receives nor grants adequacy status independently.

Adequacy GrantedRed

Kansas does not grant adequacy determinations to other jurisdictions; this is a federal/international function.

Claims (1):

  • Adequacy decisions are federal/international-level determinations; Kansas as a US state neither receives nor grants adequacy status independently.

Sccs And BcrsAmber

SCC/BCR uptake in Kansas-domiciled entities follows federal/EU-side contractual practice; no state-specific form exists.

Claims (1):

  • Kansas has no state-specific cross-border data-transfer mechanism; Kansas-based entities engaged in international data flows rely on federal or counterpart-jurisdiction mechanisms such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.

Transfer Impact AssessmentRed

No Kansas-specific TIA requirement exists; any such assessment obligation would derive from the data exporter's non-US counterpart regime (e.g., EU GDPR Article 44-49 obligations on an EU exporter transferring to a Kansas-based importer).

Data LocalisationRed

Kansas imposes no data-localisation mandate, partial or absolute.

Claims (1):

  • Kansas imposes no data-localisation requirement, partial or absolute, on personal data processing.
Category narrative37 words

Cross-border transfer mechanisms, adequacy determinations, and data-localisation mandates are federal/international-level constructs (US Department of Commerce, EU adequacy decisions) rather than Kansas state functions. Kansas imposes no data-localisation requirement and does not independently grant or receive adequacy determinations.

Sources and claims (3)
  1. ProbableInternational Association of Privacy ProfessionalsKansas has no state-specific cross-border data-transfer mechanism; Kansas-based entities engaged in international data flows rely on federal or counterpart-jurisdiction mechanisms such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsAdequacy decisions are federal/international-level determinations; Kansas as a US state neither receives nor grants adequacy status independently.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsKansas imposes no data-localisation requirement, partial or absolute, on personal data processing.observed

#

Sector coverage exists but only via federal law; no state-specific sectoral overlay confirmed.

Primary frameworkFederal sectoral statutes (GLBA, HIPAA, FCRA, FERPA, COPPA, PPRA)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberSector coverage exists but only via federal law; no state-specific sectoral overlay confirmed.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA and its Safeguards/Privacy Rules apply federally to Kansas-based financial institutions; no additional Kansas-specific financial-privacy statute was confirmed.

Claims (1):

  • Financial institutions operating in Kansas are subject to the federal Gramm-Leach-Bliley Act's privacy and safeguards requirements.

Health Sector OverlayAmber

HIPAA applies federally to covered entities in Kansas; no additional comprehensive Kansas health-privacy statute beyond HIPAA was confirmed in this research pass.

Claims (1):

  • Covered entities and business associates in Kansas are subject to the federal HIPAA Privacy and Security Rules; no additional comprehensive Kansas-specific health-privacy statute was confirmed in this research pass.

Telecoms And EprivacyRed

No Kansas-specific ePrivacy-style regime exists; federal TCPA and FCC rules govern telecoms/marketing communications.

Employment DataRed

No Kansas-specific employment-data-privacy statute was identified in this research pass.

Credit And ScoringAmber

The federal Fair Credit Reporting Act governs credit-scoring data nationally, including Kansas; no Kansas-specific credit-scoring statute was identified.

Claims (1):

  • Credit-scoring and consumer-report data involving Kansas residents is governed by the federal Fair Credit Reporting Act; no Kansas-specific credit-scoring statute was identified.

EducationAmber

FERPA, COPPA, and PPRA govern student data at the federal level; no dedicated Kansas student-data-privacy statute analogous to California's SOPIPA was confirmed via allowlisted sources.

Claims (1):

  • Student data in Kansas is governed by the federal FERPA, COPPA, and PPRA frameworks; no dedicated Kansas student-data-privacy statute analogous to California's Student Online Personal Information Protection Act was confirmed.

InsuranceAmber

Insurance entities in Kansas are subject to GLBA at the federal level; adoption of the NAIC Insurance Data Security Model Law in Kansas was not confirmed.

