South Dakota

South Dakota Privacy Law

South Dakota was the last state in the country to adopt a breach-notification statute, in 2018, and it has since built outward from consumer protection rather than toward a comprehensive privacy code. The 2026 Legislature added a direct-to-consumer genetic testing regime to chapter 37-24 — the deceptive-practices chapter — requiring separate express consent for each transfer, use and retention of a consumer’s genetic data and biological sample. Breach notice, by contrast, sits in the criminal code at chapter 22-40, is prosecuted by the Attorney General as a deceptive act, and carries a civil penalty measured per day rather than per violation.

Sector-Specific Privacy Laws in South Dakota

Genetic data privacy (SDCL ch. 37-24, added by 2026 Senate Bill 49)

The Act adds six sections to the deceptive-practices chapter and applies to a “direct-to-consumer genetic testing company”, defined as an entity offering genetic testing products or services directly to consumers or analyzing, collecting or using genetic data collected through such a product. Section 2 requires a plain-language privacy policy and a prominent public privacy notice covering access, consent, collection, deletion, disclosure, retention, security and transfer; a security program; and a consumer process to access genetic data, delete the account and the data, and obtain destruction of the biological sample. Its consent architecture is layered: initial express consent describing the uses of the data and who can see the results, then separate express consent naming the recipient for each transfer to anyone other than the company’s vendors and service providers, for each use beyond the primary purpose of the test, for retaining a biological sample after testing is complete, and for marketing based on genetic data. Informed consent complying with 45 C.F.R. part 46 is required to transfer data for research. Section 3 gives a company thirty days to honour a revocation of consent and thirty days to destroy a biological sample after revocation. Section 4 binds service providers to the same obligations. Section 6 exempts HIPAA protected health information, samples and data generated for medical screening, diagnosis or treatment, institutions of higher education and entities they own, forensic laboratories working with law enforcement, research conducted under the federal human-subjects rules, and hospitals licensed under chapter 34-12 together with their affiliated laboratories and facilities. Senate Bill 49 was introduced by the chair of the Senate Judiciary Committee at the request of the Attorney General, passed the Senate 34-0 on January 22, 2026 and the House 65-2 on March 4, 2026, and the Senate concurred in the House amendments 34-0 on March 9, 2026.

Deceptive acts and practices (SDCL ch. 37-24)

Section 37-24-6(1) makes it a deceptive act to knowingly use any deceptive act or practice, fraud, false pretense, false promise or misrepresentation, or to conceal, suppress or omit any material fact, in connection with the sale or advertisement of merchandise — expressly “regardless of whether any person has in fact been misled, deceived, or damaged thereby”. The section also reaches misleading caller-identification transmission under subdivision (16) and unsolicited commercial email that omits an “ADV:” subject-line prefix under subdivision (13). Unusually, the section carries criminal grading tied to amount: each act under $1,000 is a Class 1 misdemeanor, each act over $1,000 but under $100,000 is a Class 6 felony, and each act over $100,000 is a Class 5 felony. Section 37-24-23 lets the Attorney General sue for a temporary or permanent injunction on three days’ notice and recover attorney’s fees and costs if the prevailing plaintiff; § 37-24-27 adds a civil penalty of up to $2,000 per violation where the court finds the use was intentional, which the section defines as the violator knowing or having reason to know the conduct violated § 37-24-6. Section 37-24-31 permits any person adversely affected to bring a civil action, but limits the recovery to actual damages suffered.

Recording, images and digitally fabricated material (SDCL § 22-21-4)

South Dakota’s invasion-of-privacy offense turns on both consent and purpose: it reaches conduct done without the consent or knowledge of the individual depicted and with intent to self-gratify or to alarm, annoy, embarrass, harass, invade the privacy of, threaten, or cause emotional, financial, physical, psychological or reputational harm. Subdivision (1) covers using a device to photograph or visually record a person without clothing or under or through clothing; subdivision (2) covers disclosing, disseminating, distributing or selling such a recording. Subdivision (3), added by 2026 Senate Bill 41, extends the section to knowingly and intentionally creating or distributing “digitally fabricated material” depicting an identifiable individual in a state of nudity or engaged in sexual conduct, where an ordinary viewer would conclude the depiction is of that individual. A violation of subdivision (1) or (2) is a Class 1 misdemeanor, rising to a Class 6 felony where the victim is seventeen or younger and the perpetrator at least twenty-one, or on any subsequent violation; a violation of subdivision (3) is a Class 5 felony.

