Law / United States / South Dakota

Breach of system security, notification statute

SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 July 2018.

A breach notification rule binding private bodies.

As of 28 August 2026.

What it requires

  • Notify each affected South Dakota resident of a breach of system security not later than 60 days after discovery, absent a law enforcement delay.
  • Notify the South Dakota Attorney General by mail or electronic mail if a breach affects 250 or more South Dakota residents. This threshold is 250, not 250,000.
  • Treat biometric data as a breach-notification trigger only when it is paired with an employer-assigned identification number used for authentication, not on its own.
  • Do not assume a private right of action is settled either way for a notice violation here. It is left as an open question here: a deeming-plus-UDAP chain to SDCL sec. 37-24-31 exists in the text with no exclusivity clause closing it, but no confirming case is located.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Following discovery of a breach of system security, an information holder must disclose the breach to any affected South Dakota resident not later than 60 days from discovery, absent a law-enforcement delay. An information holder whose breach exceeds 250 South Dakota residents (not 250,000, correcting an initial WebSearch summary against the enrolled bill's own text) must also disclose the breach to the Attorney General by mail or electronic mail.

Personal information excludes information lawfully made available to the general public from government records; it folds in biometric data only in a narrow, conditional way, as one component of an employer-assigned identification number used for authentication, not as a freestanding sensitive category. The Attorney General may prosecute a failure to disclose as a deceptive act under SDCL sec. 37-24-6 and may separately bring an action for a civil penalty of up to $10,000 per day per violation.

South Dakota's general Deceptive Trade Practices and Consumer Protection chapter independently arms any person adversely affected by a sec. 37-24-6 violation with a private civil action for actual damages (SDCL sec. 37-24-31), and unlike the comparable enforcement clauses in Pennsylvania, South Carolina's Chapter 80, or West Virginia, this breach statute's enforcement section contains no exclusivity language naming the Attorney General as the sole enforcer.

Whether this deeming-plus-private-action chain actually arms a resident to sue over a notice violation is left here as an open, statute-supported question rather than a settled finding, since no case construing sec. 22-40-25 together with sec. 37-24-31 was found.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics

Read the law

official South Dakota statute text, SDCL secs. 22-40-19 to 22-40-26, South Dakota Legislature website (api.Statutes path)
enrolled bill text via mylrc.sdlegislature.gov/api/Documents/Bill/50500.html?Year=2018

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app