USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

South Dakota Privacy & Data Security Laws

Every statute below can apply to a business handling South Dakota residents' data, depending on your revenue, the number of South Dakota consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Data Security & Breach Notification · 1

Varies by state
South Dakota data breach notification law
SD Breach Notification
Verify details

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

State breach-notification statute (citation pending verification)

Genetic Privacy · 1

Jul 1, 2026 — newly effective
South Dakota DTC genetic testing law
SD Genetic Privacy
Verify details

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. Written consent required before use of genetic data; civil AG-driven penalty regime. No stable official deep link could be verified (SD's statute browser is JS-rendered) — recommend a manual check of sdlegislature.gov/Statutes/37-24 before treating this as fully confirmed.

S.D. Codified Laws ch. 37-24 (2026 session, SB 49)