🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-SC v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing16 sources retrieved model claude-sonnet-5 · 2026-08-06

South Carolina, USA

US-SC schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 24 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

South Carolina's Age-Appropriate Design Code Act (Act No. 96) took effect immediately upon Governor McMaster's signature on February 5, 2026, requiring covered online services reasonably likely to be accessed by minors to implement privacy-by-default settings and parental account-management tools, and requiring covered online services' independent audit reports to describe the algorithms used and how covered design features apply to minors. The Act also prohibits covered online services from facilitating targeted advertising to minors. It is understood to be enforced by the Attorney General, who may seek treble financial damages, with no statutory right to cure and personal liability exposure for officers and employees of covered services.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No omnibus statute or dedicated DPA, but a substantive new minors-focused statute and clear breach-notification/insurance-security instruments exist and are actively enforced.

Primary frameworkNo comprehensive state privacy statute; federal FTC Act Section 5 + S.C. Code §39-1-90 (breach notification) + S.C. Code §38-99-10 et seq. (Insurance Data Security Act) + H.3431 (2026, Social Media Regulation and Age-Appropriate Design Code Act)
Traffic-light rationale — AmberNo omnibus statute or dedicated DPA, but a substantive new minors-focused statute and clear breach-notification/insurance-security instruments exist and are actively enforced.

Sub-modules (5)

Regulator And AuthorityAmber

Enforcement authority is split between the SC Attorney General (H.3431, general consumer protection) and SCDCA (breach notification).

Claims (2):

  • South Carolina has no dedicated data protection authority; privacy-adjacent enforcement is divided between the South Carolina Attorney General and the South Carolina Department of Consumer Affairs (SCDCA).
  • The South Carolina Attorney General is the enforcing authority for the state's new Age-Appropriate Design Code / Social Media Regulation Act (H.3431).

Act And InstrumentsAmber

Primary instruments: §39-1-90 breach law, §38-99-10 et seq. Insurance Data Security Act, and H.3431; no general omnibus act.

Claims (2):

  • South Carolina's breach notification statute, S.C. Code §39-1-90, is enforced by the SCDCA and requires notice to the SCDCA only when a business provides notice to more than 1,000 persons at one time.
  • South Carolina has no comprehensive consumer-privacy statute analogous to GDPR or CPRA; a comprehensive privacy bill (House Bill 4696) has been introduced but not enacted.

Material ScopeRed

No general material-scope definition exists absent an omnibus statute; scope is defined narrowly and sectorally (breach data, insurer nonpublic information, minors' online services).

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , c, o, m, p, r, e, h, e, n, s, i, v, e, , c, o, n, s, u, m, e, r, , p, r, i, v, a, c, y, , l, a, w, , 2, 0, 2, 6, , s, t, a, t, u, s, ;, , S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , b, r, e, a, c, h, , n, o, t, i, f, i, c, a, t, i, o, n, , s, t, a, t, u, t, e, , 2, 0, 2, 6.

Territorial ScopeAmber

H.3431 applies extraterritorially to any controller conducting business in South Carolina whose online service is reasonably likely to be accessed by minors, subject to disjunctive revenue/data-volume thresholds.

Claims (1):

  • H.3431 applies to any data controller that conducts business in South Carolina and owns, operates, controls, or provides an online service reasonably likely to be accessed by minors, subject to a revenue threshold, a 50,000-consumer processing threshold, or a 50%-of-revenue-from-data-sale threshold.

Regulator Registration And FilingRed

No state controller/processor registration or filing regime was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, g, i, s, t, r, a, t, i, o, n, , f, i, l, i, n, g, , r, e, q, u, i, r, e, m, e, n, t, s.

Category narrative86 words

South Carolina has no dedicated data-protection authority. Enforcement is split between the South Carolina Attorney General (general consumer protection and, since 2026, the new minors' online-safety/design-code statute) and the South Carolina Department of Consumer Affairs (SCDCA), which enforces the state's breach-notification statute. There is no state omnibus consumer-privacy law: a comprehensive bill (HB 4696) has been introduced but not enacted. The most consequential recent development is H.3431, the Social Media Regulation and Age-Appropriate Design Code Act, signed by Gov. McMaster and effective without a cure period.

Sources and claims (6)
  1. ConfirmedDataGuidance — South Carolina has no dedicated data protection authority; privacy-adjacent enforcement is divided between the South Carolina Attorney General and the South Carolina Department of Consumer Affairs (SCDCA).observed
  2. ConfirmedSouth Carolina Legislature (summarized via DataGuidance) — South Carolina's breach notification statute, S.C. Code §39-1-90, is enforced by the SCDCA and requires notice to the SCDCA only when a business provides notice to more than 1,000 persons at one time.observed
  3. ConfirmedDataGuidance — South Carolina has no comprehensive consumer-privacy statute analogous to GDPR or CPRA; a comprehensive privacy bill (House Bill 4696) has been introduced but not enacted.observed
  4. ConfirmedFederal Trade Commission — Federal Trade Commission Act Section 5 provides general unfair/deceptive-practices authority applicable nationally, including South Carolina, but is reactive rather than a comprehensive proactive privacy regime.observed
  5. ConfirmedDataGuidance — The South Carolina Attorney General is the enforcing authority for the state's new Age-Appropriate Design Code / Social Media Regulation Act (H.3431).observed
  6. ConfirmedIAPP — H.3431 applies to any data controller that conducts business in South Carolina and owns, operates, controls, or provides an online service reasonably likely to be accessed by minors, subject to a revenue threshold, a 50,000-consumer processing threshold, or a 50%-of-revenue-from-data-sale threshold.observed

#

No general lawful-basis, consent, or special-category regime exists outside narrow sectoral carve-outs.

