Law / United States / South Carolina

Business data breach of security, notification statute

S.C. Code Ann. sec. 39-1-90

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 July 2009.

A breach notification rule binding private bodies.

As of 2 September 2026.

What it requires

  • Notify each affected South Carolina resident of a breach of security involving personal identifying information in the most expedient time possible and without unreasonable delay.
  • Notify the Consumer Protection Division of the Department of Consumer Affairs and all nationwide consumer reporting agencies if you notify more than 1,000 persons of a breach at one time.
  • Expect a South Carolina resident injured by a violation of this statute to be able to sue you directly for damages, an injunction, and attorney's fees. This statute grants a private right of action on its face.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Administrative fine of $1,000 for each resident whose information was accessible by reason of the breach, decided by the Department of Consumer Affairs, available only for a knowing and willful violation; no fine is stated for a merely negligent violation.

Rule
Per violation only
As of
2 September 2026
Currency
USD
Per violation unit
Person
Per violation amount
1,000

Who enforces it

Enforcement body

South Carolina Department of Consumer Affairs (administrative fine for a knowing and willful violation); private civil action by an injured resident.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A person conducting business in South Carolina that owns or licenses computerized data including personal identifying information must disclose a breach of the security of the system to an affected South Carolina resident in the most expedient time possible and without unreasonable delay, where the breach creates a material risk of harm.

Personal identifying information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, or another government-issued identifying number; biometric, genetic, or health data is not folded into this definition. If a business notifies more than 1,000 persons at one time, it must also notify the Consumer Protection Division of the Department of Consumer Affairs and nationwide consumer reporting agencies.

The current definition of personal identifying information took effect April 23, 2013; the notification duty itself took effect July 1, 2009. A resident injured by a violation may bring a civil action for damages (willful and knowing violations) or actual damages (negligent violations), seek an injunction, and recover attorney's fees, an express, direct private right of action rather than one reached indirectly through a deeming clause.

An administrative fine of $1,000 per affected resident is also available to the Department of Consumer Affairs for a knowing and willful violation.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official South Carolina statute text, S.C. Code Ann. sec. 39-1-90, consolidated South Carolina Code of Laws

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app