South Dakota
South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

South Dakota has no dedicated biometric privacy law and no consent requirement for collecting biometric identifiers such as fingerprints, face scans, or voiceprints. The state's breach notification statute, SDCL 22-40-20, is the main protection for those identifiers, requiring businesses to notify residents within 60 days when a breach exposes biometric authentication data. Genetic data is the one carve-out: SDCL 37-24-59 to 37-24-64 impose express-consent duties on direct-to-consumer genetic testing companies.
South Dakota takes a minimal approach to biometric privacy regulation. Unlike states such as Illinois or Texas that have enacted specific biometric privacy statutes, South Dakota protects biometric identifiers only through its data breach notification law.
This means businesses operating in South Dakota can collect, store, and use biometric data such as fingerprints, facial recognition templates, and voiceprints without obtaining consent from individuals. Protection only kicks in after a security breach has already occurred.
For a broader overview of privacy protections in the state, see the parent guide to South Dakota Data Privacy Laws.
How South Dakota Law Defines Biometric Data
South Dakota's breach notification statute, SDCL 22-40-19, defines biometric data as data generated from measurements or analysis of human body characteristics for authentication purposes. This definition appears within the broader definition of "personal information" that triggers breach notification requirements.
Under the statute, biometric data is protected when it appears in combination with an identification number assigned to a person by their employer; the statute lists biometric data itself as one of the qualifying secondary elements, alongside a security code, access code, or password, rather than requiring one of those on top of it.
The definition is notably narrow compared to other states. It covers biometric data only when used for authentication purposes. Biometric data collected for other reasons, such as marketing analytics or research, falls outside the statute's scope.
Common types of biometric data that would qualify under this definition include:
- Fingerprint scans used for device or system login
- Facial recognition templates used for identity verification
- Iris scans used for building access
- Voiceprints used for phone authentication
- Hand geometry measurements used for timekeeping systems
Photographs, video recordings, and audio recordings are not explicitly addressed in the biometric data definition under SDCL 22-40-19.
Breach Notification Requirements for Biometric Data
South Dakota's breach notification law, enacted through SB 62 in 2018 and codified at SDCL 22-40-20, establishes the primary legal framework that protects biometric data in the state.
Who Must Comply
Any person or business that conducts business in South Dakota and owns or licenses computerized personal information of South Dakota residents must comply with the breach notification requirements. This applies to both in-state and out-of-state entities.
Notification Timeline
When a breach of system security exposes personal information that includes biometric data, the information holder must notify affected South Dakota residents no later than 60 days from discovery or notification of the breach.
This 60-day window can be extended only if law enforcement determines that notification would impede a criminal investigation. In that case, notification must occur within 30 days after law enforcement clears the delay.
Attorney General Reporting
Any breach affecting more than 250 South Dakota residents must be reported to the South Dakota Attorney General by mail or email. This report must include information about the nature of the breach and the types of personal information compromised.
What Triggers a Notification
A "breach of system security" under the law means the unauthorized acquisition of unencrypted computerized data, or encrypted data along with the encryption key, that materially compromises the security, confidentiality, or integrity of personal or protected information.
If biometric authentication data is exposed in such a breach, the notification obligations apply.
What South Dakota Law Does Not Cover
The gaps in South Dakota's biometric privacy framework are significant. Understanding what the law does not do is just as important as understanding what it does.
No Collection Consent Requirements

South Dakota does not require businesses or employers to obtain consent before collecting biometric identifiers. A company can implement fingerprint scanners, facial recognition cameras, or voice authentication systems without providing notice or obtaining any form of permission from the individuals whose data is collected. The one exception is genetic data handled by consumer DNA testing companies, covered in the next section.
No Retention or Destruction Rules
The law does not set limits on how long organizations can store biometric data. There are no requirements to publish a data retention schedule or to destroy biometric data after a set period or when the purpose for collection has ended.
No Purpose Limitation
Businesses that collect biometric data in South Dakota face no restrictions on how they use it. The law does not prohibit selling, sharing, or repurposing biometric data, so long as no breach notification obligations are triggered.

No BIPA-Style Private Right of Action
South Dakota has no private right of action for biometric data misuse comparable to Illinois's BIPA, which allows individuals to sue for $1,000 to $5,000 per violation. Enforcement of the breach notification statute runs primarily through the Attorney General.
One indirect route exists on paper, but it is unsettled. SDCL 22-40-25 lets the Attorney General prosecute a failure to disclose a breach as a deceptive act or practice under SDCL 37-24-6, and SDCL 37-24-31 permits any person who claims to have been adversely affected by an act or practice declared unlawful by 37-24-6 to bring a civil action for actual damages. Whether a private plaintiff can actually reach a notification failure through that chain has not been settled, and the main deceptive-practice provision in 37-24-6(1) is tied to the sale or advertisement of merchandise. Treat it as an open question, not a dependable remedy.
Civil Penalties for Noncompliance
Under SDCL 22-40-25, the Attorney General may prosecute a failure to disclose as a deceptive act or practice and may bring an action to recover a civil penalty of up to $10,000 per day per violation, in addition to attorney's fees and costs associated with enforcement actions.
Genetic Data: South Dakota's One Consent Statute
South Dakota does regulate one category of body-derived data at the point of collection. SDCL 37-24-59 through 37-24-64 apply to direct-to-consumer genetic testing companies, meaning entities that offer genetic testing products or services directly to consumers or that analyze genetic data collected through such a product.
SDCL 37-24-60 requires those companies to publish a privacy policy and privacy notice in plain language, obtain the consumer's express consent to collect, disclose, or use genetic data, and obtain a separate express consent for each transfer or disclosure to an outside party, for each use beyond the primary purpose of the test, for retaining a biological sample after testing is complete, and for marketing. The statute also requires a security program for genetic data and a process letting the consumer access the data, delete the account and genetic data, and request destruction of the biological sample. Under SDCL 37-24-61, a revocation of consent must be honored within 30 days, and a biological sample must be destroyed within 30 days of a revocation covering it.
SDCL 37-24-63 lets the Attorney General petition a court for a civil penalty of up to $5,000 per violation. SDCL 37-24-64 exempts protected health information held by HIPAA covered entities, samples collected for medical screening, diagnosis, or treatment, higher education institutions, forensic laboratories working with law enforcement, certain research entities, and licensed hospitals.
The scope limit matters: these sections cover DNA and biological samples. They do not reach fingerprints, facial recognition templates, iris scans, or voiceprints, which is why South Dakota still has no general biometric consent requirement.
Federal Laws That May Apply in South Dakota
Because South Dakota lacks comprehensive biometric privacy protections, federal laws provide some additional coverage in specific contexts.
HIPAA
Health care providers, insurers, and their business associates in South Dakota must comply with HIPAA when handling biometric data in a health care context. South Dakota's breach notification law recognizes this by deeming HIPAA-regulated entities in compliance if they follow federal breach notification requirements.
Gramm-Leach-Bliley Act (GLBA)
Financial institutions in South Dakota that collect biometric data for customer authentication must comply with GLBA data security requirements. Similar to HIPAA entities, financial institutions that follow their federal regulator's breach notification requirements are deemed compliant with South Dakota's state law.
Children's Online Privacy Protection Act (COPPA)
Companies collecting biometric data from children under 13 in South Dakota must comply with COPPA requirements, which include obtaining verifiable parental consent before collecting biometric identifiers.
How South Dakota Compares to Neighboring States
South Dakota's approach to biometric privacy is among the least protective in the region.
Iowa enacted a consumer data protection law that classifies biometric data as sensitive, but Iowa Code 715D.4(2) requires only that the consumer be presented with clear notice and an opportunity to opt out before sensitive data is processed. That makes Iowa the outlier among comprehensive privacy states, which generally require opt-in consent. Montana similarly passed comprehensive privacy legislation with biometric data protections.
Nebraska goes further than South Dakota as well. Under the Nebraska Data Privacy Act, Neb. Rev. Stat. 87-1102(30)(b) treats genetic or biometric data processed for the purpose of uniquely identifying an individual as sensitive data, and 87-1112(2)(d) bars a controller from processing sensitive data without obtaining the consumer's consent. Nebraska therefore requires opt-in consent for biometric processing, even though it has no standalone biometric statute.
North Dakota and Wyoming share South Dakota's limited approach, relying primarily on breach notification laws without dedicated biometric privacy statutes.
Minnesota, to the east, has enacted stronger consumer data privacy protections that include biometric data provisions.
Practical Guidance for South Dakota Residents
Without a dedicated biometric privacy law, South Dakota residents have limited legal recourse regarding their biometric data. However, there are practical steps to protect yourself.
Ask employers and businesses what biometric data they collect and how they store it. While they are not legally required to tell you, many organizations have privacy policies that address biometric data.
Review privacy policies before using apps, devices, or services that collect fingerprints, facial scans, or voice data. Federal laws like COPPA and sector-specific regulations may provide some protections depending on the context.
If you use a consumer DNA testing service, read the consent screens carefully. SDCL 37-24-60 entitles you to a separate express consent before your genetic data or sample is transferred, reused, or retained, and SDCL 37-24-61 requires the company to honor a revocation within 30 days.
If you believe your biometric data was compromised in a breach and you did not receive notification, contact the South Dakota Attorney General's Consumer Protection Division to file a complaint.
Legislative Outlook
South Dakota has not enacted a comprehensive consumer data privacy law or a standalone biometric privacy statute. Its only collection-stage privacy duties for body-derived data sit in the genetic testing sections at SDCL 37-24-59 to 37-24-64, which do not reach fingerprints, face scans, or voiceprints.
Given that a growing number of states have enacted comprehensive privacy laws with biometric data provisions, legislative activity in South Dakota remains possible. Any new legislation would be introduced during the state's annual legislative session, which typically runs from January through March.
Residents and businesses should monitor the South Dakota Legislature website for any proposed privacy-related bills.
Sources and References
This article references South Dakota statutes available through the South Dakota Legislature website. For the full text of the breach notification law, see SDCL 22-40-19 through SDCL 22-40-26. For the genetic data provisions, see SDCL 37-24-59 through SDCL 37-24-64. For consumer complaints related to data breaches, contact the South Dakota Attorney General.
This article provides general legal information about South Dakota biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official South Dakota government sources.
More South Dakota Laws
Frequently Asked Questions
Does South Dakota have a biometric privacy law?
No. South Dakota does not have a dedicated biometric privacy law. Biometric identifiers such as fingerprints, face scans, and voiceprints are protected mainly through the state's breach notification statute (SDCL 22-40-19 through 22-40-26), which requires businesses to notify affected individuals within 60 days when a data breach exposes biometric authentication data. Genetic data is separately regulated at SDCL 37-24-59 to 37-24-64, which apply only to direct-to-consumer genetic testing companies.
Can my employer collect my fingerprints without consent in South Dakota?
Yes. South Dakota law does not require employers to obtain consent before collecting biometric data such as fingerprints, facial scans, or iris scans. There are no state-level restrictions on employer collection or use of biometric data, though federal laws like HIPAA or GLBA may apply in specific industries.
Can I sue a company in South Dakota for misusing my biometric data?
South Dakota has no BIPA-style private right of action for biometric data misuse, so there is no statute letting you sue over the collection or use of a fingerprint or face scan. Breach notification enforcement runs primarily through the Attorney General. One indirect route is unsettled: SDCL 22-40-25 routes a failure to disclose a breach into SDCL 37-24-6 as a deceptive act or practice, and SDCL 37-24-31 lets a person adversely affected by an act unlawful under 37-24-6 sue for actual damages, but whether that chain reaches a notification failure has not been settled. You can also file a complaint with the Attorney General's Consumer Protection Division at atg.sd.gov.
What biometric data is protected under South Dakota's breach notification law?
SDCL 22-40-19 protects biometric data generated from measurements or analysis of human body characteristics for authentication purposes. This includes fingerprint scans, facial recognition templates, iris scans, and voiceprints when used for authentication and combined with an employer-assigned identification number; biometric data itself completes that pairing, without needing an additional security code or password.
Does South Dakota regulate DNA and genetic testing data?
Yes. SDCL 37-24-59 through 37-24-64 apply to direct-to-consumer genetic testing companies. SDCL 37-24-60 requires express consent to collect, disclose, or use genetic data, plus a separate express consent for each transfer, each use beyond the primary purpose of the test, retention of a biological sample, and marketing. SDCL 37-24-61 requires a revocation of consent to be honored within 30 days and the biological sample destroyed within 30 days, and SDCL 37-24-63 allows the Attorney General to seek a civil penalty of up to $5,000 per violation. These sections cover DNA only, not fingerprints, face scans, or voiceprints.
