South Dakota
South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 2 primary sources cited on this page. How we verify our legal content

South Dakota requires businesses to notify affected residents of a data breach within 60 days of discovery under SDCL 22-40-20. When more than 250 residents are affected, the Attorney General must also receive notice. Penalties reach up to $10,000 per day per violation for noncompliance.
South Dakota was one of the last states in the nation to enact a data breach notification law. The statute, S.D. Codified Laws 22-40-19 through 22-40-26, took effect on July 1, 2018, and applies to any information holder conducting business in South Dakota that owns or licenses computerized personal or protected information of state residents.
Despite being a late adopter, South Dakota's law includes several features that put it in line with more modern breach notification statutes: a firm 60-day notification deadline, a low Attorney General reporting threshold of 250 residents, and substantial daily penalties for noncompliance. The law also introduces the concept of "protected information," which covers login credentials even without a name.
This guide covers the full scope of South Dakota's breach notification requirements, including how they connect to the broader South Dakota data privacy laws framework.
Who Must Comply
South Dakota's law applies to any "information holder," defined as any person or business that conducts business in South Dakota and owns or licenses computerized personal or protected information of state residents. Businesses located outside South Dakota are covered if they hold data belonging to South Dakota residents.
That definition stops at ownership and licensing. Unlike many other state breach laws, South Dakota's statute has no separate prong for a vendor or service provider that merely maintains or processes data on behalf of someone else, and it imposes no statutory duty on such a vendor to report a breach to the owner or licensee. The duty to notify residents and the Attorney General rests with the owner or licensee, so vendor contracts need to spell out the breach reporting obligations the statute itself does not supply.
Federal Law Compliance Exception
Under Section 22-40-26, information holders regulated by federal law that maintain breach notification procedures under federal requirements (such as HIPAA or the Gramm-Leach-Bliley Act) are deemed in compliance with South Dakota law if they notify affected residents in accordance with applicable federal requirements.
Own Security Policy Exception
An information holder that maintains its own notification procedure as part of an information security policy is also in compliance, provided the policy is consistent with the timing requirements and the holder notifies affected individuals in accordance with its own procedures.
What Triggers Notification
Under Section 22-40-19, a "breach of system security" means the unauthorized acquisition of unencrypted computerized data, or encrypted computerized data and the encryption key, by any person that materially compromises the security, confidentiality, or integrity of personal or protected information.
The definition focuses on unauthorized acquisition, not just unauthorized access. Mere access without acquisition may not trigger the law.
Encryption Safe Harbor
Encrypted data is excluded from the breach definition unless the encryption key was also compromised. South Dakota defines "encrypted" as data rendered unusable, unreadable, or indecipherable without a decryption process or key, or data encrypted in accordance with the version of FIPS 140-2 (the Federal Information Processing Standard) in effect as of January 1, 2018.
Personal Information That Triggers the Law
South Dakota's definition of personal information under Section 22-40-19 means a person's first name or first initial and last name, in combination with any one or more of the following data elements:
- Social security number
- Driver's license number or other unique identification number created or collected by a government body
- Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or additional information that would permit access to a financial account
- Health information as defined in 45 CFR 160.103 (the HIPAA definition, covering past, present, or future physical or mental health conditions, healthcare provision, or healthcare payment)
- Identification number assigned by the person's employer, in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication
Personal information does not include information lawfully available from federal, state, or local government records, or information that has been redacted or otherwise made unusable.
Notable: SSN Coverage
South Dakota's statute lists Social Security numbers directly as their own data element, separate from the "driver license number or other unique identification number created or collected by a government body" category.

Protected Information: A Broader Category
South Dakota is one of relatively few states that defines a separate "protected information" category. Protected information includes:
- Username or email address in combination with a password, security question answer, or other information that permits access to an online account
- Account number or credit or debit card number in combination with any required security code, access code, or password that permits access to a financial account
Protected information does not require a name component to trigger notification. This means a breach of email addresses combined with passwords triggers notification even without names being compromised.
The 60-Day Notification Deadline

Under Section 22-40-20, an information holder must disclose the breach to any affected South Dakota resident not later than 60 days from the discovery or notification of the breach.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that notification will impede a criminal investigation. Once law enforcement determines that notification will no longer compromise the investigation, notification must be provided within 30 days.
Risk-of-Harm Exemption
SDCL 22-40-20 also contains an exemption that can eliminate the duty to notify individuals entirely. An information holder is not required to make the disclosure if, following an appropriate investigation and notice to the Attorney General, it reasonably determines that the breach will not likely result in harm to the affected persons. The business must document that determination in writing and keep the documentation for at least three years. Note the sequencing: the Attorney General must still be notified before the business can rely on this exemption, so "no harm" is never a reason to tell no one.
Who Must Be Notified
Affected Individuals
Every South Dakota resident whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person must receive notification.
Attorney General (250+ Threshold)

When a breach affects more than 250 South Dakota residents, the information holder must notify the South Dakota Attorney General by mail or email. This is one of the lower AG notification thresholds in the country.
Consumer Reporting Agencies
Under Section 22-40-24, if an information holder discovers circumstances that require notification under Section 22-40-20, it must also notify, without unreasonable delay, all consumer reporting agencies as defined under 15 U.S.C. 1681a (in effect as of January 1, 2018), and any other credit bureau or agency that compiles and maintains files on consumers on a nationwide basis. That reaches specialty reporting agencies, not only Equifax, Experian, and TransUnion. The notice must cover the timing, distribution, and content of the notice sent to residents. This duty is keyed to Section 22-40-20 generally, not to the 250-resident Attorney General threshold.
Methods of Notification
Under Section 22-40-22, South Dakota permits three types of notice:
- Written notice to the last known address
- Electronic notice, if consistent with federal electronic records provisions or if electronic communication is the information holder's primary method of contact with the resident
- Substitute notice, if the cost would exceed $250,000, the affected class exceeds 500,000 persons, or the holder lacks sufficient contact information. Substitute notice requires email to available addresses, conspicuous website posting, and notification to statewide media.
Penalties for Noncompliance
South Dakota's penalty structure is among the more aggressive in the country for a state without a private right of action.
Civil Penalties
Under Section 22-40-25, the Attorney General may bring an action to recover a civil penalty of up to $10,000 per day per violation. For a breach that goes unreported for weeks or months, this daily structure creates significant financial exposure.
Deceptive Acts Prosecution
The Attorney General may also prosecute each failure to disclose as a deceptive act or practice under Chapter 37-24, which provides additional remedies including injunctive relief, consumer restitution, and civil penalties.
Attorney's Fees and Costs
The Attorney General may recover attorney's fees and costs associated with any enforcement action.
No Private Right of Action
South Dakota's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute. Individuals may pursue claims under other legal theories such as negligence, but not under the breach notification statute itself.
This article provides general legal information about South Dakota data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in South Dakota for guidance specific to your situation.
More South Dakota Laws
Frequently Asked Questions
How quickly must a business notify South Dakota residents after a data breach?
South Dakota requires notification within 60 days of discovering or being notified of the breach. If law enforcement requests a delay because notification would impede a criminal investigation, the notification must be sent within 30 days after law enforcement determines it will no longer compromise the investigation. One exception: after investigating and notifying the Attorney General, a business that reasonably determines the breach will not likely result in harm is not required to notify individuals, though it must document that determination in writing for at least three years.
When must the South Dakota Attorney General be notified of a data breach?
The Attorney General must be notified by mail or email when a breach affects more than 250 South Dakota residents. This is one of the lower AG notification thresholds in the country. Separately, consumer reporting agencies must be notified whenever notification under Section 22-40-20 is required, with no minimum number of affected residents.
What is the difference between personal information and protected information under South Dakota law?
Personal information requires a name combined with data elements like government ID numbers, financial account data, health information, or employer-assigned IDs combined with a required security code, access code, password, or biometric data. Protected information does not require a name. It covers usernames or email addresses combined with passwords or security answers, and financial account numbers with access codes. Both categories trigger notification obligations.
What are the penalties for failing to notify about a data breach in South Dakota?
The Attorney General may seek civil penalties of up to $10,000 per day per violation, plus attorney's fees and costs. Violations may also be prosecuted as deceptive acts under Chapter 37-24, which provides additional remedies. There is no private right of action for individuals.
Does South Dakota's breach notification law cover health information?
Yes. South Dakota defines health information by reference to 45 CFR 160.103, the HIPAA definition. This covers information relating to past, present, or future physical or mental health conditions, healthcare provision, or healthcare payment created or received by healthcare providers, health plans, employers, schools, or clearinghouses.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the South Dakota breach notification page: removed an incorrect statement that vendors holding data for another business must report breaches to the owner, clarified that consumer reporting agency notice is required whenever resident notice is required and extends beyond the three nationwide bureaus, and restored the full list of data elements that make an employer-assigned ID number personal information.