Data Breach Notification in South Dakota

South Dakota’s breach law sits in the criminal code, at SDCL §§ 22-40-19 to 22-40-26, enacted in 2018. Section 22-40-19 separates two categories: “personal information” is a name plus a Social Security number, driver license or other government-issued identification number, a financial account or card number with its access code, health information as defined in 45 C.F.R. § 160.103, or an employer-assigned identification number combined with an access code or authentication biometric; “protected information” is a username or email address with a password or security-question answer, or an account or card number with a code permitting account access, and it carries no name requirement. The definition of a breach reaches encrypted data where the encryption key is also acquired. Section 22-40-20 requires disclosure to any affected resident not later than sixty days from discovery or notification. It also builds in a risk-of-harm exception with a filing condition: an information holder need not notify if, following an appropriate investigation and notice to the attorney general, it reasonably determines the breach will not likely result in harm — and it must document that determination in writing and keep the documentation for at least three years. Separately, any breach exceeding 250 South Dakota residents must be disclosed to the Attorney General by mail or email. Substitute notice under § 22-40-22(3) requires a cost exceeding $250,000 or an affected class exceeding 500,000 persons. Section 22-40-24 requires notice to all nationwide consumer reporting agencies without unreasonable delay whenever resident notice is triggered, and § 22-40-26 deems a holder regulated under HIPAA or the Gramm-Leach-Bliley Act compliant if it notifies affected South Dakota residents under those federal rules.

Residents must be notified not later than 60 days from discovery of or notification of the breach, unless law enforcement needs a longer period. Notify the Attorney General for any breach exceeding 250 South Dakota residents, and also where the holder decides not to notify at all. Complaints are taken by the South Dakota Attorney General, which enforces the statute.

How South Dakota Enforces Its Privacy Laws

Breach failures are prosecuted as deceptive practices, with a per-day penalty. Section 22-40-25 provides that the Attorney General may prosecute each failure to disclose as a deceptive act or practice under § 37-24-6, which pulls in the criminal grading and the remedies of chapter 37-24. On top of those, the section authorises a separate civil action to recover, on behalf of the state, a civil penalty of “not more than ten thousand dollars per day per violation”, and permits recovery of attorney’s fees and costs. The per-day measure is what distinguishes the South Dakota exposure from the per-violation caps in most neighbouring states.

The genetic data statute is enforced only by the Attorney General. Section 5 of 2026 Senate Bill 49 provides that the Attorney General, on petition to the court, may impose a civil penalty against a person for violating the Act’s consent, revocation or service-provider sections, and caps that penalty at $5,000 per violation. The Act contains no private right of action and no cure period.

Recent Enforcement in South Dakota

23andMe — multistate suit to block the sale of genetic data, 2025. The Attorney General’s office states that Attorney General Marty Jackley joined a coalition of 29 attorneys general that filed a 2025 lawsuit against 23andMe to block the company’s sale of personal genetic data without customer consent. The office describes that action as the direct origin of the state’s own genetic data statute: announcing the signing of Senate Bill 49 on March 23, 2026, it said the bill “was a result of him joining a coalition of 29 Attorneys General” in that suit, and quoted the Attorney General saying that “our genetic data, like our other personal information, should not be sold to the highest bidder”.

Nationwide Mutual Insurance — 33-jurisdiction data-breach settlement, $119,585.50 to South Dakota. The Attorney General’s office announced joining the attorneys general of 32 other states in settling with Nationwide Mutual Insurance Company and its subsidiary Allied Property & Casualty over an October 2012 breach that the states alleged was caused by a failure to apply a critical security patch. The office reports the breach exposed personal information of 1.27 million consumers, including Social Security numbers, driver’s license numbers and credit-scoring information, of whom 14,728 were South Dakotans, and that the state’s share of the $5.5 million payment was $119,585.50. The injunctive terms require Nationwide to hire a technology officer responsible for security updates, to inventory patches applied to systems holding personal information, to commission an annual independent audit of its data-collection practices, and to disclose to consumers that it retains their information even when they do not become customers — a term the office attributes to the fact that many affected people had only requested quotes.

Pending Privacy Legislation

The 2026 session was the Attorney General’s, not a privacy-advocacy coalition’s: his office reports that all ten of its legislative measures were signed, among them Senate Bill 49 on genetic data, Senate Bill 41 on digitally fabricated intimate imagery and criminal invasion of privacy, Senate Bill 43 on search and seizure of digital currency, and Senate Bill 44 establishing investigative subpoena authority to gather business records. No comprehensive consumer privacy bill of the kind enacted in Montana or Minnesota was among them, and South Dakota consumers still have no statutory right of access, deletion, correction or opt-out outside the genetic-testing context.

Federal Privacy Laws That Apply in South Dakota

Federal privacy law applies in South Dakota by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Deceptive acts and practices (SDCL ch. 37-24), which the South Dakota Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach South Dakota Businesses

With no comprehensive state statute, most privacy obligations on a South Dakota business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach South Dakota businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while South Dakota itself has none, and any business holding personal information about South Dakota residents is subject to the state’s breach-notification statute described above.

South Dakota Privacy Law FAQ

How long does a South Dakota business have to notify residents of a breach?
Section 22-40-20 sets an outer limit of sixty days from the discovery of or notification of the breach, unless a longer period is required by the legitimate needs of law enforcement under § 22-40-21. Where law enforcement delays the notice, § 22-40-21 requires it to be made within thirty days after the agency determines notification will not compromise the criminal investigation.
Can a South Dakota business decide not to notify at all?
Section 22-40-20 allows it only on conditions. An information holder is not required to disclose if, following an appropriate investigation and notice to the attorney general, it reasonably determines the breach will not likely result in harm to the affected person. The determination must be documented in writing and the documentation kept for at least three years. The exception therefore involves the Attorney General rather than avoiding the office.
What is “protected information” under South Dakota’s breach law?
Section 22-40-19(5) defines it separately from “personal information” and, unlike that definition, does not require a name. It covers a username or email address in combination with a password, security-question answer or other information permitting access to an online account, and an account, credit-card or debit-card number in combination with a security code, access code or password permitting access to a financial account. A breach of protected information triggers the same notification duty under § 22-40-20.
What penalty does South Dakota attach to a failure to give breach notice?
Section 22-40-25 lets the Attorney General prosecute each failure to disclose as a deceptive act or practice under § 37-24-6, and adds a civil action to recover on behalf of the state a civil penalty of not more than $10,000 per day per violation, plus attorney’s fees and costs. The penalty runs per day, not per record or per violation.
What does South Dakota’s 2026 genetic data law require?
Senate Bill 49 added sections to SDCL chapter 37-24 requiring a direct-to-consumer genetic testing company to publish a plain-language privacy policy and a prominent privacy notice, maintain a security program, and give consumers a way to access their genetic data, delete their account and data, and have their biological sample destroyed. Consent is layered: initial express consent, then separate express consent naming the recipient for each transfer beyond the company’s vendors, for each use beyond the primary testing purpose, for retaining a sample after testing, and for marketing based on the data. A revocation must be honoured, and any retained sample destroyed, within thirty days.
Who can sue under South Dakota’s genetic data law?
Only the state. Section 5 of the Act gives the Attorney General, on petition to the court, the power to impose a civil penalty of up to $5,000 per violation, and the Act creates no private right of action. That contrasts with the general deceptive-practices chapter, where § 37-24-31 lets a person adversely affected sue — though only for actual damages suffered.
Which entities are outside the South Dakota genetic data statute?
Section 6 of the Act lists seven exclusions from its consent, revocation, service-provider and penalty sections: HIPAA protected health information held by a covered entity or business associate; samples obtained or data generated for a consumer’s medical screening, diagnosis or treatment; public or private institutions of higher education and entities they own or operate; forensic laboratories operated by or under contract with a law enforcement agency doing forensic analysis in a criminal investigation; entities using genetic data only for research complying with the federal human-subjects rules, ICH Good Clinical Practice or the FDA’s human-subject regulations; and hospitals licensed under chapter 34-12, including affiliated laboratories and health-care facilities.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.