South Carolina
South Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

South Carolina has no general-purpose biometric privacy law covering private businesses' collection of biometric data from adults. The state's general breach notification statute (S.C. Code 39-1-90) does not list biometric data as protected information. The Insurance Data Security Act (S.C. Code 38-99) covers biometric records for insurance licensees only. In 2026, South Carolina enacted a narrower law restricting how online services likely to be accessed by minors may collect and use biometric data (S.C. Code Title 39, Chapter 80). Separate general-purpose bills modeled on Illinois BIPA have stalled without becoming law.
South Carolina does not have a general-purpose biometric privacy law covering adults. Unlike Illinois, Texas, and Washington, the state has not enacted legislation that broadly regulates how private businesses collect, store, use, or share biometric identifiers such as fingerprints, facial geometry, or iris scans from adult consumers. It has, however, enacted a narrower 2026 law that restricts biometric data collection specifically by online services reasonably likely to be accessed by minors.
South Carolina's existing data protections touch biometric data in limited and indirect ways. The state's general breach notification law does not explicitly list biometric data in its definition of personal identifying information. However, the Insurance Data Security Act includes biometric records as part of protected nonpublic information for insurance licensees, and a 2026 law now restricts biometric data collection by online services likely to be accessed by minors. A separate general-purpose SC Biometric Data Privacy Act modeled on Illinois BIPA has been proposed twice but has not advanced into law.
This guide explains the current legal framework, what protections exist, where the gaps are, and what proposed legislation could change.
For broader context on South Carolina's overall privacy framework, see the parent guide to South Carolina Data Privacy Laws.
South Carolina Breach Notification Law (S.C. Code 39-1-90)
South Carolina's primary data breach law is codified at S.C. Code 39-1-90. This law requires businesses conducting business in South Carolina to notify residents when their personal identifying information has been compromised in a data breach.
Definition of Personal Identifying Information
Under S.C. Code 39-1-90, "personal identifying information" means an individual's first name or first initial and last name combined with one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to a financial account
- Other numbers or information that may be used to access a person's financial accounts, or numbers or information issued by a governmental or regulatory entity that uniquely identifies an individual
Biometric data is not explicitly listed as a category of personal identifying information under this statute. The fourth category, covering "other numbers or information" issued by a governmental entity that uniquely identifies an individual, could theoretically encompass some government-held biometric data, but this interpretation is untested.
This limited scope means that a breach exposing fingerprint templates, facial recognition data, or iris scans stored by a private company may not trigger notification obligations under S.C. Code 39-1-90 unless that data also falls under one of the enumerated categories.
Notification Requirements
When a breach is discovered, the business must disclose it to affected residents "in the most expedient time possible and without unreasonable delay," consistent with the legitimate needs of law enforcement and measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
If a business provides notice to more than 1,000 people at one time, it must also notify the Consumer Protection Division of the South Carolina Department of Consumer Affairs and all nationwide consumer reporting agencies without unreasonable delay.
Penalties and Enforcement
Administrative fines. A person who knowingly and willfully violates S.C. Code 39-1-90 is subject to an administrative fine of $1,000 for each resident whose information was accessible by reason of the breach.
Private right of action. South Carolina is one of the states that allows individuals to sue for breach notification violations. A resident injured by a violation may:
- Institute a civil action to recover damages for a willful and knowing violation
- Institute a civil action limited to actual damages for a negligent violation
- Seek an injunction to enforce compliance
- Recover attorney's fees and court costs if successful
Unfair Trade Practices. A violation of the breach notification law may also be actionable under the South Carolina Unfair Trade Practices Act (S.C. Code 39-5-10 et seq.), which provides additional remedies.
Exemptions
Financial institutions that are subject to and in compliance with the federal Gramm-Leach-Bliley Act are considered in compliance with S.C. Code 39-1-90.

South Carolina Insurance Data Security Act (S.C. Code 38-99)
The Insurance Data Security Act, enacted in 2018, provides stronger protections for biometric data within the insurance industry specifically.
