EnglishEspañol
South Dakota flag

South Dakota

South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 21 primary sources cited on this page. How we verify our legal content

South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does South Dakota have a comprehensive consumer data privacy law?

No. As of May 2026, South Dakota does not have a comprehensive consumer data privacy law similar to California's CCPA, Virginia's VCDPA, or Colorado's CPA. The state relies on its data breach notification law (SDCL 22-40-19 through 22-40-26), its new Genetic Data Privacy Act (SB 49, effective July 1, 2026), consumer protection statutes, and federal frameworks. SB 111, signed March 2026, will require social media services with more than 100 million monthly active users to provide users with their collected data on request once it takes effect July 1, 2027, but it does not create general consumer privacy rights.

How quickly must a business notify South Dakota residents of a data breach?

Under SDCL 22-40-20, businesses must notify affected South Dakota residents within 60 days of discovering or being notified of a data breach, unless a longer period is needed for the legitimate needs of law enforcement under SDCL 22-40-21. If law enforcement requests a delay, notification must still occur within 30 days after law enforcement clears the delay. There is no exception allowing indefinite postponement.

What are the penalties for failing to report a data breach in South Dakota?

Failure to comply with South Dakota's breach notification law is treated as a deceptive act under SDCL 37-24. The Attorney General can impose civil penalties of up to $10,000 per day for each violation, plus attorney's fees and court costs. Only the Attorney General can bring enforcement actions. There is no private right of action allowing individual consumers to sue.

When must a business notify the South Dakota Attorney General about a breach?

Under SDCL 22-40-20, any information holder must notify the South Dakota Attorney General by mail or email when a breach affects more than 250 South Dakota residents. A second trigger applies at any breach size: an information holder that skips individual notice because it reasonably determined, after an appropriate investigation, that the breach will not likely result in harm must give notice to the attorney general in order to rely on that exception. Where neither trigger applies, notice goes to the affected individuals and to consumer reporting agencies rather than to the Attorney General.

Does South Dakota's breach notification law apply to encrypted data?

Generally, no. Encrypted data is exempt because the law defines a breach as involving unencrypted computerized data. However, this safe harbor does not apply if the encryption key was also compromised. If an unauthorized person obtains both the encrypted data and the decryption key, the full notification requirements apply.

What is South Dakota's Genetic Data Privacy Act (SB 49)?

South Dakota's Genetic Data Privacy Act, signed March 23, 2026, and effective July 1, 2026, regulates direct-to-consumer genetic testing companies. Covered companies must publish privacy notices, allow consumers to access and delete their genetic data and biological samples, and disclose when de-identified data is shared with third parties for research. Civil penalties can reach $5,000 per violation. HIPAA-covered entities and hospitals are expressly exempt.

What does the TAKE IT DOWN Act mean for South Dakota residents?

The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that criminalizes the nonconsensual publication of intimate images, including AI-generated deepfakes. It applies in all 50 states, including South Dakota. Covered online platforms must remove such images within 48 hours of a valid request. The FTC began enforcing the platform removal obligations on May 19, 2026, with civil penalties up to $53,088 per violation.

Updates

Corrected the Attorney General notification FAQ to note that notice to the attorney general is also required at any breach size when a business relies on the no-likely-harm exception to skip individual notice, removed the unsupported claim that government agencies are covered by the breach notification law, and restated the federal compliance exemption using the statutory test rather than a "stricter rules" test.

Corrected a fabricated claim that South Dakota adopted the NAIC Insurance Data Security Model Law (it has not); added the 100-million-user threshold and July 1, 2027 effective date to every mention of SB 111's social media data access right; fixed swapped felony classifications under South Dakota's computer crimes law; completed SB 110's legislative history through its death in a House committee; and corrected the 23andMe multistate coalition count to 27 states.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected four wrong statute citations: the 60-day notice and 250-resident AG-reporting duty sit in SDCL 22-40-20 (not 22-40-19, which is only definitions, and not 22-40-24, which covers notice to consumer reporting agencies); the $10,000/day penalty sits in SDCL 22-40-25 (not 22-40-26, which is the federal-regulator compliance exemption). Updated the Sources list to match.

Governing law re-checked for recent changes

May 2026 refresh: Added South Dakota Genetic Data Privacy Act (SB 49, signed March 23, 2026, effective July 1, 2026) covering DTC genetic testing companies; added AG Jackley's June 2025 23andMe multistate enforcement action; added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025, FTC platform enforcement live May 19, 2026); updated APRA status (expired January 2025, not reintroduced); corrected insurance section after confirming SD has NOT adopted the NAIC Insurance Data Security Model Law (SDCL Chapter 58-43 is an unrelated insurer-audit chapter; NAIC's tracker lists SD under related activity only, citing S.D. Admin. R. 20:06:45:20 to 20:06:45:26); expanded KeyTakeaways and FAQ to reflect new laws; updated comparison table to reflect SB 49 deletion right.

Reviewed and approved by an editor

Sources and References

  1. South Dakota Codified Laws Chapter 22-40: Data Breach Notification(sdlegislature.gov).gov
  2. SDCL 22-40-19: Definitions for Data Breach Notification(sdlegislature.gov).gov
  3. SDCL 22-40-22: Methods of Notification(sdlegislature.gov).gov
  4. SDCL 22-40-20: Notice of Breach of System Security (60-Day Deadline; Attorney General Notification)(sdlegislature.gov).gov
  5. SDCL 22-40-25: Prosecution for Violations; Civil Penalties(sdlegislature.gov).gov
  6. SB 62 (2018): South Dakota Data Breach Notification Law (Full Bill Text)(mylrc.sdlegislature.gov).gov
  7. SB 49 (2026): South Dakota Genetic Data Privacy Act(sdlegislature.gov).gov
  8. SB 111 (2026): Social Media Data Transparency Act(sdlegislature.gov).gov
  9. South Dakota Consumer Protection: Security Breaches(consumer.sd.gov).gov
  10. South Dakota Consumer Protection: Laws(consumer.sd.gov).gov
  11. Deceptive Trade Practices and Consumer Protection Act (SDCL 37-24)(consumer.sd.gov).gov
  12. South Dakota Computer Crimes Law (SDCL 43-43B)(sdlegislature.gov).gov
  13. South Dakota Division of Insurance: Laws, Rules and Bulletins(dlr.sd.gov).gov
  14. South Dakota Department of Education: FERPA(doe.sd.gov).gov
  15. FTC: TAKE IT DOWN Act Enforcement Information(ftc.gov).gov
  16. FTC: Take It Down Act Enforcement Starts Now (May 2026)(ftc.gov).gov
  17. HHS: HIPAA for Professionals(hhs.gov).gov
  18. FTC: Gramm-Leach-Bliley Act(ftc.gov).gov
  19. FTC: COPPA(ftc.gov).gov
  20. FTC: Federal Trade Commission Act(ftc.gov).gov
  21. IdentityTheft.gov(identitytheft.gov).gov
  22. Hunton: South Dakota Enacts Genetic Data Privacy Act (April 2026)(hunton.com)
  23. SDCL 22-40-26: Compliance With Federal Requirements Deemed Compliance(sdlegislature.gov)
Share: