South Dakota
South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 21 primary sources cited on this page. How we verify our legal content

South Dakota does not have a comprehensive consumer data privacy law. The state's primary data protection tool, SDCL 22-40-20, requires businesses to notify affected residents within 60 days of a breach and report incidents affecting more than 250 residents to the Attorney General.
South Dakota takes a targeted approach to data privacy regulation rather than enacting a single comprehensive consumer privacy statute. The state's primary data protection tool is its Data Breach Notification Law, codified at SDCL 22-40-19 through 22-40-26, which took effect July 1, 2018.
South Dakota was the 49th state to pass a breach notification law. While the state has not adopted an omnibus privacy law comparable to those in California, Colorado, or Virginia, it enforces data protection through its breach notification requirements, consumer protection statutes, a new genetic data privacy law, and federal regulatory frameworks that apply to businesses in every state.
This guide covers every South Dakota data privacy statute currently in effect, the 2026 legislative developments that added new protections, federal frameworks that apply to South Dakota businesses and residents, and practical steps for both consumers and organizations.
South Dakota Data Breach Notification Law (SDCL 22-40-19 Through 22-40-26)
The South Dakota Data Breach Notification Law was established through Senate Bill 62, signed March 21, 2018, and effective July 1, 2018. Governor Dennis Daugaard signed the legislation after South Dakota had spent years as one of only two states without breach notification requirements.

Who Must Comply
The law applies to any "information holder": any person or business that conducts business in South Dakota and owns or licenses computerized personal or protected information of South Dakota residents. Businesses headquartered outside the state must comply if they hold data belonging to South Dakota residents.
Nonprofits, healthcare providers, financial institutions, and educational organizations that conduct business in South Dakota fall under this requirement. The statute does not reach state or local government agencies on its face: SDCL 22-40-19 defines an information holder as a person or business that conducts business in this state, and nothing in SDCL 22-40-19 through 22-40-26 extends the chapter to public entities. Separately, under SDCL 22-40-26 an information holder regulated by federal law is deemed compliant if it maintains breach procedures under its primary or functional federal regulator and notifies affected South Dakota residents under that federal law, whether or not the federal rules are stricter than the state rules.
What Constitutes a Breach
Under SDCL 22-40-19, a "breach of system security" is the unauthorized acquisition of unencrypted computerized data, or encrypted computerized data along with the encryption key, that materially compromises the security, confidentiality, or integrity of personal or protected information. A good-faith acquisition by an employee or agent does not constitute a breach, provided the information is not used improperly or further disclosed.
Categories of Protected Data
South Dakota's law protects two distinct categories of information.
Personal Information requires a person's first name or first initial and last name in combination with one or more of: Social Security number; driver's license or government-issued ID number; account, credit card, or debit card number combined with any required security code or PIN; health information as defined under HIPAA; or an employer-assigned identification number combined with a required security code or biometric authentication data.
Protected Information stands alone without requiring a name combination and includes: a username or email address combined with a password or security question answer that permits access to an online account; or an account or credit/debit card number combined with any security code that permits access to a financial account.
The law excludes information lawfully obtained from publicly available government records and data that has been redacted or modified to render it unusable.
The 60-Day Notification Deadline
Once an information holder discovers or is notified of a breach, it must disclose to any affected South Dakota resident whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. This disclosure must occur no later than 60 days from discovery or notification of the breach. Several other states use vaguer language such as "without unreasonable delay," making South Dakota's requirement more predictable for businesses.
Notification Methods
Information holders can provide breach notifications through several channels under SDCL 22-40-22: written notice to the affected individual's mailing address; electronic notice consistent with the federal E-SIGN Act; or substitute notice when the cost of direct notification exceeds $250,000, the affected class exceeds 500,000 persons, or the information holder lacks sufficient contact information. Substitute notice requires all three of: email notice, conspicuous website posting, and notification to statewide media.
The statute does not prescribe specific content requirements for the notice itself, but the information holder must notify nationwide consumer reporting agencies about the timing, distribution, and content of notices sent to affected individuals.
