HB 2591 allows Kansas financial institutions (like banks and credit unions) to report suspected financial exploitation of adult account holders (18+) to law enforcement or the Kansas Department for Children and Families. It permits institutions to notify a designated "trusted contact" adult and temporarily pause certain transactions for up to 10 business days (extendable to 30 days) if exploitation is suspected. The bill protects institutions from liability for these actions or inaction when taken in good faith, covering reporting, notification, and transaction holds. This directly affects adult account holders, financial institutions, and designated trusted contacts by creating a legal framework to address financial exploitation.
HB 2574 removes expiration dates from existing cybersecurity requirements for Kansas state government, making them permanent. It requires chief information security officers in all government branches to annually assess agency compliance with cybersecurity standards, report findings to the legislature, and link compliance to budget decisions. The bill creates a new judicial branch technology oversight council to set IT standards, approve plans, and oversee cybersecurity programs for courts. These changes apply directly to all executive branch agencies, the judiciary, and their IT security staff, focusing on mandatory annual reviews and alignment with national cybersecurity frameworks.
SB 410 expands Kansas' financial institutions information security law to require earned wage access service providers to comply with cybersecurity standards. It adds "earned wage access service registrants" to the list of covered entities - like credit services and mortgage companies - that must follow the state's information security rules. This means companies offering early access to earned wages (e.g., via apps or payroll services) must now implement security measures to protect customer data. The bill directly affects these providers by mandating adherence to existing cybersecurity requirements under Kansas law. The change applies to all such registrants operating in Kansas, aligning them with other financial service entities.
HB 2271 removes an expiration date for cybersecurity requirements that were set to end on July 1, 2026, making these provisions permanent. The bill requires each branch of Kansas state government to appoint a chief information security officer (CISO) responsible for developing a cybersecurity program meeting federal standards, ensuring annual employee training, and coordinating with federal cybersecurity agencies for annual audits. It also mandates that audit results remain confidential and not subject to public disclosure under Kansas' open records laws.
HB 2270 updates Kansas law to require that information technology audit reports be shared with the chief information security officer (CISO) in addition to the chief information technology officer (CITO). The bill revises statutes governing the CITO's office, clarifying that it provides data processing and cloud services to state agencies and must approve major IT equipment purchases (costing $75,000+). These changes improve coordination between security and technology teams across state government. The bill directly affects state agencies, the CITO, and the CISO in all branches (executive, legislative, judicial) when IT systems are audited.
SB 51 provides a sales tax exemption in Kansas for qualified data center construction, equipment, and eligible labor costs, targeting firms committing to a minimum $250 million investment and creating 20 new Kansas-based jobs within two years of operations. The exemption covers construction/remodeling of data centers, data center equipment (like servers and cooling systems), and installation/maintenance labor, but excludes electricity costs. To qualify, companies must register with the state, submit an application, and sign an agreement with the Commerce Secretary outlining investment and job creation commitments. Failure to meet these requirements may result in repayment of tax exemptions or termination of the benefit.
This bill establishes an Information Technology Executive Council to oversee state IT policies, including developing standards for data management, cybersecurity, and strategic IT planning across all state agencies. It requires the council to create a plan integrating executive branch IT services into a centralized office and develop a cybersecurity program for judicial branches by 2025. The bill mandates all government websites move to ".gov" domains by February 2025, requires separate budget line items for IT/cybersecurity spending, and expires July 1, 2026. It directly affects all state agencies, judicial branches, and IT operations by restructuring oversight and requiring specific reporting timelines.