Law / United States / Kansas

Kansas

United States law applies in Kansas Kansas is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Kansas, described on this page below, applies here too.

12 of 14 named instruments researched to a stage, across five of the six areas of law we track: 4 in force, 7 enacted but not yet in force and 1 proposed. As of 14 September 2026.

  1. AI law 1
  2. Privacy law 7
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (321 words)

Kansas has enacted two narrow artificial-intelligence statutes, both outside the consumer AI-transparency model other states use, and only one of them binds a private actor.

Signed April 8, 2025, 2025 Kan. Sess. Laws ch. 84 bars any state-agency-owned or state-issued electronic device from accessing an artificial intelligence platform of concern (DeepSeek by name, or any AI model owned or controlled by a country of concern: China, Cuba, Iran, North Korea, Russia, or Venezuela, explicitly excluding Taiwan), requires state agency networks to block such access, and requires an agency already using such a platform to deactivate and delete its account, subject to an exception for law-enforcement or cybersecurity-investigation activities.

2025 Kan. Sess. Laws ch. 120 (HB 2183), effective July 1, 2026, amended Kansas's sexual-exploitation-of-a-child, unlawful-transmission, and breach-of-privacy statutes to expressly cover images produced or altered by artificial intelligence: an artificially generated visual depiction indistinguishable from a real child, or morphed from a real child's image, is now itself sexual exploitation of a child, and non-consensual dissemination of an intimate image of an identifiable adult now expressly includes one created, altered, or modified by artificial intelligence.

Two further AI-specific bills died without reaching a floor vote in either chamber in the 2025-2026 session: a Companion Chatbot Safety Act (HB 2671) and an AI-training restriction bill (SB 405).

A third bill a legacy tracker describes as an AI-imagery expansion of the blackmail statute (HB 2594) passed both chambers unanimously but died before enrollment; read on its own text, it only would have decoupled the blackmail offense's cross-reference to the breach-of-privacy statute and separately described the image's content, adding no artificial-intelligence-specific element, so it is not recorded here as an AI instrument.

Kansas has no consumer-facing AI-transparency, chatbot-disclosure, or high-risk-system statute of the kind Colorado and Utah have enacted; the Kansas Consumer Protection Act's general deceptive-acts prohibition, K.S.A. 50-626, remains available against AI-related consumer deception on the same non-AI-specific terms as any other deceptive practice.

AI prohibited practices

AI-generated and AI-altered images in child exploitation and non-consensual dissemination offenses

K.S.A. 21-5510, 21-5611, 21-6101 (as amended by 2025 Kan. Sess. Laws ch. 120, HB 2183)official Kansas Statutes Annotated text, Kansas Office of Revisor of Statutes

In force 84 days, effective 1 July 2026. Binds public and private bodies.

What this law does

K.S.A. 21-5510(a)(2)(B) separately criminalizes possessing an artificially generated visual depiction, defined as an obscene image produced through computer software, digital manipulation, or other means that appears to depict a child under 18 engaging in sexually explicit conduct, including one indistinguishable from a real child, morphed from a real child's image, or generated without any actual child's involvement, with intent to arouse or gratify sexual desire; this is a severity level 5 person felony.

K.S.A. 21-5611's definition of visual depiction for the unlawful-transmission-of-a-child's-image offense was extended to include any item that has been created, in whole or in part, altered or modified by artificial intelligence or any digital means to appear to depict or purport to depict an identifiable child, regardless of whether such identifiable child was involved in the creation of the original image.

K.S.A. 21-6101(a)(8), the breach-of-privacy offense for non-consensual dissemination of an intimate image, was extended on the same terms to reach any videotape, photograph, film or image that has been created, in whole or in part, altered or modified by artificial intelligence or any digital means to appear to depict or purport to depict such identifiable person, regardless of whether such identifiable person was involved in the creation of the original image. This amendment, 2025 Kan. Sess. Laws ch. 120 (HB 2183), became effective July 1, 2026.

What it requires

Privacy law7 instruments, 7 enacted but not yet in force

Research summary (147 words)

Kansas has no comprehensive consumer personal-data statute.

