Law note · South Dakota

Genetic Data Privacy Act, definitions, consent, and consumer rights

cite SDCL secs. 37-24-59 to 37-24-61 (SB 49, SL 2026 ch. 164, secs. 1-3) stage NEW in force 59 days effective 2026-07-01 reviewed 2026-08-28

South Dakota's Genetic Data Privacy Act defines genetic data as data other than de-identified data, regardless of format, concerning a consumer's genetic characteristics, and applies only to a direct-to-consumer genetic testing company and its service providers, not to personal data generally.

A covered company must obtain a consumer's opt-in express consent for collection, and separately for disclosure, third-party transfer, research use, retention beyond the initial test, and marketing use, and must maintain a security program. A consumer may access their genetic data, delete their account and genetic data, and obtain destruction of their biological sample; revocation of consent must be honored, and a biological sample destroyed, within 30 days.

The Act never mentions biometric data anywhere in its text; genetic and biometric data are treated as distinct categories in South Dakota law, not interchangeably. Exemptions cover HIPAA-covered entities, medical screening, diagnosis or treatment, higher-education institutions, forensic laboratories, and human-subjects research.

What it asks of an app

  • Obtain a South Dakota consumer's opt-in express consent, separately for collection, third-party transfer, research use, retention beyond the initial test, and marketing use of genetic data or a biological sample, if you operate a direct-to-consumer genetic testing service.
  • Honor a consumer's revocation of consent and destroy their biological sample within 30 days.
  • Do not treat this Act as reaching biometric data. It is scoped to genetic data and direct-to-consumer genetic testing companies only.

When LexLint raises it

Declared activities: high_risk_decisions

Primary source: official South Dakota statute text, SDCL secs. 37-24-59 to 37-24-61, South Dakota Legislature website (api.Statutes path)

← Back to the example  ·  Lint your app →