Data Breach Requirements: S.C. Code Ann. § 39-1-90.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
The term “personal identifying information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of this State, when the data elements are neither encrypted nor redacted:
(a) Social Security number;
(b) Driver’s license number or state identification card number issued instead of a driver’s license;
(c) Financial account number, or credit card or debit card number in combination with any required security code, access code, or password that would permit access to a resident’s financial account; or
(d) Other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual.
Security Breach Definition
The term “breach of the security of the system” means unauthorized access to and acquisition of computerized data that was not rendered unusable through encryption, redaction, or other methods that compromises the security, confidentiality, or integrity of personal identifying information maintained by the person, when illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to a resident.
Good Faith Exception
Good faith acquisition of personal identifying information by an employee or agent of the person for the purposes of its business is not a breach of the security of the system if the personal identifying information is not used or subject to further unauthorized disclosure.
Risk of Harm Analysis
A covered entity shall disclose a breach of the security of the system following discovery or notification of the breach of the data to a resident of this state whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident.
Notification Timeline
The breach notification must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Security and Investigation Exceptions
The breach notification may be delayed if a law enforcement agency determines that the notification impedes a criminal investigation. The notification must be made after the law enforcement agency determines that it no longer compromises the investigation.
Notification Content Requirements
The breach notification to the South Caroline Consumer Protection Division should include all the following: (1) Date of the breach; (2) Date business became aware of the breach; (3) Date notice was/will be sent to affected consumers; (4) Method of consumer notification (i.e., direct mail, electronic mail, etc.); (5) Number of affected South Carolina consumers; (6) Content of the consumer notice (i.e., copy of the letter sent to consumers); and (7) Action taken to avoid future breaches.
Delivery Methods
A breach notice may be provided by one of the following methods:
(1) Written notice;
(2) Electronic notice, if the person’s primary method of communication with the individual is by electronic means or is consistent with the provisions regarding electronic records and signatures in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act);
(3) Telephonic notice; or
(4) Substitute notice, if the person demonstrates that the cost of providing notice exceeds $250.000 or that the affected class of subject persons to be notified exceeds 500,000 or the person has insufficient contact information.
Substitute Notice
Substitute notice consists of:
(a) Email notice when the person has an email address for the subject persons;
(b) Conspicuous posting of the notice on the website page of the person, if the person maintains one; or
(c) Notification to major statewide media.
Notice to Government Agencies
If a business provides breach notices to more than 1,000 persons at one time, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Department of Consumer Affairs of the timing, distribution, and content of the notice.
Consumer Reporting Agencies
If a business provides breach notices to more than 1,000 persons at one time, the business shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution, and content of the notice.
Preemption and Compliance
This law does not apply to a bank or financial institution that is subject to and in compliance with the privacy and security provision of the Gramm-Leach-Bliley Act.
A financial institution that is subject to and in compliance with the federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice is considered to be in compliance with this section.
Data Processor Obligations
A person conducting business in this state and maintaining computerized data, or other data that includes personal identifying information that the person does not own, shall notify the owner or licensee of the information of a breach of the security of the data immediately following discovery, if the personal identifying information was, or is reasonably believed to have been, acquired by an unauthorized person.
Data Disposal and Security: S.C. Code Ann. §§ 37-20-110 and 37-20-190.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal identifying information” means personal identifying information as defined in Section 16-13-510(D). It does not mean information about vehicular accidents, driving violations, and driver’s status.
Section 16-13-510(D): The term “personal identifying information” includes, but is not limited to:
(1) Social Security numbers;
(2) Driver’s license numbers or state identification card numbers issued instead of a driver’s license;
(3) Checking account numbers;
(4) Savings account numbers;
(5) Credit card numbers;
(6) Debit card numbers;
(7) Personal identification (PIN) numbers;
(8) Electronic identification numbers;
(9) Digital signatures;
(10) Dates of birth;
(11) Current or former names, including first and last names, middle and last names, or first, middle, and last names, but only when the names are used in combination with, and linked to, other identifying information provided in this section;
(12) Current or former addresses, but only when the addresses are used in combination with, and linked to, other identifying information provided in this section; or
(13) Other numbers, passwords, or information which may be used to access a person’s financial resources, numbers, or information issued by a governmental or regulatory entity that uniquely will identify an individual or an individual’s financial resources.
The term “disposal” means the (a) discarding or abandonment of records containing personal identifying information; or (b) sale, donation, discarding, or transfer of any medium, including computer equipment or computer media, containing records of personal identifying information, other non-paper media upon which records of personal identifying information are stored, or other equipment for non-paper storage of information.
Data Disposal
When a business disposes of a business record that contains personal identifying information of a customer of a business, the business shall modify, by shredding, erasing, or other means, the personal identifying information to make it unreadable or undecipherable.
A business is considered to comply with this law if it contracts with a person engaged in the business of disposing of records for the modification of personal identifying information on behalf of the business in accordance with this law.