EnglishEspañol
South Carolina flag

South Carolina

South Carolina Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 20 primary sources cited on this page. How we verify our legal content

South Carolina Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does South Carolina have a comprehensive consumer data privacy law?

No. As of May 2026, South Carolina does not have a comprehensive consumer data privacy law similar to the California Consumer Privacy Act or the Virginia Consumer Data Protection Act. South Carolina residents do not have a general statutory right to access, delete, or correct personal data held by private businesses. The state relies on breach notification requirements, the Insurance Data Security Act, the Financial Identity Fraud and Identity Theft Protection Act, and federal laws for data privacy protection. House Bill 3401 (Technology Transparency Act) has been introduced in the 2025-2026 legislative session and would establish comprehensive consumer data privacy rights if enacted, but it remains in committee as of May 2026.

What personal information is covered by South Carolina's breach notification law?

South Carolina's breach notification law (S.C. Code Ann. Section 39-1-90) covers a resident's first name or first initial and last name in combination with one or more of the following unencrypted data elements: Social Security number, driver's license number or state identification card number, financial account number, credit card number, or debit card number combined with any required security code, access code, or password, or other numbers or information that may be used to access a person's financial accounts, or numbers or information issued by a governmental or regulatory entity that uniquely identifies an individual. Publicly available information and government records lawfully available to the public are excluded from the definition. Note that South Carolina's definition is narrower than many other states and does not currently include biometric data, medical information, or online credentials.

How quickly must a business notify South Carolina residents of a data breach?

South Carolina does not set a specific number of days for breach notification. The law requires disclosure in the most expedient time possible and without unreasonable delay. The timeline must account for the legitimate needs of law enforcement and the measures necessary to determine the scope of the breach and restore system integrity. Law enforcement may request a delay if notification would impede a criminal investigation. When a breach affects more than 1,000 residents, the business must also notify the SC Department of Consumer Affairs and all nationwide consumer reporting agencies.

What are the penalties for failing to comply with South Carolina's breach notification law?

South Carolina residents injured by a breach notification violation may file a civil action. For willful and knowing violations, courts have discretion in awarding damages. For negligent violations, recovery is limited to actual damages. Successful plaintiffs may also recover attorney's fees and court costs, and may seek injunctive relief to enforce compliance. The Department of Consumer Affairs may also impose an administrative fine of $1,000 per resident whose information was accessible by reason of the breach for knowing and willful violations.

What does South Carolina's Act 37 of 2025 prohibit?

Act 37 of 2025, codified at S.C. Code Ann. Section 16-15-332 and signed on May 12, 2025, criminalizes the unauthorized disclosure of intimate images and digitally forged intimate images (including AI-generated deepfakes). A person who intentionally disseminates such images without the depicted person's effective consent commits a crime whose severity turns on intent. Disclosure with intent to harm, harass, intimidate, or profit is a felony: up to $5,000 and five years for a first offense, up to $10,000 and one to ten years for a second or subsequent offense. Disclosure without that intent is a misdemeanor for a first offense (up to $5,000 and one year) and a felony for a second or subsequent offense (up to $5,000 and five years). Dissemination of multiple intimate images of the same individual as part of a common act is a single offense.

What does the TAKE IT DOWN Act require of online platforms?

The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, requires covered online platforms to create a process for receiving reports of nonconsensual intimate visual depictions and to remove reported depictions within 48 hours of receiving notice. Platforms must also make reasonable efforts to identify and remove identical copies. The FTC began enforcing these platform requirements on May 19, 2026. A platform's failure to comply constitutes an unfair or deceptive act or practice under the FTC Act. The criminal prohibition on publishing nonconsensual intimate visual depictions took effect immediately upon the law's signing.

Does the South Carolina Insurance Data Security Act apply to all businesses?

No. The South Carolina Insurance Data Security Act (S.C. Code Ann. Title 38, Chapter 99) applies only to licensees of the South Carolina Department of Insurance, including insurance companies, agents, brokers, and adjusters. These licensees must maintain a comprehensive written information security program, conduct risk assessments, oversee third-party service providers, and notify the Director of Insurance within 72 hours of a cybersecurity event meeting specified thresholds. Under S.C. Code Ann. Section 38-99-80, which incorporates the penalty schedule in Section 38-2-10, licensed insurers, pharmacy benefits managers, and HMOs face fines of up to $15,000 per violation, or $30,000 if willful, while other licensees such as agents, brokers, and adjusters face fines of up to $2,500 per violation, or $5,000 if willful. Businesses outside the insurance industry are not covered by this Act but may be subject to federal or other state data security requirements.

What is the South Carolina Social Media Regulation Act?

The South Carolina Social Media Regulation Act (Act No. 96, HB 3431) was signed by Governor McMaster on February 5, 2026. It applies to covered online services reasonably likely to be accessed by minors and meeting specified size thresholds. Covered platforms must implement privacy-by-default settings for minor users, provide parental monitoring tools, and restrict certain account features for minors. An independent audit report is due July 1, 2026. The Act does not create general consumer data rights for adult South Carolina residents.