Traffic-light rationale — RedNo general lawful-basis, consent, or special-category regime exists outside narrow sectoral carve-outs.

Sub-modules (4)

Lawful BasesRed

No general statutory lawful-basis framework exists in South Carolina.

Claims (1):

  • South Carolina does not have a general statutory lawful-basis framework governing commercial data processing outside of insurance and minors' online services.

Special CategoriesRed

Special/sensitive category protections are sectoral, limited to genetic information in the insurance context.

Claims (1):

  • South Carolina's genetic-privacy protections are sectoral, addressed under Title 38, Chapter 93 of the South Carolina Code (Privacy of Genetic Information), applying in the insurance context rather than as a general special-category regime.

Pseudonymisation And AnonymisationRed

No general statutory pseudonymisation/anonymisation definition or safe harbor was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , d, a, t, a, , s, t, a, t, u, t, e.

Claims (1):

  • South Carolina has no statutory definition or safe harbor for pseudonymised or anonymised data outside the insurance sector.
Category narrative47 words

South Carolina has no general lawful-basis or consent framework for commercial data processing. Consent-like mechanisms exist only within H.3431 (default opt-out of personalized recommendations for minors). Special-category/genetic data protections are confined to the insurance sector under Title 38, Chapter 93. No general pseudonymisation/anonymisation safe harbor was identified.

Sources and claims (4)
  1. ConfirmedDataGuidance — South Carolina does not have a general statutory lawful-basis framework governing commercial data processing outside of insurance and minors' online services.observed
  2. ConfirmedIAPP — Under H.3431, covered online services must provide minors default privacy settings that opt out of personalized recommendation systems, except for optimizations based on the user's expressed preferences.observed
  3. ProbableSouth Carolina Legislature (summarized via DataGuidance) — South Carolina's genetic-privacy protections are sectoral, addressed under Title 38, Chapter 93 of the South Carolina Code (Privacy of Genetic Information), applying in the insurance context rather than as a general special-category regime.observed
  4. UncertainDataGuidance — South Carolina has no statutory definition or safe harbor for pseudonymised or anonymised data outside the insurance sector.observed

#

No general DSR framework exists; only narrow, minors-focused design-control rights under H.3431.

Traffic-light rationale — RedNo general DSR framework exists; only narrow, minors-focused design-control rights under H.3431.

Sub-modules (5)

Access RightRed

No general statutory right of access exists in South Carolina.

Claims (1):

  • South Carolina law does not provide a general right of access, rectification, erasure, restriction, objection, or data portability for consumers' personal data outside of the insurance and minors' online-service contexts.

Rectification And ErasureRed

No general right to rectify or delete personal data exists outside sectoral contexts.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , r, i, g, h, t, , t, o, , d, e, l, e, t, e, , r, e, c, t, i, f, y, , p, e, r, s, o, n, a, l, , d, a, t, a, , s, t, a, t, u, t, e.

Restriction And ObjectionRed

No general right to restrict processing or object to profiling exists for the general population; H.3431 provides minors-focused profiling opt-outs (see algorithmic_biometric module).

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , r, i, g, h, t, , t, o, , r, e, s, t, r, i, c, t, , p, r, o, c, e, s, s, i, n, g, , o, b, j, e, c, t, , p, r, o, f, i, l, i, n, g, , s, t, a, t, u, t, e.

Data PortabilityRed

No statutory data-portability right exists in South Carolina.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , r, i, g, h, t, , s, t, a, t, u, t, e.

Deadlines And Response WindowsRed

No statutory deadline for controller response to a data-subject request exists because no comprehensive statute establishes such rights.

Claims (1):

  • No statutory deadline exists for controller response to a data-subject rights request in South Carolina because no comprehensive statute establishes such rights.
Category narrative47 words

South Carolina provides no general consumer right of access, rectification, erasure, restriction, objection, or portability. The only individual-facing control rights exist within H.3431, which requires user-facing design controls (usage timers, spending caps, engagement-metric visibility controls, etc.) for minors and, more narrowly, for all users of covered services.

Sources and claims (3)
  1. ConfirmedDataGuidance — South Carolina law does not provide a general right of access, rectification, erasure, restriction, objection, or data portability for consumers' personal data outside of the insurance and minors' online-service contexts.observed
  2. ConfirmedIAPP — H.3431 requires covered online services to provide users, not limited to minors, accessible tools to disable design features such as infinite scroll, auto-playing videos, and gamification, with default protective settings for minors.observed
  3. ConfirmedDataGuidance — No statutory deadline exists for controller response to a data-subject rights request in South Carolina because no comprehensive statute establishes such rights.observed

#

Robust sectoral (insurance) security/breach duties and a new minors-specific audit/minimization regime exist, but no general accountability, DPO, ROPA, or retention framework applies economy-wide.

Primary frameworkS.C. Code §38-99-10 et seq. (Insurance Data Security Act); S.C. Code §39-1-90 (breach notification); H.3431 (minors' data minimization/audit)
Traffic-light rationale — AmberRobust sectoral (insurance) security/breach duties and a new minors-specific audit/minimization regime exist, but no general accountability, DPO, ROPA, or retention framework applies economy-wide.

Sub-modules (7)

Accountability And DpiaAmber

H.3431 imposes data-minimization standards and a third-party audit requirement submitted to the Attorney General, functioning as a DPIA analogue for children's data.

Claims (1):

  • H.3431 includes data-minimization standards, opt-out rights around personalized recommendation systems, and a third-party audit requirement, with audits submitted to the Attorney General for public disclosure.

Dpo RequirementsRed

No DPO appointment requirement exists in South Carolina law.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, f, f, i, c, e, r, , r, e, q, u, i, r, e, m, e, n, t, , s, t, a, t, u, t, e.

Ropa RequirementsRed

No records-of-processing-activities requirement exists in South Carolina law.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , r, e, c, o, r, d, s, , o, f, , p, r, o, c, e, s, s, i, n, g, , a, c, t, i, v, i, t, i, e, s, , r, e, q, u, i, r, e, m, e, n, t.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists in South Carolina.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , d, a, t, a, , p, r, o, c, e, s, s, i, n, g, , s, t, a, t, u, t, e.

Security MeasuresAmber

The Insurance Data Security Act requires a comprehensive written information security program, risk assessments, staff training, and third-party diligence for insurers.

Claims (1):

  • South Carolina's Insurance Data Security Act (S.C. Code §38-99-10 et seq.) requires insurers, agents, and other licensed entities to establish a comprehensive written information security program, conduct risk assessments, provide staff training, and exercise due diligence in selecting third-party service providers.

Breach NotificationAmber

The general breach statute (§39-1-90) requires SCDCA notification only above a 1,000-person threshold; insurers face an additional 72-hour cyber-event notice requirement to state insurance regulators.

Claims (1):

  • South Carolina's breach notification statute (§39-1-90) requires notification to the SCDCA only when a business provides notice to more than 1,000 persons at a single time, and does not impose a general accountability, DPIA, DPO, or ROPA obligation.

Retention And DisposalRed

No general statutory retention-limitation or disposal duty applies outside sector-specific regimes.

Claims (1):

  • No general statutory retention-limitation or disposal duty applies to commercial data processing in South Carolina outside sector-specific regimes such as insurance.
Category narrative54 words

General accountability, DPIA, DPO, ROPA, and retention obligations do not exist outside the insurance sector. The Insurance Data Security Act imposes security-program, risk-assessment, training, and vendor-diligence duties on insurers. H.3431 imposes children's-data-specific data-minimization, opt-out, and third-party audit obligations functioning as a DPIA analogue for covered services. The breach-notification statute imposes narrow notification duties only.

Sources and claims (4)
  1. ConfirmedSouth Carolina Legislature (summarized via DataGuidance) — South Carolina's Insurance Data Security Act (S.C. Code §38-99-10 et seq.) requires insurers, agents, and other licensed entities to establish a comprehensive written information security program, conduct risk assessments, provide staff training, and exercise due diligence in selecting third-party service providers.observed
  2. ConfirmedSouth Carolina Legislature (summarized via DataGuidance) — South Carolina's breach notification statute (§39-1-90) requires notification to the SCDCA only when a business provides notice to more than 1,000 persons at a single time, and does not impose a general accountability, DPIA, DPO, or ROPA obligation.observed
  3. ProbableIAPP — H.3431 includes data-minimization standards, opt-out rights around personalized recommendation systems, and a third-party audit requirement, with audits submitted to the Attorney General for public disclosure.observed
  4. ConfirmedDataGuidance — No general statutory retention-limitation or disposal duty applies to commercial data processing in South Carolina outside sector-specific regimes such as insurance.observed

#

No state-level cross-border transfer framework exists; this is a genuine regulatory gap at the state level, consistent with the seed disambiguation.

Traffic-light rationale — RedNo state-level cross-border transfer framework exists; this is a genuine regulatory gap at the state level, consistent with the seed disambiguation.

Sub-modules (6)

Transfer MechanismsRed

No state-level transfer mechanism exists.

Claims (1):

  • South Carolina has not enacted any state-level cross-border data-transfer mechanism, adequacy determination, SCC/BCR regime, or data-localisation mandate; cross-border transfer governance affecting this jurisdiction is determined at the U.S. federal level rather than by state law.