Under S.C. Code 38-99-10, "nonpublic information" includes biometric records as a protected data element alongside Social Security numbers, driver's license numbers, account numbers, and security codes. Licensed insurers, insurance producers, and other entities regulated by the South Carolina Department of Insurance must protect this nonpublic information.
Key Requirements for Insurers
Information security program. Licensees must develop, implement, and maintain a comprehensive written information security program that protects nonpublic information, including biometric records.
Risk assessment. Licensees must conduct periodic risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorized access to nonpublic information.
72-hour notification. A licensee must notify the Director of the South Carolina Department of Insurance no later than 72 hours after determining that a cybersecurity event has occurred that meets certain criteria.
Consumer notification. Licensees must notify affected consumers as required by S.C. Code 39-1-90 and other applicable state and federal laws.
This Act is significant because it explicitly includes biometric records in its definition of protected information, filling a gap left by the general breach notification statute.

South Carolina's 2026 Minors' Online Privacy Law (S.C. Code Title 39, Chapter 80)
In February 2026, South Carolina enacted the South Carolina Social Media Regulation Act (2026 Act No. 96 / H.3431), ratified February 3, 2026, and approved by the Governor February 5, 2026, effective on that date. The act adds a new Chapter 80 to Title 39 of the S.C. Code and is the first South Carolina statute to expressly treat biometric data as sensitive personal data, though only within a narrow scope.
Section 39-80-10(18)(g) defines sensitive personal data to include biometric data collected for the purpose of uniquely identifying an individual. The chapter applies to covered online services, meaning businesses that conduct business in South Carolina, are reasonably likely to be accessed by minors, and meet a revenue or data-volume threshold (more than 25 million dollars in annual gross revenue, or personal data from 50,000 or more consumers, households, or devices annually, among other criteria).
For those covered online services, Section 39-80-40 requires collecting, using, or sharing only the minimum amount of a minor's personal data, including biometric data, necessary to provide the service the minor knowingly engaged with, bars using data collected for age verification for any other purpose, and requires it be deleted after use. The chapter also bars targeted advertising directed at minors. Section 39-80-80 assigns enforcement to the Attorney General and makes a covered online service liable for treble the financial damages incurred as a result of a violation. It also provides that officers and employees of a covered online service may be held personally liable for wilful and wanton violations of the chapter. The statute does not expressly address whether a private right of action exists.
This law is narrower than a general biometric privacy statute. It does not create consent or deletion rights for adults, and it does not regulate employer collection of biometric data from employees. Businesses that collect biometric data only from adult consumers, or only in an employment context, are not covered by Chapter 80.
What South Carolina Law Does Not Cover
South Carolina's existing laws leave significant gaps in biometric privacy protection.
No consent requirement for biometric data collection. South Carolina does not require businesses or employers to obtain consent before collecting biometric data from adults. Companies can implement fingerprint time clocks or facial recognition systems without providing notice or obtaining approval.
No retention or destruction timelines. The state does not mandate specific retention schedules or destruction timelines for biometric data held by private entities.
No general restrictions on biometric data sales. Outside the narrow minors' online-services restrictions in S.C. Code Title 39, Chapter 80 (discussed above), South Carolina does not prohibit or restrict the sale or sharing of biometric data with third parties.
Limited breach notification coverage. The general breach notification law does not explicitly list biometric data as personal identifying information, leaving a potential gap in notification obligations for biometric-only breaches.
No law enforcement restrictions. South Carolina has not enacted limits on government or law enforcement use of facial recognition or other biometric surveillance technologies.
