Law note · South Dakota
Breach of system security, notification statute
Following discovery of a breach of system security, an information holder must disclose the breach to any affected South Dakota resident not later than 60 days from discovery, absent a law-enforcement delay. An information holder whose breach exceeds 250 South Dakota residents (not 250,000, correcting an initial WebSearch summary against the enrolled bill's own text) must also disclose the breach to the Attorney General by mail or electronic mail.
Personal information excludes information lawfully made available to the general public from government records; it folds in biometric data only in a narrow, conditional way, as one component of an employer-assigned identification number used for authentication, not as a freestanding sensitive category. The Attorney General may prosecute a failure to disclose as a deceptive act under SDCL sec. 37-24-6 and may separately bring an action for a civil penalty of up to $10,000 per day per violation.
South Dakota's general Deceptive Trade Practices and Consumer Protection chapter independently arms any person adversely affected by a sec. 37-24-6 violation with a private civil action for actual damages (SDCL sec. 37-24-31), and unlike the comparable enforcement clauses in Pennsylvania, South Carolina's Chapter 80, or West Virginia, this breach statute's enforcement section contains no exclusivity language naming the Attorney General as the sole enforcer.
Whether this deeming-plus-private-action chain actually arms a resident to sue over a notice violation is left here as an open, statute-supported question rather than a settled finding, since no case construing sec. 22-40-25 together with sec. 37-24-31 was found.
What it asks of an app
- Notify each affected South Dakota resident of a breach of system security not later than 60 days after discovery, absent a law enforcement delay.
- Notify the South Dakota Attorney General by mail or electronic mail if a breach affects 250 or more South Dakota residents. This threshold is 250, not 250,000.
- Treat biometric data as a breach-notification trigger only when it is paired with an employer-assigned identification number used for authentication, not on its own.
- Do not assume a private right of action is settled either way for a notice violation here. This document leaves it as an open question; a deeming-plus-UDAP chain to SDCL sec. 37-24-31 exists in the text with no exclusivity clause closing it, but no confirming case was found.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_biometrics
Primary source: official South Dakota statute text, SDCL secs. 22-40-19 to 22-40-26, South Dakota Legislature website (api.Statutes path)
enrolled bill text via mylrc.sdlegislature.gov/api/Documents/Bill/50500.html?Year=2018