Law / United States / Kansas

Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information

K.S.A. 50-6,139b

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 July 2016.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds any holder of personal information: any individual, partnership, corporation, trust, estate, cooperative, association, government, governmental subdivision, agency, or other entity that in the ordinary course of business collects, maintains, or possesses another person's personal information.
  • Implement and maintain reasonable procedures and practices appropriate to the nature of the information, and exercise reasonable care to protect it from unauthorized access, use, modification, or disclosure. Being subject to and compliant with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this duty.
  • Unless a federal law or regulation requires otherwise, destroy or arrange for the destruction of records containing personal information once you no longer intend to maintain or possess them, by shredding, erasing, or otherwise rendering the personal information unreadable or undecipherable.
  • There is no private right of action. Only the Kansas Attorney General may enforce this section, as an unconscionable act or practice under the Kansas Consumer Protection Act, seeking a civil penalty of up to $10,000 per violation under K.S.A. 50-636.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Civil penalty under K.S.A. 50-636(a) for a violation deemed an unconscionable act or practice under K.S.A. 50-627; the statute names no aggregate cap and each undestroyed record is a separate violation. Kansas's separate breach-notification statute, K.S.A. 50-7a01 through 50-7a04, carries its own enforcement provisions and is filed under this jurisdiction's privacy row.

Rule
Per violation only
As of
14 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
10,000

Who enforces it

Enforcement body

K.S.A. 50-6,139b names no dedicated regulator of its own; a violation is deemed an unconscionable act or practice under K.S.A. 50-627, and the exclusive authority to bring an action for any violation, for injunctive relief and a civil penalty under K.S.A. 50-636 of up to $10,000 per violation, rests with the Kansas Attorney General.

What it reaches

Obligation class

Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any holder of personal information, defined to include any individual, partnership, corporation, trust, estate, cooperative, association, government, governmental subdivision, agency, or other entity that in the ordinary course of business collects, maintains, or possesses another person's personal information, must implement and maintain reasonable procedures and practices appropriate to the nature of the information and exercise reasonable care to protect it from unauthorized access, use, modification or disclosure.

Compliance with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this safeguards duty, and failure to comply with that other law is prima facie evidence of a violation.

Unless federal law requires otherwise, a holder must also take reasonable steps to destroy or arrange for the destruction of records containing personal information it no longer intends to maintain or possess, by shredding, erasing, or otherwise rendering the information unreadable. A holder has an affirmative defense to a violation of the destruction duty where the failure could not reasonably have been foreseen despite the holder's exercise of reasonable care in selecting a destruction method.

The defense is also available where the holder had a bona fide written or electronic records management policy reasonably designed to prevent the violation, its employees received training on the policy, the violation was a good faith error, and no reasonable likelihood exists that it may cause, enable or contribute to identity theft or identity fraud.

Each violation of this section is an unconscionable act or practice under the Kansas Consumer Protection Act's unconscionability provision, section 50-627, with each undestroyed record its own separate violation. Only the Kansas Attorney General may enforce this section. The Attorney General may seek a civil penalty of up to $10,000 per violation under the Act's civil-penalties provision, section 50-636. The section itself creates no private right of action.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official Kansas Statutes Annotated text, Kansas Office of the Revisor of Statutes

Back to the example  ·  Lint your app