Kansas
Kansas Biometric Privacy Laws: What You Need to Know (2026)

Kansas has no dedicated biometric privacy law and its breach notification statute, K.S.A. 50-7a01, does not cover biometric data. The sole exception is the Student Data Privacy Act, K.S.A. 72-6315, which requires written parental consent before K-12 schools may collect student biometric information.
Kansas is one of the majority of U.S. states that have not enacted a dedicated biometric privacy law. If you work in Kansas, use biometric time clocks at your job, or simply wonder whether your fingerprint or face scan data has legal protection, the short answer is: very little at the state level.
This guide covers every Kansas statute that touches biometric data, the limited protections that do exist, federal laws that fill some of the gaps, and what Kansas residents and businesses should know in 2026.
For broader context on how Kansas handles personal data, see our Kansas Data Privacy Laws overview.

Kansas Does Not Have a Biometric Privacy Law
Kansas has not passed any law comparable to the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, or the Washington Biometric Identifier statute. There is no Kansas statute that requires businesses or employers to:
- Obtain consent before collecting fingerprints, facial geometry, iris scans, voiceprints, or other biometric identifiers
- Provide written notice explaining how biometric data will be used or stored
- Establish retention and destruction schedules for biometric records
- Limit the sale or sharing of biometric information with third parties
This means that a private employer in Kansas can generally implement fingerprint-based time clocks, facial recognition access systems, or other biometric tools without any state-mandated consent or disclosure obligations specific to biometric data.
Kansas Breach Notification Law and Biometric Data
The Kansas Protection of Consumer Information Act (K.S.A. 50-7a01 through 50-7a04) requires businesses to notify Kansas residents when a security breach exposes their personal information. However, the law defines "personal information" narrowly. Under K.S.A. 50-7a01(g), protected data elements include only:
- Social Security numbers
- Driver's license or state identification card numbers
- Financial account numbers, credit card numbers, or debit card numbers in combination with security codes or passwords that would allow account access
Biometric data is not listed. A breach that exposes fingerprint templates, facial recognition data, or other biometric identifiers does not trigger notification obligations under this statute.
This stands in contrast to states like California, New York, and Illinois, which have amended their breach notification laws to explicitly include biometric information.
For details on what Kansas's breach law does cover, see our Kansas Data Breach Notification Laws guide.
Student Data Privacy Act: The One Exception
The only Kansas statute that directly addresses biometric data is the Student Data Privacy Act (K.S.A. 72-6311 through 72-6320). The biometric-data provision, K.S.A. 72-6315, was enacted in 2014, though the broader student-privacy framework dates back to 1976.

What the Law Requires
Under K.S.A. 72-6315, no school district may collect biometric data from a student, or use any device or mechanism to assess a student's physiological or emotional state, unless the student (if an adult) or the parent or legal guardian (if a minor) provides written consent.
How Kansas Defines Biometric Data
K.S.A. 72-6313 defines "biometric data" as "one or more measurable biological or behavioral characteristics that can be used for automated recognition of an individual." The statute lists these examples:
- Fingerprints
- Retina and iris patterns
- Voiceprints
- DNA sequences
- Facial characteristics
- Handwriting
Enforcement
The Kansas Attorney General or a district attorney may enforce the Student Data Privacy Act by bringing a court action and seeking injunctive relief against any educational agency, employee, or agent that violates the law. Complaints about student data privacy violations can be filed with the Kansas Attorney General's office.
This law applies only to school districts and the Kansas Department of Education. It does not apply to private employers, businesses, landlords, or any other entity outside the K-12 education system.
Kansas Consumer Protection Act
The Kansas Consumer Protection Act (K.S.A. 50-623 et seq.) prohibits deceptive and unconscionable trade practices. While the statute does not mention biometric data by name, the Kansas Attorney General could potentially use these broad consumer protection powers to take action against a business that collects biometric data through deceptive means.
Additionally, K.S.A. 50-6,139b requires any entity that holds personal information to "implement and maintain reasonable procedures and practices appropriate to the nature of the information" and to take "reasonable steps to destroy" records when they are no longer needed. Violations are treated as unconscionable acts under the Consumer Protection Act, and enforcement authority rests exclusively with the Attorney General.
However, no Kansas court has applied these provisions specifically to biometric data as of March 2026.