Adequacy ReceivedRed

Not applicable at state level; adequacy is a federal/international-level determination.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , a, d, e, q, u, a, c, y, , d, e, t, e, r, m, i, n, a, t, i, o, n, , c, r, o, s, s, -, b, o, r, d, e, r, , d, a, t, a, , t, r, a, n, s, f, e, r.

Adequacy GrantedRed

Not applicable at state level.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , a, d, e, q, u, a, c, y, , d, e, t, e, r, m, i, n, a, t, i, o, n, , c, r, o, s, s, -, b, o, r, d, e, r, , d, a, t, a, , t, r, a, n, s, f, e, r.

Sccs And BcrsRed

No state-level SCC/BCR framework exists.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , s, t, a, n, d, a, r, d, , c, o, n, t, r, a, c, t, u, a, l, , c, l, a, u, s, e, s, , b, i, n, d, i, n, g, , c, o, r, p, o, r, a, t, e, , r, u, l, e, s.

Transfer Impact AssessmentRed

No state-level TIA requirement exists.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Data LocalisationRed

No state-level data-localisation mandate was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , s, t, a, t, u, t, e.

Category narrative36 words

South Carolina has enacted no state-level cross-border transfer mechanism, adequacy determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data-flow governance affecting South Carolina entities is determined at the U.S. federal level, not by state law.

Sources and claims (1)
  1. ProbableDataGuidance — South Carolina has not enacted any state-level cross-border data-transfer mechanism, adequacy determination, SCC/BCR regime, or data-localisation mandate; cross-border transfer governance affecting this jurisdiction is determined at the U.S. federal level rather than by state law.observed

#

Insurance sector is comprehensively regulated at state level; other sectors rely entirely on federal sectoral statutes with no state overlay identified.

Primary frameworkS.C. Code §38-99-10 et seq. (Insurance Data Security Act); HIPAA; GLBA (federal)
Traffic-light rationale — AmberInsurance sector is comprehensively regulated at state level; other sectors rely entirely on federal sectoral statutes with no state overlay identified.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA governs financial institutions' nonpublic personal information nationally, including South Carolina, absent a state comprehensive law.

Claims (1):

  • The Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationally, including South Carolina, as the primary sectoral financial-privacy framework absent a state comprehensive law.

Health Sector OverlayAmber

HIPAA governs protected health information nationally, including South Carolina.

Claims (1):

  • HIPAA governs protected health information nationally, including in South Carolina, in the absence of a state comprehensive health-privacy statute.

Telecoms And EprivacyRed

No state-specific eprivacy/telecoms data statute exists beyond federal TCPA application.

Claims (1):

  • South Carolina has no state-specific eprivacy/telecoms data statute beyond application of the federal Telephone Consumer Protection Act; no dedicated state cookie law exists.

Employment DataRed

No South Carolina employment-data-specific privacy statute was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , e, m, p, l, o, y, m, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , s, t, a, t, u, t, e.

Credit And ScoringRed

Credit-scoring data is governed by the federal Fair Credit Reporting Act; no state-specific statute was identified.

Claims (1):

  • Credit-scoring and consumer-report data in South Carolina are governed by the federal Fair Credit Reporting Act; no state-specific credit-scoring privacy statute was identified.

EducationRed

No South Carolina education-sector-specific student-data-privacy statute was identified this run.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , e, d, u, c, a, t, i, o, n, , s, t, a, t, u, t, e.

InsuranceGreen

The Insurance Data Security Act models the NAIC Insurance Data Security Model Law and requires a 72-hour cybersecurity-event notice to state insurance regulators.

Claims (2):

  • The South Carolina Insurance Data Security Act constitutes a sector-specific overlay for insurers, agents, and licensees modeled on the NAIC Insurance Data Security Model Law.
  • South Carolina insurers must notify state insurance regulatory authorities of a cybersecurity event within 72 hours of confirming nonpublic information was disrupted, misused, or accessed without authorization, in addition to general breach-notification requirements.
Category narrative54 words

South Carolina's data-protection landscape is dominated by sectoral overlays: federal HIPAA, GLBA, and COPPA apply nationally in the absence of a state omnibus law; the state's own Insurance Data Security Act imposes NAIC-model security obligations and a 72-hour cyber-incident notice to insurance regulators; no state-specific telecoms/eprivacy, employment-data, credit-scoring, or education-sector privacy statute was identified.

Sources and claims (6)
  1. ProbableDataGuidance — HIPAA governs protected health information nationally, including in South Carolina, in the absence of a state comprehensive health-privacy statute.observed
  2. ProbableDataGuidance — The Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationally, including South Carolina, as the primary sectoral financial-privacy framework absent a state comprehensive law.observed
  3. UncertainDataGuidance — South Carolina has no state-specific eprivacy/telecoms data statute beyond application of the federal Telephone Consumer Protection Act; no dedicated state cookie law exists.observed
  4. UncertainDataGuidance — Credit-scoring and consumer-report data in South Carolina are governed by the federal Fair Credit Reporting Act; no state-specific credit-scoring privacy statute was identified.observed
  5. ConfirmedIAPP — The South Carolina Insurance Data Security Act constitutes a sector-specific overlay for insurers, agents, and licensees modeled on the NAIC Insurance Data Security Model Law.observed
  6. ConfirmedIAPP — South Carolina insurers must notify state insurance regulatory authorities of a cybersecurity event within 72 hours of confirming nonpublic information was disrupted, misused, or accessed without authorization, in addition to general breach-notification requirements.observed

#

Meaningful minors-focused dark-pattern and targeted-advertising prohibitions exist, but general adtech governance (cookies, opt-out signals, clean rooms, direct marketing) is absent.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act)
Supervisory authoritySouth Carolina Attorney General
Traffic-light rationale — AmberMeaningful minors-focused dark-pattern and targeted-advertising prohibitions exist, but general adtech governance (cookies, opt-out signals, clean rooms, direct marketing) is absent.

Sub-modules (6)

Cookies And TrackersRed

No state-specific cookie-consent statute exists.

Claims (1):

  • South Carolina has no state-specific cookie-consent statute distinct from H.3431's minors-focused design provisions.

Dark PatternsAmber

H.3431 prohibits dark patterns via an expansive, indeterminate definition enforceable through the state consumer-protection statute.

Claims (2):

  • H.3431 prohibits the use of dark patterns by covered online services, adopting an expansive and indeterminate definition of the practice.
  • H.3431's private right of action for dark-pattern violations arises by reference to South Carolina's general consumer-protection statute, subject to the standard limits of that statute.

Opt Out SignalsRed

No statutory recognition of Global Privacy Control or DAA opt-out signals was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n.

Clean Rooms And DcrRed

No South Carolina statute addresses data clean rooms or data-collaboration rooms.

Claims (1):

  • No South Carolina statute addresses data clean rooms or data-collaboration rooms.

Cross Context AdvertisingAmber

H.3431 prohibits targeted advertising to minors on covered online services.

Claims (1):

  • H.3431 prohibits targeted advertising to minors on covered online services.

Direct MarketingRed

No state-specific direct-marketing consent/suppression statute beyond federal TCPA/CAN-SPAM was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, i, r, e, c, t, , m, a, r, k, e, t, i, n, g, , c, o, n, s, e, n, t, , s, u, p, p, r, e, s, s, i, o, n, , s, t, a, t, u, t, e.

Category narrative48 words

H.3431 prohibits dark patterns and targeted advertising directed at minors, with a private right of action for dark-pattern violations arising via the state's general consumer-protection statute. No general state cookie-consent law, GPC-recognition requirement, or clean-room/data-collaboration-room regime exists, and no state-specific direct-marketing consent statute beyond federal TCPA/CAN-SPAM was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedIAPP — H.3431 prohibits the use of dark patterns by covered online services, adopting an expansive and indeterminate definition of the practice.observed
  2. ConfirmedDataGuidance — H.3431 prohibits targeted advertising to minors on covered online services.observed
  3. UncertainDataGuidance — South Carolina has no state-specific cookie-consent statute distinct from H.3431's minors-focused design provisions.observed
  4. UncertainDataGuidance — No South Carolina statute addresses data clean rooms or data-collaboration rooms.observed
  5. ConfirmedIAPP — H.3431's private right of action for dark-pattern violations arises by reference to South Carolina's general consumer-protection statute, subject to the standard limits of that statute.observed

#

Substantive but narrow (minors-only) profiling restrictions exist and are under active litigation; general ADM/biometric/genetic/AI governance is absent.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act)
Supervisory authoritySouth Carolina Attorney General
Traffic-light rationale — AmberSubstantive but narrow (minors-only) profiling restrictions exist and are under active litigation; general ADM/biometric/genetic/AI governance is absent.

Sub-modules (6)

Profiling RestrictionsAmber

H.3431's core purpose is to regulate the use of surveillance data to behaviorally profile minors.

Claims (2):

  • H.3431 restricts behavioral profiling of minors through surveillance data and requires default opt-out from personalized recommendation systems for minors.
  • NetChoice, LLC filed suit seeking an injunction against South Carolina's Age-Appropriate Design Code's restrictions on behavioral profiling of minors via surveillance data; EPIC filed an amicus brief defending the law on April 13, 2026.

Automated Decision Making TransparencyRed

No general ADM-transparency or explanation-right statute exists outside H.3431's minors-specific profiling opt-outs.

Claims (1):

  • South Carolina has no general statute governing automated decision-making transparency outside of H.3431's children-specific audit and minimization requirements.

Ai Risk AssessmentsRed

No AI-specific risk-assessment statute exists; H.3431's audit requirement is the closest analogue, limited to minors' data.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , A, I, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , s, t, a, t, u, t, e.

