Kansas Consumer Protection Act

· About Kansas Consumer Protection Act

Key Takeaways

  • The Kansas Consumer Protection Act (KCPA) is Kansas’s general unfair and deceptive practices statute, and it applies to consumer transactions rather than functioning as a comprehensive privacy law.[1][2]
  • The KCPA is enforced primarily through the Kansas Attorney General and county/district attorneys, while consumers also have a private right of action for certain violations.[3][6]
  • For violations of the Act, a court may impose civil penalties of up to $10,000 per violation, and willful violation of a court order can trigger penalties of up to $20,000 per violation.[6]
  • The KCPA does not itself create Kansas’s primary data-breach notification regime; that subject is covered by the Protection of Consumer Information Act at K.S.A. 50-7a01 et seq., which requires notice after certain breaches of personal information.[4][14]
  • As of the current 2026 materials reviewed, Kansas has no comprehensive consumer privacy law comparable to CPRA or TDPSA, and no confirmed 2025–2026 delay or broad privacy overhaul appears in the primary materials reviewed.[4][15]
  • Kansas’s consumer-protection rules are read liberally in favor of consumer protection, but liability still turns on the statutory definitions of deceptive, unconscionable, and other prohibited practices.[1][8]

What It Is

The Kansas Consumer Protection Act is Kansas’s main statute governing consumer transactions and prohibiting deceptive and unconscionable practices.[1][8] Its stated purpose is to simplify and modernize consumer-transaction law, protect consumers from deceptive and unconscionable practices, prevent unbargained-for warranty disclaimers, and provide a three-day cancellation period for door-to-door sales.[1]

The Act is codified in Chapter 50 of the Kansas Statutes and is enforced through civil actions by public prosecutors and, in some cases, by consumers themselves.[3][6] The official statutory text currently shows the Act as continuing law in the 2026 compilation.[1][6]

The KCPA was originally enacted in 1973; the official revisor text for K.S.A. 50-623 reflects legislative history showing enactment in 1973 with later amendments, and the statute’s operative effective date is shown as 1 July 1973 in the historical note.[1] The current official Kansas Legislature materials indicate the Act remains in force through the 2025–2026 session codification.[2][8]

This guide’s current-status check found no 2025–2026 amendment that converted the KCPA into a comprehensive privacy statute or delayed its core consumer-protection obligations.[4][15] The separate Kansas breach-notification framework remains in place under the Protection of Consumer Information Act.[4][14]

Who Must Comply

The KCPA applies to suppliers and other persons or businesses engaged in consumer transactions in Kansas, including conduct directed at Kansas consumers.[1][3] Its reach is transaction-based: it covers unfair or deceptive practices in the sale, lease, assignment, or other disposition of consumer goods, services, and certain other consumer transactions under the statutory scheme.[1][8]

The Act is not limited to Kansas-incorporated companies; out-of-state businesses can be reached if they engage in covered consumer transactions involving Kansas consumers or Kansas commerce.[1][3] Private and public enforcement provisions mean that a non-Kansas business can face suit in Kansas if its conduct falls within the Act’s scope.[3][6]

The KCPA is not a comprehensive data-privacy law with a numerical threshold such as revenue or processing volume.[4][15] Kansas’s separate breach-notification law applies to entities that conduct business in Kansas and experience a qualifying breach of personal information, regardless of industry, subject to statutory exceptions.[4][14]

Exemptions are narrower than in modern privacy statutes and typically arise from the text of the statute, such as conduct outside a consumer transaction or conduct otherwise regulated by specific federal or state law.[1][8] The Act is construed liberally, but it is still limited to the practices the statute actually proscribes.[1]

Core Requirements

  1. Do not engage in deceptive practices. The Act prohibits false, misleading, or deceptive statements and omissions in consumer transactions, including representations that would mislead a reasonable consumer.[1][8]
  1. Do not engage in unconscionable acts. Suppliers may not use bargaining power, pressure, or other conduct that is unconscionable under the statute’s framework.[1][8]
  1. Honor consumer cancellation rights where the statute grants them. The KCPA preserves a three-day cancellation period for covered door-to-door sales and similar statutory protections.[1]
  1. Avoid unlawful warranty disclaimers and unfair contract terms. The statute is designed in part to prevent consumers from being bound by unbargained-for disclaimer terms in covered transactions.[1]
  1. Maintain truthful privacy and security disclosures. Although the KCPA is not the primary breach-notification law, misleading claims about data security, privacy practices, or breach handling can still create KCPA exposure if they are deceptive in consumer transactions.[1][4]
  1. Provide legally required breach notices under the separate Kansas breach-notification law when applicable. Entities subject to the Protection of Consumer Information Act must notify affected individuals after qualifying breaches of personal information in the manner and time the statute requires.[4][14]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | KCPA originally enacted | 1973 | Kansas adopts the Consumer Protection Act framework.[1] | | KCPA effective date in historical note | 1 July 1973 | The Act’s statutory history reflects this effective date.[1] | | Current codification in force | 2026 compilation | The Act remains active in the Kansas statutes.[2][8] | | Separate breach-notification law operative | 2006 onward | Kansas breach notice rules apply under K.S.A. 50-7a01 et seq.[4][14] |