Claims (1):

  • Insurance entities and financial institutions operating in Kansas remain subject to the federal Gramm-Leach-Bliley Act's affirmative obligation to protect the security and confidentiality of customers' non-public personal information, absent a confirmed Kansas-specific insurance data-security statute mirroring the NAIC Insurance Data Security Model Law.
Category narrative41 words

Sectoral overlays in Kansas are exclusively federal: GLBA (financial), HIPAA (health), FCRA (credit/scoring), FERPA/COPPA/PPRA (education). No Kansas-specific comprehensive sectoral privacy statute was confirmed for financial, health, telecoms, employment, credit, education, or insurance sectors beyond these federal baselines and general consumer-protection/breach-notification law.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsFinancial institutions operating in Kansas are subject to the federal Gramm-Leach-Bliley Act's privacy and safeguards requirements.observed
  2. ProbableOneTrust DataGuidanceCovered entities and business associates in Kansas are subject to the federal HIPAA Privacy and Security Rules; no additional comprehensive Kansas-specific health-privacy statute was confirmed in this research pass.observed
  3. ProbableInternational Association of Privacy ProfessionalsCredit-scoring and consumer-report data involving Kansas residents is governed by the federal Fair Credit Reporting Act; no Kansas-specific credit-scoring statute was identified.observed
  4. UncertainOneTrust DataGuidanceStudent data in Kansas is governed by the federal FERPA, COPPA, and PPRA frameworks; no dedicated Kansas student-data-privacy statute analogous to California's Student Online Personal Information Protection Act was confirmed.observed

#

No state adtech/commercial-privacy regime exists; only generic federal deception and marketing-communications law applies.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo state adtech/commercial-privacy regime exists; only generic federal deception and marketing-communications law applies.

Sub-modules (6)

Cookies And TrackersRed

No Kansas cookie/tracker consent law exists.

Claims (1):

  • Kansas has no cookie/tracker consent regime, dark-pattern prohibition, mandated opt-out-signal recognition, or cross-context-advertising 'sale'/'share' framework of the kind found in states with comprehensive privacy laws.

Dark PatternsRed

No Kansas-specific dark-pattern prohibition exists; deceptive design practices could be reached only via the general Kansas Consumer Protection Act or FTC Section 5.

Claims (1):

  • Kansas has no cookie/tracker consent regime, dark-pattern prohibition, mandated opt-out-signal recognition, or cross-context-advertising 'sale'/'share' framework of the kind found in states with comprehensive privacy laws.

Opt Out SignalsRed

Kansas does not mandate recognition of universal opt-out mechanisms such as Global Privacy Control, unlike states with comprehensive privacy laws.

Claims (1):

  • Kansas has no cookie/tracker consent regime, dark-pattern prohibition, mandated opt-out-signal recognition, or cross-context-advertising 'sale'/'share' framework of the kind found in states with comprehensive privacy laws.

Clean Rooms And DcrRed

No Kansas clean-room or data-collaboration-room regulation exists.

Cross Context AdvertisingRed

Kansas has no 'sale'/'share' framework for cross-context behavioral advertising analogous to CPRA.

Claims (1):

  • Kansas has no cookie/tracker consent regime, dark-pattern prohibition, mandated opt-out-signal recognition, or cross-context-advertising 'sale'/'share' framework of the kind found in states with comprehensive privacy laws.

Direct MarketingAmber

Direct-marketing suppression obligations in Kansas arise only from federal TCPA (telemarketing/robocalls) and CAN-SPAM (email) frameworks; no Kansas-specific direct-marketing consent statute exists.

