EnglishEspañol
South Dakota flag

South Dakota

South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 2 primary sources cited on this page. How we verify our legal content

South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify South Dakota residents after a data breach?

South Dakota requires notification within 60 days of discovering or being notified of the breach. If law enforcement requests a delay because notification would impede a criminal investigation, the notification must be sent within 30 days after law enforcement determines it will no longer compromise the investigation. One exception: after investigating and notifying the Attorney General, a business that reasonably determines the breach will not likely result in harm is not required to notify individuals, though it must document that determination in writing for at least three years.

When must the South Dakota Attorney General be notified of a data breach?

The Attorney General must be notified by mail or email when a breach affects more than 250 South Dakota residents. This is one of the lower AG notification thresholds in the country. Separately, consumer reporting agencies must be notified whenever notification under Section 22-40-20 is required, with no minimum number of affected residents.

What is the difference between personal information and protected information under South Dakota law?

Personal information requires a name combined with data elements like government ID numbers, financial account data, health information, or employer-assigned IDs combined with a required security code, access code, password, or biometric data. Protected information does not require a name. It covers usernames or email addresses combined with passwords or security answers, and financial account numbers with access codes. Both categories trigger notification obligations.

What are the penalties for failing to notify about a data breach in South Dakota?

The Attorney General may seek civil penalties of up to $10,000 per day per violation, plus attorney's fees and costs. Violations may also be prosecuted as deceptive acts under Chapter 37-24, which provides additional remedies. There is no private right of action for individuals.

Does South Dakota's breach notification law cover health information?

Yes. South Dakota defines health information by reference to 45 CFR 160.103, the HIPAA definition. This covers information relating to past, present, or future physical or mental health conditions, healthcare provision, or healthcare payment created or received by healthcare providers, health plans, employers, schools, or clearinghouses.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the South Dakota breach notification page: removed an incorrect statement that vendors holding data for another business must report breaches to the owner, clarified that consumer reporting agency notice is required whenever resident notice is required and extends beyond the three nationwide bureaus, and restored the full list of data elements that make an employer-assigned ID number personal information.

Added the SDCL 22-40-20 risk-of-harm exemption (skip individual notice only after investigating and notifying the Attorney General, with a documented written determination kept 3 years), and fixed a misrouted Chapter 37-24 statute link.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the citation for South Dakota's HIPAA/GLBA compliance exemption (SDCL 22-40-26, not 22-40-23) and fixed a claim that understated Social Security number coverage in the personal-information definition.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. S.D. Codified Laws Chapter 22-40 - Identity Crimes(sdlegislature.gov).gov
  2. Section 22-40-19 - Definitions(law.justia.com)
  3. Section 22-40-20 - Notice of Breach(law.justia.com)
  4. Section 22-40-25 - Prosecution for Violations(law.justia.com)
  5. South Dakota Consumer Protection - Security Breaches(consumer.sd.gov).gov
  6. S.D. Codified Laws 22-40-19 - Definition of terms(sdlegislature.gov)
  7. S.D. Codified Laws 22-40-20 - Disclosure of breach of system security(sdlegislature.gov)
  8. S.D. Codified Laws 22-40-24 - Notice to consumer reporting agencies(sdlegislature.gov)
Share: