Law / United States / South Dakota

South Dakota

United States law applies in South Dakota South Dakota is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of South Dakota, described on this page below, applies here too.

All 8 named instruments researched to a stage, across four of the six areas of law we track: 8 in force. As of 15 September 2026.

  1. AI law 3
  2. Privacy law 3
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 in force

Research summary (190 words)

South Dakota has no general-purpose AI governance statute and no state-agency AI task force law; the AI-specific law on the books is confined to criminal prohibitions and one sector-specific disclosure duty.

SDCL §§ 22-24A-2(5), 22-24A-35 to 22-24A-37 (S.L. 2024, ch. 87, from SB 79) criminalize computer-generated child pornography, defined to include a depiction of an individual indistinguishable from an actual minor created using artificial intelligence, on the same felony terms as a depiction of an actual minor.

SDCL § 22-21-4(3), 22-21-4.1 (S.L. 2026, ch. 104, from SB 41) separately criminalizes creating or distributing nonconsensual digitally fabricated material depicting an identifiable individual in a state of nudity or engaged in sexual conduct, binding any person.

SDCL §§ 12-26-32 to 12-26-37 (S.L. 2025, ch. 68, from SB 164) imposes an election-specific disclosure duty on anyone who disseminates an AI-manipulated or -generated deepfake targeting a candidate within 90 days of an election, with a text-disclosure safe harbor and civil remedies for the candidate or the depicted individual. Two 2026 bills that would have added chatbot-specific disclosure duties, for minors (SB 168) and for consumers generally (SB 170), both died without passing either chamber.

AI prohibited practices

Computer-generated child pornography ban (SB 79, 2024)

SDCL §§ 22-24A-2(5), 22-24A-35 to 22-24A-37 (S.L. 2024, ch. 87)official codified text, South Dakota Legislature (sdlegislature.gov)

In force. Binds public and private bodies.

What this law does

SDCL § 22-24A-2(5) defines computer-generated child pornography to include a visual depiction of an actual minor altered to show a prohibited sexual act, an actual adult altered to appear as a minor engaged in a prohibited sexual act, or an individual indistinguishable from an actual minor created by the use of artificial intelligence or other computer technology capable of processing and interpreting specific data inputs to create a visual depiction.

Sections 22-24A-35 to 22-24A-37 were enacted by SB 79, signed by the Governor on February 12, 2024. Possessing computer-generated child pornography is a Class 4 felony with a mandatory minimum sentence of one year, on the same terms as possessing a depiction of an actual minor. Distributing it is a Class 3 felony with a mandatory minimum of five years.

Manufacturing it is a Class 2 felony with a mandatory minimum of ten years, and there is no exemption for synthetic or AI-generated output in any of the three offenses. SDCL § 22-24A-7's civil-damages provision, unamended since 2014, arms a plaintiff for conduct proscribed by "§§ 22-24A-1 to 22-24A-20", a range that does not by its own terms reach §§ 22-24A-35 to -37; no source located addresses whether a court would read the civil-damages chapter to reach the successor sections.

What it requires

Nonconsensual Digitally Fabricated Intimate Image Law (SB 41, 2026)

SDCL §§ 22-21-4(3), 22-21-4.1 (S.L. 2026, ch. 104)official codified text, South Dakota Legislature (sdlegislature.gov)

In force. Binds public and private bodies.

What this law does

SB 41 was introduced at the request of the Attorney General and signed by the Governor on March 16, 2026.

SDCL § 22-21-4(3) makes it a Class 5 felony for an individual, without the consent or knowledge of the person depicted and with intent to self-gratify, alarm, annoy, embarrass, harass, invade privacy, threaten, or cause emotional, financial, physical, psychological, or reputational harm, to knowingly and intentionally create, disclose, disseminate, distribute, or sell digitally fabricated material depicting an identifiable individual in a state of nudity or engaged in sexual conduct.

Section 22-21-4.1 defines digitally fabricated material as an image, photograph, video, or other visual depiction that appears to an ordinary person to be an authentic depiction of an identifiable individual and is adapted, generated, or modified to falsely depict that individual's appearance, conduct, or voice; "identifiable" means recognizable by face, likeness, or another distinguishing characteristic.

Section 22-21-5 shields an electronic communication, information, mobile, telecommunication, interactive computer, or cable service provider, as those terms are defined under federal law, from liability under this section.

What it requires

AI sector rules

Election Deepfake Disclosure Law (SB 164, 2025)

SDCL §§ 12-26-32 to 12-26-37 (S.L. 2025, ch. 68)official codified text, South Dakota Legislature (sdlegislature.gov)

In force. Binds public and private bodies.

What this law does

SB 164 was signed by the Governor on March 25, 2025.

This law prohibits any person, with intent to injure a candidate, from disseminating a deepfake (an image, audio recording, or video recording created or manipulated with artificial intelligence or other digital technology that a reasonable person would believe depicts the real speech or conduct of someone who did not engage in it) within 90 days of an election, unless the item carries the disclosure described in SDCL § 12-26-37; a violation is a Class 1 misdemeanor.

The required disclosure must be sized and placed as the statute specifies for each media type. The prohibition exempts satire or parody, a bona fide news broadcast that acknowledges questions about the item's authenticity, a paid periodical or website of general circulation carrying news and commentary, and an internet, hosting, or connectivity provider acting in a merely technical or automatic capacity.

The Attorney General, an injured or likely-to-be-injured candidate, or the individual depicted may seek injunctive or other equitable relief prohibiting the dissemination. A violator is also civilly liable to the candidate and the depicted individual for damages, costs, and attorney fees, proven by clear and convincing evidence.

What it requires

Privacy law3 instruments, 3 in force

Research summary (270 words)

South Dakota has no general controller or processor personal-data statute, and no comprehensive bill is even pending; the chatbot-disclosure bills in this session (SB 168, SB 170) both died and are unrelated to a comprehensive regime. South Dakota instead has two enacted sectoral instruments.

The Genetic Data Privacy Act, SDCL secs. 37-24-59 to 37-24-64 (SB 49, SL 2026 ch. 164), signed March 23, 2026 and in force since July 1, 2026, requires opt-in express consent for a direct-to-consumer genetic testing company to collect, disclose, or use a consumer's genetic data or biological sample, and gives the consumer access, deletion, and destruction rights; it does not use the term biometric anywhere and treats genetic data as its own category, not interchangeable with biometric data.

South Dakota's breach-notification statute, SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135), in force since July 1, 2018, folds biometric data into personal information only narrowly, when paired with an employer-assigned identification number and used for authentication, and requires Attorney General notice above a threshold of 250 affected residents, not the 250,000 some secondary sources report.

That breach statute deems a notice violation a deceptive act under the state's general Deceptive Trade Practices and Consumer Protection chapter, which independently arms any adversely affected person with a private right of action; unlike Pennsylvania's, South Carolina's Chapter 80, or West Virginia's equivalents, South Dakota's Attorney General enforcement clause contains no exclusivity language closing that route, so whether the deeming-plus-UDAP chain actually arms a private plaintiff for a notice violation is an open question rather than a settled finding, since no case construing the two sections together is located.

Breach notification

Breach of system security, notification statute

SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135)official South Dakota statute text, SDCL secs. 22-40-19 to 22-40-26, South Dakota Legislature website (api.Statutes path)

In force since 1 July 2018. Binds private bodies.

What this law does

Following discovery of a breach of system security, an information holder must disclose the breach to any affected South Dakota resident not later than 60 days from discovery, absent a law-enforcement delay. An information holder whose breach exceeds 250 South Dakota residents (not 250,000, correcting an initial WebSearch summary against the enrolled bill's own text) must also disclose the breach to the Attorney General by mail or electronic mail.

Personal information excludes information lawfully made available to the general public from government records; it folds in biometric data only in a narrow, conditional way, as one component of an employer-assigned identification number used for authentication, not as a freestanding sensitive category. The Attorney General may prosecute a failure to disclose as a deceptive act under SDCL sec. 37-24-6 and may separately bring an action for a civil penalty of up to $10,000 per day per violation.

South Dakota's general Deceptive Trade Practices and Consumer Protection chapter independently arms any person adversely affected by a sec. 37-24-6 violation with a private civil action for actual damages (SDCL sec. 37-24-31), and unlike the comparable enforcement clauses in Pennsylvania, South Carolina's Chapter 80, or West Virginia, this breach statute's enforcement section contains no exclusivity language naming the Attorney General as the sole enforcer.

Whether this deeming-plus-private-action chain actually arms a resident to sue over a notice violation is left here as an open, statute-supported question rather than a settled finding, since no case construing sec. 22-40-25 together with sec. 37-24-31 was found.

What it requires

Enforcement supervision

Genetic Data Privacy Act, enforcement

SDCL sec. 37-24-63 (SL 2026 ch. 164, sec. 5)official South Dakota statute text, SDCL sec. 37-24-63, South Dakota Legislature website (api.Statutes path)

In force 84 days, effective 1 July 2026. Binds private bodies.

What this law does

The Attorney General may petition a court to impose a civil penalty of up to $5,000 per violation of SDCL secs. 37-24-60 to 37-24-62.

This standalone enforcement provision does not cross-reference SDCL sec. 37-24-6, the general deceptive-act provision that the breach statute's own enforcement section deems a violation into, so the general Deceptive Trade Practices and Consumer Protection chapter's private right of action, SDCL sec. 37-24-31, which is keyed specifically to a sec. 37-24-6 violation, does not reach a Genetic Data Privacy Act violation. No damages-preservation clause exists either. This Act creates no private right of action.

What it requires

Sensitive categories

Genetic Data Privacy Act, definitions, consent, and consumer rights

SDCL secs. 37-24-59 to 37-24-61 (SB 49, SL 2026 ch. 164, secs. 1-3)official South Dakota statute text, SDCL secs. 37-24-59 to 37-24-61, South Dakota Legislature website (api.Statutes path)

In force 84 days, effective 1 July 2026. Binds private bodies.

What this law does

South Dakota's Genetic Data Privacy Act defines genetic data as data other than de-identified data, regardless of format, concerning a consumer's genetic characteristics, and applies only to a direct-to-consumer genetic testing company and its service providers, not to personal data generally.

A covered company must obtain a consumer's opt-in express consent for collection, and separately for disclosure, third-party transfer, research use, retention beyond the initial test, and marketing use, and must maintain a security program. A consumer may access their genetic data, delete their account and genetic data, and obtain destruction of their biological sample; revocation of consent must be honored, and a biological sample destroyed, within 30 days.

The Act never mentions biometric data anywhere in its text; genetic and biometric data are treated as distinct categories in South Dakota law, not interchangeably. Exemptions cover Health Insurance Portability and Accountability Act (HIPAA)-covered entities, medical screening, diagnosis or treatment, higher-education institutions, forensic laboratories, and human-subjects research.

What it requires

Scraping law1 instrument, 1 in force

Research summary (122 words)

South Dakota diverges from the federal computer-fraud baseline through SDCL §§ 43-43B-1 to 43-43B-3, its own computer-crime statute, which turns on lack of the owner's consent rather than on defeating a technical access barrier and grades nine listed acts from a Class 1 misdemeanor up to a Class 2 felony; no South Dakota appellate decision applying this chapter to automated public-web collection was located.

Terms-of-service enforceability, database rights, and robots.txt are governed by ordinary contract law and federal copyright law alone; South Dakota has no dedicated terms-of-service statute, no state database right, and no statute giving robots.txt independent legal weight. South Dakota's own publicly-available-information carve-out for personal data is researched under the privacy topic for this jurisdiction and is not restated here.

Computer misuse

South Dakota Unlawful Use of a Computer System, Software, or Data

SDCL §§ 43-43B-1 to 43-43B-3, 43-43B-7, 43-43B-8official codified text, South Dakota Legislature (sdlegislature.gov)

In force. Binds public and private bodies.

What this law does

SDCL § 43-43B-1 makes it unlawful for a person to knowingly access, or exceed authorized access to, copy or obtain information from, disrupt or deny access to, or modify or destroy a computer system, software, or data, in each case without the consent of the owner; ordinary automated access to a page the operator has made generally available is not itself addressed by any reported South Dakota decision.

Section 43-43B-3 grades the nine listed acts from a Class 1 misdemeanor up to a Class 2 felony depending on which act was committed and, for the top tier, whether it was done as part of a deceptive scheme to obtain money, property, or services; § 43-43B-7 states that the chapter neither creates nor forecloses a private civil claim over the same conduct.

What it requires

Age gating law1 instrument, 1 in force

Research summary (92 words)

South Dakota has required age verification for websites with content harmful to minors since July 2025, a law bolstered in public officials' view by the U.S. Supreme Court's June 2025 ruling in Free Speech Coalition v. Paxton. App store age verification bills have failed twice: SB 180 was rejected in committee in 2025, and HB 1275 (2026) passed the House 50 to 17 but was defeated in a Senate committee in March 2026. South Dakota has not enacted a social media minor-access law or a design code law as of this date.

Adult content age verification (AV)

HB 1053 (2025), age verification for websites containing material harmful to minors

S.D. Codified Laws ch. 22-24 (new sections enacted by 2025 S.D. Laws, HB 1053)official South Dakota Legislature bill page and text

In force since 1 July 2025. Binds private bodies.

What this law does

Requires a covered platform, defined as a website whose regular course of trade or business is to create, host, or make available material harmful to minors, to implement reasonable age verification (state issued driver license or non-driver ID, bank account information, an age restricted debit or credit card, or another reliable method) and to prevent minors from accessing that material. Verifiers may not sell or retain identifying information. Search engines, internet service providers, and cloud providers are exempt.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.