Federal Laws That Protect Biometric Data in Kansas
Because Kansas lacks a comprehensive state-level biometric law, federal statutes provide the primary protections for Kansas residents in certain contexts.
HIPAA
The Health Insurance Portability and Accountability Act protects biometric data when it is collected or maintained by covered healthcare entities and their business associates. Fingerprints, voiceprints, and facial images qualify as protected health information when linked to a patient's medical records.
COPPA
The Children's Online Privacy Protection Act requires parental consent before websites and online services collect personal information from children under 13. The FTC's rules define personal information to include photographs, videos, and audio files containing a child's image or voice, which can function as biometric identifiers.
FTC Act Section 5
The Federal Trade Commission Act prohibits unfair and deceptive trade practices. The FTC has used this authority to take enforcement actions against companies that mishandle biometric data or make misleading promises about how they protect it. This applies nationwide, including in Kansas.
ADA
The Americans with Disabilities Act may limit how employers use certain biometric collection methods if those methods disproportionately affect employees with disabilities. For example, fingerprint scanners may not work reliably for individuals with certain skin conditions.
What This Means for Kansas Employers
Kansas employers who use biometric technology for timekeeping, access control, or security face no state-specific biometric consent requirements. However, prudent employers should still consider these practical steps:

- Provide written notice before collecting any biometric data, even though Kansas does not require it. This reduces legal risk if Kansas passes a biometric law with retroactive elements or if an employee relocates from a state with stricter requirements.
- Establish a retention policy that specifies how long biometric data will be stored and when it will be destroyed.
- Limit access to biometric databases to authorized personnel only.
- Monitor federal developments, including proposed biometric provisions in federal privacy legislation.
Employers with operations in multiple states must comply with the strictest applicable law. If a Kansas-based company has employees in Illinois, Texas, or Washington, those employees' biometric data is subject to the laws of their respective states.
Legislative Outlook
As of March 2026, the Kansas Legislature has not introduced a dedicated biometric privacy bill during the 2025-2026 session. Kansas also has not enacted a comprehensive consumer data privacy law comparable to those in effect in California, Virginia, or Colorado.
The national trend, however, continues moving toward broader biometric protections. Multiple states introduced biometric privacy bills during 2025 and 2026 legislative sessions, and more than 20 states now have comprehensive privacy laws that include biometric data provisions. Kansas may eventually follow this trend, but no specific timeline exists.
This article is for informational purposes only and does not constitute legal advice. Biometric privacy law is evolving rapidly at both the state and federal levels. Consult a qualified attorney licensed in Kansas for guidance on your specific situation.
More Kansas Laws
Frequently Asked Questions
Does Kansas have a biometric privacy law like Illinois BIPA?
No. Kansas has not enacted a dedicated biometric privacy statute. Unlike Illinois, Texas, and Washington, Kansas does not require businesses or employers to obtain consent before collecting fingerprints, facial scans, or other biometric identifiers. The only Kansas law addressing biometric data collection is the Student Data Privacy Act, which applies exclusively to K-12 school districts.
Can my Kansas employer require me to use a fingerprint scanner without my consent?
Under current Kansas law, yes. No state statute requires private employers in Kansas to obtain consent before collecting biometric data for timekeeping or security purposes. However, federal laws like the ADA may apply in limited circumstances, and employers with workers in other states must follow the biometric laws of those states.
Does a biometric data breach in Kansas trigger notification requirements?
Not under Kansas law. The Kansas breach notification statute (K.S.A. 50-7a01) only covers Social Security numbers, driver's license numbers, and financial account information. Biometric data is not included. A breach exposing only biometric identifiers would not require notification to affected Kansas residents under state law.
Are Kansas schools allowed to collect fingerprints from students?
Only with written consent. The Kansas Student Data Privacy Act (K.S.A. 72-6315) prohibits school districts from collecting biometric data from students unless the student (if an adult) or the parent or legal guardian (if a minor) provides written consent. Biometric data includes fingerprints, iris patterns, voiceprints, facial characteristics, and handwriting.
What federal laws protect biometric data for Kansas residents?
HIPAA protects biometric data held by healthcare providers and their associates. COPPA requires parental consent before collecting biometric-capable data from children under 13 online. The FTC Act allows the Federal Trade Commission to take action against companies that engage in unfair or deceptive biometric data practices. The ADA may also limit certain biometric collection methods that affect employees with disabilities.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected: Verified against the mirrored statutes table: K.
Governing law re-checked for recent changes
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 6 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Kansas Statutes Annotated, Chapter 50: UNFAIR TRADE AND CONSUMER PROTECTION
§ 50-623Kansas consumer protection act; purpose; construction.In forcecited in 4 of our articles