Claims (1):

  • Direct-marketing communications targeting Kansas residents remain subject to federal telemarketing (TCPA) and email (CAN-SPAM) suppression rules in the absence of a Kansas-specific direct-marketing consent statute.
Category narrative40 words

Kansas has no cookie/tracker consent regime, no dark-pattern prohibition, no state-mandated recognition of opt-out signals (e.g., GPC), no clean-room/data-collaboration rules, and no cross-context-advertising 'sale/share' framework. Direct-marketing suppression obligations exist only via federal TCPA/CAN-SPAM and general FTC Section 5 deception standards.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsKansas has no cookie/tracker consent regime, dark-pattern prohibition, mandated opt-out-signal recognition, or cross-context-advertising 'sale'/'share' framework of the kind found in states with comprehensive privacy laws.observed
  2. ProbableFederal Trade CommissionDirect-marketing communications targeting Kansas residents remain subject to federal telemarketing (TCPA) and email (CAN-SPAM) suppression rules in the absence of a Kansas-specific direct-marketing consent statute.observed

#

No state algorithmic, biometric, or AI-governance statute exists in Kansas.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo state algorithmic, biometric, or AI-governance statute exists in Kansas.

Sub-modules (6)

Profiling RestrictionsRed

No Kansas profiling-restriction statute analogous to GDPR Art 22 exists.

Claims (1):

  • Kansas has enacted no profiling-restriction, automated-decision-making transparency, or AI-specific risk-assessment statute.

Automated Decision Making TransparencyRed

No Kansas ADM-transparency or explanation-right statute exists.

Claims (1):

  • Kansas has enacted no profiling-restriction, automated-decision-making transparency, or AI-specific risk-assessment statute.

Ai Risk AssessmentsRed

Kansas has not enacted an AI-specific risk-assessment statute comparable to Colorado's AI Act or California's ADMT regulations.

Claims (1):

  • Kansas has enacted no profiling-restriction, automated-decision-making transparency, or AI-specific risk-assessment statute.

Biometric RegimeRed

Kansas has no dedicated biometric-privacy statute; among US states, only Illinois (BIPA), Texas, and Washington have enacted biometric-specific legislation.

Claims (1):

  • Among US states, only Illinois, Texas, and Washington have enacted biometric-specific privacy legislation; Kansas has no dedicated biometric-data statute.

Genetic DataRed

No Kansas-specific genetic-data statute was identified; federal GINA provides narrow non-discrimination protections in employment and health insurance contexts only.

State Surveillance CarveoutsRed

No Kansas-specific state-surveillance carve-out statute for data protection purposes was identified; national-security and law-enforcement exemptions are governed by federal law.

Category narrative59 words

Kansas has no profiling-restriction statute, no ADM-transparency law, no AI-specific risk-assessment mandate, and no dedicated biometric-privacy statute. Industry analysis confirms that, among US states, only Illinois, Washington, and Texas have enacted biometric-specific legislation; Kansas is not among them. Genetic-data protections and state-surveillance carve-outs are governed only by narrow federal provisions where applicable (e.g., GINA for genetic non-discrimination in insurance/employment).

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsKansas has enacted no profiling-restriction, automated-decision-making transparency, or AI-specific risk-assessment statute.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsAmong US states, only Illinois, Texas, and Washington have enacted biometric-specific privacy legislation; Kansas has no dedicated biometric-data statute.observed

#

Federal COPPA/FERPA provide baseline child protections; no Kansas-specific enhancement exists.

Primary frameworkCOPPA (federal) + FERPA/PPRA (federal, education settings)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal COPPA/FERPA provide baseline child protections; no Kansas-specific enhancement exists.

Sub-modules (5)

Age VerificationAmber

No Kansas-specific age-verification statute exists; COPPA's actual-knowledge standard for under-13 users applies federally.

Claims (1):

  • Children's online personal information collected from Kansas residents under age 13 is governed by the federal COPPA parental-consent requirement; Kansas has no additional state-level age-of-consent or parental-consent statute.

Minor Profiling BansRed

No Kansas statute bans profiling of minors; some comprehensive-privacy states restrict targeted advertising to minors, but Kansas has no such law.

