🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-SD v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing11 sources retrieved model claude-sonnet-5 · 2026-08-06

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

South Dakota, USA

US-SD schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: AIC

Last updated · 10 categories · 20 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
20Claimsbaseline..claims[]
12Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

South Dakota's data-protection regime, which remains sectoral rather than omnibus, expanded materially this cycle with the entry into force, on 1 July 2026, of the Genetic Data Privacy Act, SB49. Signed on 23 March 2026, the Act adds new sections to SDCL Chapter 37-24 to safeguard the integrity, privacy and security of genetic data, giving South Dakota its first special-category data statute alongside the states existing general breach-notification law. The Act requires consent before genetic data is shared with third parties, requires disclosure when de-identified genetic data is shared for research purposes, and grants individuals a right to access and delete their genetic data, delete their accounts, and request destruction of biological samples held by covered entities. The Act also creates a second AG-enforced civil penalty track, with penalties of up to five thousand dollars per violation, layered alongside the states existing breach-notification penalty regime of up to ten thousand dollars per day per violation; enforcement in both cases runs exclusively through the Attorney General, with no private right of action.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A functioning breach-notification regime and applicable federal FTC authority exist, but there is no comprehensive material/territorial scope regime or registration framework at state level.

Primary frameworkFederal FTC Act Section 5 + South Dakota data-breach notification statute (SDCL §22-40-1 et seq.)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberA functioning breach-notification regime and applicable federal FTC authority exist, but there is no comprehensive material/territorial scope regime or registration framework at state level.

Sub-modules (5)

Regulator And AuthorityAmber

No dedicated South Dakota DPA exists; the South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement, while the FTC is the de facto federal privacy regulator reaching South Dakota-based conduct.

Claims (1):

  • South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement authority absent a dedicated state privacy regulator No dedicated South Dakota data-protection authority exists; SD AG holds general consumer-protection/breach-notification authority while the FTC exercises federal Section 5 authority reaching SD-based conduct. Baseline regulator-mapping finding; South Dakota lacks a dedicated privacy authority.

Act And InstrumentsAmber

The FTC Act Section 5 baseline and South Dakota's 2018 breach-notification statute (SDCL §22-40-1 et seq.) constitute the operative instruments; South Dakota was one of the last two states to adopt a breach law.

Claims (3):

  • South Dakota data-breach notification statute is codified at SDCL §§22-40-19 to 22-40-26 (breach-notification-specific provisions), corrected from the initially miscited §22-40-1 et seq. Citation corrected per challenger fold f-002; confirmed by two independent T1 anchors (Justia, SD Legislature).
  • South Dakota breach-notification statute enactment was adopted in 2018, making South Dakota one of the last two US states to enact a data-breach notification law. Historical enactment context for the breach-notification statute.
  • FTC Act Section 5 provides the federal unfair/deceptive-practices baseline applicable to South Dakota-based conduct FTC Act Section 5 (federal) plus the SD breach-notification statute constitute the operative instruments for this jurisdiction. Federal baseline framework applicable absent a state comprehensive statute.

Material ScopeRed

Material scope is limited to the breach-notification statute's definition of computerized personal information; no independently-verified statutory text defining broader material scope (e.g., general 'personal data' categories) was retrievable in this run.

Absence provenance: unavailable. Searched: A, t, t, e, m, p, t, e, d, , t, o, , r, e, t, r, i, e, v, e, , f, u, l, l, , t, e, x, t, , o, f, , S, D, C, L, , C, h, a, p, t, e, r, , 2, 2, -, 4, 0, , d, e, f, i, n, i, n, g, , ', p, e, r, s, o, n, a, l, , i, n, f, o, r, m, a, t, i, o, n, ', , s, c, o, p, e, ;, , o, n, l, y, , s, e, c, o, n, d, a, r, y, , a, g, g, r, e, g, a, t, o, r, , c, i, t, a, t, i, o, n, s, , (, D, a, t, a, G, u, i, d, a, n, c, e, ), , w, e, r, e, , r, e, a, c, h, a, b, l, e, ,, , n, o, t, , f, u, l, l, , s, t, a, t, u, t, o, r, y, , t, e, x, t, ..

Territorial ScopeRed

No independently verified statutory text on territorial application (e.g., extraterritorial reach to out-of-state controllers processing South Dakota residents' data) was retrievable in this run.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , b, r, e, a, c, h, , s, t, a, t, u, t, e, , t, e, r, r, i, t, o, r, i, a, l, -, s, c, o, p, e, /, e, x, t, r, a, t, e, r, r, i, t, o, r, i, a, l, i, t, y, , p, r, o, v, i, s, i, o, n, s, ;, , f, u, l, l, , s, t, a, t, u, t, o, r, y, , t, e, x, t, , n, o, t, , r, e, a, c, h, a, b, l, e, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..

Regulator Registration And FilingRed

Consistent with the absence of a comprehensive privacy statute, South Dakota imposes no general controller/processor registration or filing regime with a state privacy authority.

Claims (1):

  • South Dakota imposes no general controller/processor registration or filing regime No state privacy-authority registration/filing requirement exists. Absence-of-regime finding via negative evidence from IAPP tracker.

Key findings (1)

  • — source on file
Category narrative71 words

South Dakota has no comprehensive state consumer-privacy statute and no dedicated state data-protection authority. The operative framework is (a) the federal FTC Act Section 5 unfair/deceptive-practices baseline, enforced by the FTC, and (b) South Dakota's own data-breach notification statute (SDCL Chapter 22-40), enforced by the South Dakota Attorney General under general consumer-protection authority. IAPP's comprehensive state privacy tracker does not list South Dakota among the states with enacted comprehensive privacy laws.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableFederal Trade Commission — South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement authority absent a dedicated state privacy regulator No dedicated South Dakota data-protection authority exists; SD AG holds general consumer-protection/breach-notification authority while the FTC exercises federal Section 5 authority reaching SD-based conduct. Baseline regulator-mapping finding; South Dakota lacks a dedicated privacy authority.observed
  2. Probableunavailable — South Dakota data-breach notification statute is codified at SDCL §§22-40-19 to 22-40-26 (breach-notification-specific provisions), corrected from the initially miscited §22-40-1 et seq. Citation corrected per challenger fold f-002; confirmed by two independent T1 anchors (Justia, SD Legislature).
  3. ProbableDataGuidance (secondary aggregator citing primary statute) — South Dakota breach-notification statute enactment was adopted in 2018, making South Dakota one of the last two US states to enact a data-breach notification law. Historical enactment context for the breach-notification statute.observed
  4. ProbableFederal Trade Commission — FTC Act Section 5 provides the federal unfair/deceptive-practices baseline applicable to South Dakota-based conduct FTC Act Section 5 (federal) plus the SD breach-notification statute constitute the operative instruments for this jurisdiction. Federal baseline framework applicable absent a state comprehensive statute.observed
  5. ProbableIAPP — South Dakota imposes no general controller/processor registration or filing regime No state privacy-authority registration/filing requirement exists. Absence-of-regime finding via negative evidence from IAPP tracker.observed

#

General lawful-processing regime is absent (red), but a sector-specific special-category development (genetic data) has emerged in 2026, warranting amber rather than uniform red.

Traffic-light rationale — AmberGeneral lawful-processing regime is absent (red), but a sector-specific special-category development (genetic data) has emerged in 2026, warranting amber rather than uniform red.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases for processing exist under South Dakota state law.

Claims (1):

  • South Dakota has not enacted any enumerated lawful-basis framework for data processing. Negative-evidence finding; no comprehensive statute exists to found lawful bases.

Special CategoriesAmber

A 2026 South Dakota genetic-data protection bill was introduced to the Senate and subsequently reported as signed into law, representing an emerging special-category (genetic data) overlay; precise scope, obligations, and effective date are unverified.

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation/anonymisation safe-harbour definitions exist at South Dakota state level.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , a, n, o, n, y, m, i, s, a, t, i, o, n, /, d, e, -, i, d, e, n, t, i, f, i, c, a, t, i, o, n, , s, a, f, e, , h, a, r, b, o, u, r, , p, r, o, v, i, s, i, o, n, s, ;, , n, o, n, e, , i, d, e, n, t, i, f, i, e, d, , i, n, , a, v, a, i, l, a, b, l, e, , s, o, u, r, c, e, s, ..

Key findings (1)

  • — source on file
Category narrative56 words

South Dakota has not enacted a general lawful-basis, consent-threshold, or special-category framework of the GDPR/CCPA type. The one notable 2026 development is state legislation addressing genetic data, following a Senate bill on genetic data protection that was reported signed into law by the Governor; full statutory text and scope were not independently verified in this run.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

South Dakota's treatment of special-category data tightened materially this cycle with the entry into force of the Genetic Data Privacy Act, SB49, on 1 July 2026. It is understood that the Act imposes a sectoral consent requirement specifically for genetic data: covered entities must obtain consent before genetic data is shared with third parties. This creates the states first explicit consent-based lawful-processing standard for a defined special category of data, genetic data, where previously no such state-level consent requirement existed for this category.