Maximum sanctions under the KCPA include a civil penalty of not more than $10,000 for each violation in actions brought as authorized by the statute.[6] A supplier that willfully violates a court order issued under the Act can be fined not more than $20,000 per violation.[6]

Other sanctions include attorney general or county/district attorney enforcement, private consumer suits in appropriate cases, and recovery of reasonable expenses and investigation fees where authorized.[3][6] Because continuing violations can be treated as separate violations each day they persist, exposure can escalate quickly in an ongoing deceptive-practice matter.[6]

How to Comply

  1. Map every consumer-facing claim. Inventory website statements, sales scripts, app disclosures, chat responses, contract language, and privacy notices to ensure they are not misleading under the KCPA.[1][8]
  1. Align legal review with a deceptive-practices control. Build a review gate for marketing and product disclosures that tests whether claims are substantiated and whether omissions could mislead a reasonable consumer.[1]
  1. Adopt a consumer complaint intake and remediation process. Documented complaint handling helps detect recurring issues before they become AG enforcement matters or private lawsuits.[3][6]
  1. Use ISO 27001 and NIST CSF 2.0 for security governance. These frameworks map well to the security controls, risk management, incident handling, and evidence preservation needed to support truthful security representations and breach response.[4][14]
  1. Use ISO 42001 for AI-enabled consumer interactions. Where chatbots or automated decision tools make consumer-facing statements, AI management controls help reduce hallucinated or inaccurate representations that could become deceptive-practice issues.[1]
  1. Separate breach-notification playbooks from general privacy notices. Kansas breach duties arise under the Protection of Consumer Information Act, so incident response should have state-specific decision trees for notice timing, content, and recipient lists.[4][14]
  1. Train marketing, sales, and support teams. Front-line staff often create KCPA risk through informal promises or unsupported privacy/security claims, so training should emphasize approved language and escalation triggers.[1][3]

Related Regulations

  • Protection of Consumer Information Act (K.S.A. 50-7a01 et seq.) governs notification after certain breaches of personal information and is Kansas’s primary data-breach law.[4][14]
  • FTC Act Section 5 overlaps because unfair or deceptive acts in commerce can be pursued federally, especially when consumer privacy or security claims are misleading.
  • Kansas breach-related student data laws may impose separate notice duties for educational records and student personal information, which can be stricter than the general breach law.[10]
  • HIPAA can preempt or supplement state breach duties for covered entities and business associates handling protected health information.
  • GLBA can overlap for financial institutions, where federal privacy and safeguard rules can sit alongside Kansas consumer-protection expectations.

FAQ

Does the Kansas Consumer Protection Act apply to companies outside Kansas?

Yes, if an out-of-state company engages in covered consumer transactions involving Kansas consumers or Kansas commerce, the Act can still apply.[1][3] The statute is transaction-focused, not incorporation-focused, so the key question is whether the conduct falls within the Act’s reach.[1]

Does the KCPA create Kansas’s data-breach notice rule?

No. Kansas’s breach-notification rule is found in the separate Protection of Consumer Information Act at K.S.A. 50-7a01 et seq.[4][14] The KCPA can still matter if a company makes deceptive statements about security, privacy, or breach response.[1]

What are the maximum penalties under the KCPA?

A civil penalty of up to $10,000 per violation may be imposed for a violation of the Act, and a willful violation of a court order can result in up to $20,000 per violation.[6] Continuing conduct may be counted as separate daily violations.[6]

Who enforces the KCPA?

The Kansas Attorney General and county/district attorneys may bring actions under the statute, and consumers may have private remedies in some circumstances.[3][6] Enforcement can therefore come from both public and private plaintiffs.[3][6]

Is Kansas a comprehensive privacy-law state in 2026?

No comprehensive Kansas consumer privacy law appeared in the primary materials reviewed, and Kansas is still operating mainly with the KCPA plus the separate breach-notification law.[4][15] The current 2026 materials did not show a finalized 2025–2026 broad privacy statute or a delay to one.[4][15]

Sources

Put it into practice

More compliance guides