Added the SDCL 22-40-20 risk-of-harm exemption (skip individual notice only after investigating and notifying the Attorney General, with a documented written determination kept 3 years), and fixed a misrouted Chapter 37-24 statute link.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the citation for South Dakota's HIPAA/GLBA compliance exemption (SDCL 22-40-26, not 22-40-23) and fixed a claim that understated Social Security number coverage in the personal-information definition.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
South Dakota Codified Laws, Chapter 22-40: IDENTITY CRIMES
§ 22-40-20Notice of breach of system security--Exception.In forcecited in 3 of our articles
Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement as provided under § 22-40-21. An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at sdlegislature.gov
Also relied on in: South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026), South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 22-40-19Definition of terms in §§ 22-40-19 to 22-40-26.In forcecited in 4 of our articles
Terms in §§ 22-40-19 to 22-40-26, inclusive, mean: (1) "Breach of system security," the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure; (2) "Encrypted," computerized data that is rendered unusable, unreadable, or indecipherable without the use of a decryption process or key or in accordance with the Federal Information Processing Standard 140-2 in effect on January 1, 2018; (3) "Information holder," any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; (4) "Personal information," a person's first name or first initial and last name, in combination with any one or more of…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
Also relied on in: South Dakota Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 22-40-25Prosecution for violations.In forcecited in 3 of our articles
The attorney general may prosecute each failure to disclose under the provisions of §§ 22-40-19 to 22-40-26, inclusive, as a deceptive act or practice under § 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than ten thousand dollars per day per violation. The attorney general may recover attorney's fees and any costs associated with any action brought under this section.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at sdlegislature.gov
Code of Federal Regulations Title 45
§ 160.103Definitions.In forcecited in 10 of our articles
Except as otherwise provided, the following definitions apply to this subchapter: Act means the Social Security Act. Administrative simplification provision means any requirement or prohibition established by: (1) 42 U.S.C. 1320d-1320d-4, 1320d-7, 1320d-8, and 1320d-9; (2) Section 264 of Pub. L. 104-191; (3) Sections 13400-13424 of Public Law 111-5; or (4) This subchapter. ALJ means Administrative Law Judge. ANSI stands for the American National Standards Institute. Business associate: (1) Except as provided in paragraph (4) of this definition, business associate means, with respect to a covered entity, a person who: (i) On behalf of such covered entity or of an organized health care arrangement (as defined in this section) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing,…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 374 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts apply the Section 160.103 definitions inside and outside HIPAA. Zani v. Rite Aid Headquarters Corp. (2017) used its health care definition to hold pharmacy flu shot calls fell within the TCPA health care exemption. Kenneth Wilson v. UnitedHealthcare Insurance Co (2022) applied its individually identifiable health information test.
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…mation” as “individually identifiable health information.” 45 C.F.R. § 160.103 . Both Congress and HHS define “individ…”
- Florida Ex Rel. Attorney General v. United States Department of Health & Human Services (Court of Appeals for the Eleventh Circuit 2011, 648 F.3d 1235)“…is paid for health care in the normal course of business.” 45 C.F.R. § 160.103. And in 2009, Congress expanded HIPAA’s…”
- Zani v. Rite Aid Headquarters Corp. (District Court, S.D. New York 2017, 246 F. Supp. 3d 835)✓Rite Aid sent a prerecorded flu shot reminder to a pharmacy customer's cell phone. Reading the TCPA health care exemption against 160.103, the court held the call conveyed a health care message made on behalf of a covered entity, and granted Rite Aid summary judgment.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Does a Failed Drug Test Show Up on Your Record?, When Is a Business Associate Agreement Required? (2026), District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- S.D. Codified Laws Chapter 22-40 - Identity Crimes(sdlegislature.gov).gov
- Section 22-40-19 - Definitions(law.justia.com)
- Section 22-40-20 - Notice of Breach(law.justia.com)
- Section 22-40-25 - Prosecution for Violations(law.justia.com)
- South Dakota Consumer Protection - Security Breaches(consumer.sd.gov).gov
- S.D. Codified Laws 22-40-19 - Definition of terms(sdlegislature.gov)
- S.D. Codified Laws 22-40-20 - Disclosure of breach of system security(sdlegislature.gov)
- S.D. Codified Laws 22-40-24 - Notice to consumer reporting agencies(sdlegislature.gov)