Law / South Dakota

South Dakota

age

South Dakota has required age verification for websites with content harmful to minors since July 2025, a law bolstered in public officials' view by the U.S. Supreme Court's June 2025 ruling in Free Speech Coalition v. Paxton. App store age verification bills have failed twice: SB 180 was rejected in committee in 2025, and HB 1275 (2026) passed the House 50 to 17 but was defeated in a Senate committee in March 2026. South Dakota has not enacted a social media minor-access law or a design code law as of this date.

privacy

South Dakota has no general controller or processor personal-data statute, and no comprehensive bill is even pending; the chatbot-disclosure bills in this session (SB 168, SB 170) both died and are unrelated to a comprehensive regime. South Dakota instead has two enacted sectoral instruments.

The Genetic Data Privacy Act, SDCL secs. 37-24-59 to 37-24-64 (SB 49, SL 2026 ch. 164), signed March 23, 2026 and in force since July 1, 2026, requires opt-in express consent for a direct-to-consumer genetic testing company to collect, disclose, or use a consumer's genetic data or biological sample, and gives the consumer access, deletion, and destruction rights; it does not use the term biometric anywhere and treats genetic data as its own category, not interchangeable with biometric data.

South Dakota's breach-notification statute, SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135), in force since July 1, 2018, folds biometric data into personal information only narrowly, when paired with an employer-assigned identification number and used for authentication, and requires Attorney General notice above a threshold of 250 affected residents, not 250,000 as an initial WebSearch pass on this research incorrectly reported.

That breach statute deems a notice violation a deceptive act under the state's general Deceptive Trade Practices and Consumer Protection chapter, which independently arms any adversely affected person with a private right of action; unlike Pennsylvania's, South Carolina's Chapter 80, or West Virginia's equivalents, South Dakota's Attorney General enforcement clause contains no exclusivity language closing that route, so this document leaves whether the deeming-plus-UDAP chain actually arms a private plaintiff for a notice violation as an open question rather than a settled finding, since no case construing the two sections together was found.

8 instruments named 4 researched in detail As of 2026-08-28

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

HB 1053 (2025), age verification for websites containing material harmful to minors

cite S.D. Codified Laws ch. 22-24 (new sections enacted by 2025 S.D. Laws, HB 1053) stage IN FORCE in force since 2025-07-01 source official South Dakota Legislature bill page and text

Requires a covered platform, defined as a website whose regular course of trade or business is to create, host, or make available material harmful to minors, to implement reasonable age verification (state issued driver license or non-driver ID, bank account information, an age restricted debit or credit card, or another reliable method) and to prevent minors from accessing that material. Verifiers may not sell or retain identifying information. Search engines, internet service providers, and cloud providers are exempt.

Note and primary source

Breach notification

Breach of system security, notification statute

cite SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135) stage IN FORCE in force since 2018-07-01 source official South Dakota statute text, SDCL secs. 22-40-19 to 22-40-26, South Dakota Legislature website (api.Statutes path)

Following discovery of a breach of system security, an information holder must disclose the breach to any affected South Dakota resident not later than 60 days from discovery, absent a law-enforcement delay. An information holder whose breach exceeds 250 South Dakota residents (not 250,000, correcting an initial WebSearch summary against the enrolled bill's own text) must also disclose the breach to the Attorney General by mail or electronic mail.

Personal information excludes information lawfully made available to the general public from government records; it folds in biometric data only in a narrow, conditional way, as one component of an employer-assigned identification number used for authentication, not as a freestanding sensitive category. The Attorney General may prosecute a failure to disclose as a deceptive act under SDCL sec. 37-24-6 and may separately bring an action for a civil penalty of up to $10,000 per day per violation.

South Dakota's general Deceptive Trade Practices and Consumer Protection chapter independently arms any person adversely affected by a sec. 37-24-6 violation with a private civil action for actual damages (SDCL sec. 37-24-31), and unlike the comparable enforcement clauses in Pennsylvania, South Carolina's Chapter 80, or West Virginia, this breach statute's enforcement section contains no exclusivity language naming the Attorney General as the sole enforcer.

Whether this deeming-plus-private-action chain actually arms a resident to sue over a notice violation is left here as an open, statute-supported question rather than a settled finding, since no case construing sec. 22-40-25 together with sec. 37-24-31 was found.

What it asks of an app

Enforcement supervision

Genetic Data Privacy Act, enforcement

cite SDCL sec. 37-24-63 (SL 2026 ch. 164, sec. 5) stage NEW in force 59 days effective 2026-07-01 source official South Dakota statute text, SDCL sec. 37-24-63, South Dakota Legislature website (api.Statutes path)

The Attorney General may petition a court to impose a civil penalty of up to $5,000 per violation of SDCL secs. 37-24-60 to 37-24-62.

This standalone enforcement provision does not cross-reference SDCL sec. 37-24-6, the general deceptive-act provision that the breach statute's own enforcement section deems a violation into, so the general Deceptive Trade Practices and Consumer Protection chapter's private right of action, SDCL sec. 37-24-31, which is keyed specifically to a sec. 37-24-6 violation, does not reach a Genetic Data Privacy Act violation. No damages-preservation clause exists either. This Act creates no private right of action.

What it asks of an app

Sensitive categories

Genetic Data Privacy Act, definitions, consent, and consumer rights

cite SDCL secs. 37-24-59 to 37-24-61 (SB 49, SL 2026 ch. 164, secs. 1-3) stage NEW in force 59 days effective 2026-07-01 source official South Dakota statute text, SDCL secs. 37-24-59 to 37-24-61, South Dakota Legislature website (api.Statutes path)

South Dakota's Genetic Data Privacy Act defines genetic data as data other than de-identified data, regardless of format, concerning a consumer's genetic characteristics, and applies only to a direct-to-consumer genetic testing company and its service providers, not to personal data generally.

A covered company must obtain a consumer's opt-in express consent for collection, and separately for disclosure, third-party transfer, research use, retention beyond the initial test, and marketing use, and must maintain a security program. A consumer may access their genetic data, delete their account and genetic data, and obtain destruction of their biological sample; revocation of consent must be honored, and a biological sample destroyed, within 30 days.

The Act never mentions biometric data anywhere in its text; genetic and biometric data are treated as distinct categories in South Dakota law, not interchangeably. Exemptions cover HIPAA-covered entities, medical screening, diagnosis or treatment, higher-education institutions, forensic laboratories, and human-subjects research.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.