South Carolina Privacy Law
South Carolina routes breach notification through an agency rather than the Attorney General: Section 39-1-90 makes the Department of Consumer Affairs the recipient of notice for larger breaches and gives that Department, not a court, the power to set the administrative fine. The same section does something most breach statutes do not, which is give the affected resident a claim of their own, distinguishing willful and negligent violations and adding attorney’s fees for a successful plaintiff. Around that sit two other statutes with real teeth — a 2018 Insurance Data Security Act that puts licensees on a seventy-two-hour clock to the Director of Insurance, and a 2008 identity-theft chapter that restricts what any business may do with a Social Security number. The state’s general unfair-trade-practices statute is the outlier in the other direction: it forbids private claims brought in a representative capacity, so the class action is not available under it.
Sector-Specific Privacy Laws in South Carolina
South Carolina Insurance Data Security Act (S.C. Code tit. 38, ch. 99)
Enacted as 2018 Act No. 171 (H. 4655) and effective January 1, 2019, the chapter requires each licensee under Section 38-99-20 to develop, implement and maintain a comprehensive written information security program based on its own risk assessment, containing administrative, technical and physical safeguards, and designed to protect the confidentiality of nonpublic information, to protect against threats and unauthorized access, and to define and periodically re-evaluate a retention schedule and a destruction mechanism for information no longer needed. Section 38-99-40 sets a seventy-two-hour notification clock to the Director of Insurance running from the determination that a cybersecurity event has occurred, triggered either where South Carolina is the insurer’s state of domicile or the producer’s home state, or where the licensee reasonably believes the nonpublic information of no fewer than 250 South Carolina consumers is involved and the event either requires notice to another supervisory body or has a reasonable likelihood of materially harming a South Carolina consumer or a material part of the licensee’s operations. Section 38-99-70 exempts a licensee with fewer than ten employees including independent contractors from the security-program requirement, along with an agent or designee already covered by another licensee’s program and a HIPAA-compliant licensee that certifies its compliance in writing; a licensee that ceases to qualify has 180 days to comply. Section 38-99-80 routes penalties to Section 38-2-10, and Sections 1 and 2 of the enacting act state that the chapter neither creates nor implies a private cause of action, nor curtails one that would exist without it.
Financial Identity Fraud and Identity Theft Protection Act (S.C. Code tit. 37, ch. 20)
Section 37-20-180, added by 2008 Act No. 190 effective December 31, 2008, restricts what anyone may do with a consumer’s Social Security number or any portion of it containing six digits or more. It prohibits publicly posting or displaying the number, printing or embedding it on a card required to access products or services, requiring its transmission over the internet unless the connection is secure or the number is encrypted, requiring its use to access a website unless a password or other authentication device is also required, printing it on materials mailed to the individual unless state or federal law requires it, and selling, leasing, loaning, trading, renting or otherwise intentionally disclosing it to a third party without written consent, with an express statement that a legitimate business purpose does not include bulk purchase or rental of Social Security numbers or use in marketing. Ten exceptions follow, including applications and enrolment documents, internal verification, fraud investigation and background checks, legal process, and employment records. Section 37-20-190 requires a business disposing of a record containing a customer’s personal identifying information to shred, erase or otherwise render it undecipherable, and Section 37-20-160 gives consumers the security freeze. Section 37-20-200 makes a wilful violator liable for three times actual damages or up to $1,000 per incident, whichever is greater, plus fees and costs.
South Carolina Unfair Trade Practices Act (S.C. Code tit. 39, ch. 5)
Section 39-5-20 declares unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce unlawful, and directs courts construing it to be guided by the interpretations the Federal Trade Commission and the federal courts give to section 5(a)(1) of the FTC Act. Section 39-5-50 lets the Attorney General seek a temporary restraining order or injunction on reasonable cause, ordinarily after three days’ notice to the target unless the Attorney General determines in writing that delay would substantially impair the article’s purposes; Sections 39-5-70 and 39-5-80 supply the investigative demand and further powers, and Section 39-5-60 the assurance of voluntary compliance. Section 39-5-110 sets the civil penalty at not more than $5,000 per wilful violation and not more than $15,000 for each violation of an injunction, with the issuing court retaining jurisdiction. Section 39-5-140 is the provision that most distinguishes the Act: a person suffering an ascertainable loss may sue “individually, but not in a representative capacity”, so no class action lies under the statute; treble damages are mandatory on a finding of wilful or knowing violation, and attorney’s fees and costs follow any finding of violation. Section 39-5-150 bars an action brought more than three years after discovery of the unlawful conduct.
Data Breach Notification in South Carolina
Section 39-1-90 conditions the duty to notify on a harm test rather than on acquisition alone: disclosure is required to a South Carolina resident whose unencrypted and unredacted personal identifying information was or is reasonably believed to have been acquired by an unauthorized person “when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident”. Subsection (D)(3) defines personal identifying information as a first name or initial and last name linked to a Social Security number, a driver’s license or state identification card number, a financial account or card number with the code that would permit access, or — a catch-all most states lack — “other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual”. Substitute notice is available under subsection (E)(4) where the cost of notice exceeds $250,000, the affected class exceeds 500,000, or contact information is insufficient. Subsection (K) requires notice to the Consumer Protection Division of the Department of Consumer Affairs and to the nationwide consumer reporting agencies, covering the timing, distribution and content of the notice, whenever a business notifies more than 1,000 persons at one time. Subsection (H) sets the penalty: a person who knowingly and wilfully violates the section is subject to an administrative fine of $1,000 for each resident whose information was accessible by reason of the breach, in an amount decided by the Department. Subsections (I) and (J) exclude a bank or financial institution subject to and compliant with the Gramm-Leach-Bliley privacy and security provisions, and deem compliance for a financial institution following the 2005 federal Interagency Guidance.
Residents must be notified in the most expedient time possible and without unreasonable delay following discovery; no fixed number of days. Notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies when more than 1,000 residents are notified at one time. Complaints are taken by the South Carolina Department of Consumer Affairs, which enforces the statute.
How South Carolina Enforces Its Privacy Laws
The breach fine is set administratively, not by a court. Section 39-1-90(H) gives the amount of the per-resident fine to the Department of Consumer Affairs to decide, which places the first decision about a notification failure with the agency rather than with a judge. The Department describes its own posture as administering and enforcing more than 120 statutes, some of which permit it to open investigations, issue orders, take civil or administrative action, or refer a matter for criminal prosecution, and it states that a business affected by an order or subpoena may request a contested case hearing at the Administrative Law Court.
Guidance to the Attorney General on interpreting the trade practices act. Section 39-5-20(b) records the legislature’s intent that courts construing the prohibition be guided by the interpretations given by the Federal Trade Commission and the federal courts to section 5(a)(1) of the FTC Act, as amended from time to time. That makes federal unfairness and deception doctrine the reference point for a South Carolina privacy claim founded on a misstatement about data practices, rather than a body of state-specific standards.
Recent Enforcement in South Carolina
Community Health Systems — 28-state judgment over a breach affecting 400,903 South Carolinians. On October 8, 2020 the Attorney General announced that South Carolina, with the attorneys general of twenty-seven other states, had obtained a judgment against Tennessee-based CHS/Community Health Systems, Inc. and its subsidiary CHSPSC LLC, resolving an investigation into a data breach that affected roughly 6.1 million patients nationwide, including 400,903 in South Carolina. The company owned, leased or operated 206 affiliated hospitals at the time, and the breach exposed patients’ names, birthdates, Social Security numbers, telephone numbers and addresses. The agreed judgment required a $5 million payment to the states and required CHS to implement and maintain a comprehensive information security program with specified requirements, among them a written incident response plan, security awareness and privacy training for all personnel with access to protected health information, limits on unnecessary or inappropriate access to that information, and specific policies on business associates including business associate agreements and audits of those associates.
23andMe — multistate bankruptcy settlement covering 80,181 South Carolina consumers. The Attorney General joined a coalition of forty-two attorneys general in a settlement with the bankruptcy trustee for 23andMe over the October 2023 credential-stuffing breach that exposed data on 6.9 million consumers worldwide, including 80,181 in South Carolina. The settlement allowed $150 million in state claims against a limited estate, with recovery capped at $18 million paid immediately from available bankruptcy funds, of which South Carolina received $280,000. The multistate investigation found the company failed to guard against credential stuffing by comparing passwords against blocklists of known breached passwords or requiring multifactor authentication, failed to implement rate limiting or intrusion prevention, failed to implement logging and monitoring likely to detect a breach, failed to investigate unusual login patterns including a spike in login attempts, failed to remediate known vulnerabilities and failed to review and test design features. The company’s consumer data was sold in bankruptcy to TTAM Research Institute on terms including enhanced data security requirements, an advisory board, continued deletion rights and an agreement to be bound by comprehensive privacy laws without exception.
Pending Privacy Legislation
House Bill 3401 of the 126th General Assembly, styled “Technology Transparency” and sponsored by Representatives Guffey and Pope, would add a new Chapter 31 to Title 37 of the South Carolina Code. As prefiled on December 5, 2024 it provides consumer rights of access, correction, deletion and portability, an appeals process for denied requests, duties for controllers and processors, a privacy notice requirement, data protection assessments, limits on the sale of certain personal data and on the processing of sensitive data, obligations for deidentified data, and a provision voiding contracts and agreements that waive the chapter’s rights. It also restricts communication between a governmental entity and a social media platform in certain circumstances, states that the chapter does not establish a private cause of action, makes a violation an unfair and deceptive trade practice, and exempts information regulated under HIPAA, the Fair Credit Reporting Act, the Driver’s Privacy Protection Act, FERPA and the Farm Credit Act. The bill was introduced and read the first time on January 14, 2025 and referred to the House Judiciary Committee, where the recorded history ends.
Federal Privacy Laws That Apply in South Carolina
Federal privacy law applies in South Carolina by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the South Carolina Unfair Trade Practices Act (S.C. Code tit. 39, ch. 5), which the South Carolina Department of Consumer Affairs enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach South Carolina Businesses
With no comprehensive state statute, most privacy obligations on a South Carolina business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach South Carolina businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while South Carolina itself has none, and any business holding personal information about South Carolina residents is subject to the state’s breach-notification statute described above.
South Carolina Privacy Law FAQ
Who receives breach notices in South Carolina, and at what threshold?
Can a South Carolina resident sue over a breach-notification failure?
How large can the fine be for a South Carolina notification failure?
How many South Carolinians have been affected by reported breaches recently?
Does South Carolina allow class actions under its unfair trade practices statute?
How quickly must a South Carolina insurance licensee report a cybersecurity event?
What can a business do with a South Carolina consumer’s Social Security number?
Does the South Carolina Insurance Data Security Act create a private claim?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- S.C. Code § 39-1-90 — Business data, breach of security; notifications, definitions, penalties, exceptions statute
- S.C. Code tit. 38, ch. 99 — South Carolina Insurance Data Security Act statute
- S.C. Code tit. 39, ch. 5 — South Carolina Unfair Trade Practices Act statute
- S.C. Code tit. 37, ch. 20 — Financial Identity Fraud and Identity Theft Protection Act statute
- H. 3401 (2025-2026) — Technology Transparency, status and text legislation
- S.C. Department of Consumer Affairs — breach report for January to June 2026 agency
- S.C. Department of Consumer Affairs — enforcement actions agency
- S.C. Attorney General — judgment resolving the Community Health Systems data breach investigation agency
- S.C. Attorney General — multistate settlement of bankruptcy claims against 23andMe agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.