Attorney General Notification
Under SDCL 22-40-20, any information holder experiencing a breach affecting more than 250 South Dakota residents must disclose the breach to the South Dakota Attorney General by mail or email. The notification must include the details of the breach and the scope of affected individuals.
Law Enforcement Delay and Harm Assessment
Notification may be delayed if a law enforcement agency determines it would impede a criminal investigation. Once law enforcement clears the delay, the information holder must issue notifications within 30 days. There is no open-ended postponement.
South Dakota also allows an information holder to forgo notification if, after an appropriate investigation, it reasonably determines the breach will not likely result in harm to affected individuals. That determination must be documented in writing and retained for at least three years. The Attorney General must still be notified of the determination even when individual notice is not sent.
Encryption Safe Harbor
Encrypted data is generally exempt from notification requirements. The safe harbor does not apply, however, if the encryption key was also compromised in the breach. If an unauthorized party obtains both the encrypted data and the decryption key, the full notification obligations apply.
Federal Compliance Exemption
Entities regulated by federal law, including those subject to HIPAA or the Gramm-Leach-Bliley Act, are deemed to comply with South Dakota's breach notification requirements if they maintain breach notification procedures pursuant to their primary federal regulator's rules and notify affected South Dakota residents in accordance with applicable federal law.
Penalties for Breach Notification Violations
Under SDCL 22-40-25, failure to comply is classified as a deceptive act or practice under South Dakota's Deceptive Trade Practices and Consumer Protection Act (SDCL 37-24). The Attorney General may recover civil penalties of up to $10,000 per day for each violation, plus attorney's fees and costs.
There is no private right of action. Only the Attorney General can bring enforcement proceedings.
South Dakota Deceptive Trade Practices and Consumer Protection Act (SDCL 37-24)
The Deceptive Trade Practices and Consumer Protection Act serves as an additional layer of data privacy enforcement. It is unlawful for a business to engage in deceptive acts or practices, which can include misrepresenting data security measures, failing to honor privacy policies, or making false claims about how consumer data is protected.
The Attorney General enforces this statute when an action is deemed in the public interest. Penalties for intentional violations include civil fines of up to $2,000 per violation. Consumers adversely affected may bring private actions to recover actual damages. Because breach notification failures are classified as deceptive practices, the Attorney General can pursue violators under both SDCL 22-40-25 and this broader consumer protection framework.
South Dakota Genetic Data Privacy Act (SB 49, 2026)

Governor Larry Rhoden signed Senate Bill 49 into law on March 23, 2026. The law takes effect July 1, 2026 and was championed by AG Marty Jackley, who said the 2025 multistate action against 23andMe's bankruptcy sale of genetic data directly influenced the bill's drafting.
SB 49 passed the full House 65-2 and the Senate 34-0 before the governor signed it.
Who SB 49 Covers
The Act applies to "direct-to-consumer genetic testing companies": any entity that offers genetic testing products or services directly to consumers, or that analyzes, collects, or uses genetic data collected via a DTC genetic testing product or service. HIPAA-covered entities and business associates are expressly exempt, as is genetic data used for medical screening, diagnosis, or treatment at hospitals and affiliated facilities.
Key Requirements
Covered companies must publish a prominent, publicly available privacy notice disclosing their data collection, disclosure, use, retention, and security practices. The notice must specifically state whether de-identified genetic data is shared with or disclosed to third parties for research purposes.
Companies must provide a process enabling consumers to access their account and genetic data and to request deletion of their account or destruction of their biological sample.
Penalties
Civil penalties under SB 49 may not exceed $5,000 per violation. Enforcement authority rests with the Attorney General.
AG Jackley and the 23andMe Action
In June 2025, AG Jackley joined a 27-state coalition lawsuit seeking to block 23andMe from selling customer genetic data as part of the company's bankruptcy proceedings. The coalition argued that customers had not consented to the sale of their DNA information to a third-party buyer. The 2025 multistate action was the direct impetus for Jackley proposing SB 49 in the 2026 legislative session.
