South Carolina

South Carolina Privacy Law

South Carolina routes breach notification through an agency rather than the Attorney General: Section 39-1-90 makes the Department of Consumer Affairs the recipient of notice for larger breaches and gives that Department, not a court, the power to set the administrative fine. The same section does something most breach statutes do not, which is give the affected resident a claim of their own, distinguishing willful and negligent violations and adding attorney’s fees for a successful plaintiff. Around that sit two other statutes with real teeth — a 2018 Insurance Data Security Act that puts licensees on a seventy-two-hour clock to the Director of Insurance, and a 2008 identity-theft chapter that restricts what any business may do with a Social Security number. The state’s general unfair-trade-practices statute is the outlier in the other direction: it forbids private claims brought in a representative capacity, so the class action is not available under it.

Sector-Specific Privacy Laws in South Carolina

South Carolina Insurance Data Security Act (S.C. Code tit. 38, ch. 99)

Enacted as 2018 Act No. 171 (H. 4655) and effective January 1, 2019, the chapter requires each licensee under Section 38-99-20 to develop, implement and maintain a comprehensive written information security program based on its own risk assessment, containing administrative, technical and physical safeguards, and designed to protect the confidentiality of nonpublic information, to protect against threats and unauthorized access, and to define and periodically re-evaluate a retention schedule and a destruction mechanism for information no longer needed. Section 38-99-40 sets a seventy-two-hour notification clock to the Director of Insurance running from the determination that a cybersecurity event has occurred, triggered either where South Carolina is the insurer’s state of domicile or the producer’s home state, or where the licensee reasonably believes the nonpublic information of no fewer than 250 South Carolina consumers is involved and the event either requires notice to another supervisory body or has a reasonable likelihood of materially harming a South Carolina consumer or a material part of the licensee’s operations. Section 38-99-70 exempts a licensee with fewer than ten employees including independent contractors from the security-program requirement, along with an agent or designee already covered by another licensee’s program and a HIPAA-compliant licensee that certifies its compliance in writing; a licensee that ceases to qualify has 180 days to comply. Section 38-99-80 routes penalties to Section 38-2-10, and Sections 1 and 2 of the enacting act state that the chapter neither creates nor implies a private cause of action, nor curtails one that would exist without it.

Financial Identity Fraud and Identity Theft Protection Act (S.C. Code tit. 37, ch. 20)

Section 37-20-180, added by 2008 Act No. 190 effective December 31, 2008, restricts what anyone may do with a consumer’s Social Security number or any portion of it containing six digits or more. It prohibits publicly posting or displaying the number, printing or embedding it on a card required to access products or services, requiring its transmission over the internet unless the connection is secure or the number is encrypted, requiring its use to access a website unless a password or other authentication device is also required, printing it on materials mailed to the individual unless state or federal law requires it, and selling, leasing, loaning, trading, renting or otherwise intentionally disclosing it to a third party without written consent, with an express statement that a legitimate business purpose does not include bulk purchase or rental of Social Security numbers or use in marketing. Ten exceptions follow, including applications and enrolment documents, internal verification, fraud investigation and background checks, legal process, and employment records. Section 37-20-190 requires a business disposing of a record containing a customer’s personal identifying information to shred, erase or otherwise render it undecipherable, and Section 37-20-160 gives consumers the security freeze. Section 37-20-200 makes a wilful violator liable for three times actual damages or up to $1,000 per incident, whichever is greater, plus fees and costs.

South Carolina Unfair Trade Practices Act (S.C. Code tit. 39, ch. 5)

Section 39-5-20 declares unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce unlawful, and directs courts construing it to be guided by the interpretations the Federal Trade Commission and the federal courts give to section 5(a)(1) of the FTC Act. Section 39-5-50 lets the Attorney General seek a temporary restraining order or injunction on reasonable cause, ordinarily after three days’ notice to the target unless the Attorney General determines in writing that delay would substantially impair the article’s purposes; Sections 39-5-70 and 39-5-80 supply the investigative demand and further powers, and Section 39-5-60 the assurance of voluntary compliance. Section 39-5-110 sets the civil penalty at not more than $5,000 per wilful violation and not more than $15,000 for each violation of an injunction, with the issuing court retaining jurisdiction. Section 39-5-140 is the provision that most distinguishes the Act: a person suffering an ascertainable loss may sue “individually, but not in a representative capacity”, so no class action lies under the statute; treble damages are mandatory on a finding of wilful or knowing violation, and attorney’s fees and costs follow any finding of violation. Section 39-5-150 bars an action brought more than three years after discovery of the unlawful conduct.

Data Breach Notification in South Carolina

Section 39-1-90 conditions the duty to notify on a harm test rather than on acquisition alone: disclosure is required to a South Carolina resident whose unencrypted and unredacted personal identifying information was or is reasonably believed to have been acquired by an unauthorized person “when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident”. Subsection (D)(3) defines personal identifying information as a first name or initial and last name linked to a Social Security number, a driver’s license or state identification card number, a financial account or card number with the code that would permit access, or — a catch-all most states lack — “other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual”. Substitute notice is available under subsection (E)(4) where the cost of notice exceeds $250,000, the affected class exceeds 500,000, or contact information is insufficient. Subsection (K) requires notice to the Consumer Protection Division of the Department of Consumer Affairs and to the nationwide consumer reporting agencies, covering the timing, distribution and content of the notice, whenever a business notifies more than 1,000 persons at one time. Subsection (H) sets the penalty: a person who knowingly and wilfully violates the section is subject to an administrative fine of $1,000 for each resident whose information was accessible by reason of the breach, in an amount decided by the Department. Subsections (I) and (J) exclude a bank or financial institution subject to and compliant with the Gramm-Leach-Bliley privacy and security provisions, and deem compliance for a financial institution following the 2005 federal Interagency Guidance.

Residents must be notified in the most expedient time possible and without unreasonable delay following discovery; no fixed number of days. Notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies when more than 1,000 residents are notified at one time. Complaints are taken by the South Carolina Department of Consumer Affairs, which enforces the statute.

How South Carolina Enforces Its Privacy Laws

The breach fine is set administratively, not by a court. Section 39-1-90(H) gives the amount of the per-resident fine to the Department of Consumer Affairs to decide, which places the first decision about a notification failure with the agency rather than with a judge. The Department describes its own posture as administering and enforcing more than 120 statutes, some of which permit it to open investigations, issue orders, take civil or administrative action, or refer a matter for criminal prosecution, and it states that a business affected by an order or subpoena may request a contested case hearing at the Administrative Law Court.

Guidance to the Attorney General on interpreting the trade practices act. Section 39-5-20(b) records the legislature’s intent that courts construing the prohibition be guided by the interpretations given by the Federal Trade Commission and the federal courts to section 5(a)(1) of the FTC Act, as amended from time to time. That makes federal unfairness and deception doctrine the reference point for a South Carolina privacy claim founded on a misstatement about data practices, rather than a body of state-specific standards.

Recent Enforcement in South Carolina

Community Health Systems — 28-state judgment over a breach affecting 400,903 South Carolinians. On October 8, 2020 the Attorney General announced that South Carolina, with the attorneys general of twenty-seven other states, had obtained a judgment against Tennessee-based CHS/Community Health Systems, Inc. and its subsidiary CHSPSC LLC, resolving an investigation into a data breach that affected roughly 6.1 million patients nationwide, including 400,903 in South Carolina. The company owned, leased or operated 206 affiliated hospitals at the time, and the breach exposed patients’ names, birthdates, Social Security numbers, telephone numbers and addresses. The agreed judgment required a $5 million payment to the states and required CHS to implement and maintain a comprehensive information security program with specified requirements, among them a written incident response plan, security awareness and privacy training for all personnel with access to protected health information, limits on unnecessary or inappropriate access to that information, and specific policies on business associates including business associate agreements and audits of those associates.

23andMe — multistate bankruptcy settlement covering 80,181 South Carolina consumers. The Attorney General joined a coalition of forty-two attorneys general in a settlement with the bankruptcy trustee for 23andMe over the October 2023 credential-stuffing breach that exposed data on 6.9 million consumers worldwide, including 80,181 in South Carolina. The settlement allowed $150 million in state claims against a limited estate, with recovery capped at $18 million paid immediately from available bankruptcy funds, of which South Carolina received $280,000. The multistate investigation found the company failed to guard against credential stuffing by comparing passwords against blocklists of known breached passwords or requiring multifactor authentication, failed to implement rate limiting or intrusion prevention, failed to implement logging and monitoring likely to detect a breach, failed to investigate unusual login patterns including a spike in login attempts, failed to remediate known vulnerabilities and failed to review and test design features. The company’s consumer data was sold in bankruptcy to TTAM Research Institute on terms including enhanced data security requirements, an advisory board, continued deletion rights and an agreement to be bound by comprehensive privacy laws without exception.

Pending Privacy Legislation

House Bill 3401 of the 126th General Assembly, styled “Technology Transparency” and sponsored by Representatives Guffey and Pope, would add a new Chapter 31 to Title 37 of the South Carolina Code. As prefiled on December 5, 2024 it provides consumer rights of access, correction, deletion and portability, an appeals process for denied requests, duties for controllers and processors, a privacy notice requirement, data protection assessments, limits on the sale of certain personal data and on the processing of sensitive data, obligations for deidentified data, and a provision voiding contracts and agreements that waive the chapter’s rights. It also restricts communication between a governmental entity and a social media platform in certain circumstances, states that the chapter does not establish a private cause of action, makes a violation an unfair and deceptive trade practice, and exempts information regulated under HIPAA, the Fair Credit Reporting Act, the Driver’s Privacy Protection Act, FERPA and the Farm Credit Act. The bill was introduced and read the first time on January 14, 2025 and referred to the House Judiciary Committee, where the recorded history ends.

Federal Privacy Laws That Apply in South Carolina

Federal privacy law applies in South Carolina by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the South Carolina Unfair Trade Practices Act (S.C. Code tit. 39, ch. 5), which the South Carolina Department of Consumer Affairs enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach South Carolina Businesses

With no comprehensive state statute, most privacy obligations on a South Carolina business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach South Carolina businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while South Carolina itself has none, and any business holding personal information about South Carolina residents is subject to the state’s breach-notification statute described above.

South Carolina Privacy Law FAQ

Who receives breach notices in South Carolina, and at what threshold?
Not the Attorney General. Section 39-1-90(K) directs that when a business provides notice to more than one thousand persons at one time, it must notify the Consumer Protection Division of the Department of Consumer Affairs, along with all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution and content of the notice. The Department publishes the notices it receives and has maintained that list since 2015.
Can a South Carolina resident sue over a breach-notification failure?
Section 39-1-90(G) says so expressly, and separates the two states of mind. A resident injured by a violation may institute a civil action to recover damages in the case of a wilful and knowing violation, or an action limited to actual damages in the case of a negligent violation, may seek an injunction to enforce compliance, and may recover attorney’s fees and court costs if successful. The subsection states that these rights are in addition to and cumulative of all other rights and remedies available at law.
How large can the fine be for a South Carolina notification failure?
It scales with the number of people affected rather than being capped. Section 39-1-90(H) provides that a person who knowingly and wilfully violates the section is subject to an administrative fine of one thousand dollars for each resident whose information was accessible by reason of the breach, with the amount to be decided by the Department of Consumer Affairs.
How many South Carolinians have been affected by reported breaches recently?
The Department of Consumer Affairs publishes the figures. In a July 6, 2026 release the Department reported that between January 1 and June 30, 2026, forty-one businesses reported security breaches affecting 1,131,320 South Carolina residents. Financial businesses reported the most breaches at twelve, involving 801,652 residents; the hospitality sector reported four breaches affecting 154,455 residents and the education sector three breaches affecting 91,842.
Does South Carolina allow class actions under its unfair trade practices statute?
No. Section 39-5-140(a) provides that a person who suffers an ascertainable loss as a result of an unfair or deceptive method, act or practice declared unlawful by Section 39-5-20 may bring an action “individually, but not in a representative capacity”, to recover actual damages. The same subsection makes treble damages mandatory where the court finds the violation was wilful or knowing, and requires an award of reasonable attorney’s fees and costs on any finding of violation.
How quickly must a South Carolina insurance licensee report a cybersecurity event?
Section 38-99-40(A) requires notice to the Director of Insurance no later than seventy-two hours after determining that a cybersecurity event has occurred, where South Carolina is the insurer’s state of domicile or the producer’s home state, or where the licensee reasonably believes the nonpublic information of no fewer than 250 South Carolina consumers is involved and the event either triggers notice to another supervisory body or has a reasonable likelihood of materially harming a South Carolina consumer or a material part of the licensee’s normal operations.
What can a business do with a South Carolina consumer’s Social Security number?
Section 37-20-180 lists what it may not do with the number or any portion containing six digits or more: publicly post or display it, print or embed it on an access card, require its transmission over an unsecured internet connection, require it as a website credential without a second authentication factor, print it on mailed materials unless required by law, or sell, lease, loan, trade, rent or otherwise disclose it to a third party without written consent. The last prohibition carries an exception for a third party’s legitimate business or government purpose, which the section states does not include bulk purchase or rental of Social Security numbers or use in marketing.
Does the South Carolina Insurance Data Security Act create a private claim?
Section 1 of 2018 Act No. 171, reproduced in the editor’s note to the chapter, states that the act “may not be construed to create or imply a private cause of action for a violation of its provisions nor may it be construed to curtail a private cause of action which would otherwise exist in the absence of this act”. Section 38-99-100 separately provides that nothing in the chapter creates a duty or liability for a provider of communication services for transmitting voice, data or other information over its network.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.