Claims (1):

  • Kansas has no statutory ban on profiling or targeted advertising directed at minors, unlike several states with comprehensive privacy laws.

Education SettingsAmber

FERPA and PPRA govern education-setting data at the federal level; no confirmed Kansas-specific education-privacy statute exists.

Claims (1):

  • Student data in Kansas is governed by the federal FERPA, COPPA, and PPRA frameworks; no dedicated Kansas student-data-privacy statute analogous to California's Student Online Personal Information Protection Act was confirmed.

Dependent AdultsRed

No Kansas-specific data-privacy statute for dependent or elderly adults was identified; general adult-protective-services law may address financial exploitation but not data-privacy rights specifically.

Category narrative35 words

Children's data protection in Kansas derives entirely from the federal COPPA regime (parental consent for under-13 data collection) and FERPA/PPRA for education settings. Kansas has no state-level age-of-consent statute, minor-profiling ban, or dependent-adults data-privacy statute.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceChildren's online personal information collected from Kansas residents under age 13 is governed by the federal COPPA parental-consent requirement; Kansas has no additional state-level age-of-consent or parental-consent statute.observed
  2. ProbableInternational Association of Privacy ProfessionalsKansas has no statutory ban on profiling or targeted advertising directed at minors, unlike several states with comprehensive privacy laws.observed

#

Enforcement exists but is narrow (AG consumer-protection powers plus federal FTC authority); no dedicated privacy regulator or comprehensive penalty regime.

Primary frameworkKansas Consumer Protection Act (K.S.A. §50-623 et seq.) + FTC Act Section 5
Traffic-light rationale — AmberEnforcement exists but is narrow (AG consumer-protection powers plus federal FTC authority); no dedicated privacy regulator or comprehensive penalty regime.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Kansas Attorney General may bring enforcement actions under the Kansas Consumer Protection Act for deceptive or unconscionable practices, including privacy-related misrepresentations, and can invoke the breach-notification statute in enforcement contexts; the FTC has parallel Section 5 authority.

Claims (1):

  • The Kansas Attorney General has authority under the Kansas Consumer Protection Act to bring enforcement actions for deceptive or unconscionable acts, including privacy-related misrepresentations, and can enforce the breach-notification statute; the FTC retains concurrent federal Section 5 authority over the same conduct.

Enforcement Activity IndexAmber

No Kansas-specific major data-privacy enforcement decision was confirmed in the trailing 12 months via allowlisted sources; enforcement activity is dominated by states with comprehensive privacy statutes (e.g., California, Colorado, Texas, Oregon).

Claims (1):

  • Recent US state privacy-enforcement activity has concentrated in states with comprehensive privacy statutes (e.g., California, Colorado, Oregon, Texas); no comparable Kansas-specific privacy enforcement action was confirmed in this research pass.

Regulator Funding And CapacityAmber

No specific funding or headcount data for a dedicated Kansas privacy-enforcement unit was identified; enforcement is handled within the AG's general Consumer Protection Division.

Absence provenance: not recorded. Searched: Kansas Attorney General consumer protection division data breach enforcement 2025 2026.

Collective Redress And Class ActionsRed

No Kansas-specific class-action mechanism exists for data-privacy claims beyond general Kansas civil procedure rules; no confirmed private right of action under the breach-notification statute.

Claims (1):

  • US state breach-notification statutes, including Kansas's, generally reserve enforcement to the state Attorney General rather than conferring a private right of action, though a minority of states' statutes do allow private suits.

Private Right Of ActionRed

The Kansas breach-notification statute does not confer a private right of action; enforcement is reserved to the Attorney General, consistent with the majority pattern among US state breach laws.

Claims (1):

  • US state breach-notification statutes, including Kansas's, generally reserve enforcement to the state Attorney General rather than conferring a private right of action, though a minority of states' statutes do allow private suits.

