Law / United States /
South Carolina
Business data breach of security, notification statute
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 July 2009.
A breach notification rule binding private bodies.
As of 2 September 2026.
What it requires
- Notify each affected South Carolina resident of a breach of security involving personal identifying information in the most expedient time possible and without unreasonable delay.
- Notify the Consumer Protection Division of the Department of Consumer Affairs and all nationwide consumer reporting agencies if you notify more than 1,000 persons of a breach at one time.
- Expect a South Carolina resident injured by a violation of this statute to be able to sue you directly for damages, an injunction, and attorney's fees. This statute grants a private right of action on its face.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Administrative fine of $1,000 for each resident whose information was accessible by reason of the breach, decided by the Department of Consumer Affairs, available only for a knowing and willful violation; no fine is stated for a merely negligent violation.
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Person
- Per violation amount
- 1,000
Who enforces it
Enforcement body
South Carolina Department of Consumer Affairs (administrative fine for a knowing and willful violation); private civil action by an injured resident.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A person conducting business in South Carolina that owns or licenses computerized data including personal identifying information must disclose a breach of the security of the system to an affected South Carolina resident in the most expedient time possible and without unreasonable delay, where the breach creates a material risk of harm.
Personal identifying information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, or another government-issued identifying number; biometric, genetic, or health data is not folded into this definition. If a business notifies more than 1,000 persons at one time, it must also notify the Consumer Protection Division of the Department of Consumer Affairs and nationwide consumer reporting agencies.
The current definition of personal identifying information took effect April 23, 2013; the notification duty itself took effect July 1, 2009. A resident injured by a violation may bring a civil action for damages (willful and knowing violations) or actual damages (negligent violations), seek an injunction, and recover attorney's fees, an express, direct private right of action rather than one reached indirectly through a deeming clause.
An administrative fine of $1,000 per affected resident is also available to the Department of Consumer Affairs for a knowing and willful violation.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.