This act shall be construed liberally to promote the following policies: (a) To simplify, clarify and modernize the law governing consumer transactions; (b) to protect consumers from suppliers who commit deceptive and unconscionable practices; (c) to protect consumers from unbargained for warranty disclaimers; and (d) to provide consumers with a three-day cancellation period for door-to-door sales.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ksrevisor.gov
Also relied on in: Kansas AI Laws and Regulation (2026), Kansas Data Privacy Laws: Breach Notification & Consumer Rights (2026), Kansas Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 50-7a01Consumer information; security breach; definitions.In forcecited in 3 of our articles
As used in K.S.A. 50-7a01 and 50-7a02, and amendments thereto: (a) "Consumer" means an individual who is a resident of this state. (b) "Encrypted" means transformation of data through the use of algorithmic process into a form in which there is a low probability of assigning meaning without the use of a confidential process or key, or securing the information by another method that renders the data elements unreadable or unusable. (c) "Notice" means: (1) Written notice; (2) electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or (3) substitute notice, if the individual or the commercial entity required to provide notice demonstrates that the cost of providing notice will exceed $100,000, or that the affected class of consumers to be notified exceeds 5,000, or that the individual or the commercial entity does not have sufficient contact information to provide notice.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ksrevisor.gov
§ 50-7a02Security breach; requirements.In forcecited in 3 of our articles
(a) A person that conducts business in this state, or a government, governmental subdivision or agency that owns or licenses computerized data that includes personal information shall, when it becomes aware of any breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused. If the investigation determines that the misuse of information has occurred or is reasonably likely to occur, the person or government, governmental subdivision or agency shall give notice as soon as possible to the affected Kansas resident. Notice must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ksrevisor.gov
Kansas Statutes Annotated, Chapter 72: SCHOOLS
§ 72-6311Right of privacy policies; definitions.In forcecited in 2 of our articles
(a) As used in this section, the following terms shall have the meanings respectively ascribed to them unless the context requires otherwise: (1) "Board" means the state board of regents, the state board of education, the board of trustees of any public community college, the board of regents of any municipal university, the governing board of any technical college and the board of education of any school district. (2) "Student" means a person who has attained 18 years of age, or is attending an institution of postsecondary education. (3) "Pupil" means a person who has not attained 18 years of age and is attending an educational institution below the postsecondary level. (b) Every board shall adopt a policy in accordance with the student data privacy act and applicable federal laws and regulations to protect the right of privacy of any student, or pupil and such pupil's family regarding personally identifiable records, files and data directly related to such student or pupil. The board shall adopt and implement procedures to effectuate such policy by January 1, 1977.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ksrevisor.gov
§ 72-6313Definitions.In force
As used in K.S.A. 72-6312 through 72-6320, and amendments thereto: (a) "Aggregate data" means data collected or reported at the group, cohort or institutional level and which contains no personally identifiable student data. (b) "Biometric data" means one or more measurable biological or behavioral characteristics that can be used for automated recognition of an individual, such as fingerprints, retina and iris patterns, voiceprints, DNA sequence, facial characteristics and handwriting. (c) "Department" means the state department of education. (d) "Directory information" means a student's name, address, telephone listing, participation in officially recognized activities and sports, weight and height if the student is a member of an athletic team, and degrees, honors or awards received. (e) "Educational agency" means a school district or the department. (f) "School district" means a unified school district organized and operated under the laws of this state.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ksrevisor.gov
§ 72-6315Collection of biometric data prohibited.In force
No school district shall collect biometric data from a student, or use any device or mechanism to assess a student's physiological or emotional state, unless the student, if an adult, or the parent or legal guardian of the student, if a minor, consents in writing.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ksrevisor.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- K.S.A. 50-7a01 - Consumer information security breach definitions(ksrevisor.gov).gov
- K.S.A. 50-7a02 - Security breach notification requirements(ksrevisor.gov).gov
- K.S.A. 72-6315 - Student Data Privacy Act biometric data provisions(kslegislature.gov).gov
- K.S.A. 72-6313 - Student Data Privacy Act definitions including biometric data(ksrevisor.gov).gov
- K.S.A. 50-623 - Kansas Consumer Protection Act(ksrevisor.gov).gov
- K.S.A. 50-6,139b - Personal information protection requirements(ksrevisor.gov).gov
- Kansas Attorney General - Student Data Privacy complaints(ag.ks.gov).gov
- HIPAA - Health Insurance Portability and Accountability Act(hhs.gov).gov
- COPPA - Children's Online Privacy Protection Rule(ftc.gov).gov
- Federal Trade Commission Act(ftc.gov).gov
- Americans with Disabilities Act(ada.gov).gov