EnglishEspañol
South Carolina flag

South Carolina

South Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

South Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does South Carolina have a biometric privacy law?

South Carolina does not have a standalone, general-purpose biometric privacy statute like Illinois BIPA. The state's general breach notification law (S.C. Code 39-1-90) does not explicitly list biometric data as personal identifying information. However, the Insurance Data Security Act (S.C. Code 38-99) includes biometric records as protected nonpublic information for insurance licensees, and a 2026 law (S.C. Code Title 39, Chapter 80) restricts biometric data collection by online services likely to be accessed by minors. The general-purpose SC Biometric Data Privacy Act has been proposed twice (2019 and 2021) but has not been enacted.

Can my employer collect my fingerprints without consent in South Carolina?

Yes. South Carolina has no law requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees. Employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval.

Does a biometric data breach trigger notification requirements in South Carolina?

Potentially, but the coverage is unclear. South Carolina's breach notification law (S.C. Code 39-1-90) does not explicitly list biometric data in its definition of personal identifying information. A biometric-only breach may not trigger notification obligations unless the data falls under another enumerated category. However, insurers must comply with the Insurance Data Security Act's 72-hour notification requirement, which does cover biometric records.

Can I sue a company for a data breach in South Carolina?

Yes. South Carolina allows residents to bring private lawsuits for breach notification violations. For knowing and willful violations, you can sue for damages. For negligent violations, recovery is limited to actual damages. Courts can also award attorney's fees and costs to successful plaintiffs. Additionally, businesses face a $1,000 administrative fine for each resident whose information was accessible by reason of a knowing and willful violation.

What protections does the Insurance Data Security Act provide for biometric data?

The South Carolina Insurance Data Security Act (S.C. Code 38-99) requires insurance licensees to protect biometric records as part of nonpublic information. Licensees must maintain comprehensive written information security programs, conduct periodic risk assessments, and notify the Director of Insurance within 72 hours of determining that a qualifying cybersecurity event has occurred. This law applies only to entities regulated by the Department of Insurance, not to businesses generally.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the description of enforcement under South Carolina Code 39-80-80: the statute assigns enforcement to the Attorney General but does not make that authority exclusive or address a private right of action, and it also allows officers and employees to be held personally liable for wilful and wanton violations.

Added coverage of South Carolina's 2026 law (S.C. Code Title 39, Chapter 80, effective February 5, 2026) restricting biometric data collection by online services likely to be accessed by minors, and clarified that the state's lack of a biometric privacy statute applies to general adult and employment contexts, not this narrower minors' law.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected S.C. Code 39-1-90(H)'s administrative fine from a flat '$1,000 per violation' to the statute's actual per-affected-resident basis, and removed a fabricated 'treble damages' enhancement not present in 39-1-90's civil-remedy subsection.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. S.C. Code 39-1-90 breach notification law full text(scstatehouse.gov).gov
  2. South Carolina Insurance Data Security Act (S.C. Code 38-99)(scstatehouse.gov).gov
  3. SC Department of Consumer Affairs security breach notices(consumer.sc.gov).gov
  4. SC Department of Insurance cybersecurity requirements(doi.sc.gov).gov
  5. SC Biometric Data Privacy Act Bill 4812 (2019-2020)(scstatehouse.gov).gov
  6. SC Biometric Data Privacy Act Bill 3063 (2021-2022)(scstatehouse.gov).gov
  7. South Carolina Unfair Trade Practices Act(scstatehouse.gov).gov
  8. FTC Act Section 5 enforcement authority(ftc.gov).gov
  9. HIPAA Privacy Rule(hhs.gov).gov
  10. COPPA rule on children online privacy(ftc.gov).gov
  11. Gramm-Leach-Bliley Act(ftc.gov).gov
  12. South Carolina Social Media Regulation Act, S.C. Code Title 39 Ch. 80 (2026 Act No. 96 / H.3431)(scstatehouse.gov).gov
Share: