Law / United States / Kansas
Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 July 2016.
A security baseline statutes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds any holder of personal information: any individual, partnership, corporation, trust, estate, cooperative, association, government, governmental subdivision, agency, or other entity that in the ordinary course of business collects, maintains, or possesses another person's personal information.
- Implement and maintain reasonable procedures and practices appropriate to the nature of the information, and exercise reasonable care to protect it from unauthorized access, use, modification, or disclosure. Being subject to and compliant with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this duty.
- Unless a federal law or regulation requires otherwise, destroy or arrange for the destruction of records containing personal information once you no longer intend to maintain or possess them, by shredding, erasing, or otherwise rendering the personal information unreadable or undecipherable.
- There is no private right of action. Only the Kansas Attorney General may enforce this section, as an unconscionable act or practice under the Kansas Consumer Protection Act, seeking a civil penalty of up to $10,000 per violation under K.S.A. 50-636.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Civil penalty under K.S.A. 50-636(a) for a violation deemed an unconscionable act or practice under K.S.A. 50-627; the statute names no aggregate cap and each undestroyed record is a separate violation. Kansas's separate breach-notification statute, K.S.A. 50-7a01 through 50-7a04, carries its own enforcement provisions and is filed under this jurisdiction's privacy row.
- Rule
- Per violation only
- As of
- 14 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 10,000
Who enforces it
Enforcement body
K.S.A. 50-6,139b names no dedicated regulator of its own; a violation is deemed an unconscionable act or practice under K.S.A. 50-627, and the exclusive authority to bring an action for any violation, for injunctive relief and a civil penalty under K.S.A. 50-636 of up to $10,000 per violation, rests with the Kansas Attorney General.
What it reaches
Obligation class
Security, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Any holder of personal information, defined to include any individual, partnership, corporation, trust, estate, cooperative, association, government, governmental subdivision, agency, or other entity that in the ordinary course of business collects, maintains, or possesses another person's personal information, must implement and maintain reasonable procedures and practices appropriate to the nature of the information and exercise reasonable care to protect it from unauthorized access, use, modification or disclosure.
Compliance with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this safeguards duty, and failure to comply with that other law is prima facie evidence of a violation.
Unless federal law requires otherwise, a holder must also take reasonable steps to destroy or arrange for the destruction of records containing personal information it no longer intends to maintain or possess, by shredding, erasing, or otherwise rendering the information unreadable. A holder has an affirmative defense to a violation of the destruction duty where the failure could not reasonably have been foreseen despite the holder's exercise of reasonable care in selecting a destruction method.
The defense is also available where the holder had a bona fide written or electronic records management policy reasonably designed to prevent the violation, its employees received training on the policy, the violation was a good faith error, and no reasonable likelihood exists that it may cause, enable or contribute to identity theft or identity fraud.
Each violation of this section is an unconscionable act or practice under the Kansas Consumer Protection Act's unconscionability provision, section 50-627, with each undestroyed record its own separate violation. Only the Kansas Attorney General may enforce this section. The Attorney General may seek a civil penalty of up to $10,000 per violation under the Act's civil-penalties provision, section 50-636. The section itself creates no private right of action.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
official Kansas Statutes Annotated text, Kansas Office of the Revisor of Statutes