{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/south-dakota",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/south-dakota.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/south-dakota",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/south-dakota/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/south-dakota/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "south-dakota",
    "frontmatter": {
      "title": "South Dakota Consumer Privacy Law",
      "description": "South Dakota has no comprehensive consumer-privacy statute. The operative state laws are the breach-notification act (SDCL §§ 22-40-19 to 22-40-26), a knowledge-gated deceptive-practices chapter, the new Genetic Data Privacy Act effective July 1, 2026, and a social-media data-portability law arriving July 1, 2027 — with the federal overlay carrying the rest.",
      "state": "South Dakota",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "No comprehensive consumer-privacy statute — the operative framework is the breach-notification act (S.D. Codified Laws §§ 22-40-19 to 22-40-26), the deceptive-trade-practices chapter (ch. 37-24), and the Genetic Data Privacy Act (§§ 37-24-59 to 37-24-64, effective July 1, 2026)",
        "appliesTo": "Breach duties reach any person or business that conducts business in South Dakota and owns or licenses computerized personal or protected information of residents — no size or revenue threshold; the Genetic Data Privacy Act reaches direct-to-consumer genetic-testing companies; the 2027 portability law reaches only social-media services with more than 100 million monthly users",
        "privacyPolicyRequired": "No general mandate — from July 1, 2026 only direct-to-consumer genetic-testing companies must publish a plain-language privacy policy plus a prominent privacy notice; everyone else's policy contents are driven by FTC Act § 5 and the sectoral federal rules",
        "privateRightOfAction": "None in the breach act or the Genetic Data Privacy Act — the only consumer path is S.D. Codified Laws § 37-24-31, which allows actual-damages suits solely for knowing deceptive acts under § 37-24-6",
        "regulator": "South Dakota Attorney General (Consumer Protection division)",
        "bottomLine": "South Dakota has no comprehensive consumer-privacy law — compliance today means the 60-day breach-notification statute, truthful privacy statements under a knowledge-gated deceptive-practices law, and the federal overlay; direct-to-consumer genetic-testing companies face a consent-heavy Genetic Data Privacy Act on July 1, 2026, and the largest social-media platforms face data-portability duties on July 1, 2027.",
        "lawCoverage": "sectoral",
        "policyMandate": "sectoralPolicy",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "categorySpecific",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "South Dakota consumer privacy law",
        "South Dakota no comprehensive privacy law",
        "South Dakota Genetic Data Privacy Act SB 49",
        "South Dakota genetic testing consent requirements",
        "South Dakota data breach notification 22-40-20",
        "South Dakota privacy policy requirements",
        "South Dakota attorney general privacy enforcement",
        "South Dakota deceptive trade practices 37-24-6",
        "South Dakota privacy private right of action",
        "South Dakota social media data portability SB 111"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in South Dakota?",
        "heading": "Which privacy laws apply to your business in South Dakota?",
        "answerText": "South Dakota has no comprehensive consumer-privacy law. The state framework is sectoral: a breach-notification statute that reaches any person or business that conducts business in the state and owns or licenses computerized personal or protected information of residents; a deceptive-trade-practices chapter that polices only knowing misstatements, including misstatements about data practices; and — effective July 1, 2026 — the Genetic Data Privacy Act, which imposes privacy-policy, consent, security, and deletion duties on direct-to-consumer genetic-testing companies.",
        "sources": [
          {
            "id": "q1-breach-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-19",
            "citation": "S.D. Codified Laws § 22-40-19(3).",
            "url": "https://sdlegislature.gov/Statutes/22-40-19",
            "proposition": "The breach-notification statute applies to any person or business that conducts business in South Dakota and owns or licenses computerized personal or protected information of residents, with no size threshold.",
            "verbatimQuote": "(3) \"Information holder,\" any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q1-breach-scope"
          },
          {
            "id": "q1-udap-knowing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-6",
            "citation": "S.D. Codified Laws § 37-24-6(1).",
            "url": "https://sdlegislature.gov/Statutes/37-24-6",
            "proposition": "South Dakota's deceptive-trade-practices statute reaches only knowing deceptive acts or material omissions in connection with the sale or advertisement of merchandise — a scienter element that narrows its use against privacy missteps.",
            "verbatimQuote": "It is a deceptive act or practice for any person to: (1) Knowingly act, use, or employ any deceptive act or practice, fraud, false pretense, false promises, or misrepresentation or to conceal, suppress, or omit any material fact in connection with the sale or advertisement of any merchandise or the solicitation of contributions for charitable purposes, regardless of whether any person has in fact been misled, deceived, or damaged thereby;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q1-udap-knowing"
          },
          {
            "id": "q1-genetic-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-60",
            "citation": "S.D. Codified Laws § 37-24-60(1).",
            "url": "https://sdlegislature.gov/Statutes/37-24-60",
            "proposition": "Effective July 1, 2026, a direct-to-consumer genetic-testing company must safeguard genetic data and publish a plain-language privacy policy and a prominent privacy notice.",
            "verbatimQuote": "To safeguard the confidentiality, integrity, privacy, and security of a consumer's genetic data, a direct-to-consumer genetic testing company shall: (1) Make available to the consumer in plain language: (a) A privacy policy that includes basic, essential information about the company's collection, disclosure, and use of genetic data; and (b) A prominent, publicly available privacy notice that includes information about the company's access, consent, data collection, deletion, disclosure, maintenance, retention, security, and transfer practices; and how the company uses genetic data;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q1-genetic-duty"
          },
          {
            "id": "q1-social-copy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 53-12-51",
            "citation": "S.D. Codified Laws § 53-12-51 (effective July 1, 2027).",
            "url": "https://sdlegislature.gov/Statutes/53-12-51",
            "proposition": "Beginning July 1, 2027, a social-media service with more than one hundred million active monthly users must provide a requesting user a portable, readily usable copy of the user's personal data.",
            "verbatimQuote": "If a user requests a copy of the user's personal data being held by a social media service with more than one hundred million active monthly users and whose primary focus is not charity or religion, the social media service must provide the personal data in a format that: (1) Is portable to the extent technically feasible; (2) Is readily usable to the extent practicable; and (3) Allows the user to transmit the data to another social media service, without impediment.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q1-social-copy"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your privacy policy contain in South Dakota?",
        "heading": "What must your privacy policy contain in South Dakota?",
        "answerText": "No South Dakota statute requires a general commercial privacy policy or fixes what one must say. The only South Dakota privacy-policy publication mandate addressed here arrives July 1, 2026: a direct-to-consumer genetic-testing company must make available, in plain language, both a privacy policy with basic, essential information about its collection, disclosure, and use of genetic data and a prominent, publicly available privacy notice covering its access, consent, data collection, deletion, disclosure, maintenance, retention, security, and transfer practices. For everyone else, the governing rule is truthfulness: under Section 5 of the FTC Act, a policy that misstates how you actually collect, use, share, or secure data is a deceptive practice.",
        "sources": [
          {
            "id": "q2-genetic-policy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-60(1)",
            "citation": "S.D. Codified Laws § 37-24-60(1).",
            "url": "https://sdlegislature.gov/Statutes/37-24-60",
            "proposition": "From July 1, 2026, a direct-to-consumer genetic-testing company must publish in plain language both a privacy policy and a prominent, publicly available privacy notice covering its access, consent, collection, deletion, disclosure, maintenance, retention, security, and transfer practices.",
            "verbatimQuote": "(1) Make available to the consumer in plain language: (a) A privacy policy that includes basic, essential information about the company's collection, disclosure, and use of genetic data; and (b) A prominent, publicly available privacy notice that includes information about the company's access, consent, data collection, deletion, disclosure, maintenance, retention, security, and transfer practices; and how the company uses genetic data;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q2-genetic-policy"
          },
          {
            "id": "q2-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q2-ftc5-deceptive"
          },
          {
            "id": "q2-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520.",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q2-hipaa-notice"
          },
          {
            "id": "q2-udap-knowing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-6",
            "citation": "S.D. Codified Laws § 37-24-6(1).",
            "url": "https://sdlegislature.gov/Statutes/37-24-6",
            "proposition": "The South Dakota deceptive-practices statute requires that the deceptive act or material omission be committed knowingly, so it does not reach innocent or negligent privacy-policy misstatements.",
            "verbatimQuote": "It is a deceptive act or practice for any person to: (1) Knowingly act, use, or employ any deceptive act or practice, fraud, false pretense, false promises, or misrepresentation or to conceal, suppress, or omit any material fact in connection with the sale or advertisement of any merchandise or the solicitation of contributions for charitable purposes, regardless of whether any person has in fact been misled, deceived, or damaged thereby;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q2-udap-knowing"
          }
        ]
      },
      {
        "slug": "genetic-data-consent",
        "label": "Do you need consent to collect or share genetic data in South Dakota?",
        "heading": "Do you need consent to collect or share genetic data in South Dakota?",
        "answerText": "Yes — beginning July 1, 2026. South Dakota's Genetic Data Privacy Act requires a direct-to-consumer genetic-testing company to obtain the consumer's express consent to collect, disclose, or use genetic data: an initial consent describing the uses of the data, who has access to test results, and how the data may be shared, plus a separate consent — naming the recipient — for each transfer or disclosure to any person other than the company's vendors and service providers. Express consent means an affirmative written response, which may be presented and captured electronically.",
        "sources": [
          {
            "id": "q3-effective",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-59 (enacting law)",
            "citation": "S.D. Codified Laws §§ 37-24-59 to 37-24-64 (SL 2026, ch. 164; effective July 1, 2026).",
            "url": "https://sdlegislature.gov/Statutes/37-24-59",
            "proposition": "Section 37-24-59, part of South Dakota's Genetic Data Privacy Act (§§ 37-24-59 to 37-24-64), was enacted by 2026 Session Laws chapter 164 — and South Dakota acts take effect July 1 following enactment, so the Act is effective July 1, 2026.",
            "verbatimQuote": "Source: SL 2026, ch 164, § 1.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-effective"
          },
          {
            "id": "q3-coverage",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-59",
            "citation": "S.D. Codified Laws § 37-24-59(4)-(6).",
            "url": "https://sdlegislature.gov/Statutes/37-24-59",
            "proposition": "The act covers an entity that offers genetic-testing products directly to consumers or that analyzes, collects, or uses consumer-supplied genetic data from such products; express consent is an affirmative written response, and genetic data is any non-de-identified data concerning a consumer's genetic characteristics.",
            "verbatimQuote": "(4) \"Direct-to-consumer genetic testing company,\" an entity that: (a) Offers genetic testing products or services directly to consumers; or (b) Analyzes, collects, or uses genetic data collected via a direct-to-consumer genetic testing product or service that is provided to the company by the consumer; (5) \"Express consent,\" an affirmative written response, which may be presented and captured electronically; (6) \"Genetic data,\" data other than de-identified data, regardless of format, which concerns a consumer's genetic characteristics; and",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-coverage"
          },
          {
            "id": "q3-consents",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-60(3)",
            "citation": "S.D. Codified Laws § 37-24-60(3).",
            "url": "https://sdlegislature.gov/Statutes/37-24-60",
            "proposition": "A direct-to-consumer genetic-testing company must obtain express consent to collect, disclose, or use genetic data, including initial, transfer, secondary-use, sample-retention, research, and marketing consents.",
            "verbatimQuote": "(3) Obtain the consumer's express consent to collect, disclose, or use the consumer's genetic data, including: (a) Initial express consent that describes the uses of genetic data collected through a genetic testing product or service and specifies who has access to the test results and how the genetic data may be shared; (b) Separate express consent, which must include the name of the person receiving the information, for each transfer or disclosure of the consumer's genetic data or biological sample to any person other than the company's vendors and service providers; (c) Separate express consent for each use of the consumer's genetic data or the biological sample beyond the primary purpose of the genetic testing product or service; (d) Separate express consent to retain any biological sample provided by the consumer following completion of the initial testing service requested by the consumer; (e) Informed consent, in compliance with federal policy for the protection of human research subjects under 45 C.F.R. part 46 (November 25, 2025), to transfer or disclose the consumer's genetic data to a third-party for research purposes, or for research conducted under the control of the company for publication or generalizable knowledge purposes; and (f) Separate express consent for marketing by the direct-to-consumer genetic testing company, to another consumer, based on the consumer's genetic data, or by a third party, to another consumer, based on the consumer having ordered or purchased a genetic testing product or service;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-consents"
          },
          {
            "id": "q3-security-program",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-60(4)",
            "citation": "S.D. Codified Laws § 37-24-60(4).",
            "url": "https://sdlegislature.gov/Statutes/37-24-60",
            "proposition": "A direct-to-consumer genetic-testing company must develop, implement, and maintain a security program protecting genetic data against unauthorized access, disclosure, or use.",
            "verbatimQuote": "(4) Develop, implement, and maintain a security program to protect the consumer's genetic data against unauthorized access, disclosure, or use;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-security-program"
          },
          {
            "id": "q3-rights",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-60(5)-(6)",
            "citation": "S.D. Codified Laws § 37-24-60(5)-(6).",
            "url": "https://sdlegislature.gov/Statutes/37-24-60",
            "proposition": "The company must give consumers a process to access their genetic data, delete their account and data, and obtain destruction of their biological sample, plus low-friction consent-revocation mechanisms.",
            "verbatimQuote": "(5) Provide a process for the consumer to: (a) Access the consumer's genetic data; (b) Delete the consumer's account and genetic data; and (c) Request and obtain the destruction of the consumer's biological sample; and (6) Provide mechanisms, without any unnecessary steps, for the consumer to revoke any consent of the consumer. At least one mechanism must utilize the primary medium through which the company communicates to the consumer.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-rights"
          },
          {
            "id": "q3-revocation",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-61",
            "citation": "S.D. Codified Laws § 37-24-61.",
            "url": "https://sdlegislature.gov/Statutes/37-24-61",
            "proposition": "A consent revocation must be honored within thirty days, and a revocation of consent to store a biological sample requires destruction of the sample within thirty days.",
            "verbatimQuote": "If a consumer revokes consent pursuant to § 37-24-60, the company must honor the consumer's revocation of consent within thirty days. If a consumer revokes consent to store the consumer's biological sample, the company must destroy the consumer's biological sample within thirty days of receiving the consumer's revocation of consent.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-revocation"
          },
          {
            "id": "q3-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-63",
            "citation": "S.D. Codified Laws § 37-24-63.",
            "url": "https://sdlegislature.gov/Statutes/37-24-63",
            "proposition": "Enforcement of the Genetic Data Privacy Act is by attorney-general petition for a civil penalty of up to five thousand dollars per violation.",
            "verbatimQuote": "The attorney general, upon petition to the court, may impose a civil penalty against a person for violating § 37-24-60, 37-24-61, or 37-24-62. The amount of the civil penalty may not exceed five thousand dollars per violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-penalty"
          },
          {
            "id": "q3-exemptions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-64",
            "citation": "S.D. Codified Laws § 37-24-64.",
            "url": "https://sdlegislature.gov/Statutes/37-24-64",
            "proposition": "The act exempts HIPAA protected health information held by covered entities or business associates and samples or data generated for medical screening, diagnosis, or treatment, among other carve-outs including hospitals, higher education, forensic labs, and regulated research.",
            "verbatimQuote": "The provisions of §§ 37-24-60 to 37-24-63, inclusive, do not apply to: (1) Protected health information collected by a covered entity or business associate, as those terms are defined in 45 C.F.R. § 160.103 (November 25, 2025); (2) A biological sample that is obtained or genetic data that is generated for the purpose of a consumer's medical screening, diagnosis, or treatment; (3) A public or private institution of higher education; (4) An entity owned or operated by a public or private institution of higher education; (5) A forensic laboratory that is operated by, associated with, or under contract with, a law enforcement agency, when performing forensic analysis or related services as part of a criminal investigation; (6) An entity that analyzes, collects, or uses genetic data or biological samples only in the context of research, as defined in 24 C.F.R. § 164.501 (November 25, 2025), in a manner that complies with the federal policy of the protection of human research subjects under 45 C.F.R. part 46 (November 25, 2025); the Guideline for Good Clinical Practice issued by the International Council for Harmonisation (January 6, 2025); or the United States Food and Drug Administration policy for the protection of human subjects under 21 C.F.R. part 50 (December 4, 2025) and 21 C.F.R. part 56 (December 4, 2025); or (7) A hospital licensed under chapter 34-12, including any laboratory or health care facility owned, operated by, or affiliated with the hospital.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q3-exemptions"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors and service providers say?",
        "heading": "What must your contracts with vendors and service providers say?",
