South Carolina
South Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

South Carolina requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay under S.C. Code 39-1-90. No fixed-day deadline applies. When a business provides notice to more than 1,000 persons at one time, it must also notify the Consumer Protection Division of the Department of Consumer Affairs.
If your business handles personal data belonging to South Carolina residents, a data breach triggers notification obligations under S.C. Code Section 39-1-90. South Carolina's breach notification law has been in effect since 2009 and applies to any person conducting business in the state who owns or licenses computerized data that includes personal identifying information.
Unlike many states that have adopted firm day-count deadlines in recent years, South Carolina still uses a "without unreasonable delay" standard. The law also stands out for granting individuals a private right of action and for routing enforcement through the Department of Consumer Affairs rather than the Attorney General.
This guide covers the full requirements under South Carolina law, including how they connect to the broader South Carolina data privacy laws framework.
Who Must Comply
South Carolina's law applies to any person conducting business in the state who owns or licenses computerized data that includes personal identifying information of South Carolina residents. The term "person" includes individuals, businesses, corporations, partnerships, and other entities.
When a third party maintains data on behalf of the data owner or licensee, the third party must notify the data owner or licensee immediately following the discovery of a breach. The data owner then carries the notification obligation to affected residents.
Financial Institution Exception
Banks and financial institutions have two separate compliance paths under the statute. A bank or financial institution subject to and in compliance with the privacy and security provisions of the Gramm-Leach-Bliley Act (GLBA) is exempt from Section 39-1-90 entirely (39-1-90(I)). Separately, a financial institution that complies with the 2005 federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information, issued by the federal banking regulators, is considered to be in compliance with Section 39-1-90 (39-1-90(J)).
What Triggers Notification
Under Section 39-1-90, a breach of the security of the system means unauthorized access to and acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the entity.
Notification is required when personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person, and either:
- Illegal use of the information has occurred or is reasonably likely to occur, or
- The use of the information creates a material risk of harm to the resident
This two-pronged trigger gives entities some latitude to assess risk. Not every technical breach automatically requires notification. The entity must determine whether unauthorized acquisition actually occurred and whether it poses a meaningful risk.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the person is not a breach, provided the information is not used for or subject to further unauthorized disclosure.
Encryption Safe Harbor
If personal identifying information was rendered unusable through encryption, redaction, or other methods, notification is not required. South Carolina does not specify a minimum encryption standard (unlike Rhode Island, which requires 128-bit encryption), so any generally accepted encryption method should qualify.
Personal Information That Triggers the Law
Under Section 39-1-90, personal identifying information means the first name or first initial and last name of a resident, in combination with and linked to any one or more of the following data elements, when the data elements are not encrypted or redacted:
- Social Security number
- Driver's license number or state identification card number
- Financial account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a resident's financial account
- Other numbers or information that may be used to access a person's financial accounts
- Government-issued identification numbers
South Carolina's inclusion of "other numbers or information which may be used to access a person's financial accounts" is a catch-all provision that extends coverage beyond the specific categories listed. However, the law does not cover medical information, health insurance data, biometric data, or email credentials, making it narrower than some more recently updated state laws.
Personal identifying information does not include information that is lawfully obtained from publicly available sources or from federal, state, or local government records that are lawfully made available to the general public.
Notification Timeline

South Carolina requires notification "in the most expedient time possible and without unreasonable delay." The law does not impose a specific day-count deadline.
The notification timeline must be consistent with:
- The legitimate needs of law enforcement (if law enforcement requests a delay)
- Measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. Once law enforcement determines that notification will no longer compromise the investigation, the entity must proceed with notification.

Who Must Be Notified
Affected Individuals
Every South Carolina resident whose personal identifying information was or is reasonably believed to have been acquired by an unauthorized person must receive notification.
Consumer Reporting Agencies and Consumer Protection Division (More Than 1,000 Threshold)
When a person provides notice to more than 1,000 persons at one time, the person must also notify, without unreasonable delay, the Consumer Protection Division of the South Carolina Department of Consumer Affairs and all nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) of the timing, distribution, and content of the notices.
Note that this threshold counts notices sent, not residents affected. A breach can involve more than 1,000 South Carolina residents and still fall below the threshold if notice is not owed to all of them, for example where part of the affected data was encrypted or redacted or where the entity determines that illegal use is not reasonably likely and no material risk of harm exists.
No Attorney General Notification
South Carolina is one of the few states that does not route breach notifications to the Attorney General's office. The Department of Consumer Affairs handles enforcement and receives large-breach reports.
Methods of Notification
South Carolina permits several notification methods:
- Written notice to the affected resident
- Electronic notice, if the entity's primary method of communication with the resident is electronic
- Telephonic notice
- Substitute notice, if the cost of providing notice exceeds $250,000, the affected population exceeds 500,000 persons, or the entity does not have sufficient contact information. Substitute notice consists of any of the following, as applicable: email notice to available addresses, conspicuous posting on the entity's website, or notification to major statewide media.
Penalties and Enforcement

