State Guide
South Dakota Privacy & Data Security Laws
Every statute below can apply to a business handling South Dakota residents' data, depending on your revenue, the number of South Dakota consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Data Security & Breach Notification · 1
Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. Express written consent required before use of genetic data, with access/deletion rights, sample destruction within 30 days of a revoked consent, and a civil AG-driven penalty regime. The bill record — SB 49 of the 2026 session, carried by the Judiciary chair at the Attorney General's request, titled to "safeguard the integrity, privacy, and security of genetic data and provide a civil penalty therefor" — was confirmed against the Legislature's own bill data. The Mar 23, 2026 signing date and the placement of the new sections within SDCL ch. 37-24 rest on secondary legal-reference reporting, because SD's statute browser is JS-rendered and its enrolled-bill PDFs could not be read here — reconfirm the exact section numbers before quoting the citation.