Biometric RegimeRed

No dedicated biometric-privacy statute (e.g., facial recognition or fingerprint regulation) analogous to Illinois' BIPA exists in South Carolina.

Claims (1):

  • South Carolina has no dedicated biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act.

Genetic DataAmber

Genetic-data protection is confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code.

Claims (1):

  • South Carolina's genetic-data protections are confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code and do not extend to a general genetic-data protection regime.

State Surveillance CarveoutsRed

No South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified.

Claims (1):

  • No South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified beyond the general absence of a comprehensive privacy statute.
Category narrative61 words

H.3431 restricts behavioral profiling of minors via surveillance data and mandates default opt-outs from personalized recommendation systems; this is currently subject to a First Amendment challenge by NetChoice, LLC, with EPIC defending the law via amicus brief. No general ADM-transparency, AI-risk-assessment, biometric-privacy, or broad genetic-data statute exists; genetic data protection is confined to the insurance sector. No state-surveillance carve-out was identified.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

South Carolina's Age-Appropriate Design Code Act (Act No. 96), in force since February 5, 2026, requires covered online services' independent audit reports to include a description of the algorithms used and how covered design features are applied with respect to minors. This is the state's one enacted algorithmic-transparency instrument, and it is scoped specifically to services reasonably likely to be accessed by minors rather than operating as a general algorithmic-accountability regime. The audit-report requirement gives regulators and the public a documented account of how algorithmic design choices affecting minors are structured, though the sources reviewed this cycle do not indicate whether any audit reports have yet been filed or reviewed under the requirement.

The provision sits within the broader Act, which also mandates privacy-by-default settings and parental account-management tools and prohibits targeted advertising to minors, meaning the algorithmic-disclosure requirement functions as one component of a wider minor-protection design-code framework rather than a standalone governance instrument.

Outlook

The Act's algorithmic-disclosure requirement is subject to the same constitutional challenge affecting the rest of the statute: NetChoice's suit, with its preliminary-injunction motion fully briefed as of April 20, 2026, could suspend or narrow the requirement's enforceability depending on the court's ruling. Absent a ruling, the requirement remains formally in force and is the item to watch for any indication that covered services have begun producing the required algorithm-description audits.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance — H.3431 restricts behavioral profiling of minors through surveillance data and requires default opt-out from personalized recommendation systems for minors.observed
  2. ConfirmedDataGuidance — NetChoice, LLC filed suit seeking an injunction against South Carolina's Age-Appropriate Design Code's restrictions on behavioral profiling of minors via surveillance data; EPIC filed an amicus brief defending the law on April 13, 2026.observed
  3. ConfirmedDataGuidance — South Carolina has no general statute governing automated decision-making transparency outside of H.3431's children-specific audit and minimization requirements.observed
  4. ConfirmedDataGuidance — South Carolina has no dedicated biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act.observed
  5. ProbableSouth Carolina Legislature (summarized via DataGuidance) — South Carolina's genetic-data protections are confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code and do not extend to a general genetic-data protection regime.observed
  6. UncertainDataGuidance — No South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified beyond the general absence of a comprehensive privacy statute.observed

#

Substantively strong and very recent minors' regime, but novel, untested (active NetChoice litigation), and offers no cure period, creating material compliance and legal-durability risk.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act, 2026)
Supervisory authoritySouth Carolina Attorney General
Traffic-light rationale — AmberSubstantively strong and very recent minors' regime, but novel, untested (active NetChoice litigation), and offers no cure period, creating material compliance and legal-durability risk.

Sub-modules (5)

Age VerificationAmber

H.3431 requires commercially reasonable age-verification efforts by covered social media companies from March 1, 2026.

Claims (1):

  • H.3431 requires covered social media companies, beginning March 1, 2026, to make commercially reasonable efforts to verify the age of account holders or apply minor-protective accommodations to all account holders.

Minor Profiling BansAmber

See algorithmic_biometric_and_surveillance_governance.profiling_restrictions for the core minors' profiling-ban claims.

Claims (1):

  • A predecessor South Carolina bill (HB 4842) defined 'child' as a consumer under 18 years of age; whether H.3431 as finally enacted retains this exact definition was not independently confirmed against the final statutory text this run.

Education SettingsRed

No South Carolina education-setting-specific student-data-privacy statute was identified this run.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , e, d, u, c, a, t, i, o, n, , s, t, a, t, u, t, e.

Dependent AdultsRed

No South Carolina statute specifically protecting dependent adults' (elderly, mentally incapacitated) personal data was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, , e, l, d, e, r, l, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Category narrative64 words

South Carolina's most developed data-protection regime is minors-focused: H.3431 (effective Feb. 5, 2026, with an additional social-media age-verification duty from March 1, 2026) requires age assurance, restricts minors' account creation absent parental consent, mandates default protective design settings, and prohibits targeted advertising and dark patterns aimed at minors. COPPA applies federally to under-13s alongside this state regime. No education-setting-specific or dependent-adult-specific statute was identified.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

South Carolina's Age-Appropriate Design Code Act (Act No. 96) was signed by Governor McMaster on February 5, 2026 and took effect immediately, making it the state's central instrument in this module. The Act requires privacy-by-default settings and parental account-management tools for covered online services reasonably likely to be accessed by minors, and it prohibits covered online services from facilitating targeted advertising to minors. Enforcement rests with the Attorney General, who may pursue treble financial damages, with no statutory right to cure and potential personal liability for officers and employees of covered services — a comparatively aggressive enforcement structure relative to notice-and-cure regimes used in some other states' children's-privacy statutes.