What penalties does South Dakota impose for failing to report a biometric data breach?
South Dakota's breach notification law allows the Attorney General to recover a civil penalty of up to $10,000 per day per violation, plus attorney's fees and costs associated with enforcement actions. Businesses that experience a breach affecting more than 250 residents must report it to the Attorney General within 60 days of discovery.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected how this page describes Iowa and Nebraska law, added South Dakota's genetic data statute (SDCL 37-24-59 to 37-24-64), and qualified the claim that only the Attorney General can enforce breach notification duties.
Corrected the description of when biometric data triggers breach notification: the statute lists biometric data as an alternative qualifying element with an employer ID, not one requiring an additional security code.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the citation and content of this page's civil-penalty claim: SD's breach law does specify a penalty (up to $10,000 per day per violation under SDCL 22-40-25), and fixed a mismatched statute citation for the 60-day notice duty.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
South Dakota Codified Laws, Chapter 22-40: IDENTITY CRIMES
§ 22-40-20Notice of breach of system security--Exception.In forcecited in 3 of our articles
Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement as provided under § 22-40-21. An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at sdlegislature.gov
Also relied on in: South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026), South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 22-40-19Definition of terms in §§ 22-40-19 to 22-40-26.In forcecited in 4 of our articles
Terms in §§ 22-40-19 to 22-40-26, inclusive, mean: (1) "Breach of system security," the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure; (2) "Encrypted," computerized data that is rendered unusable, unreadable, or indecipherable without the use of a decryption process or key or in accordance with the Federal Information Processing Standard 140-2 in effect on January 1, 2018; (3) "Information holder," any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; (4) "Personal information," a person's first name or first initial and last name, in combination with any one or more of…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
Also relied on in: South Dakota Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 22-40-22Types of notice of breach of system security.In forcecited in 2 of our articles
A disclosure under § 22-40-20 may be provided by: (1) Written notice; (2) Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 in effect as of January 1, 2018, or if the information holder's primary method of communication with the resident of this state has been by electronic means; or (3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder's website, if the information holder maintains a website page; and (c) Notification to statewide media.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
§ 22-40-25Prosecution for violations.In forcecited in 3 of our articles
The attorney general may prosecute each failure to disclose under the provisions of §§ 22-40-19 to 22-40-26, inclusive, as a deceptive act or practice under § 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than ten thousand dollars per day per violation. The attorney general may recover attorney's fees and any costs associated with any action brought under this section.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- SDCL 22-40-19 - Definition of Terms (Breach Notification)(sdlegislature.gov).gov
- SDCL 22-40-20 - Disclosure of Breach Required(sdlegislature.gov).gov
- SDCL 22-40-22 - Notification to Attorney General(sdlegislature.gov).gov
- SDCL 22-40-25 - Prosecution for Violations(sdlegislature.gov).gov
- SDCL Chapter 22-40 - Identity Crimes(sdlegislature.gov).gov
- SB 62 (2018) - Data Breach Notification Act(mylrc.sdlegislature.gov).gov
- South Dakota Attorney General - Consumer Protection(atg.sd.gov).gov
- SDCL 37-24-59 - Genetic Material Protection: Definitions(sdlegislature.gov)
- SDCL 37-24-60 - Genetic Material Protection: Requirements (Express Consent)(sdlegislature.gov)
- SDCL 37-24-61 - Genetic Material Protection: Revocation of Consent(sdlegislature.gov)
- SDCL 37-24-63 - Genetic Material Protection: Civil Penalty(sdlegislature.gov)
- SDCL 37-24-64 - Genetic Material Protection: Exceptions(sdlegislature.gov)
- SDCL 37-24-6 - Deceptive Act or Practice(sdlegislature.gov)
- SDCL 37-24-31 - Action for Damages Brought by Person Adversely Affected(sdlegislature.gov)
- Neb. Rev. Stat. 87-1102 - Nebraska Data Privacy Act Definitions (Sensitive Data)(nebraskalegislature.gov)
- Neb. Rev. Stat. 87-1112 - Controller Duties (Consent for Sensitive Data)(nebraskalegislature.gov)
- Iowa Code 715D.4 - Data Controller Duties (Notice and Opt-Out for Sensitive Data)(legis.iowa.gov)