Recent Developments 180DAmber

No new Kansas comprehensive privacy legislation, case law, or regulatory guidance was identified in the 180 days preceding this run (i.e., since approximately February 2026); Kansas continues to rely on its existing breach-notification and consumer-protection statutes.

Claims (1):

  • No new comprehensive Kansas consumer-privacy legislation, adequacy determination, or major case law development was identified in the 180 days preceding this research run (i.e., since approximately February 2026).
Category narrative65 words

Enforcement in Kansas is limited to the Attorney General's Consumer Protection Division acting under the Kansas Consumer Protection Act and breach-notification statute, plus concurrent federal FTC Section 5 authority. There is no private right of action under Kansas's breach statute, no state class-action-specific data-privacy mechanism beyond general Kansas civil procedure, and no dedicated data-protection regulator with independent rule-making or fining power analogous to a DPA.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidanceThe Kansas Attorney General has authority under the Kansas Consumer Protection Act to bring enforcement actions for deceptive or unconscionable acts, including privacy-related misrepresentations, and can enforce the breach-notification statute; the FTC retains concurrent federal Section 5 authority over the same conduct.observed
  2. ProbableInternational Association of Privacy ProfessionalsRecent US state privacy-enforcement activity has concentrated in states with comprehensive privacy statutes (e.g., California, Colorado, Oregon, Texas); no comparable Kansas-specific privacy enforcement action was confirmed in this research pass.observed
  3. ProbableInternational Association of Privacy ProfessionalsUS state breach-notification statutes, including Kansas's, generally reserve enforcement to the state Attorney General rather than conferring a private right of action, though a minority of states' statutes do allow private suits.observed
  4. UncertainInternational Association of Privacy ProfessionalsNo new comprehensive Kansas consumer-privacy legislation, adequacy determination, or major case law development was identified in the 180 days preceding this research run (i.e., since approximately February 2026).observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Kansas
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 31 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated. Coverage relied primarily on T1 anchors (FTC Act Section 5; Kansas breach-notification statute via NAAG seed anchor; Kansas AG Consumer Protection Division) for regulator_and_framework, controller_processor_duties (breach_notification), and enforcement_and_redress. Modules lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups relied predominantly on T2/T3 secondary compiler sources (IAPP, DataGuidance) to establish the negative finding that no comprehensive Kansas statute exists in these areas, consistent with the seed's disambiguation note. sectoral_watch relied on T2/T3 sources for federal sectoral overlays (GLBA, HIPAA, FCRA, FERPA, COPPA) with several sub-modules (insurance NAIC-model adoption, education-specific Kansas statute, employment data) flagged Uncertain/absent due to inability to confirm via allowlisted sources. Primary Kansas Revisor of Statutes text for K.S.A. §50-7a01 et seq. and §50-623 et seq. was not directly retrievable in this run; citations rely on NAAG seed anchor and DataGuidance secondary compiler pages, which is a T3-level limitation on otherwise T1-anchored statutory claims.

Unresolved questions (5):

  • Does Kansas's breach-notification statute (K.S.A. §50-7a01 et seq.) specify a numeric notification deadline (e.g., X days) or only a 'without unreasonable delay' standard? Primary statutory text was not retrieved.
  • Has Kansas adopted the NAIC Insurance Data Security Model Law in whole or in part? No confirming enactment was located via allowlisted sources.
  • Does Kansas have any dedicated student-data-privacy statute (analogous to California's SOPIPA) supplementing FERPA/COPPA/PPRA? None was confirmed, but exhaustive Kansas legislative-code search was not possible via allowlisted sources.
  • Does the Kansas breach-notification statute confer any private right of action, or is enforcement exclusively reserved to the Attorney General? Not independently verified against primary text.
  • What is the precise territorial-scope language of K.S.A. §50-7a01 et seq. regarding out-of-state entities holding Kansas residents' data?

Escalate to primary-source review: yes