2026 Legislative Session: Social Media and Other Bills
SB 111: Social Media Data Transparency (Enacted)
Governor Larry Rhoden signed Senate Bill 111 on March 10, 2026. The law applies only to social media services with more than 100 million active monthly users whose primary focus is not charity or religion, and it does not take effect until July 1, 2027. Once effective, covered platforms must provide users with their collected personal data upon request and maintain transparent interoperability interfaces. It passed the Senate 34-0.
Key provisions include: user-friendly reports on data collection practices; the right to request and receive all personal data a social media company has collected; consumer control over how personal information is used; and transparency requirements for data interoperability.
SB 110: Internet Service Provider Data Privacy (Failed)
Senator Rohl also introduced SB 110, which would have restricted ISPs from using or transferring customer data without explicit consumer permission unless necessary to provide the service. The bill initially failed 5-3 in the Senate State Affairs Committee on February 11, 2026, but the Senate recalled it from committee, placed it on the floor calendar, and passed it 28-6. SB 110 then died in the House Commerce Committee on March 2, 2026, when a motion to pass the bill failed 3-9 and a motion to hold it over to the legislature's nonexistent "41st day" (a procedural kill) passed 10-2.
HB 1275: App Store Age Verification (Failed)
House Bill 1275 would have required app store providers to implement age verification and obtain parental consent for minors. It passed the House 50-17 but was defeated 5-4 in the Senate State Affairs Committee. Opponents noted the bill was nearly identical to Texas SB 2420, which a federal court blocked in December 2025 as unconstitutional.
South Dakota Insurance Data Security
South Dakota's Division of Insurance regulates insurance companies and producers under Title 58 of the South Dakota Codified Laws. South Dakota has not adopted the NAIC Insurance Data Security Model Law. SDCL Chapter 58-43 is titled "Independent Audit Of Insurers" and covers financial-reporting audit requirements, not data security. The NAIC's own model-law adoption tracker lists South Dakota only under "related activity," pointing to an older administrative rule, S.D. Admin. R. 20:06:45:20 to 20:06:45:26 (2004), rather than adoption of the current model law. Absent a state-specific insurance data security statute, South Dakota insurers remain subject to the general Data Breach Notification Law (SDCL 22-40), and insurers that meet GLBA requirements under their primary federal regulator are deemed compliant with that law under its federal compliance exemption.
Insurers who comply with GLBA requirements under their primary federal regulator are deemed compliant with South Dakota's breach notification provisions under the federal compliance exemption in SDCL 22-40.
South Dakota Computer Crimes Law (SDCL 43-43B)
South Dakota's Computer Crimes Law criminalizes unauthorized access to computer systems, data tampering, and the introduction of malware. The law establishes a graduated penalty structure under SDCL 43-43B-3: basic unauthorized access to a computer system is a Class 1 misdemeanor; accessing confidential data, or copying, obtaining, or disclosing access codes without authorization, is a Class 6 felony; disrupting or denying access to software or data is a Class 5 felony; disrupting or denying access to a computer system, or modifying data, is a Class 4 felony; and the most severe offenses, including destroying or disabling a computer system or data and using deception to obtain money, property, or services, are charged as Class 3 or Class 2 felonies.
The computer crimes statute complements the civil breach notification law by providing criminal consequences for individuals who perpetrate data breaches.
Federal Privacy Frameworks Applicable in South Dakota
Because South Dakota lacks a comprehensive state privacy law, federal frameworks carry particular weight for businesses and residents within the state.

TAKE IT DOWN Act (Pub. L. 119-12, 2025)
President Trump signed the TAKE IT DOWN Act on May 19, 2025. The law stands for "Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act."
The criminal prohibition against publishing nonconsensual intimate images (NCII), including AI-generated deepfakes, took effect immediately upon signing. The platform notice-and-removal obligation, which requires covered platforms to remove NCII within 48 hours of a valid request, became enforceable by the FTC on May 19, 2026. Platforms that fail to implement compliant notice-and-removal processes face FTC law enforcement action and civil penalties of up to $53,088 per violation.