Its privacy law is sectoral: the Kansas Breach Notification Act (K.S.A. 50-7a01 to 50-7a02) requires notice to affected residents without a fixed numeric deadline and to the Attorney General, with no biometric element in its personal information definition; the Student Data Privacy Act (K.S.A. 72-6312 to 72-6320) requires a school district to obtain written parental or adult-student consent before collecting a K-12 student's biometric data and layers its own immediate breach-notice duty for student data; and a genetic-testing insurance-underwriting statute (K.S.A. 40-2259) bars health-benefit insurers from conditioning coverage or rates on a genetic test result.

No provision creates a private right of action; enforcement runs to the Attorney General (and, for insurers, the insurance commissioner) or, for student data, the Attorney General or a district attorney seeking injunctive relief. Kansas has not adopted the NAIC Insurance Data Security Model Law.

Breach notification

Kansas Breach Notification Act, notice of security breach

K.S.A. 50-7a02(a)-(f)official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds public and private bodies.

What this law does

A person conducting business in Kansas, or a government, governmental subdivision, or agency that owns or licenses computerized personal information, must conduct a good-faith, reasonable, and prompt investigation on learning of a suspected breach and, if misuse occurred or is reasonably likely, give notice to the affected Kansas resident as soon as possible, in the most expedient time possible and without unreasonable delay.

The codified text sets no fixed numeric deadline, despite secondary-source claims of a 45-day figure, which does not appear anywhere in K.S.A. 50-7a02. Personal information is a name combined with a Social Security number, driver's license or state ID number, or financial account or card number with access credentials, and excludes publicly available government-record information; it does not reach biometric identifiers.

Notice to each nationwide consumer reporting agency is required when more than 1,000 consumers are affected at one time. Enacted 2006 (L. 2006, ch. 149, sec. 4); no separate effective date beyond that original enactment is recorded here.

What it requires

Student Data Privacy Act, breach notice for student data

K.S.A. 72-6318official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds public and private bodies.

What this law does

Layers a narrower, immediate breach-notice duty on top of the general Kansas Breach Notification Act: any entity with access to student data must immediately notify the affected student or the student's parent or guardian of a breach or unauthorized disclosure of student data, with no numeric threshold or deadline given beyond "immediately".

What it requires

Enforcement supervision

Kansas Breach Notification Act, enforcement

K.S.A. 50-7a02(g)-(h)official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds public and private bodies.

What this law does

The Kansas Attorney General may bring an action in law or equity to address a violation of the Breach Notification Act, except that a violation by an insurance company is enforced solely by the Insurance Commissioner. No provision creates a private right of action, and no clause deems a violation an unfair trade practice under the Kansas Consumer Protection Act, K.S.A. 50-626, which is a freestanding backstop with no textual link to this Act.

What it requires

Student Data Privacy Act, enforcement

K.S.A. 72-6317official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds government bodies.

What this law does

The Attorney General or any district attorney may enforce K.S.A. 72-6312 through 72-6319 by bringing an action in a court of competent jurisdiction and may seek injunctive relief against any educational agency, its employee or agent, or any other entity in possession of student data. Government enforcement only, injunctive relief, no damages provision, and no private right of action.

What it requires

Sensitive categories

Genetic testing nondiscrimination in health-benefit insurance underwriting

K.S.A. 40-2259official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds private bodies.

What this law does

Bars a health-benefit insurer from requiring, requesting, or using an individual's genetic test results to condition coverage, set rates, or adjust premiums. The restriction does not apply to a life, disability-income, or long-term-care insurer, though even those insurers face a narrower after-acquired-use restriction. This is an insurance-underwriting nondiscrimination statute, not a data-processing or retention duty, and it does not define sensitive data as a category.

What it requires

Student Data Privacy Act, biometric data collection consent

K.S.A. 72-6315official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds government bodies.

What this law does

No school district may collect biometric data from a student, or use a device or mechanism to assess a student's physiological or emotional state, without the written consent of an adult student or the parent or legal guardian of a minor student, K.S.A. 72-6315.

What it requires

Student Data Privacy Act, definitions of biometric data

K.S.A. 72-6313official Kansas statute text, Kansas Statutes Annotated, Office of Revisor of Statutes

Commencement not set. Binds government bodies.

What this law does

The Student Data Privacy Act defines biometric data, K.S.A. 72-6313(b), as one or more measurable biological or behavioral characteristics usable for automated recognition of an individual, such as fingerprints, retina and iris patterns, voiceprints, DNA sequence, facial characteristics, and handwriting.

The definition never mentions a photograph, video, or audio recording in either an inclusion or exclusion clause; there is no clause imposing a recording-derived exclusion and none clawing one back, so whether an identifier derived from a recording is covered cannot be determined from this text and is not recorded as either true or false.

What it requires

Scraping law1 instrument, 1 in force

Research summary (259 words)

Kansas's general computer-crime statute, K.S.A. 21-5839, reaches automated web access in a way comparable to a peer state such as Arizona: alongside three paragraphs requiring an added element (intent to defraud, or knowing damage, alteration, destruction, copying, disclosure, or taking possession without authorization or in excess of it), paragraph (a)(5) separately criminalizes knowingly and without authorization accessing, or attempting to access, any computer, computer system, social networking website, computer network, or computer software, program, documentation, data, or property, with no further intent element required, a bare unauthorized-access offense standing on its own, though Kansas grades it only as a class A nonperson misdemeanor rather than a felony.

Nothing in the statute's text exempts ordinary, non-disruptive automated access to a publicly available page from the authorization requirement, and no reported Kansas case applying section 21-5839 to an automated web-scraping or bulk-data-collection fact pattern was located.

A claim-of-right defense (property or services appropriated openly and avowedly under a claim of title made in good faith) is available for the damage-based paragraphs but is not extended to the bare unauthorized-access paragraph. Kansas has no comprehensive consumer privacy statute reaching scraped public personal data at the state level; its Breach Notification Act and Student Data Privacy Act are sectoral and are covered under the privacy topic, not restated here.

Terms-of-service enforceability rests on ordinary Kansas contract law, with no statutory modification located. Copyright, text-and-data-mining, database rights, unfair competition, and robots.txt's legal weight raise only the federal and common-law questions the national document already covers; Kansas adds no state-specific statute on any of them.

Computer misuse

Unlawful acts concerning computers (Kansas's computer-crime statute)

K.S.A. 21-5839official Kansas Statutes Annotated text, Kansas Office of Revisor of Statutes

In force. Binds public and private bodies.

What this law does

Subsection (a) lists five ways to commit the offense. Paragraphs (1) through (3) require an added element: knowing, unauthorized damage, modification, alteration, destruction, copying, disclosure, or taking possession of a computer, computer system, computer network, or other property (paragraph 1), a fraud scheme (paragraph 2), or the same conduct as paragraph (1) but done in excess of authorization rather than without it (paragraph 3).

Paragraph (4) criminalizes knowingly and without authorization disclosing a password, code, or other means of access to a computer, computer network, social networking website, or personal electronic content.

Paragraph (5) separately criminalizes knowingly and without authorization accessing, or attempting to access, any computer, computer system, social networking website, computer network, or computer software, program, documentation, data, or property, with no further intent element beyond knowledge and lack of authorization, a bare unauthorized-access offense standing on its own.

A violation of paragraphs (1) through (3) is a severity level 8 nonperson felony, rising to a severity level 5 nonperson felony where the victim's monetary loss exceeds $100,000; a violation of paragraph (4) or (5) is a class A nonperson misdemeanor. It is a defense to a paragraph (1) through (3) prosecution that the property or services were appropriated openly and avowedly under a claim of title made in good faith.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (349 words)

Kansas's private-sector security-law posture rests on one enacted baseline statute rather than a product-security, sector-specific, or safe-harbor regime: K.S.A. 50-6,139b, part of and supplemental to the Kansas Consumer Protection Act (History: L. 2016, ch. 103, section 2; effective July 1, 2016), requires any holder of personal information, a term defined broadly enough to include a government or governmental subdivision alongside a private business, to implement and maintain reasonable safeguards and to destroy unneeded records containing personal information, enforceable only by the Kansas Attorney General as an unconscionable act or practice with a civil penalty of up to $10,000 per violation and no private right of action.