        "answerText": "South Dakota has no omnibus data-processing-agreement requirement — no state statute prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs for general commercial contracts. The one sectoral exception is the Genetic Data Privacy Act: from July 1, 2026, a service provider under contract with a direct-to-consumer genetic-testing company is subject by statute to the same confidentiality obligations as the company itself, for all biological samples, genetic data, and consumer-identity information in its possession.",
        "sources": [
          {
            "id": "q4-service-provider",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-62",
            "citation": "S.D. Codified Laws § 37-24-62.",
            "url": "https://sdlegislature.gov/Statutes/37-24-62",
            "proposition": "A service provider under contract with a direct-to-consumer genetic-testing company is subject to the same statutory confidentiality obligations as the company for all samples, genetic data, and consumer-identity information it holds.",
            "verbatimQuote": "A service provider under contract with a direct-to-consumer genetic testing company is subject to the same confidentiality obligations as the direct-to-consumer genetic testing company, as set forth in § 37-24-60, with respect to all biological samples, genetic data, and information regarding the identity of any consumer that is in the service provider's possession.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q4-service-provider"
          },
          {
            "id": "q4-transfer-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-60(3)(b)",
            "citation": "S.D. Codified Laws § 37-24-60(3)(b).",
            "url": "https://sdlegislature.gov/Statutes/37-24-60",
            "proposition": "Each transfer or disclosure of genetic data or a biological sample to any person other than the company's vendors and service providers requires a separate express consent naming the recipient.",
            "verbatimQuote": "(b) Separate express consent, which must include the name of the person receiving the information, for each transfer or disclosure of the consumer's genetic data or biological sample to any person other than the company's vendors and service providers;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q4-transfer-consent"
          },
          {
            "id": "q4-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q4-glba-safeguards"
          },
          {
            "id": "q4-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,with%20respect%20to%20such%20information%3B",
            "proposition": "HIPAA requires a written business-associate contract that establishes permitted uses and disclosures, requires safeguards and breach reporting, and flows the same restrictions to subcontractors.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity, except that: (A) The contract may permit the business associate to use and disclose protected health information for the proper management and administration of the business associate, as provided in paragraph (e)(4) of this section; and (B) The contract may permit the business associate to provide data aggregation services relating to the health care operations of the covered entity. (ii) Provide that the business associate will: (A) Not use or further disclose the information other than as permitted or required by the contract or as required by law; (B) Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract; (C) Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410; (D) In accordance with § 164.502(e)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate with respect to such information;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q4-hipaa-baa"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in South Dakota?",
        "heading": "When must you notify people of a data breach in South Dakota?",
        "answerText": "Within sixty days. After discovering or being notified of a breach of system security, an information holder must disclose the breach to any South Dakota resident whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person, not later than sixty days from discovery, unless law enforcement needs a delay. If the breach exceeds two hundred fifty residents, the information holder must also disclose it to the attorney general, and any breach requiring resident notice triggers notice to the nationwide consumer reporting agencies without unreasonable delay.",
        "sources": [
          {
            "id": "q5-trigger",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-19(1)",
            "citation": "S.D. Codified Laws § 22-40-19(1).",
            "url": "https://sdlegislature.gov/Statutes/22-40-19",
            "proposition": "A breach of system security is the unauthorized acquisition of unencrypted computerized data, or encrypted data plus the key, that materially compromises personal or protected information.",
            "verbatimQuote": "(1) \"Breach of system security,\" the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-trigger"
          },
          {
            "id": "q5-protected-info",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-19(5)",
            "citation": "S.D. Codified Laws § 22-40-19(5).",
            "url": "https://sdlegislature.gov/Statutes/22-40-19",
            "proposition": "Protected information — online-account credentials or financial-account access combinations — triggers breach duties without being tied to the individual's name.",
            "verbatimQuote": "(5) \"Protected information,\" includes: (a) A user name or email address, in combination with a password, security question answer, or other information that permits access to an online account; and (b) Account number or credit or debit card number, in combination with any required security code, access code, or password that permits access to a person's financial account;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-protected-info"
          },
          {
            "id": "q5-notice-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-20",
            "citation": "S.D. Codified Laws § 22-40-20.",
            "url": "https://sdlegislature.gov/Statutes/22-40-20",
            "proposition": "An information holder must notify affected South Dakota residents of a breach not later than sixty days from discovery or notification, subject to a law-enforcement delay.",
            "verbatimQuote": "Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement as provided under § 22-40-21.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-notice-duty"
          },
          {
            "id": "q5-harm-offramp",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-20 (risk-of-harm exemption)",
            "citation": "S.D. Codified Laws § 22-40-20.",
            "url": "https://sdlegislature.gov/Statutes/22-40-20",
            "proposition": "The no-notice harm determination is available only after an appropriate investigation and notice to the attorney general, and the written determination must be kept for at least three years.",
            "verbatimQuote": "An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-harm-offramp"
          },
          {
            "id": "q5-ag-threshold",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-20 (attorney-general notice)",
            "citation": "S.D. Codified Laws § 22-40-20.",
            "url": "https://sdlegislature.gov/Statutes/22-40-20",
            "proposition": "Any breach of system security that exceeds two hundred fifty South Dakota residents must be disclosed to the attorney general by mail or electronic mail.",
            "verbatimQuote": "Any information holder that experiences a breach of system security under this section shall disclose to the attorney general by mail or electronic mail any breach of system security that exceeds two hundred fifty residents of this state.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-ag-threshold"
          },
          {
            "id": "q5-methods",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-22",
            "citation": "S.D. Codified Laws § 22-40-22(3).",
            "url": "https://sdlegislature.gov/Statutes/22-40-22",
            "proposition": "Breach notice may be written, electronic, or substitute notice; substitute notice is available where cost, class size, or insufficient contact information makes direct notice impracticable.",
            "verbatimQuote": "A disclosure under § 22-40-20 may be provided by: (1) Written notice; (2) Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 in effect as of January 1, 2018, or if the information holder's primary method of communication with the resident of this state has been by electronic means; or (3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder's website, if the information holder maintains a website page; and (c) Notification to statewide media.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-methods"
          },
          {
            "id": "q5-own-policy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-23",
            "citation": "S.D. Codified Laws § 22-40-23.",
            "url": "https://sdlegislature.gov/Statutes/22-40-23",
            "proposition": "An information holder may comply by using its own notification procedure if it is part of an information-security policy and is otherwise consistent with the statute's timing requirements.",
            "verbatimQuote": "Notwithstanding § 22-40-22, if an information holder maintains its own notification procedure as part of an information security policy for the treatment of personal or protected information and the policy is otherwise consistent with the timing requirements of this section, the information holder is in compliance with the notification requirements of § 22-40-22 if the information holder notifies each person in accordance with the information holder's policies in the event of a breach of system security.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-own-policy"
          },
          {
            "id": "q5-cra-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-24",
            "citation": "S.D. Codified Laws § 22-40-24.",
            "url": "https://sdlegislature.gov/Statutes/22-40-24",
            "proposition": "Whenever resident notice is required, the information holder must also notify the nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution, and content of the notice.",
            "verbatimQuote": "If an information holder discovers circumstances that require notification pursuant to § 22-40-20 the information holder shall also notify, without unreasonable delay, all consumer reporting agencies, as defined under 15 U.S.C. § 1681a in effect as of January 1, 2018, and any other credit bureau or agency that compiles and maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-cra-notice"
          },
          {
            "id": "q5-federal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-26",
            "citation": "S.D. Codified Laws § 22-40-26.",
            "url": "https://sdlegislature.gov/Statutes/22-40-26",
            "proposition": "An information holder regulated by federal law, including HIPAA or the GLBA, is deemed compliant if it notifies affected South Dakota residents under its federal regulator's breach regime.",
            "verbatimQuote": "Notwithstanding any other provisions in §§ 22-40-19 to 22-40-26, inclusive, any information holder that is regulated by federal law or regulation, including the Health Insurance Portability and Accountability Act of 1996 (P.L. 104-191, as amended) or the Gramm Leach Bliley Act (15 U.S.C. § 6801 et seq., as amended) and that maintains procedures for a breach of system security pursuant to the laws, rules, regulations, guidance, or guidelines established by its primary or functional federal regulator is deemed to be in compliance with this chapter if the information holder notifies affected South Dakota residents in accordance with the provisions of the applicable federal law or regulation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q5-federal"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in South Dakota over privacy?",
        "heading": "Can a consumer sue your business in South Dakota over privacy?",
        "answerText": "Rarely. Neither the breach-notification statute nor the Genetic Data Privacy Act creates a private right of action. Breach enforcement belongs to the attorney general, who may prosecute each failure to disclose as a deceptive act and seek a civil penalty of up to ten thousand dollars per day per violation, plus attorney's fees; genetic-act enforcement is an attorney-general civil penalty of up to five thousand dollars per violation. The only general consumer path is S.D. Codified Laws § 37-24-31, which permits a civil action for actual damages by a person adversely affected by an act declared unlawful under § 37-24-6 — and § 37-24-6 reaches only knowing deceptive acts.",
        "sources": [
          {
            "id": "q6-breach-enforcement",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 22-40-25",
            "citation": "S.D. Codified Laws § 22-40-25.",
            "url": "https://sdlegislature.gov/Statutes/22-40-25",
            "proposition": "The attorney general may prosecute breach-notification failures as deceptive acts under § 37-24-6 and may recover a civil penalty of up to $10,000 per day per violation, plus attorney's fees.",
            "verbatimQuote": "The attorney general may prosecute each failure to disclose under the provisions of §§ 22-40-19 to 22-40-26, inclusive, as a deceptive act or practice under § 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than ten thousand dollars per day per violation. The attorney general may recover attorney's fees and any costs associated with any action brought under this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q6-breach-enforcement"
          },
          {
            "id": "q6-genetic-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-63",
            "citation": "S.D. Codified Laws § 37-24-63.",
            "url": "https://sdlegislature.gov/Statutes/37-24-63",
            "proposition": "The quoted Genetic Data Privacy Act enforcement section identifies attorney-general petition for a civil penalty of up to $5,000 per violation.",
            "verbatimQuote": "The attorney general, upon petition to the court, may impose a civil penalty against a person for violating § 37-24-60, 37-24-61, or 37-24-62. The amount of the civil penalty may not exceed five thousand dollars per violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q6-genetic-penalty"
          },
          {
            "id": "q6-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-31",
            "citation": "S.D. Codified Laws § 37-24-31.",
            "url": "https://sdlegislature.gov/Statutes/37-24-31",
            "proposition": "A person adversely affected by a deceptive act under § 37-24-6 may sue, but recovery is limited to actual damages.",
            "verbatimQuote": "Any person who claims to have been adversely affected by any act or a practice declared to be unlawful by § 37-24-6 shall be permitted to bring a civil action for the recovery of actual damages suffered as a result of such act or practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q6-pra"
          },
          {
            "id": "q6-udap-knowing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 37-24-6",
            "citation": "S.D. Codified Laws § 37-24-6(1).",
            "url": "https://sdlegislature.gov/Statutes/37-24-6",
            "proposition": "Liability under the deceptive-practices statute requires a knowing act or omission, so negligent privacy failures fall outside the private action.",
            "verbatimQuote": "It is a deceptive act or practice for any person to: (1) Knowingly act, use, or employ any deceptive act or practice, fraud, false pretense, false promises, or misrepresentation or to conceal, suppress, or omit any material fact in connection with the sale or advertisement of any merchandise or the solicitation of contributions for charitable purposes, regardless of whether any person has in fact been misled, deceived, or damaged thereby;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q6-udap-knowing"
          }
        ]
      },
      {
        "slug": "social-media-data-portability",
        "label": "Will social-media users get a right to take their data with them in South Dakota?",
        "heading": "Will social-media users get a right to take their data with them in South Dakota?",