Employer Use of Biometric Data in South Carolina
South Carolina has no state law that restricts employers from collecting biometric data from employees. Companies operating in South Carolina that use fingerprint scanners for timekeeping, facial recognition for building access, or other biometric systems are not required by state law to:
- Provide written notice before collecting biometric data
- Obtain employee consent
- Establish data retention or destruction policies
- Limit sharing of employee biometric data with vendors or third parties
This stands in sharp contrast to Illinois, where employers face statutory damages of $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
Pending Legislation

South Carolina has seen multiple attempts to pass a general-purpose, Illinois-style biometric privacy law. None of those general bills has been enacted, though in 2026 the legislature did pass a narrower minors-focused online privacy law that touches biometric data (S.C. Code Title 39, Chapter 80, discussed above).
SC Biometric Data Privacy Act (Bill 4812, 2019-2020 Session). This bill proposed comprehensive biometric privacy protections modeled in part on Illinois BIPA. It would have required businesses to obtain written consent before collecting biometric information, allowed consumers to request deletion of their biometric data, prohibited the sale of biometric information, and established standards of care for businesses collecting biometric data. The bill was introduced in December 2019 but did not advance.
SC Biometric Data Privacy Act (Bill 3063, 2021-2022 Session). A reintroduced version of the biometric privacy bill was filed again in December 2020. It contained similar provisions, including requirements to inform consumers of the purpose for collection, obtain consent, and limit the use and sharing of biometric data. This version also did not advance.
Neither general bill has been enacted. If a future SC Biometric Data Privacy Act passes, it would create significant new obligations for businesses collecting biometric information from adults in South Carolina, obligations that go well beyond the minors-focused restrictions already in effect under Chapter 80.
Federal Protections That Apply in South Carolina
Because South Carolina lacks a comprehensive biometric privacy law, federal statutes provide additional protections for residents.
Section 5 of the FTC Act allows the Federal Trade Commission to take enforcement action against companies engaged in unfair or deceptive practices involving biometric data.
HIPAA protects biometric data collected or used by covered healthcare entities and their business associates under the Privacy Rule.
COPPA requires parental consent before collecting biometric data from children under 13, enforced by the FTC.
How South Carolina Compares to Other States
South Carolina falls into a lower tier of states for biometric privacy protection. The omission of biometric data from the general breach notification law's definition of personal identifying information is a notable gap.
- Illinois has the strongest biometric law in the nation (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (Colorado, Connecticut, Virginia) classify biometric data as sensitive and require opt-in consent
- South Carolina protects biometric data mainly through the Insurance Data Security Act (for insurers), a 2026 law restricting biometric data collection by online services accessed by minors, and general unfair trade practices enforcement, with no explicit biometric coverage in its general breach notification law and no general-purpose consent or deletion rights for adults
This article provides general legal information about South Carolina biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in South Carolina for advice about your specific situation.
More South Carolina Laws
Frequently Asked Questions
Does South Carolina have a biometric privacy law?
South Carolina does not have a standalone, general-purpose biometric privacy statute like Illinois BIPA. The state's general breach notification law (S.C. Code 39-1-90) does not explicitly list biometric data as personal identifying information. However, the Insurance Data Security Act (S.C. Code 38-99) includes biometric records as protected nonpublic information for insurance licensees, and a 2026 law (S.C. Code Title 39, Chapter 80) restricts biometric data collection by online services likely to be accessed by minors. The general-purpose SC Biometric Data Privacy Act has been proposed twice (2019 and 2021) but has not been enacted.
Can my employer collect my fingerprints without consent in South Carolina?
Yes. South Carolina has no law requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees. Employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval.
Does a biometric data breach trigger notification requirements in South Carolina?
Potentially, but the coverage is unclear. South Carolina's breach notification law (S.C. Code 39-1-90) does not explicitly list biometric data in its definition of personal identifying information. A biometric-only breach may not trigger notification obligations unless the data falls under another enumerated category. However, insurers must comply with the Insurance Data Security Act's 72-hour notification requirement, which does cover biometric records.
Can I sue a company for a data breach in South Carolina?