Kansas has not enacted a conditioned cybersecurity safe-harbor act of the kind Utah, Ohio, Iowa, and Connecticut have passed, an affirmative defense to a data-breach claim available to a business that adopts a named security framework: the closest instrument, the Kansas financial institutions information security act (K.S.A. 9-551 to 9-554, enacted 2023), is a mandatory information-security-program duty rather than a liability shield, and it binds a financial-sector role, a credit services organization, mortgage company, supervised lender, money transmitter, trust company, or technology-enabled fiduciary financial institution, that the LexLint activity vocabulary cannot yet express, so it is recorded here rather than flagged on a guess (#6740): no instrument for it is filed here.

No enacted Kansas statute is confirmed in the primary text and searches consulted here to set security requirements a connected device or software product must meet before or after it is placed on the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and none imposes a private-sector duty to report an exploited vulnerability or a security incident to an authority or to users: the state's own incident-reporting duty, K.S.A. 75-7244, binds a public entity and a government contractor handling state networks or systems, a government-accountability duty rather than a private-sector one, and is recorded here rather than filed as an instrument.

Kansas's breach-notification statute, the Kansas Consumer Information Security Breach Notification Act at K.S.A. 50-7a01 through 50-7a04, is this jurisdiction's privacy-topic row rather than repeated here.

Security baseline statutes

Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information

K.S.A. 50-6,139bofficial Kansas Statutes Annotated text, Kansas Office of the Revisor of Statutes

In force since 1 July 2016. Binds public and private bodies.

What this law does

Any holder of personal information, defined to include any individual, partnership, corporation, trust, estate, cooperative, association, government, governmental subdivision, agency, or other entity that in the ordinary course of business collects, maintains, or possesses another person's personal information, must implement and maintain reasonable procedures and practices appropriate to the nature of the information and exercise reasonable care to protect it from unauthorized access, use, modification or disclosure.

Compliance with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this safeguards duty, and failure to comply with that other law is prima facie evidence of a violation.

Unless federal law requires otherwise, a holder must also take reasonable steps to destroy or arrange for the destruction of records containing personal information it no longer intends to maintain or possess, by shredding, erasing, or otherwise rendering the information unreadable. A holder has an affirmative defense to a violation of the destruction duty where the failure could not reasonably have been foreseen despite the holder's exercise of reasonable care in selecting a destruction method.

The defense is also available where the holder had a bona fide written or electronic records management policy reasonably designed to prevent the violation, its employees received training on the policy, the violation was a good faith error, and no reasonable likelihood exists that it may cause, enable or contribute to identity theft or identity fraud.

Each violation of this section is an unconscionable act or practice under the Kansas Consumer Protection Act's unconscionability provision, section 50-627, with each undestroyed record its own separate violation. Only the Kansas Attorney General may enforce this section. The Attorney General may seek a civil penalty of up to $10,000 per violation under the Act's civil-penalties provision, section 50-636. The section itself creates no private right of action.

What it requires

Age gating law2 instruments, 1 in force, 1 proposed

Research summary (72 words)

Kansas has required age verification for adult websites since 2024, backed by both attorney general enforcement and a private right of action. An app store accountability bill requiring age verification and parental consent for app downloads by minors passed the Senate in February 2026 and cleared a House committee in March 2026 but died without a House floor vote. No social media minor-access law or design code law has advanced past introduction.

App store age verification (AV)

SB 372, App Store Accountability Act

Senate Bill No. 372 (2025-2026 session), died in the Houseofficial Kansas Legislature bill text and status page

Proposed: draft date not recorded. Binds private bodies.

What this law does

Would require app store providers to verify a user's age category at account creation, link minor accounts to a parent account, and require parental consent before minors can download apps. The bill passed the Senate in February 2026 and was reported favorably as amended by a House committee on March 18, 2026, but died without a House floor vote.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.