South Carolina's breach notification law includes both private and public enforcement mechanisms.
Private Right of Action
South Carolina is one of the states that grants individuals the right to sue for breach notification violations:
- Knowing and willful violations: A resident injured by a violation may bring a civil action to recover damages
- Negligent violations: A resident may bring a civil action, but recovery is limited to actual damages
This distinction matters. For willful violations, plaintiffs may recover broader damages. For negligent violations, the claim is capped at provable actual losses.
Administrative Penalties
A person who knowingly and willfully violates the statute is subject to an administrative fine of $1,000 for each South Carolina resident whose information was accessible by reason of the breach. The fine is determined by the Department of Consumer Affairs.
Injunctive Relief
A resident injured by a violation may also seek an injunction to enforce compliance, as part of the private right of action under Section 39-1-90(G)(3). This remedy belongs to the injured resident, not the Department of Consumer Affairs.
No AG Enforcement
Unlike most states, the South Carolina Attorney General does not have a direct enforcement role under Section 39-1-90. Enforcement authority rests with the Department of Consumer Affairs.
The Insurance Data Security Act (S.C. Code 38-99)
South Carolina enacted the Insurance Data Security Act in 2018, based on the NAIC Insurance Data Security Model Law. This separate statute applies specifically to licensees of the Department of Insurance, including insurers, agents, and other entities licensed under Title 38.
Key differences from the general breach notification law:
- 72-hour reporting: Licensees must notify the Director of Insurance within 72 hours of determining that a cybersecurity event has occurred, when certain thresholds are met
- Information security program: Licensees must implement a comprehensive written information security program
- Third-party service providers: Licensees must exercise due diligence in selecting third-party service providers and require them to implement appropriate security measures
Insurers with direct contractual relationships with affected consumers must still fulfill the consumer notification requirements of Section 39-1-90 in addition to the Insurance Data Security Act obligations.
This article provides general legal information about South Carolina data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in South Carolina for guidance specific to your situation.
More South Carolina Laws
Frequently Asked Questions
How quickly must a business notify South Carolina residents after a data breach?
South Carolina requires notification in the most expedient time possible and without unreasonable delay. Unlike many states, South Carolina does not impose a specific day-count deadline such as 30, 45, or 60 days. The timeline must be consistent with the needs of law enforcement and measures necessary to determine the scope of the breach.
Does South Carolina require Attorney General notification for data breaches?
No. South Carolina does not require Attorney General notification. Instead, when an entity provides notice to more than 1,000 persons at one time, it must notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies. The Department of Consumer Affairs, not the AG, handles breach notification enforcement.
Can individuals sue for breach notification violations in South Carolina?
Yes. South Carolina grants a private right of action to residents injured by a violation. For knowing and willful violations, residents may sue for damages. For negligent violations, residents may sue but recovery is limited to actual damages. This is a broader private remedy than many states offer.
What is the relationship between S.C. Code 39-1-90 and the Insurance Data Security Act?
The general breach notification law (39-1-90) applies to all businesses. The Insurance Data Security Act (S.C. Code 38-99) adds additional obligations for insurers and other Department of Insurance licensees, including a 72-hour notification requirement to the Director of Insurance. Insurers must comply with both statutes.
Does South Carolina's breach notification law cover medical or biometric information?
No. South Carolina's personal identifying information definition covers SSNs, driver's license numbers, financial account numbers with security codes, and other numbers that may access financial accounts. It does not cover medical information, health insurance data, biometric data, or email credentials, making it narrower than many states that have updated their laws in recent years.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the 1,000-person reporting threshold: S.C. Code 39-1-90(K) is triggered by the number of breach notices a business sends at one time, not the number of residents affected.
Corrected the consumer-reporting-agency/Consumer Protection Division notice threshold from "1,000 or more" to "more than 1,000" residents (S.C. Code 39-1-90(K)), re-attributed the injunctive relief remedy to the injured resident's private right of action rather than the Department of Consumer Affairs (39-1-90(G)(3)), and clarified that the financial-institution exemption has two separate paths (GLBA compliance under 39-1-90(I), or 2005 interagency guidance compliance under 39-1-90(J)).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the substitute-notice description: S.C. Code 39-1-90(E)(4) lists email, website posting, and media notice disjunctively ('or'), not as three mandatory requirements.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
South Carolina Code of Laws, Title 39: TRADE AND COMMERCE
§ 39-1-90Business data, breach of security; notifications, definitions, penalties, and exceptionsIn forcecited in 4 of our articles
(A) A person conducting business in this State, and owning or licensing computerized data or other data that includes personal identifying information, shall disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of this State whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (C), or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at scstatehouse.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):Federal courts treat 39-1-90 as two separate claims. Allen v. Blackbaud (2021) held that possessing or hosting data does not make a company one owning or licensing it under subsection (A). Roper v. Rise Interactive (2023) dismissed an (A) claim but let a subsection (B) notice claim proceed.
Opinions citing this section in our collection:
- Roper v. Rise Interactive Media & Analytics, LLC (District Court, N.D. Illinois 2023)✓A patient sued a marketing vendor that got her data from a medical supplier and told her of a possible breach two months later; the court dismissed her subsection (A) claim because she did not plead the vendor owned or licensed the data, but let the subsection (B) claim proceed.
- Crosby v. OneTouchPoint Inc (District Court, E.D. Wisconsin 2024)✓A healthcare mailing vendor notified a South Carolina plaintiff of an April 2022 breach three months later; the court held she adequately alleged the vendor owned or licensed her data through its contracts with health insurers and that the delay was plausibly untimely.
- Allen v. Blackbaud Inc (District Court, D. South Carolina 2021)✓After a ransomware attack on a cloud software company that hosted data nonprofits had entrusted to it, South Carolina plaintiffs sued; the court dismissed their claim, holding that possessing data is not enough to make a company one that owns or licenses it under subsection (A).
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: South Carolina Data Privacy Laws: Breach Notification & Consumer Rights (2026), South Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026), South Carolina Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Explore the law
This article also draws on these acts and chapters (opening at their first section): South Carolina Code of Laws, Title 38: INSURANCE § 38-99-10 (Definitions)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- S.C. Code Section 39-1-90 - Business Data Breach Notification(scstatehouse.gov).gov
- SC Consumer Affairs - Security Breach Notices(consumer.sc.gov).gov
- S.C. Code Title 38 Chapter 99 - Insurance Data Security Act(scstatehouse.gov).gov
- SC Department of Insurance - Cybersecurity(doi.sc.gov).gov