Law / South Carolina

South Carolina

age

South Carolina has required age verification for adult content sites since January 2025, and enacted an Age-Appropriate Design Code Act in February 2026 that took immediate effect. NetChoice sued over the design code within days of enactment, and a preliminary injunction motion is pending. South Carolina has not enacted a social-media-specific age verification law or an app store accountability law; an App Store Accountability Act bill (H.3405) has not advanced out of the House.

privacy

South Carolina has no enacted general controller or processor personal-data statute, and no comprehensive bill has even passed a chamber. It does have an enacted minors-focused design-code statute, the South Carolina Age-Appropriate Design Code, enacted as Act No. 96 of 2026 (H. 3431), codified as new Chapter 80 of Title 39, S.C. Code Ann. secs. 39-80-10 et seq., signed and effective February 5, 2026.

A different, unrelated bill, H. 3402, carries the same short title but would have created Chapter 79 and never advanced past committee referral; the citation for this document is drawn from the enacted H. 3431 text itself, not from either bill number alone.

Chapter 80 lists biometric data among sensitive personal data requiring heightened, minor-protective design duties, but never defines the term anywhere in the chapter, so whether it excludes an identifier derived from a photograph, video, or audio recording cannot be determined from the text; a narrower, separate clause excludes only a minor's biometric data collected without the minor's knowledge from the chapter's definition of publicly available data.

Chapter 80's own enforcement section names only the Attorney General and imposes treble damages, but does not say whether that remedy is available to a private plaintiff, an open question this document leaves unresolved rather than guessing.

South Carolina's breach-notification statute, S.C. Code Ann. sec. 39-1-90, in force since July 1, 2009, carries an express, direct private right of action for an injured resident, unusual in this wave, which typically finds a private route only by an indirect deeming-plus-UDAP chain or not at all.

13 instruments named 6 researched in detail As of 2026-08-28

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

H.3424 (2024), Child Online Safety Act

cite S.C. Code Ann. section 37-1-310 stage IN FORCE in force since 2025-01-01 source official South Carolina Code of Laws statute text

Requires a commercial entity that knowingly publishes material on a website, more than one third of which is material harmful to minors, to perform reasonable age verification of South Carolina visitors using a digitized identification card, a third party verification service, or a commercially reasonable method relying on transactional data.

Note and primary source

Age-appropriate design code

H.3431 (2026), Age-Appropriate Design Code Act (Act No. 96 of 2026)

cite S.C. Code Ann. Title 39, ch. 80 stage RECENT in force 7 months effective 2026-02-05 source official South Carolina Legislature bill and act text

Requires online services reasonably likely to be accessed by minors to set protective default privacy settings for known minors, offer opt outs from personalized recommendation systems, limit addictive design features and nighttime and school hours notifications, and undergo independent third party audits reported to the Attorney General. NetChoice sued days after enactment and a preliminary injunction motion is pending.

Note and primary source

Breach notification

Business data breach of security, notification statute

cite S.C. Code Ann. sec. 39-1-90 stage IN FORCE in force since 2009-07-01 source official South Carolina statute text, S.C. Code Ann. sec. 39-1-90, consolidated South Carolina Code of Laws

A person conducting business in South Carolina that owns or licenses computerized data including personal identifying information must disclose a breach of the security of the system to an affected South Carolina resident in the most expedient time possible and without unreasonable delay, where the breach creates a material risk of harm.

Personal identifying information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, or another government-issued identifying number; biometric, genetic, or health data is not folded into this definition. If a business notifies more than 1,000 persons at one time, it must also notify the Consumer Protection Division of the Department of Consumer Affairs and nationwide consumer reporting agencies.

The current definition of personal identifying information took effect April 23, 2013; the notification duty itself took effect July 1, 2009. A resident injured by a violation may bring a civil action for damages (willful and knowing violations) or actual damages (negligent violations), seek an injunction, and recover attorney's fees, an express, direct private right of action rather than one reached indirectly through a deeming clause.

