South Dakota
South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026)

South Dakota has no dedicated biometric privacy law and no consent requirements for collecting biometric data. The state's breach notification statute, , provides the only protection, requiring businesses to notify residents within 60 days when a breach exposes biometric authentication data.
South Dakota takes a minimal approach to biometric privacy regulation. Unlike states such as Illinois or Texas that have enacted specific biometric privacy statutes, South Dakota provides biometric data protection only through its data breach notification law.
This means businesses operating in South Dakota can collect, store, and use biometric data such as fingerprints, facial recognition templates, and voiceprints without obtaining consent from individuals. Protection only kicks in after a security breach has already occurred.
For a broader overview of privacy protections in the state, see the parent guide to South Dakota Data Privacy Laws.
How South Dakota Law Defines Biometric Data
South Dakota's breach notification statute, SDCL 22-40-19, defines biometric data as data generated from measurements or analysis of human body characteristics for authentication purposes. This definition appears within the broader definition of "personal information" that triggers breach notification requirements.
Under the statute, biometric data is protected when it appears in combination with an identification number assigned to a person by their employer and any required security code, access code, or password.
The definition is notably narrow compared to other states. It covers biometric data only when used for authentication purposes. Biometric data collected for other reasons, such as marketing analytics or research, falls outside the statute's scope.
Common types of biometric data that would qualify under this definition include:
- Fingerprint scans used for device or system login
- Facial recognition templates used for identity verification
- Iris scans used for building access
- Voiceprints used for phone authentication
- Hand geometry measurements used for timekeeping systems
Photographs, video recordings, and audio recordings are not explicitly addressed in the biometric data definition under .
Breach Notification Requirements for Biometric Data
South Dakota's breach notification law, enacted through SB 62 in 2018 and codified at SDCL 22-40-20, establishes the primary legal framework that protects biometric data in the state.
Who Must Comply
Any person or business that conducts business in South Dakota and owns or licenses computerized personal information of South Dakota residents must comply with the breach notification requirements. This applies to both in-state and out-of-state entities.
Notification Timeline
When a breach of system security exposes personal information that includes biometric data, the information holder must notify affected South Dakota residents no later than 60 days from discovery or notification of the breach.
This 60-day window can be extended only if law enforcement determines that notification would impede a criminal investigation. In that case, notification must occur within 30 days after law enforcement clears the delay.
Attorney General Reporting
Any breach affecting more than 250 South Dakota residents must be reported to the South Dakota Attorney General by mail or email. This report must include information about the nature of the breach and the types of personal information compromised.
What Triggers a Notification
A "breach of system security" under the law means the unauthorized acquisition of unencrypted computerized data, or encrypted data along with the encryption key, that materially compromises the security, confidentiality, or integrity of personal or protected information.
If biometric authentication data is exposed in such a breach, the notification obligations apply.
What South Dakota Law Does Not Cover
The gaps in South Dakota's biometric privacy framework are significant. Understanding what the law does not do is just as important as understanding what it does.
No Collection Consent Requirements

South Dakota does not require businesses or employers to obtain consent before collecting biometric data. A company can implement fingerprint scanners, facial recognition cameras, or voice authentication systems without providing notice or obtaining any form of permission from the individuals whose data is collected.
No Retention or Destruction Rules
The law does not set limits on how long organizations can store biometric data. There are no requirements to publish a data retention schedule or to destroy biometric data after a set period or when the purpose for collection has ended.
No Purpose Limitation
Businesses that collect biometric data in South Dakota face no restrictions on how they use it. The law does not prohibit selling, sharing, or repurposing biometric data, so long as no breach notification obligations are triggered.

No Private Right of Action
Individual South Dakota residents cannot file lawsuits over biometric data misuse. Only the Attorney General has enforcement authority related to breach notification violations. This stands in sharp contrast to Illinois's BIPA, which allows individuals to sue for $1,000 to $5,000 per violation.
Civil Penalties for Noncompliance
Under SDCL 22-40-25, the Attorney General may prosecute a failure to disclose as a deceptive act or practice and may bring an action to recover a civil penalty of up to $10,000 per day per violation, in addition to attorney's fees and costs associated with enforcement actions.
Federal Laws That May Apply in South Dakota
Because South Dakota lacks comprehensive biometric privacy protections, federal laws provide some additional coverage in specific contexts.
HIPAA
Health care providers, insurers, and their business associates in South Dakota must comply with HIPAA when handling biometric data in a health care context. South Dakota's breach notification law recognizes this by deeming HIPAA-regulated entities in compliance if they follow federal breach notification requirements.
Gramm-Leach-Bliley Act (GLBA)
Financial institutions in South Dakota that collect biometric data for customer authentication must comply with GLBA data security requirements. Similar to HIPAA entities, financial institutions that follow their federal regulator's breach notification requirements are deemed compliant with South Dakota's state law.
Children's Online Privacy Protection Act (COPPA)
Companies collecting biometric data from children under 13 in South Dakota must comply with COPPA requirements, which include obtaining verifiable parental consent before collecting biometric identifiers.
How South Dakota Compares to Neighboring States
South Dakota's approach to biometric privacy is among the least protective in the region.
Iowa enacted a consumer data protection law that classifies biometric data as sensitive and requires affirmative consent for processing. Montana similarly passed comprehensive privacy legislation with biometric data protections.
North Dakota, Nebraska, and Wyoming share South Dakota's limited approach, relying primarily on breach notification laws without dedicated biometric privacy statutes.
Minnesota, to the east, has enacted stronger consumer data privacy protections that include biometric data provisions.
Practical Guidance for South Dakota Residents
Without a dedicated biometric privacy law, South Dakota residents have limited legal recourse regarding their biometric data. However, there are practical steps to protect yourself.
Ask employers and businesses what biometric data they collect and how they store it. While they are not legally required to tell you, many organizations have privacy policies that address biometric data.
Review privacy policies before using apps, devices, or services that collect fingerprints, facial scans, or voice data. Federal laws like COPPA and sector-specific regulations may provide some protections depending on the context.
If you believe your biometric data was compromised in a breach and you did not receive notification, contact the South Dakota Attorney General's Consumer Protection Division to file a complaint.
Legislative Outlook
As of early 2026, South Dakota has not introduced biometric privacy legislation. The state has not proposed a comprehensive consumer data privacy law or a standalone biometric privacy statute.
Given that 20 states have now enacted comprehensive privacy laws with biometric data provisions, legislative activity in South Dakota remains possible. Any new legislation would likely be introduced during the state's annual legislative session, which typically runs from January through March.
Residents and businesses should monitor the South Dakota Legislature website for any proposed privacy-related bills.
Sources and References
This article references South Dakota statutes available through the South Dakota Legislature website. For the full text of the breach notification law, see SDCL 22-40-19 through SDCL 22-40-26. For consumer complaints related to data breaches, contact the South Dakota Attorney General.
This article provides general legal information about South Dakota biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official South Dakota government sources.
More South Dakota Laws
Frequently Asked Questions
Does South Dakota have a biometric privacy law?
No. South Dakota does not have a dedicated biometric privacy law. Biometric data receives limited protection only through the state's breach notification statute (SDCL 22-40-19 through 22-40-26), which requires businesses to notify affected individuals within 60 days when a data breach exposes biometric authentication data.
Can my employer collect my fingerprints without consent in South Dakota?
Yes. South Dakota law does not require employers to obtain consent before collecting biometric data such as fingerprints, facial scans, or iris scans. There are no state-level restrictions on employer collection or use of biometric data, though federal laws like HIPAA or GLBA may apply in specific industries.
Can I sue a company in South Dakota for misusing my biometric data?
No. South Dakota does not provide a private right of action for biometric data misuse. Only the South Dakota Attorney General can enforce breach notification requirements. If you believe a company mishandled your biometric data, you can file a complaint with the Attorney General's Consumer Protection Division at atg.sd.gov.
What biometric data is protected under South Dakota's breach notification law?
SDCL 22-40-19 protects biometric data generated from measurements or analysis of human body characteristics for authentication purposes. This includes fingerprint scans, facial recognition templates, iris scans, and voiceprints when used for authentication and combined with employer identification numbers and security credentials.
What penalties does South Dakota impose for failing to report a biometric data breach?
South Dakota's breach notification law allows the Attorney General to recover a civil penalty of up to $10,000 per day per violation, plus attorney's fees and costs associated with enforcement actions. Businesses that experience a breach affecting more than 250 residents must report it to the Attorney General within 60 days of discovery.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected the citation and content of this page's civil-penalty claim: SD's breach law does specify a penalty (up to $10,000 per day per violation under SDCL 22-40-25), and fixed a mismatched statute citation for the 60-day notice duty.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
South Dakota Codified Laws, Chapter 22-40: IDENTITY CRIMES
§ 22-40-19Definition of terms in §§ 22-40-19 to 22-40-26.In forcecited in 4 of our articles
Terms in §§ 22-40-19 to 22-40-26, inclusive, mean: (1) "Breach of system security," the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure; (2) "Encrypted," computerized data that is rendered unusable, unreadable, or indecipherable without the use of a decryption process or key or in accordance with the Federal Information Processing Standard 140-2 in effect on January 1, 2018; (3) "Information holder," any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; (4) "Personal information," a person's first name or first initial and last name, in combination with any one or more of…
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
Also relied on in: South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026), South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026), South Dakota Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 22-40-20Notice of breach of system security--Exception.In forcecited in 3 of our articles
Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement as provided under § 22-40-21. An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
§ 22-40-22Types of notice of breach of system security.In forcecited in 2 of our articles
A disclosure under § 22-40-20 may be provided by: (1) Written notice; (2) Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 in effect as of January 1, 2018, or if the information holder's primary method of communication with the resident of this state has been by electronic means; or (3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder's website, if the information holder maintains a website page; and (c) Notification to statewide media.
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
§ 22-40-25Prosecution for violations.In forcecited in 3 of our articles
The attorney general may prosecute each failure to disclose under the provisions of §§ 22-40-19 to 22-40-26, inclusive, as a deceptive act or practice under § 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than ten thousand dollars per day per violation. The attorney general may recover attorney's fees and any costs associated with any action brought under this section.
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- SDCL 22-40-19 - Definition of Terms (Breach Notification)(sdlegislature.gov).gov
- SDCL 22-40-20 - Disclosure of Breach Required(sdlegislature.gov).gov
- SDCL 22-40-22 - Notification to Attorney General(sdlegislature.gov).gov
- SDCL 22-40-25 - Prosecution for Violations(sdlegislature.gov).gov
- SDCL Chapter 22-40 - Identity Crimes(sdlegislature.gov).gov
- SB 62 (2018) - Data Breach Notification Act(mylrc.sdlegislature.gov).gov
- South Dakota Attorney General - Consumer Protection(atg.sd.gov).gov