        "answerText": "Yes — for the very largest platforms, beginning July 1, 2027. A second 2026 enactment, Senate Bill 111, requires a social-media service with more than one hundred million active monthly users (and whose primary focus is not charity or religion) to give a requesting user a copy of the user's personal data in a format that is portable, readily usable, and transmittable to another service without impediment.",
        "sources": [
          {
            "id": "q7-effective",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 53-12-51 (effective date)",
            "citation": "S.D. Codified Laws §§ 53-12-51 to 53-12-55 (SL 2026, ch. 197; effective July 1, 2027).",
            "url": "https://sdlegislature.gov/Statutes/53-12-51",
            "proposition": "The social-media data-portability sections, S.D. Codified Laws §§ 53-12-51 to 53-12-55, take effect July 1, 2027.",
            "verbatimQuote": "Effective July 1, 2027",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q7-effective"
          },
          {
            "id": "q7-data-copy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 53-12-51",
            "citation": "S.D. Codified Laws § 53-12-51 (effective July 1, 2027).",
            "url": "https://sdlegislature.gov/Statutes/53-12-51",
            "proposition": "A social-media service with more than one hundred million active monthly users must, on request, provide a user's personal data in a portable, readily usable format the user can transmit to another service without impediment.",
            "verbatimQuote": "If a user requests a copy of the user's personal data being held by a social media service with more than one hundred million active monthly users and whose primary focus is not charity or religion, the social media service must provide the personal data in a format that: (1) Is portable to the extent technically feasible; (2) Is readily usable to the extent practicable; and (3) Allows the user to transmit the data to another social media service, without impediment.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q7-data-copy"
          },
          {
            "id": "q7-interop",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 53-12-52",
            "citation": "S.D. Codified Laws § 53-12-52 (effective July 1, 2027).",
            "url": "https://sdlegislature.gov/Statutes/53-12-52",
            "proposition": "Covered platforms must implement a transparent, third-party-accessible interoperability interface letting users expose a common set of personal data to other services and letting permissioned third parties access user content.",
            "verbatimQuote": "A social media company operating a social media service with more than one hundred million active monthly users and whose primary focus is not charity or religion shall implement a transparent, third-party-accessible interoperability interface subject to § 53-12-51 to allow the social media service's users to choose to: (1) Expose a common set of the user's personal data to other social media services; and (2) Enable third parties to access content created by the user and to be notified when new or updated content is available, with the user's permission.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q7-interop"
          },
          {
            "id": "q7-graph-export",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 53-12-53",
            "citation": "S.D. Codified Laws § 53-12-53(4) (effective July 1, 2027).",
            "url": "https://sdlegislature.gov/Statutes/53-12-53",
            "proposition": "Social-graph exports must be in a machine-readable format using a publicly available standard free from licensing fees and patent restrictions, and must be offered as a single export or as continuous exports at least every twenty-four hours.",
            "verbatimQuote": "(2) A social media service shall make the export available in a machine readable format; (3) A social media service shall make the export using a publicly available technical standard that is free from: (a) Licensing fees; and (b) Patent restrictions that any social media service can freely use; (4) The social media service shall allow a user to choose between a single export or continuous, ongoing exports, which must occur at least every twenty-four hours;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q7-graph-export"
          },
          {
            "id": "q7-security",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "S.D. Codified Laws § 53-12-54",
            "citation": "S.D. Codified Laws § 53-12-54 (effective July 1, 2027).",
            "url": "https://sdlegislature.gov/Statutes/53-12-54",
            "proposition": "Personal data obtained through an interoperability interface must be secured in accordance with the social-media company's own privacy notice and its administrative, technical, and physical security practices.",
            "verbatimQuote": "A social media company operating a social media service with more than one hundred million active monthly users and whose primary focus is not charity or religion shall secure all personal data obtained through an interoperability interface and safeguard the privacy and security of a user's personal data obtained from other social media services through the interoperability interface, in accordance with the social media company's privacy notice and administrative, technical, and physical data security practices.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/south-dakota#src-q7-security"
          }
        ]
      }
    ]
  }
}