An administrative fine of $1,000 per affected resident is also available to the Department of Consumer Affairs for a knowing and willful violation.

What it asks of an app

Data subject rights

South Carolina Age-Appropriate Design Code, general applicability and minor-protective design duties

cite S.C. Code Ann. secs. 39-80-10 et seq. (Act No. 96 of 2026, H. 3431) stage RECENT in force 7 months effective 2026-02-05 source official South Carolina session law text, Act No. 96 of 2026 (H. 3431), South Carolina Legislature website

The Age-Appropriate Design Code applies to a covered online service reasonably likely to be accessed by a minor (a person under 18). It is not a general controller or processor personal-data regime; it imposes design and data-minimization duties specifically toward minor users, including default privacy settings, limits on profiling, targeted advertising, and precise-geolocation collection for known minors, parental controls, and an annual public report by an independent auditor.

The Act was enacted as Act No. 96 of 2026 (H. 3431, the South Carolina Social Media Regulation Act on its own caption) and creates Chapter 80 of Title 39; it took effect immediately upon the Governor's approval on February 5, 2026. It is not to be confused with H. 3402, a different, still-pending bill sharing the short title 'Age-Appropriate Design,' which would have created Chapter 79 and never advanced past referral to House Judiciary.

The consolidated online Code of Laws page for the new Chapter 80 does not yet resolve as of 2026-08-28 (HTTP 404 at every tried URL pattern); the session-law text of Act No. 96 is the authoritative current source.

What it asks of an app

Enforcement supervision

Age-Appropriate Design Code, enforcement

cite S.C. Code Ann. sec. 39-80-80 (Act No. 96 of 2026, H. 3431) stage RECENT in force 7 months effective 2026-02-05 source official South Carolina session law text, Act No. 96 of 2026 (H. 3431), South Carolina Legislature website

The Attorney General enforces Chapter 80. A covered online service is liable for treble the financial damages incurred as a result of a violation, and officers and employees of a covered online service may be held personally liable for willful and wanton violations.

The 30,353-character enacted text does not resolve whether the treble-damages remedy is available to a private plaintiff or is confined to a suit the Attorney General brings: no clause reads that an injured person may bring a civil action, the phrasing South Carolina's breach statute uses to grant one, and no clause reads that the chapter creates no private right of action, the phrasing Pennsylvania's and West Virginia's comparable proposed and dead bills use to foreclose one.

This document leaves private_right_of_action unrecorded for this instrument rather than guessing; the treble-damages and personal-liability clauses read most naturally as remedies within the Attorney General's own suit given the enforcement section's framing naming only the Attorney General, but no clearer textual anchor or construing case was found.

What it asks of an app

Sensitive categories

Age-Appropriate Design Code, sensitive personal data and biometric data

cite S.C. Code Ann. sec. 39-80-10(18) (Act No. 96 of 2026, H. 3431) stage RECENT in force 7 months effective 2026-02-05 source official South Carolina session law text, Act No. 96 of 2026 (H. 3431), South Carolina Legislature website

Chapter 80 defines sensitive personal data to include a Social Security number, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, the contents of an individual's mail, email, or text messages, genetic data, biometric data for the purpose of uniquely identifying an individual, and health data.

'Biometric data' itself is never defined anywhere in the 30,353-character enacted text; the term appears exactly twice, once in this sensitive-data list and once in the publicly-available-data carve-out below, with no accompanying definitional entry among the chapter's twenty defined terms.

Whether the term excludes an identifier derived from a photograph, video, or audio recording therefore cannot be determined from the statutory text; there is no definitional clause to read as imposing or narrowing such an exclusion.

A narrower, separate carve-out excludes only 'biometric data collected by a covered online service about a minor without the minor's knowledge' from the chapter's definition of publicly available data, which does not address an adult's biometric data, or a knowingly collected minor's, drawn from a public recording.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.