Health Insurance Portability and Accountability Act (HIPAA)
Healthcare providers, health plans, healthcare clearinghouses, and their business associates in South Dakota must comply with HIPAA's Privacy and Security Rules. South Dakota healthcare entities that comply with HIPAA's breach notification requirements satisfy the state's notification obligations under the federal compliance exemption in SDCL 22-40.
Gramm-Leach-Bliley Act (GLBA)
Financial institutions in South Dakota must comply with the GLBA's Safeguards Rule. The FTC's updated Safeguards Rule, effective June 2023, strengthened requirements for risk assessments, access controls, encryption, and incident response plans.
Children's Online Privacy Protection Act (COPPA)
Businesses and websites that collect information from children under 13 must comply with COPPA, which requires verifiable parental consent before collecting personal information from minors.
Family Educational Rights and Privacy Act (FERPA)
Educational institutions in South Dakota that receive federal funding must comply with FERPA, which protects the privacy of student education records.
FTC Act Section 5
The FTC can take action against businesses that engage in unfair or deceptive practices related to data privacy and security under Section 5 of the FTC Act. South Dakota businesses are subject to FTC enforcement even without a state comprehensive privacy law.
American Privacy Rights Act (APRA)
Congress introduced a bipartisan federal comprehensive privacy bill (APRA, H.R. 8818) in June 2024. The bill did not pass the 118th Congress and expired in January 2025. It has not been reintroduced in the 119th Congress as of May 2026. No federal comprehensive consumer privacy law is in effect.
What Consumers Should Do After a Data Breach
The South Dakota Consumer Protection Division provides guidance for residents who receive breach notification letters. A security breach does not automatically result in identity theft, but prompt action reduces risk.
If your Social Security number was compromised: contact one of the three credit reporting agencies (Experian, Equifax, or TransUnion) to place a fraud alert; order and review your credit reports; contact the Social Security Administration at 1-800-772-1213; and consider placing a security freeze with all three credit agencies.
If existing financial accounts were compromised: monitor account statements closely; report unauthorized transactions immediately to your card issuer; and request new account numbers and credentials.
For identity theft recovery, the South Dakota Attorney General's office directs consumers to the Federal Trade Commission's IdentityTheft.gov for step-by-step recovery plans.
South Dakota vs. States With Comprehensive Privacy Laws
| Feature | South Dakota | States With Comprehensive Laws (e.g., CA, VA, CO) |
|---|---|---|
| Comprehensive privacy law | No | Yes |
| Right to access personal data | Limited (SB 111 social media platforms with 100M+ users, effective July 1, 2027; SB 49 genetic data) | Broad across all businesses |
| Right to delete personal data | Genetic data only (SB 49) | Yes (general) |
| Right to opt out of data sales | No | Yes |
| Breach notification deadline | 60 days | Varies (30-90 days) |
| AG notification threshold | 250+ residents | Varies (500-1,000+) |
| Private right of action | No (breach law) | Varies by state |
| Maximum penalty per violation | $10,000/day (breach); $5,000 (genetic) | Varies ($2,500-$7,500+) |
More South Dakota Laws
Frequently Asked Questions
Does South Dakota have a comprehensive consumer data privacy law?
No. As of May 2026, South Dakota does not have a comprehensive consumer data privacy law similar to California's CCPA, Virginia's VCDPA, or Colorado's CPA. The state relies on its data breach notification law (SDCL 22-40-19 through 22-40-26), its new Genetic Data Privacy Act (SB 49, effective July 1, 2026), consumer protection statutes, and federal frameworks. SB 111, signed March 2026, will require social media services with more than 100 million monthly active users to provide users with their collected data on request once it takes effect July 1, 2027, but it does not create general consumer privacy rights.
How quickly must a business notify South Dakota residents of a data breach?
Under SDCL 22-40-20, businesses must notify affected South Dakota residents within 60 days of discovering or being notified of a data breach, unless a longer period is needed for the legitimate needs of law enforcement under SDCL 22-40-21. If law enforcement requests a delay, notification must still occur within 30 days after law enforcement clears the delay. There is no exception allowing indefinite postponement.
What are the penalties for failing to report a data breach in South Dakota?
Failure to comply with South Dakota's breach notification law is treated as a deceptive act under SDCL 37-24. The Attorney General can impose civil penalties of up to $10,000 per day for each violation, plus attorney's fees and court costs. Only the Attorney General can bring enforcement actions. There is no private right of action allowing individual consumers to sue.
When must a business notify the South Dakota Attorney General about a breach?
Under SDCL 22-40-20, any information holder must notify the South Dakota Attorney General by mail or email when a breach affects more than 250 South Dakota residents. A second trigger applies at any breach size: an information holder that skips individual notice because it reasonably determined, after an appropriate investigation, that the breach will not likely result in harm must give notice to the attorney general in order to rely on that exception. Where neither trigger applies, notice goes to the affected individuals and to consumer reporting agencies rather than to the Attorney General.
Does South Dakota's breach notification law apply to encrypted data?
Generally, no. Encrypted data is exempt because the law defines a breach as involving unencrypted computerized data. However, this safe harbor does not apply if the encryption key was also compromised. If an unauthorized person obtains both the encrypted data and the decryption key, the full notification requirements apply.
What is South Dakota's Genetic Data Privacy Act (SB 49)?
South Dakota's Genetic Data Privacy Act, signed March 23, 2026, and effective July 1, 2026, regulates direct-to-consumer genetic testing companies. Covered companies must publish privacy notices, allow consumers to access and delete their genetic data and biological samples, and disclose when de-identified data is shared with third parties for research. Civil penalties can reach $5,000 per violation. HIPAA-covered entities and hospitals are expressly exempt.
What does the TAKE IT DOWN Act mean for South Dakota residents?
The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that criminalizes the nonconsensual publication of intimate images, including AI-generated deepfakes. It applies in all 50 states, including South Dakota. Covered online platforms must remove such images within 48 hours of a valid request. The FTC began enforcing the platform removal obligations on May 19, 2026, with civil penalties up to $53,088 per violation.
Updates
Corrected the Attorney General notification FAQ to note that notice to the attorney general is also required at any breach size when a business relies on the no-likely-harm exception to skip individual notice, removed the unsupported claim that government agencies are covered by the breach notification law, and restated the federal compliance exemption using the statutory test rather than a "stricter rules" test.
Corrected a fabricated claim that South Dakota adopted the NAIC Insurance Data Security Model Law (it has not); added the 100-million-user threshold and July 1, 2027 effective date to every mention of SB 111's social media data access right; fixed swapped felony classifications under South Dakota's computer crimes law; completed SB 110's legislative history through its death in a House committee; and corrected the 23andMe multistate coalition count to 27 states.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected four wrong statute citations: the 60-day notice and 250-resident AG-reporting duty sit in SDCL 22-40-20 (not 22-40-19, which is only definitions, and not 22-40-24, which covers notice to consumer reporting agencies); the $10,000/day penalty sits in SDCL 22-40-25 (not 22-40-26, which is the federal-regulator compliance exemption). Updated the Sources list to match.