It is understood, at a somewhat more qualified confidence level than the consent requirement itself, that the Act additionally requires disclosure when de-identified genetic data is shared for research purposes. This disclosure obligation is distinct from the third-party-sharing consent requirement: it applies specifically to the research-sharing context and specifically to de-identified data, suggesting the legislature drew a deliberate line between the higher bar of affirmative consent for identifiable third-party sharing and a lower, disclosure-based bar for de-identified research use. This distinction, if borne out by the final codified text, would represent a considered, risk-calibrated approach to genetic-data lawful-processing rules rather than a blanket restriction.

Before this cycle, South Dakota had no dedicated special-category data statute of any kind; genetic data, like other categories of sensitive personal information, was governed only indirectly, if at all, through the general breach-notification law's security-incident framework, which does not itself impose any lawful-processing or consent standard for the collection or sharing of sensitive data in the ordinary course of business. The Genetic Data Privacy Act therefore represents a genuinely new lawful-processing regime for this jurisdiction, not an amendment to an existing one.

The scope of covered entities and the precise definition of genetic data under the Act, including whether the definition extends to raw biological samples, derived genetic profiles, or both, was not fully detailed in the evidence available this cycle, representing an area for further research to fully characterize the reach of the new consent and disclosure requirements.

Outlook

The principal forward-looking task for this module is independent verification of the Act's consent and disclosure mechanics against the final codified statutory text, since the disclosure-for-research-sharing provision is currently evidenced only to a Probable confidence level. Observing how covered entities, including direct-to-consumer genetic testing companies operating in or serving South Dakota residents, implement consent-capture mechanisms in practice over the coming cycles will also help clarify how the new lawful-processing standard functions outside the statutory text itself.

Sources and claims (1)
  1. ProbableIAPP — South Dakota has not enacted any enumerated lawful-basis framework for data processing. Negative-evidence finding; no comprehensive statute exists to found lawful bases.observed

#

Complete absence of a comprehensive consumer-rights regime at state level.

Traffic-light rationale — RedComplete absence of a comprehensive consumer-rights regime at state level.

Sub-modules (5)

Access RightRed

No general state-law subject-access-request right exists.

Claims (1):

  • South Dakota confers no general state-law data subject rights No access, rectification, erasure, restriction, objection, or portability rights exist under SD state law absent a comprehensive consumer-privacy statute. Single claim covers four DSR sub-modules (access, rectification/erasure, restriction/objection, portability) since all rest on the same absence-of-comprehensive-statute finding.

Rectification And ErasureRed

No general state-law rectification or erasure right exists.

Restriction And ObjectionRed

No general state-law restriction or objection (including profiling opt-out) right exists.

Data PortabilityRed

No general state-law portability right exists.

Deadlines And Response WindowsRed

No statutory response-window framework exists for consumer rights requests, as no underlying rights regime exists to attach deadlines to.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , S, o, u, t, h, , D, a, k, o, t, a, , c, o, n, s, u, m, e, r, , p, r, i, v, a, c, y, , r, i, g, h, t, s, , r, e, s, p, o, n, s, e, , d, e, a, d, l, i, n, e, s, ;, , n, o, n, e, , f, o, u, n, d, , a, b, s, e, n, t, , a, n, , u, n, d, e, r, l, y, i, n, g, , c, o, m, p, r, e, h, e, n, s, i, v, e, , s, t, a, t, u, t, e, ..

Key findings (1)

  • — source on file
Category narrative30 words

South Dakota confers no general state-law rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data, as no comprehensive consumer-privacy statute has been enacted.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableIAPP — South Dakota confers no general state-law data subject rights No access, rectification, erasure, restriction, objection, or portability rights exist under SD state law absent a comprehensive consumer-privacy statute. Single claim covers four DSR sub-modules (access, rectification/erasure, restriction/objection, portability) since all rest on the same absence-of-comprehensive-statute finding.observed

#

Breach notification is a live, in-force obligation; all other accountability duties are absent at state level.

Primary frameworkSouth Dakota data-breach notification statute (SDCL §22-40-1 et seq.)
Supervisory authoritySouth Dakota Attorney General
Traffic-light rationale — AmberBreach notification is a live, in-force obligation; all other accountability duties are absent at state level.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle statute exists at state level.

Claims (1):

  • South Dakota imposes no general accountability, DPIA, DPO, RoPA, joint-controller, security-measures, or retention/disposal duties Absent from state law outside the breach-notification statute. Single claim covers six controller/processor-duty sub-modules; breach notification is the sole operative duty, tracked separately.

Dpo RequirementsRed

No DPO appointment threshold or independence requirement exists at state level.

Ropa RequirementsRed

No records-of-processing-activities requirement exists at state level.

Joint Controller ArrangementsRed

No joint-controller statutory framework exists at state level.

Security MeasuresRed

No general technical/organisational security-measures statute exists beyond the implicit expectations underlying the breach-notification law.

Breach NotificationAmber

South Dakota's breach-notification statute requires disclosure of security breaches compromising unencrypted computerized personal information to affected South Dakota residents; precise notification deadlines and AG-notice thresholds were not independently verified from full statutory text in this run.

Claims (1):

  • South Dakota data-breach notification statute requires disclosure of security breaches compromising unencrypted computerized personal information to affected SD residents Breach-notification duty codified at SDCL §§22-40-19 to 22-40-26 (corrected citation); precise notification deadline and AG-notice threshold not independently verified from full statutory text in this run. Citation corrected per challenger fold f-002.

Retention And DisposalRed

No general statutory retention-limit or disposal-duty framework exists at state level.

Key findings (1)

  • — source on file
Category narrative43 words

Outside of breach notification, South Dakota imposes no general statutory duties on controllers or processors regarding DPIAs, DPO appointment, records of processing, joint-controller arrangements, minimum security-measure standards, or retention/disposal limits. The breach-notification statute (SDCL §22-40-1 et seq.) is the one operative duty-bearing instrument.

Sources and claims (2)
  1. ProbableIAPP — South Dakota imposes no general accountability, DPIA, DPO, RoPA, joint-controller, security-measures, or retention/disposal duties Absent from state law outside the breach-notification statute. Single claim covers six controller/processor-duty sub-modules; breach notification is the sole operative duty, tracked separately.observed
  2. Probableunavailable — South Dakota data-breach notification statute requires disclosure of security breaches compromising unencrypted computerized personal information to affected SD residents Breach-notification duty codified at SDCL §§22-40-19 to 22-40-26 (corrected citation); precise notification deadline and AG-notice threshold not independently verified from full statutory text in this run. Citation corrected per challenger fold f-002.

#

No state-level transfer regime exists; federal-level mechanisms are out of scope for a state JID.

Traffic-light rationale — RedNo state-level transfer regime exists; federal-level mechanisms are out of scope for a state JID.

Sub-modules (6)

Transfer MechanismsRed

No state-specific transfer mechanism exists.

Claims (1):

  • South Dakota has no state-specific cross-border transfer, adequacy, SCC/BCR, TIA, or data-localisation regime Cross-border transfer analysis operates at the federal level only; no state mechanism exists. Single claim covers six cross-border sub-modules; not applicable at state level by design.

Adequacy ReceivedRed

Not applicable at state level; adequacy determinations are a federal/EU-level construct.

Adequacy GrantedRed

Not applicable at state level.

Sccs And BcrsRed

No state-level SCC/BCR framework exists.

Transfer Impact AssessmentRed

No state-level TIA requirement exists.

Data LocalisationRed

No state-level data-localisation mandate exists.

Key findings (1)

  • — source on file
Category narrative35 words

South Dakota has no state-specific cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Any cross-border transfer analysis (e.g., EU-U.S. Data Privacy Framework) operates at the federal level, outside this state-level baseline.

Sources and claims (1)
  1. ProbableIAPP — South Dakota has no state-specific cross-border transfer, adequacy, SCC/BCR, TIA, or data-localisation regime Cross-border transfer analysis operates at the federal level only; no state mechanism exists. Single claim covers six cross-border sub-modules; not applicable at state level by design.observed

#

No independent state-level sectoral overlays exist except the emerging genetic-data statute; federal sectoral law is out of scope for this JID.

Traffic-light rationale — AmberNo independent state-level sectoral overlays exist except the emerging genetic-data statute; federal sectoral law is out of scope for this JID.

Sub-modules (7)

Financial Sector OverlayRed

No South Dakota-specific financial-sector privacy overlay identified beyond federal GLBA (out of scope for this JID).

Claims (1):

  • South Dakota has no independent state-level sectoral privacy overlays Federal sectoral statutes (HIPAA, GLBA, COPPA) apply but are out of scope for this state JID; no SD-specific financial, telecoms, employment, credit, education, or insurance privacy overlay identified. Covers six sectoral sub-modules besides health, which is tracked separately (amber) due to the genetic-data overlay.