Yes. South Carolina allows residents to bring private lawsuits for breach notification violations. For knowing and willful violations, you can sue for damages. For negligent violations, recovery is limited to actual damages. Courts can also award attorney's fees and costs to successful plaintiffs. Additionally, businesses face a $1,000 administrative fine for each resident whose information was accessible by reason of a knowing and willful violation.
What protections does the Insurance Data Security Act provide for biometric data?
The South Carolina Insurance Data Security Act (S.C. Code 38-99) requires insurance licensees to protect biometric records as part of nonpublic information. Licensees must maintain comprehensive written information security programs, conduct periodic risk assessments, and notify the Director of Insurance within 72 hours of determining that a qualifying cybersecurity event has occurred. This law applies only to entities regulated by the Department of Insurance, not to businesses generally.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the description of enforcement under South Carolina Code 39-80-80: the statute assigns enforcement to the Attorney General but does not make that authority exclusive or address a private right of action, and it also allows officers and employees to be held personally liable for wilful and wanton violations.
Added coverage of South Carolina's 2026 law (S.C. Code Title 39, Chapter 80, effective February 5, 2026) restricting biometric data collection by online services likely to be accessed by minors, and clarified that the state's lack of a biometric privacy statute applies to general adult and employment contexts, not this narrower minors' law.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected S.C. Code 39-1-90(H)'s administrative fine from a flat '$1,000 per violation' to the statute's actual per-affected-resident basis, and removed a fabricated 'treble damages' enhancement not present in 39-1-90's civil-remedy subsection.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
South Carolina Code of Laws, Title 39: TRADE AND COMMERCE
§ 39-1-90Business data, breach of security; notifications, definitions, penalties, and exceptionsIn forcecited in 4 of our articles
(A) A person conducting business in this State, and owning or licensing computerized data or other data that includes personal identifying information, shall disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of this State whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (C), or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at scstatehouse.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):Federal courts treat 39-1-90 as two separate claims. Allen v. Blackbaud (2021) held that possessing or hosting data does not make a company one owning or licensing it under subsection (A). Roper v. Rise Interactive (2023) dismissed an (A) claim but let a subsection (B) notice claim proceed.
Opinions citing this section in our collection:
- Roper v. Rise Interactive Media & Analytics, LLC (District Court, N.D. Illinois 2023)✓A patient sued a marketing vendor that got her data from a medical supplier and told her of a possible breach two months later; the court dismissed her subsection (A) claim because she did not plead the vendor owned or licensed the data, but let the subsection (B) claim proceed.
- Crosby v. OneTouchPoint Inc (District Court, E.D. Wisconsin 2024)✓A healthcare mailing vendor notified a South Carolina plaintiff of an April 2022 breach three months later; the court held she adequately alleged the vendor owned or licensed her data through its contracts with health insurers and that the delay was plausibly untimely.
- Allen v. Blackbaud Inc (District Court, D. South Carolina 2021)✓After a ransomware attack on a cloud software company that hosted data nonprofits had entrusted to it, South Carolina plaintiffs sued; the court dismissed their claim, holding that possessing data is not enough to make a company one that owns or licenses it under subsection (A).
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: South Carolina Data Privacy Laws: Breach Notification & Consumer Rights (2026), South Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026), South Carolina Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- S.C. Code 39-1-90 breach notification law full text(scstatehouse.gov).gov
- South Carolina Insurance Data Security Act (S.C. Code 38-99)(scstatehouse.gov).gov
- SC Department of Consumer Affairs security breach notices(consumer.sc.gov).gov
- SC Department of Insurance cybersecurity requirements(doi.sc.gov).gov
- SC Biometric Data Privacy Act Bill 4812 (2019-2020)(scstatehouse.gov).gov
- SC Biometric Data Privacy Act Bill 3063 (2021-2022)(scstatehouse.gov).gov
- South Carolina Unfair Trade Practices Act(scstatehouse.gov).gov
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- South Carolina Social Media Regulation Act, S.C. Code Title 39 Ch. 80 (2026 Act No. 96 / H.3431)(scstatehouse.gov).gov