Governing law re-checked for recent changes
May 2026 refresh: Added South Dakota Genetic Data Privacy Act (SB 49, signed March 23, 2026, effective July 1, 2026) covering DTC genetic testing companies; added AG Jackley's June 2025 23andMe multistate enforcement action; added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025, FTC platform enforcement live May 19, 2026); updated APRA status (expired January 2025, not reintroduced); corrected insurance section after confirming SD has NOT adopted the NAIC Insurance Data Security Model Law (SDCL Chapter 58-43 is an unrelated insurer-audit chapter; NAIC's tracker lists SD under related activity only, citing S.D. Admin. R. 20:06:45:20 to 20:06:45:26); expanded KeyTakeaways and FAQ to reflect new laws; updated comparison table to reflect SB 49 deletion right.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
South Dakota Codified Laws, Chapter 22-40: IDENTITY CRIMES
§ 22-40-20Notice of breach of system security--Exception.In forcecited in 3 of our articles
Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement as provided under § 22-40-21. An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at sdlegislature.gov
Also relied on in: South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026), South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 22-40-19Definition of terms in §§ 22-40-19 to 22-40-26.In forcecited in 4 of our articles
Terms in §§ 22-40-19 to 22-40-26, inclusive, mean: (1) "Breach of system security," the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure; (2) "Encrypted," computerized data that is rendered unusable, unreadable, or indecipherable without the use of a decryption process or key or in accordance with the Federal Information Processing Standard 140-2 in effect on January 1, 2018; (3) "Information holder," any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; (4) "Personal information," a person's first name or first initial and last name, in combination with any one or more of…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
Also relied on in: South Dakota Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 22-40-22Types of notice of breach of system security.In forcecited in 2 of our articles
A disclosure under § 22-40-20 may be provided by: (1) Written notice; (2) Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 in effect as of January 1, 2018, or if the information holder's primary method of communication with the resident of this state has been by electronic means; or (3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder's website, if the information holder maintains a website page; and (c) Notification to statewide media.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
§ 22-40-25Prosecution for violations.In forcecited in 3 of our articles
The attorney general may prosecute each failure to disclose under the provisions of §§ 22-40-19 to 22-40-26, inclusive, as a deceptive act or practice under § 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than ten thousand dollars per day per violation. The attorney general may recover attorney's fees and any costs associated with any action brought under this section.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
Explore the law
This article also draws on these acts and chapters (opening at their first section): South Dakota Codified Laws, Chapter 22-40: IDENTITY CRIMES § 22-40-1 (Impersonation with intent to deceive law enforcement officer--Misdemeanor.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- South Dakota Codified Laws Chapter 22-40: Data Breach Notification(sdlegislature.gov).gov
- SDCL 22-40-19: Definitions for Data Breach Notification(sdlegislature.gov).gov
- SDCL 22-40-22: Methods of Notification(sdlegislature.gov).gov
- SDCL 22-40-20: Notice of Breach of System Security (60-Day Deadline; Attorney General Notification)(sdlegislature.gov).gov
- SDCL 22-40-25: Prosecution for Violations; Civil Penalties(sdlegislature.gov).gov
- SB 62 (2018): South Dakota Data Breach Notification Law (Full Bill Text)(mylrc.sdlegislature.gov).gov
- SB 49 (2026): South Dakota Genetic Data Privacy Act(sdlegislature.gov).gov
- SB 111 (2026): Social Media Data Transparency Act(sdlegislature.gov).gov
- South Dakota Consumer Protection: Security Breaches(consumer.sd.gov).gov
- South Dakota Consumer Protection: Laws(consumer.sd.gov).gov
- Deceptive Trade Practices and Consumer Protection Act (SDCL 37-24)(consumer.sd.gov).gov
- South Dakota Computer Crimes Law (SDCL 43-43B)(sdlegislature.gov).gov
- South Dakota Division of Insurance: Laws, Rules and Bulletins(dlr.sd.gov).gov
- South Dakota Department of Education: FERPA(doe.sd.gov).gov
- FTC: TAKE IT DOWN Act Enforcement Information(ftc.gov).gov
- FTC: Take It Down Act Enforcement Starts Now (May 2026)(ftc.gov).gov
- HHS: HIPAA for Professionals(hhs.gov).gov
- FTC: Gramm-Leach-Bliley Act(ftc.gov).gov
- FTC: COPPA(ftc.gov).gov
- FTC: Federal Trade Commission Act(ftc.gov).gov
- IdentityTheft.gov(identitytheft.gov).gov
- Hunton: South Dakota Enacts Genetic Data Privacy Act (April 2026)(hunton.com)
- SDCL 22-40-26: Compliance With Federal Requirements Deemed Compliance(sdlegislature.gov)