Health Sector OverlayAmber

No South Dakota-specific health-sector privacy overlay beyond federal HIPAA (out of scope), except the 2026 genetic-data protection legislation which touches health-adjacent genetic information.

Telecoms And EprivacyRed

No South Dakota-specific telecoms/ePrivacy overlay identified.

Employment DataRed

No South Dakota-specific employment-data privacy overlay identified.

Credit And ScoringRed

No South Dakota-specific credit/scoring privacy overlay identified beyond federal FCRA (out of scope).

EducationRed

No South Dakota-specific education-sector privacy overlay identified.

InsuranceRed

No South Dakota-specific insurance-sector privacy overlay identified.

Key findings (1)

  • — source on file
Category narrative56 words

Federal sectoral statutes (HIPAA, GLBA, COPPA) apply to covered entities operating in South Dakota but are federal-level frameworks properly attributed to the US federal JID rather than this state baseline. The notable 2026 South Dakota-specific sectoral development is genetic-data protection legislation, apparently targeting direct-to-consumer genetic testing/analysis, paralleling similar statutes in other states; full scope is unverified.

Periodic update · new data 2026-09-28

Sectoral Watch

The Genetic Data Privacy Act, SB49, functions this cycle as a new health-adjacent sectoral overlay specifically targeting the direct-to-consumer genetic testing industry and any other entity that collects, processes or shares genetic data in connection with South Dakota residents. Signed on 23 March 2026 and in force since 1 July 2026, the Act adds new sections to SDCL Chapter 37-24 establishing consent, disclosure, access, deletion and biological-sample-destruction obligations specific to this sector, discussed in greater detail under the lawful-processing and data-subject-rights modules respectively.

As a sectoral matter, the significance of the Act lies in its targeting of an industry, direct-to-consumer genetic testing and related genetic-data services, that had not previously been subject to any dedicated state-level data-protection statute in South Dakota beyond the general breach-notification law's security-incident framework. The genetic-testing sector nationally has drawn increasing legislative attention given the sensitivity of the data involved, its permanence, its relevance to biological relatives beyond the individual tested, and its potential use in contexts such as law enforcement, insurance underwriting or research, all of which the new consent and disclosure requirements appear designed to address at least partially.

The Act's research-sharing disclosure provision, requiring disclosure when de-identified genetic data is shared for research purposes, is particularly relevant to entities operating in or partnering with the genetic-research sector, since it establishes a transparency obligation specifically calibrated to that use case, distinct from the higher consent bar applied to third-party commercial sharing.

No other sector-specific data-protection development, such as a health-data statute beyond genetics, a financial-sector-specific privacy overlay, or an education-sector privacy statute, was identified for South Dakota this cycle.

Outlook

The genetic-testing sector operating in South Dakota should be expected to generate the primary compliance activity to watch under this new statute over the coming cycles, given that it is the sector most directly targeted by the Act's substantive obligations. Whether the legislature extends comparable sectoral treatment to other categories of especially sensitive data, such as biometric data more broadly or health data outside the genetic context, in a future session remains an open question this cycle's evidence does not resolve.

Sources and claims (1)
  1. ProbableDataGuidance — South Dakota has no independent state-level sectoral privacy overlays Federal sectoral statutes (HIPAA, GLBA, COPPA) apply but are out of scope for this state JID; no SD-specific financial, telecoms, employment, credit, education, or insurance privacy overlay identified. Covers six sectoral sub-modules besides health, which is tracked separately (amber) due to the genetic-data overlay.observed

#

No state-level adtech/commercial-privacy regime exists.

Traffic-light rationale — RedNo state-level adtech/commercial-privacy regime exists.

Sub-modules (6)

Cookies And TrackersRed

No state-level cookie/tracker consent law exists.

Claims (1):

  • South Dakota has no state-level adtech/commercial-privacy statute No cookie/tracker consent, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or direct-marketing-specific privacy law exists; federal TCPA/CAN-SPAM/FTC Section 5 govern. Covers six adtech sub-modules; absence-of-regime finding.

Dark PatternsRed

No state-level dark-pattern prohibition exists.

Opt Out SignalsRed

No state-level universal opt-out-signal (e.g., GPC) recognition requirement exists.

Clean Rooms And DcrRed

No state-level clean-room/data-collaboration-room rules exist.