Updates

Corrected the Act 37 of 2025 penalty discussion, which had reversed the statute: S.C. Code Ann. Section 16-15-332(A) treats dissemination of multiple intimate images of the same individual as part of a common act as a single offense, not as separate offenses, and removed an unsupported claim that Section 1-11-490 requires state agencies to notify the State Chief Information Officer.

Corrected the Insurance Data Security Act's penalty citation and dollar amounts (agents, brokers, and adjusters face a lower cap than insurers), completed the breach-notification law's personal-information definition and financial-institution exemptions, clarified the small-licensee exemption, added two previously omitted pending privacy bills (the Digital Choice Act and the Personal Privacy Protection Act), and noted the pending federal lawsuit challenging the Social Media Regulation Act.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the Act 37 of 2025 (S.C. Code Ann. 16-15-332) penalty description, which stated a single flat penalty scale (first offense: $5,000/5yrs felony; second: $10,000/1-10yrs felony) as if it applied to every violation. The enacted bill text (HB 3058) actually splits penalties into two tracks by subsection: disclosure WITH intent to harm, harass, intimidate, or profit carries the felony tiers the article described, but disclosure WITHOUT that intent is a lesser track -- a first offense is only a misdemeanor capped at one year, and only a second-or-subsequent offense without intent becomes a felony (capped at 5 years, not 10). The article's blanket framing overstated the exposure for a first offense lacking the intent element.

Corrected the substitute-notice description: S.C. Code 39-1-90(E)(4) lists email, website posting, and media notice disjunctively ('or'), not as three mandatory requirements.

Governing law re-checked for recent changes

May 2026 refresh: added Act 37 of 2025 (S.C. Code Ann. Section 16-15-332) covering non-consensual intimate images and AI deepfake intimate imagery, signed May 12, 2025; added TAKE IT DOWN Act (Pub. L. 119-12) federal overlay with FTC enforcement effective May 19, 2026; updated South Carolina Social Media Regulation Act (Act No. 96, HB 3431) as enacted law with July 1, 2026 audit deadline; clarified Insurance Data Security Act penalty amounts (corrected August 2026: $15,000/$30,000 applies to insurers, PBMs, and HMOs under Section 38-2-10; agents, brokers, and adjusters face $2,500/$5,000); updated state count for comprehensive privacy laws to 25+; noted APRA expired without passage and not reintroduced in 119th Congress; updated pending vs. enacted legislation section to distinguish Bills 3401 and 3400 (still in committee) from enacted 3431 and 3058; added $1,000 per-resident administrative fine for breach notification violations; updated all date references from March 2026 to May 2026.

Reviewed and approved by an editor

Sources and References

  1. S.C. Code Ann. Section 39-1-90 - Breach Notification Law(scstatehouse.gov).gov
  2. SC Department of Consumer Affairs - Reporting a Security Breach(consumer.sc.gov).gov
  3. SC Department of Consumer Affairs - Security Breach Notices(consumer.sc.gov).gov
  4. South Carolina Insurance Data Security Act (Title 38, Chapter 99)(scstatehouse.gov).gov
  5. SC Department of Insurance - Cybersecurity(doi.sc.gov).gov
  6. SC Department of Insurance - Report a Cybersecurity Event Form(doi.sc.gov).gov
  7. FIFITPA Consumer Guide - SC Department of Consumer Affairs(consumer.sc.gov).gov
  8. Family Privacy Protection Act (Title 30, Chapter 2)(scstatehouse.gov).gov
  9. South Carolina Unfair Trade Practices Act (Title 39, Chapter 5)(scstatehouse.gov).gov
  10. HB 3058 - Disclosure of Intimate Images (Act 37 of 2025)(scstatehouse.gov).gov
  11. Bill 3401 - Technology Transparency Act (2025-2026 session)(scstatehouse.gov).gov
  12. Bill 3431 - SC Social Media Regulation Act (Act No. 96, 2026)(scstatehouse.gov).gov
  13. Bill 3400 - Child Data Privacy and Protection Act (2025-2026 session)(scstatehouse.gov).gov
  14. TAKE IT DOWN Act - FTC Legal Library(ftc.gov).gov
  15. FTC - Take It Down Act Enforcement Starts Now (May 2026)(ftc.gov).gov
  16. U.S. Department of Health and Human Services - HIPAA Privacy Rule(hhs.gov).gov
  17. Federal Trade Commission - Gramm-Leach-Bliley Act(ftc.gov).gov
  18. U.S. Department of Education - FERPA(ed.gov).gov
  19. Federal Trade Commission - COPPA Rule(ftc.gov).gov
  20. SC Department of Public Health - Medical Records(dph.sc.gov).gov
  21. S.C. Code Ann. Section 16-15-332 - Disseminating Intimate Images Without Consent (Title 16, Chapter 15)(scstatehouse.gov)
  22. S.C. Code Ann. Section 1-11-490 - Breach of Security of State Agency Data (Title 1, Chapter 11)(scstatehouse.gov)
Share: