Law / United States / South Carolina

South Carolina

United States law applies in South Carolina South Carolina is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of South Carolina, described on this page below, applies here too.

8 of 15 named instruments researched to a stage, across four of the six areas of law we track: 8 in force. As of 15 September 2026.

When they take effect8 of 8 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 2 instruments (2 in force) 2026: 4 instruments (4 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 4
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (269 words)

South Carolina has not enacted a general-purpose AI-transparency, output-labeling, or risk-management statute; the state's only enacted AI-specific instrument criminalizes conduct rather than mandating disclosure.

2025 Act No. 58 (S.29), effective May 22, 2025, extended South Carolina's first, second, and third degree sexual exploitation of a minor offenses (Sections 16-15-395, 16-15-405, 16-15-410) to a 'morphed image of an identifiable minor,' a definition broad enough to reach a computer-generated or AI-altered depiction, so that producing, distributing, or possessing such a depiction of an identifiable minor is punished the same as a real photograph.

Several AI-specific consumer-protection and chatbot bills remained in committee or awaiting a floor vote as of the date shown, none having passed either chamber: S. 896 (Chatbot Protection Act, with companion H. 5138) received a favorable committee report with amendment from the Senate Labor, Commerce and Industry Committee on May 6, 2026 but has not been voted on by either full chamber; S. 963 (Consumer Protections in Interactions with Artificial Intelligence Systems Act), S. 1037 (Protecting Children from Chatbots Act), S. 443 (physician oversight of AI-informed health-insurance coverage decisions), S. 788 (AI therapy and psychotherapy disclosure), and H. 3517 (deceptive deepfake media in elections) each remain in their first committee of referral.

South Carolina's general Unfair Trade Practices Act (S.C. Code Ann. §§ 39-5-10 to 39-5-160) is available in principle as a backstop against a deceptive bot or AI-generated content used to defraud consumers, but has not been tested against an AI-specific fact pattern, and several of the pending bills would expressly designate a violation of their own AI-specific duties as an unfair trade practice actionable under it.

AI prohibited practices

AI-Generated and Morphed Images of an Identifiable Minor (2025 Act No. 58, S.29)

S.C. Code Ann. §§ 16-15-375(8), 16-15-395, 16-15-405, 16-15-410, 16-15-412official text, South Carolina Code of Laws Unannotated, South Carolina Legislature Online (scstatehouse.gov)

In force since 22 May 2025. Binds public and private bodies.

What this law does

2025 Act No. 58 (S.29), effective May 22, 2025, added a definition of 'morphed image' at Section 16-15-375(8), covering any visual depiction, including a computer or computer-generated image, that has been created, adapted, or modified to appear that an identifiable minor is engaged in sexual conduct or sexually explicit nudity.

The same act inserted that term into South Carolina's first, second, and third degree sexual exploitation of a minor offenses (Sections 16-15-395, 16-15-405, 16-15-410), so that producing, distributing, or possessing a morphed depiction of an identifiable minor is punished the same as a real photograph of that minor.

The act also added Section 16-15-412, restricting an arrest warrant for a morphed-image offense to one issued on a state grand jury true bill or a probable-cause finding from an Internet Crimes Against Children Task Force investigation conducted with the Attorney General's Office.

What it requires

Privacy law4 instruments, 4 in force

Research summary (248 words)

South Carolina has no enacted general controller or processor personal-data statute, and no comprehensive bill has even passed a chamber. It does have an enacted minors-focused design-code statute, the South Carolina Age-Appropriate Design Code, enacted as Act No. 96 of 2026 (H. 3431), codified as new Chapter 80 of Title 39, S.C. Code Ann. secs. 39-80-10 et seq., signed and effective February 5, 2026.

A different, unrelated bill, H. 3402, carries the same short title but would have created Chapter 79 and never advanced past committee referral; the citation here is drawn from the enacted H. 3431 text itself, not from either bill number alone.

Chapter 80 lists biometric data among sensitive personal data requiring heightened, minor-protective design duties, but never defines the term anywhere in the chapter, so whether it excludes an identifier derived from a photograph, video, or audio recording cannot be determined from the text; a narrower, separate clause excludes only a minor's biometric data collected without the minor's knowledge from the chapter's definition of publicly available data.

Chapter 80's own enforcement section names only the Attorney General and imposes treble damages, but does not say whether that remedy is available to a private plaintiff; the text leaves the question open. South Carolina's breach-notification statute, S.C. Code Ann. sec. 39-1-90, in force since July 1, 2009, carries an express, direct private right of action for an injured resident, unusual, which typically finds a private route only by an indirect deeming-plus-UDAP chain or not at all.

Breach notification

Business data breach of security, notification statute

S.C. Code Ann. sec. 39-1-90official South Carolina statute text, S.C. Code Ann. sec. 39-1-90, consolidated South Carolina Code of Laws

In force since 1 July 2009. Binds private bodies.

What this law does

A person conducting business in South Carolina that owns or licenses computerized data including personal identifying information must disclose a breach of the security of the system to an affected South Carolina resident in the most expedient time possible and without unreasonable delay, where the breach creates a material risk of harm.

Personal identifying information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, or another government-issued identifying number; biometric, genetic, or health data is not folded into this definition. If a business notifies more than 1,000 persons at one time, it must also notify the Consumer Protection Division of the Department of Consumer Affairs and nationwide consumer reporting agencies.

The current definition of personal identifying information took effect April 23, 2013; the notification duty itself took effect July 1, 2009. A resident injured by a violation may bring a civil action for damages (willful and knowing violations) or actual damages (negligent violations), seek an injunction, and recover attorney's fees, an express, direct private right of action rather than one reached indirectly through a deeming clause.

An administrative fine of $1,000 per affected resident is also available to the Department of Consumer Affairs for a knowing and willful violation.

What it requires

Data subject rights

South Carolina Age-Appropriate Design Code, general applicability and minor-protective design duties

S.C. Code Ann. secs. 39-80-10 et seq. (Act No. 96 of 2026, H. 3431)official South Carolina session law text, Act No. 96 of 2026 (H. 3431), South Carolina Legislature website

In force 8 months, effective 5 February 2026. Binds private bodies.

What this law does

The Age-Appropriate Design Code applies to a covered online service reasonably likely to be accessed by a minor (a person under 18). It is not a general controller or processor personal-data regime; it imposes design and data-minimization duties specifically toward minor users, including default privacy settings, limits on profiling, targeted advertising, and precise-geolocation collection for known minors, parental controls, and an annual public report by an independent auditor.

The Act was enacted as Act No. 96 of 2026 (H. 3431, the South Carolina Social Media Regulation Act on its own caption) and creates Chapter 80 of Title 39; it took effect immediately upon the Governor's approval on February 5, 2026. It is not to be confused with H. 3402, a different, still-pending bill sharing the short title 'Age-Appropriate Design,' which would have created Chapter 79 and never advanced past referral to House Judiciary.

The consolidated online Code of Laws has not yet published Chapter 80; the session-law text of Act No. 96 is the authoritative current source.

What it requires

Enforcement supervision

Age-Appropriate Design Code, enforcement

S.C. Code Ann. sec. 39-80-80 (Act No. 96 of 2026, H. 3431)official South Carolina session law text, Act No. 96 of 2026 (H. 3431), South Carolina Legislature website

In force 8 months, effective 5 February 2026. Binds private bodies.

What this law does

The Attorney General enforces Chapter 80. A covered online service is liable for treble the financial damages incurred as a result of a violation, and officers and employees of a covered online service may be held personally liable for willful and wanton violations.

The 30,353-character enacted text does not resolve whether the treble-damages remedy is available to a private plaintiff or is confined to a suit the Attorney General brings: no clause reads that an injured person may bring a civil action, the phrasing South Carolina's breach statute uses to grant one, and no clause reads that the chapter creates no private right of action, the phrasing Pennsylvania's and West Virginia's comparable proposed and dead bills use to foreclose one.

Whether a private right of action exists is therefore left unrecorded for this instrument; the treble-damages and personal-liability clauses read most naturally as remedies within the Attorney General's own suit given the enforcement section's framing naming only the Attorney General, and no construing case settles it.

What it requires

Sensitive categories

Age-Appropriate Design Code, sensitive personal data and biometric data

S.C. Code Ann. sec. 39-80-10(18) (Act No. 96 of 2026, H. 3431)official South Carolina session law text, Act No. 96 of 2026 (H. 3431), South Carolina Legislature website

In force 8 months, effective 5 February 2026. Binds private bodies.

What this law does

Chapter 80 defines sensitive personal data to include a Social Security number, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, the contents of an individual's mail, email, or text messages, genetic data, biometric data for the purpose of uniquely identifying an individual, and health data.

'Biometric data' itself is never defined anywhere in the 30,353-character enacted text; the term appears exactly twice, once in this sensitive-data list and once in the publicly-available-data carve-out below, with no accompanying definitional entry among the chapter's twenty defined terms.

Whether the term excludes an identifier derived from a photograph, video, or audio recording therefore cannot be determined from the statutory text; there is no definitional clause to read as imposing or narrowing such an exclusion.

A narrower, separate carve-out excludes only 'biometric data collected by a covered online service about a minor without the minor's knowledge' from the chapter's definition of publicly available data, which does not address an adult's biometric data, or a knowingly collected minor's, drawn from a public recording.

What it requires

Scraping law1 instrument, 1 in force

Research summary (232 words)

South Carolina's Computer Crime Act (S.C. Code Ann. §§ 16-16-10 to 16-16-40) adds a state felony and misdemeanor computer-trespass regime graded by the dollar amount of gain or loss, rather than the federal baseline's bare without-authorization test alone: a first-degree felony requires gain or loss exceeding ten thousand dollars, while a separate misdemeanor offense, computer hacking, reaches unauthorized access, port scanning, or exceeding a granted permission regardless of any financial harm.

The chapter's own civil remedy, Section 16-16-25, arms the owner or lessee of an affected computer system with a private action for compensatory damages, restitution, and attorney's fees, but only against a person already convicted under the chapter, a narrower private right than an independent civil cause of action.

South Carolina has not enacted a comprehensive consumer privacy statute, so no state privacy-regime restriction on scraped public personal data exists beyond the federal baseline; no South Carolina case law addressing robots.txt's legal weight, browsewrap or clickwrap enforceability, or trespass to chattels in a scraping-specific dispute was found.

South Carolina's Unfair Trade Practices Act (S.C. Code Ann. §§ 39-5-10 to 39-5-160), a general consumer-protection statute carrying a private right of action and Attorney General civil penalties of up to five thousand dollars per violation, is available in principle against a deceptive scraping-adjacent practice but is untested against scraping specifically. Copyright, text-and-data-mining, and database rights are federal only; South Carolina adds nothing there.

Computer misuse

South Carolina Computer Crime Act

S.C. Code Ann. §§ 16-16-10 to 16-16-40official text, South Carolina Code of Laws Unannotated, South Carolina Legislature Online (scstatehouse.gov)

In force since 2 July 2002. Binds public and private bodies.

What this law does

Sections 16-16-10 through 16-16-40 make it unlawful to wilfully, knowingly, and maliciously access a computer, computer system, or computer network without authorization or for an unauthorized purpose to devise a scheme to defraud, obtain money or property by fraud, commit another crime, or to alter, damage, destroy, or modify data, programs, software, or operation, or introduce a computer contaminant; a separate misdemeanor, computer hacking, reaches unauthorized access, port scanning, or exceeding a granted permission regardless of financial gain or loss.

The offense is graded in three degrees by the dollar amount of gain or loss, from a felony (first degree, gain or loss exceeding ten thousand dollars) down to a misdemeanor (third degree, gain or loss of one thousand dollars or less, or computer hacking alone), and each computer, system, or network affected by a violation is a separate offense.

The owner or lessee of an affected computer system may also bring a civil action for compensatory damages, restitution, and attorney's fees, but only against a person already convicted under this chapter.

What it requires

Age gating law2 instruments, 2 in force

Research summary (74 words)

South Carolina has required age verification for adult content sites since January 2025, and enacted an Age-Appropriate Design Code Act in February 2026 that took immediate effect. NetChoice sued over the design code within days of enactment, and a preliminary injunction motion is pending. South Carolina has not enacted a social-media-specific age verification law or an app store accountability law; an App Store Accountability Act bill (H.3405) has not advanced out of the House.

Adult content age verification (AV)

H.3424 (2024), Child Online Safety Act

S.C. Code Ann. section 37-1-310official South Carolina Code of Laws statute text

In force since 1 January 2025. Binds private bodies.

What this law does

Requires a commercial entity that knowingly publishes material on a website, more than one third of which is material harmful to minors, to perform reasonable age verification of South Carolina visitors using a digitized identification card, a third party verification service, or a commercially reasonable method relying on transactional data.

Note and primary source

Age-appropriate design code

H.3431 (2026), Age-Appropriate Design Code Act (Act No. 96 of 2026)

S.C. Code Ann. Title 39, ch. 80official South Carolina Legislature bill and act text

In force 8 months, effective 5 February 2026. Binds private bodies.

What this law does

Requires online services reasonably likely to be accessed by minors to set protective default privacy settings for known minors, offer opt outs from personalized recommendation systems, limit addictive design features and nighttime and school hours notifications, and undergo independent third party audits reported to the Attorney General. NetChoice sued days after enactment and a preliminary injunction motion is pending.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.