The Act is now the subject of a live federal constitutional challenge. NetChoice filed suit in the US District Court for the District of South Carolina (No. 3:26-cv-543-SAL) on February 9, 2026, four days after the Act took effect, raising First and Fourteenth Amendment claims, a COPPA-preemption argument, and a vagueness challenge. The preliminary-injunction motion was fully briefed as of April 20, 2026, with no ruling identified in the sources reviewed this cycle. The Act therefore remains formally in force while its ultimate enforceability is contested in active litigation.

Outlook

The ruling on NetChoice's preliminary-injunction motion is the single most consequential near-term development for this module. A ruling could come at any point following the April 20, 2026 full briefing; an injunction would suspend enforcement pending final resolution of the constitutional claims, while a denial would leave the Act's treble-damages, no-cure regime fully operative against covered services.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedDataGuidance — H.3431 requires covered social media companies, beginning March 1, 2026, to make commercially reasonable efforts to verify the age of account holders or apply minor-protective accommodations to all account holders.observed
  2. ProbableDataGuidance — H.3431 conditions minors' social media account holding on parental consent obtained by the platform.observed
  3. UncertainDataGuidance — A predecessor South Carolina bill (HB 4842) defined 'child' as a consumer under 18 years of age; whether H.3431 as finally enacted retains this exact definition was not independently confirmed against the final statutory text this run.observed
  4. ConfirmedIAPP — H.3431 requires default protective settings for minors on design features including usage timers, spending caps, blocking interactions from non-connected accounts, hiding engagement metrics, disabling search-engine indexing, and restricting geolocation visibility, while extending baseline access to these tools to all users.observed
  5. ProbableDataGuidance — COPPA applies nationally, including South Carolina, to operators collecting personal information from children under 13, operating alongside the state's own minors-focused design-code law.observed

#

Clear AG enforcement powers and a narrow private right of action exist for the new minors' law, but general privacy enforcement capacity and redress mechanisms remain largely undeveloped, and the flagship 2026 law faces active constitutional litigation.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act)
Traffic-light rationale — AmberClear AG enforcement powers and a narrow private right of action exist for the new minors' law, but general privacy enforcement capacity and redress mechanisms remain largely undeveloped, and the flagship 2026 law faces active constitutional litigation.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG enforces H.3431 with severe penalties for violations.

Claims (1):

  • The South Carolina Attorney General is empowered to enforce H.3431, with the statute providing for severe penalties for violations.

Enforcement Activity IndexAmber

The AG's office recently joined a multistate $80 million BSA/AML settlement with Block, Inc./Cash App, illustrating active AG enforcement capacity, though not privacy-specific.

Claims (1):

  • The South Carolina Attorney General's office joined a multistate $80 million enforcement settlement against Block, Inc. (Cash App) for Bank Secrecy Act/anti-money-laundering violations, reflecting active state AG involvement in financial-data-adjacent enforcement, though the action arose under BSA/AML rather than data-protection statutes.

Regulator Funding And CapacityAmber

The AG's office comprises over 200 employees and nearly 75 attorneys managing thousands of case files, but no privacy-specific unit or headcount figure was identified.

Claims (1):

  • The South Carolina Attorney General's Office comprises more than 200 employees and nearly 75 attorneys managing thousands of active case files, though no privacy-specific unit or headcount was identified.

Collective Redress And Class ActionsRed

General South Carolina class-action procedure applies but no privacy-specific collective-redress mechanism was identified.

Absence provenance: unavailable. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , c, l, a, s, s, , a, c, t, i, o, n, , d, a, t, a, , p, r, i, v, a, c, y, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s.

Private Right Of ActionAmber

A private right of action exists only for H.3431 dark-pattern violations via the state consumer-protection statute; no general privacy private right of action exists.

Claims (2):

  • H.3431's dark-patterns provisions carry a private right of action by reference to South Carolina's general consumer-protection statute.
  • Beyond H.3431's reference to the state's consumer-protection statute for dark-pattern violations, South Carolina does not provide a general private right of action for other data-privacy harms.

Recent Developments 180DAmber

The dominant recent development is the NetChoice v. South Carolina litigation over H.3431, with EPIC's April 13, 2026 amicus brief defending the law, which remains in force pending resolution.

Claims (1):

  • NetChoice, LLC filed suit against South Carolina seeking to enjoin enforcement of H.3431; EPIC filed an amicus brief defending the law on April 13, 2026, and the law remains in effect pending the litigation's outcome.
Category narrative88 words

The South Carolina Attorney General enforces H.3431 with severe statutory penalties and, for dark-pattern violations, a private right of action via the state's general consumer-protection statute. NetChoice has sued to enjoin the law's enforcement, with EPIC defending it; the law remains in force pending that litigation. The AG's office also participates in multistate financial-sector enforcement (e.g., the Block/Cash App BSA/AML settlement), though this arises under AML rather than data-protection statutes. No general private right of action for broader data-privacy harms, and no dedicated privacy-enforcement funding/headcount data, were identified.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Age-Appropriate Design Code Act (Act No. 96), in force since February 5, 2026, is enforceable exclusively by the South Carolina Attorney General, who may seek treble financial damages for violations. The Act contains no statutory right to cure, meaning covered services cannot avoid liability by remedying a violation after the fact, and it permits personal liability for officers and employees of covered services, extending exposure beyond the corporate entity itself. This is a materially more aggressive enforcement structure than the notice-and-cure models used in several other states' comparable statutes.

By contrast, the pending Technology Transparency Act (H.3401) explicitly provides that its chapter does not establish a private cause of action, channeling enforcement solely to the Attorney General's Office. Taken together, the enacted Age-Appropriate Design Code Act and the pending Technology Transparency Act both concentrate enforcement authority in the Attorney General rather than creating a private right of action for affected consumers, a consistent structural choice across South Carolina's privacy-adjacent legislation this cycle.

The Age-Appropriate Design Code Act's enforcement powers are presently contested in NetChoice v. Wilson, filed February 9, 2026 in the US District Court for the District of South Carolina, with a preliminary-injunction motion fully briefed as of April 20, 2026 and no ruling identified in sources reviewed this cycle. Should the court enjoin enforcement, the Attorney General's treble-damages authority under the Act would be suspended pending the litigation's resolution.

Outlook

The NetChoice v. Wilson ruling is the determinative development for this module's enforcement posture. Separately, whether the pending Technology Transparency Act advances would extend the Attorney-General-only enforcement pattern to a broader lawful-processing and consent framework, though that bill remains pending with no enactment identified this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance — The South Carolina Attorney General is empowered to enforce H.3431, with the statute providing for severe penalties for violations.observed
  2. ConfirmedIAPP — H.3431's dark-patterns provisions carry a private right of action by reference to South Carolina's general consumer-protection statute.observed
  3. ConfirmedDataGuidance — NetChoice, LLC filed suit against South Carolina seeking to enjoin enforcement of H.3431; EPIC filed an amicus brief defending the law on April 13, 2026, and the law remains in effect pending the litigation's outcome.observed
  4. ConfirmedSouth Carolina Attorney General's Office (via NAAG) — The South Carolina Attorney General's office joined a multistate $80 million enforcement settlement against Block, Inc. (Cash App) for Bank Secrecy Act/anti-money-laundering violations, reflecting active state AG involvement in financial-data-adjacent enforcement, though the action arose under BSA/AML rather than data-protection statutes.observed
  5. ProbableDataGuidance — Beyond H.3431's reference to the state's consumer-protection statute for dark-pattern violations, South Carolina does not provide a general private right of action for other data-privacy harms.observed
  6. ConfirmedNAAG — The South Carolina Attorney General's Office comprises more than 200 employees and nearly 75 attorneys managing thousands of active case files, though no privacy-specific unit or headcount was identified.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct15.38
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for South Carolina, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 24 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (insurance security/breach), sectoral_watch (insurance), adtech/children/algorithmic modules (H.3431) are grounded in T1 statutory anchors (S.C. Code §39-1-90, §38-99-10 et seq., §38-93, H.3431) corroborated by T2 secondary reporting (DataGuidance, IAPP). lawful_processing_and_special_data, data_subject_rights, and cross_border_and_adequacy rely primarily on T2/T3 absence-confirmation sourcing (DataGuidance jurisdiction overview, IAPP breach chart) since no comprehensive statute exists to anchor T1 findings. Federal sectoral overlays (HIPAA, GLBA, COPPA) are asserted at Probable confidence based on general federal-law knowledge rather than a fresh statutory-text search this run.

Unresolved questions (5):

  • Whether House Bill 4696 (comprehensive consumer privacy bill) remains pending, has died, or has been reintroduced in the current South Carolina legislative session.
  • The exact statutory definition of 'minor'/'child' under H.3431 as finally enacted, versus the under-18 definition found in predecessor bill HB 4842.
  • Current procedural status of NetChoice, LLC v. South Carolina (challenging H.3431) since the EPIC amicus filing of April 13, 2026, including whether a preliminary injunction has been granted or denied.
  • Full primary-source verification of S.C. Code §39-1-90's definitions and thresholds directly against the South Carolina Code of Laws (scstatehouse.gov), rather than via secondary summarization.
  • Whether SC Department of Insurance has issued implementing regulations under the Insurance Data Security Act beyond the 2019 cybersecurity rules.

Escalate to primary-source review: yes