EnglishEspañol
South Dakota flag

South Dakota

South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does South Dakota have a biometric privacy law?

No. South Dakota does not have a dedicated biometric privacy law. Biometric identifiers such as fingerprints, face scans, and voiceprints are protected mainly through the state's breach notification statute (SDCL 22-40-19 through 22-40-26), which requires businesses to notify affected individuals within 60 days when a data breach exposes biometric authentication data. Genetic data is separately regulated at SDCL 37-24-59 to 37-24-64, which apply only to direct-to-consumer genetic testing companies.

Can my employer collect my fingerprints without consent in South Dakota?

Yes. South Dakota law does not require employers to obtain consent before collecting biometric data such as fingerprints, facial scans, or iris scans. There are no state-level restrictions on employer collection or use of biometric data, though federal laws like HIPAA or GLBA may apply in specific industries.

Can I sue a company in South Dakota for misusing my biometric data?

South Dakota has no BIPA-style private right of action for biometric data misuse, so there is no statute letting you sue over the collection or use of a fingerprint or face scan. Breach notification enforcement runs primarily through the Attorney General. One indirect route is unsettled: SDCL 22-40-25 routes a failure to disclose a breach into SDCL 37-24-6 as a deceptive act or practice, and SDCL 37-24-31 lets a person adversely affected by an act unlawful under 37-24-6 sue for actual damages, but whether that chain reaches a notification failure has not been settled. You can also file a complaint with the Attorney General's Consumer Protection Division at atg.sd.gov.

What biometric data is protected under South Dakota's breach notification law?

SDCL 22-40-19 protects biometric data generated from measurements or analysis of human body characteristics for authentication purposes. This includes fingerprint scans, facial recognition templates, iris scans, and voiceprints when used for authentication and combined with an employer-assigned identification number; biometric data itself completes that pairing, without needing an additional security code or password.

Does South Dakota regulate DNA and genetic testing data?

Yes. SDCL 37-24-59 through 37-24-64 apply to direct-to-consumer genetic testing companies. SDCL 37-24-60 requires express consent to collect, disclose, or use genetic data, plus a separate express consent for each transfer, each use beyond the primary purpose of the test, retention of a biological sample, and marketing. SDCL 37-24-61 requires a revocation of consent to be honored within 30 days and the biological sample destroyed within 30 days, and SDCL 37-24-63 allows the Attorney General to seek a civil penalty of up to $5,000 per violation. These sections cover DNA only, not fingerprints, face scans, or voiceprints.

What penalties does South Dakota impose for failing to report a biometric data breach?

South Dakota's breach notification law allows the Attorney General to recover a civil penalty of up to $10,000 per day per violation, plus attorney's fees and costs associated with enforcement actions. Businesses that experience a breach affecting more than 250 residents must report it to the Attorney General within 60 days of discovery.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected how this page describes Iowa and Nebraska law, added South Dakota's genetic data statute (SDCL 37-24-59 to 37-24-64), and qualified the claim that only the Attorney General can enforce breach notification duties.

Corrected the description of when biometric data triggers breach notification: the statute lists biometric data as an alternative qualifying element with an employer ID, not one requiring an additional security code.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the citation and content of this page's civil-penalty claim: SD's breach law does specify a penalty (up to $10,000 per day per violation under SDCL 22-40-25), and fixed a mismatched statute citation for the 60-day notice duty.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. SDCL 22-40-19 - Definition of Terms (Breach Notification)(sdlegislature.gov).gov
  2. SDCL 22-40-20 - Disclosure of Breach Required(sdlegislature.gov).gov
  3. SDCL 22-40-22 - Notification to Attorney General(sdlegislature.gov).gov
  4. SDCL 22-40-25 - Prosecution for Violations(sdlegislature.gov).gov
  5. SDCL Chapter 22-40 - Identity Crimes(sdlegislature.gov).gov
  6. SB 62 (2018) - Data Breach Notification Act(mylrc.sdlegislature.gov).gov
  7. South Dakota Attorney General - Consumer Protection(atg.sd.gov).gov
  8. SDCL 37-24-59 - Genetic Material Protection: Definitions(sdlegislature.gov)
  9. SDCL 37-24-60 - Genetic Material Protection: Requirements (Express Consent)(sdlegislature.gov)
  10. SDCL 37-24-61 - Genetic Material Protection: Revocation of Consent(sdlegislature.gov)
  11. SDCL 37-24-63 - Genetic Material Protection: Civil Penalty(sdlegislature.gov)
  12. SDCL 37-24-64 - Genetic Material Protection: Exceptions(sdlegislature.gov)
  13. SDCL 37-24-6 - Deceptive Act or Practice(sdlegislature.gov)
  14. SDCL 37-24-31 - Action for Damages Brought by Person Adversely Affected(sdlegislature.gov)
  15. Neb. Rev. Stat. 87-1102 - Nebraska Data Privacy Act Definitions (Sensitive Data)(nebraskalegislature.gov)
  16. Neb. Rev. Stat. 87-1112 - Controller Duties (Consent for Sensitive Data)(nebraskalegislature.gov)
  17. Iowa Code 715D.4 - Data Controller Duties (Notice and Opt-Out for Sensitive Data)(legis.iowa.gov)
Share: