Skip to main content

Data Protection Map

South Dakota

Data Breach Requirements: South Dakota CL § 22-40-19 et seq.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

The term “personal information” means a person’s first name or first initial and last name, in combination with any one or more of the following data elements:
(a) Social Security number;
(b) Driver’s license number or other unique identification number created or collected by a government body;
(c) Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or any additional information that would permit access to a person’s financial account;
(d) Health information as defined in 45 CFR 160.103; or
(e) An identification number assigned to a person by the person’s employer in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication purposes.


The term “protected information” includes:
(a) A username or email address, in combination with a password, security question answer, or other information that permits access to an online account; and
(b) Account number or credit or debit card number, in combination with any required security code, access code, or password that permits access to a person’s financial account;


Security Breach Definition

The term “breach of system security” means the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder.


Good Faith Exception

A “breach of system security” does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure.


Risk of Harm Analysis

An information holder is not required to make a data breach notification if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.


Notification Timeline

The breach notification shall be made not later than 60 days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement.


Security and Investigation Exceptions

A breach notification may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. If the notification is delayed, the notification shall be made not later than 30 days after the law enforcement agency determines that notification will not compromise the criminal investigation.


Notification Content Requirements

N/A


Delivery Methods

A breach notice may be provided by one of the following methods:
(1) Written notice;
(2) Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act) in effect as of January 1, 2018, or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
(3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed $250,000, that the affected class of persons to be notified exceeds 500,000 persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following:
(a) Email notice, if the information holder has an email address for the subject persons;
(b) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and
(c) Notification to statewide media.


Substitute Notice

See Delivery Methods.


Notice to Government Agencies

Any information holder that experiences a breach of system security shall disclose to the attorney general by mail or electronic mail any breach that exceeds 250 state residents.


Consumer Reporting Agencies

If an information holder discovers circumstances that require a breach notification, the information holder shall also notify, without unreasonable delay, all consumer reporting agencies and any other credit bureau or agency that compiles and maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notice.


Preemption and Compliance

Any information holder that is regulated by federal law or regulation, including the Health Insurance Portability and Accountability Act of 1996 or the Gramm-Leach-Bliley Act and that maintains procedures for a breach of system security pursuant to the laws, rules, regulations, guidance, or guidelines established by its primary or functional federal regulator is deemed to be in compliance with this law if the information holder notifies affected South Dakota residents in accordance with the provisions of the applicable federal law or regulation.


Data Processor Obligations

N/A


Other Information

“Unauthorized person,” any person not authorized to acquire or disclose personal information, or any person authorized by the information holder to access personal information who has acquired or disclosed the personal information outside the guidelines for access of disclosure established by the information holder.