EnglishEspañol
South Carolina flag

South Carolina

South Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

South Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify South Carolina residents after a data breach?

South Carolina requires notification in the most expedient time possible and without unreasonable delay. Unlike many states, South Carolina does not impose a specific day-count deadline such as 30, 45, or 60 days. The timeline must be consistent with the needs of law enforcement and measures necessary to determine the scope of the breach.

Does South Carolina require Attorney General notification for data breaches?

No. South Carolina does not require Attorney General notification. Instead, when an entity provides notice to more than 1,000 persons at one time, it must notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies. The Department of Consumer Affairs, not the AG, handles breach notification enforcement.

Can individuals sue for breach notification violations in South Carolina?

Yes. South Carolina grants a private right of action to residents injured by a violation. For knowing and willful violations, residents may sue for damages. For negligent violations, residents may sue but recovery is limited to actual damages. This is a broader private remedy than many states offer.

What is the relationship between S.C. Code 39-1-90 and the Insurance Data Security Act?

The general breach notification law (39-1-90) applies to all businesses. The Insurance Data Security Act (S.C. Code 38-99) adds additional obligations for insurers and other Department of Insurance licensees, including a 72-hour notification requirement to the Director of Insurance. Insurers must comply with both statutes.

Does South Carolina's breach notification law cover medical or biometric information?

No. South Carolina's personal identifying information definition covers SSNs, driver's license numbers, financial account numbers with security codes, and other numbers that may access financial accounts. It does not cover medical information, health insurance data, biometric data, or email credentials, making it narrower than many states that have updated their laws in recent years.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the 1,000-person reporting threshold: S.C. Code 39-1-90(K) is triggered by the number of breach notices a business sends at one time, not the number of residents affected.

Corrected the consumer-reporting-agency/Consumer Protection Division notice threshold from "1,000 or more" to "more than 1,000" residents (S.C. Code 39-1-90(K)), re-attributed the injunctive relief remedy to the injured resident's private right of action rather than the Department of Consumer Affairs (39-1-90(G)(3)), and clarified that the financial-institution exemption has two separate paths (GLBA compliance under 39-1-90(I), or 2005 interagency guidance compliance under 39-1-90(J)).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the substitute-notice description: S.C. Code 39-1-90(E)(4) lists email, website posting, and media notice disjunctively ('or'), not as three mandatory requirements.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. S.C. Code Section 39-1-90 - Business Data Breach Notification(scstatehouse.gov).gov
  2. SC Consumer Affairs - Security Breach Notices(consumer.sc.gov).gov
  3. S.C. Code Title 38 Chapter 99 - Insurance Data Security Act(scstatehouse.gov).gov
  4. SC Department of Insurance - Cybersecurity(doi.sc.gov).gov
Share: