South Dakota
South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

South Dakota requires businesses to notify affected residents of a data breach within 60 days of discovery under SDCL 22-40-20. When more than 250 residents are affected, the Attorney General must also receive notice. Penalties reach up to $10,000 per day per violation for noncompliance.
South Dakota was one of the last states in the nation to enact a data breach notification law. The statute, S.D. Codified Laws 22-40-19 through 22-40-26, took effect on July 1, 2018, and applies to any information holder conducting business in South Dakota that owns or licenses computerized personal or protected information of state residents.
Despite being a late adopter, South Dakota's law includes several features that put it in line with more modern breach notification statutes: a firm 60-day notification deadline, a low Attorney General reporting threshold of 250 residents, and substantial daily penalties for noncompliance. The law also introduces the concept of "protected information," which covers login credentials even without a name.
This guide covers the full scope of South Dakota's breach notification requirements, including how they connect to the broader South Dakota data privacy laws framework.
Who Must Comply
South Dakota's law applies to any "information holder," defined as any person or business that conducts business in South Dakota and owns or licenses computerized personal or protected information of state residents. Businesses located outside South Dakota are covered if they hold data belonging to South Dakota residents.
When a third party maintains data on behalf of the data owner or licensee, the third party must notify the data owner or licensee immediately following discovery of a breach. The data owner then bears the responsibility to notify affected residents and the Attorney General.
Federal Law Compliance Exception
Under Section 22-40-26, information holders regulated by federal law that maintain breach notification procedures under federal requirements (such as HIPAA or the Gramm-Leach-Bliley Act) are deemed in compliance with South Dakota law if they notify affected residents in accordance with applicable federal requirements.
Own Security Policy Exception
An information holder that maintains its own notification procedure as part of an information security policy is also in compliance, provided the policy is consistent with the timing requirements and the holder notifies affected individuals in accordance with its own procedures.
What Triggers Notification
Under Section 22-40-19, a "breach of system security" means the unauthorized acquisition of unencrypted computerized data, or encrypted computerized data and the encryption key, by any person that materially compromises the security, confidentiality, or integrity of personal or protected information.
The definition focuses on unauthorized acquisition, not just unauthorized access. Mere access without acquisition may not trigger the law.
Encryption Safe Harbor
Encrypted data is excluded from the breach definition unless the encryption key was also compromised. South Dakota defines "encrypted" as data rendered unusable, unreadable, or indecipherable without a decryption process or key, or data encrypted in accordance with FIPS 140-2 (the Federal Information Processing Standard effective January 1, 2018).
Personal Information That Triggers the Law
South Dakota's definition of personal information under Section 22-40-19 means a person's first name or first initial and last name, in combination with any one or more of the following data elements:
- Social security number
- Driver's license number or other unique identification number created or collected by a government body
- Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or additional information that would permit access to a financial account
- Health information as defined in 45 CFR 160.103 (the HIPAA definition, covering past, present, or future physical or mental health conditions, healthcare provision, or healthcare payment)
- Identification number assigned by the person's employer, in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication
Personal information does not include information lawfully available from federal, state, or local government records, or information that has been redacted or otherwise made unusable.
Notable: SSN Coverage
South Dakota's statute lists Social Security numbers directly as their own data element, separate from the "driver license number or other unique identification number created or collected by a government body" category.

Protected Information: A Broader Category
South Dakota is one of relatively few states that defines a separate "protected information" category. Protected information includes:
- Username or email address in combination with a password, security question answer, or other information that permits access to an online account
- Account number or credit or debit card number in combination with any required security code, access code, or password that permits access to a financial account
Protected information does not require a name component to trigger notification. This means a breach of email addresses combined with passwords triggers notification even without names being compromised.
The 60-Day Notification Deadline

Under Section 22-40-20, an information holder must disclose the breach to any affected South Dakota resident not later than 60 days from the discovery or notification of the breach.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that notification will impede a criminal investigation. Once law enforcement determines that notification will no longer compromise the investigation, notification must be provided within 30 days.
Who Must Be Notified
Affected Individuals
Every South Dakota resident whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person must receive notification.
Attorney General (250+ Threshold)

When a breach affects more than 250 South Dakota residents, the information holder must notify the South Dakota Attorney General by mail or email. This is one of the lower AG notification thresholds in the country.
Consumer Reporting Agencies
If disclosure to consumers or the Attorney General is required, notice must also be given to the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion).
Methods of Notification
Under Section 22-40-22, South Dakota permits three types of notice:
- Written notice to the last known address
- Electronic notice, if consistent with federal electronic records provisions or if electronic communication is the information holder's primary method of contact with the resident
- Substitute notice, if the cost would exceed $250,000, the affected class exceeds 500,000 persons, or the holder lacks sufficient contact information. Substitute notice requires email to available addresses, conspicuous website posting, and notification to statewide media.
Penalties for Noncompliance
South Dakota's penalty structure is among the more aggressive in the country for a state without a private right of action.
Civil Penalties
Under Section 22-40-25, the Attorney General may bring an action to recover a civil penalty of up to $10,000 per day per violation. For a breach that goes unreported for weeks or months, this daily structure creates significant financial exposure.
Deceptive Acts Prosecution
The Attorney General may also prosecute each failure to disclose as a deceptive act or practice under Chapter 37-24, which provides additional remedies including injunctive relief, consumer restitution, and civil penalties.
Attorney's Fees and Costs
The Attorney General may recover attorney's fees and costs associated with any enforcement action.
No Private Right of Action
South Dakota's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute. Individuals may pursue claims under other legal theories such as negligence, but not under the breach notification statute itself.
This article provides general legal information about South Dakota data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in South Dakota for guidance specific to your situation.
More South Dakota Laws
Frequently Asked Questions
How quickly must a business notify South Dakota residents after a data breach?
South Dakota requires notification within 60 days of discovering or being notified of the breach. If law enforcement requests a delay because notification would impede a criminal investigation, the notification must be sent within 30 days after law enforcement determines it will no longer compromise the investigation.
When must the South Dakota Attorney General be notified of a data breach?
The Attorney General must be notified by mail or email when a breach affects more than 250 South Dakota residents. This is one of the lower AG notification thresholds in the country. Consumer reporting agencies must also be notified when AG notification is required.
What is the difference between personal information and protected information under South Dakota law?
Personal information requires a name combined with data elements like government ID numbers, financial account data, health information, or employer-assigned IDs with biometric data. Protected information does not require a name. It covers usernames or email addresses combined with passwords or security answers, and financial account numbers with access codes. Both categories trigger notification obligations.
What are the penalties for failing to notify about a data breach in South Dakota?
The Attorney General may seek civil penalties of up to $10,000 per day per violation, plus attorney's fees and costs. Violations may also be prosecuted as deceptive acts under Chapter 37-24, which provides additional remedies. There is no private right of action for individuals.
Does South Dakota's breach notification law cover health information?
Yes. South Dakota defines health information by reference to 45 CFR 160.103, the HIPAA definition. This covers information relating to past, present, or future physical or mental health conditions, healthcare provision, or healthcare payment created or received by healthcare providers, health plans, employers, schools, or clearinghouses.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected the citation for South Dakota's HIPAA/GLBA compliance exemption (SDCL 22-40-26, not 22-40-23) and fixed a claim that understated Social Security number coverage in the personal-information definition.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of Federal Regulations Title 45
§ 160.103Definitions.In forcecited in 5 of our articles
Except as otherwise provided, the following definitions apply to this subchapter: Act means the Social Security Act. Administrative simplification provision means any requirement or prohibition established by: (1) 42 U.S.C. 1320d-1320d-4, 1320d-7, 1320d-8, and 1320d-9; (2) Section 264 of Pub. L. 104-191; (3) Sections 13400-13424 of Public Law 111-5; or (4) This subchapter. ALJ means Administrative Law Judge. ANSI stands for the American National Standards Institute. Business associate: (1) Except as provided in paragraph (4) of this definition, business associate means, with respect to a covered entity, a person who: (i) On behalf of such covered entity or of an organized health care arrangement (as defined in this section) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing,…
Official text (excerpt) · as of 2026-07-28 · Read the full section at ecfr.gov
Also relied on in: Does a Failed Drug Test Show Up on Your Record?, When Is a Business Associate Agreement Required? (2026), District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
South Dakota Codified Laws, Chapter 22-40: IDENTITY CRIMES
§ 22-40-19Definition of terms in §§ 22-40-19 to 22-40-26.In forcecited in 4 of our articles
Terms in §§ 22-40-19 to 22-40-26, inclusive, mean: (1) "Breach of system security," the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure; (2) "Encrypted," computerized data that is rendered unusable, unreadable, or indecipherable without the use of a decryption process or key or in accordance with the Federal Information Processing Standard 140-2 in effect on January 1, 2018; (3) "Information holder," any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; (4) "Personal information," a person's first name or first initial and last name, in combination with any one or more of…
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
Also relied on in: South Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026), South Dakota Biometric Privacy Laws: Collection, Consent & Penalties (2026), South Dakota Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 22-40-20Notice of breach of system security--Exception.In forcecited in 3 of our articles
Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement as provided under § 22-40-21. An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years.
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
§ 22-40-25Prosecution for violations.In forcecited in 3 of our articles
The attorney general may prosecute each failure to disclose under the provisions of §§ 22-40-19 to 22-40-26, inclusive, as a deceptive act or practice under § 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than ten thousand dollars per day per violation. The attorney general may recover attorney's fees and any costs associated with any action brought under this section.
Official text (excerpt) · as of 2026-07-30 · Read the full section at sdlegislature.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- S.D. Codified Laws Chapter 22-40 - Identity Crimes(sdlegislature.gov).gov
- Section 22-40-19 - Definitions(law.justia.com)
- Section 22-40-20 - Notice of Breach(law.justia.com)
- Section 22-40-25 - Prosecution for Violations(law.justia.com)
- South Dakota Consumer Protection - Security Breaches(consumer.sd.gov).gov