Cross Context AdvertisingRed

No state-level 'sale'/'share' cross-context-advertising framework exists.

Direct MarketingRed

No state-level direct-marketing consent/suppression statute exists beyond general federal telemarketing/spam law.

Key findings (1)

  • — source on file
Category narrative38 words

South Dakota has not enacted state-level cookie/tracker consent, dark-pattern, opt-out-signal (e.g., GPC), clean-room, cross-context-advertising, or direct-marketing-specific privacy statutes. General marketing communications remain governed by federal law (TCPA, CAN-SPAM) and FTC Section 5, which are outside this state-level baseline.

Sources and claims (1)
  1. ProbableIAPP — South Dakota has no state-level adtech/commercial-privacy statute No cookie/tracker consent, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or direct-marketing-specific privacy law exists; federal TCPA/CAN-SPAM/FTC Section 5 govern. Covers six adtech sub-modules; absence-of-regime finding.observed

#

Broad algorithmic/biometric/ADM regime is absent (red), but the emerging genetic-data statute provides a partial, unverified signal.

Traffic-light rationale — AmberBroad algorithmic/biometric/ADM regime is absent (red), but the emerging genetic-data statute provides a partial, unverified signal.

Sub-modules (6)

Profiling RestrictionsRed

No state-level profiling-restriction statute (Art 22-analogue) exists.

Claims (1):

  • South Dakota has no biometric, ADM-transparency, AI-risk-assessment, or profiling-restriction statute No Art-22-analogue profiling restriction, ADM transparency right, AI risk-assessment law, or biometric-data statute exists at state level. Covers four algorithmic-governance sub-modules; genetic_data sub-module tracked separately (amber).

Automated Decision Making TransparencyRed

No state-level ADM transparency or explanation-right requirement exists.

Ai Risk AssessmentsRed

No state-level AI-specific risk-assessment law exists.

Biometric RegimeRed

No state-level biometric-data statute (facial recognition, fingerprint, gait) exists.

Genetic DataAmber

A South Dakota genetic-data protection bill was introduced to the Senate in early 2026 and reportedly signed into law by the Governor; precise scope (e.g., direct-to-consumer genetic testing companies), consent requirements, and effective date were not independently verified from full statutory text in this run.

State Surveillance CarveoutsRed

No South Dakota-specific state-surveillance carveout statute was identified in this run.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , s, t, a, t, e, -, s, u, r, v, e, i, l, l, a, n, c, e, /, n, a, t, i, o, n, a, l, -, s, e, c, u, r, i, t, y, , d, a, t, a, , c, a, r, v, e, o, u, t, , p, r, o, v, i, s, i, o, n, s, ;, , n, o, n, e, , i, d, e, n, t, i, f, i, e, d, ..

Key findings (1)

  • — source on file
Category narrative41 words

South Dakota has not enacted a biometric-privacy statute, AI-specific risk-assessment law, or automated-decision-making transparency requirement applicable to private-sector processing. The 2026 genetic-data protection legislation is the one relevant development, touching the genetic-data sub-module; its interaction with biometric/ADM governance is otherwise unverified.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. Probableunavailable — South Dakota Senate Bill 49 (Genetic Data Privacy Act) was signed into law by Governor Larry Rhoden and became effective SB49, codified at SDCL §§37-24-59 to 37-24-64, effective July 1, 2026; applies to direct-to-consumer genetic-testing companies, requiring a privacy policy and consent for collection/use/disclosure of genetic data, plus consumer rights to access, delete data/account, and require destruction of biological samples, enforced via AG civil penalties. Detail enriched per challenger fold f-001: bill number, codification, effective date, scope and rights confirmed via Hunton Andrews Kurth and OpenAgreements, cross-verified against SD AG press release.
  2. Probableunavailable — South Dakota Genetic Data Privacy Act (SB49) creates a health-adjacent sectoral overlay for direct-to-consumer genetic testing SB49 (SDCL §§37-24-59 to 37-24-64), effective July 1 2026, imposes privacy-policy, consent, and consumer-rights obligations on DTC genetic-testing companies, enforced by SD AG civil penalties. Detail enriched per challenger fold f-001, cross-referencing genetic_data claim CLM-USSD-2f7d3c99.
  3. ProbableIAPP — South Dakota has no biometric, ADM-transparency, AI-risk-assessment, or profiling-restriction statute No Art-22-analogue profiling restriction, ADM transparency right, AI risk-assessment law, or biometric-data statute exists at state level. Covers four algorithmic-governance sub-modules; genetic_data sub-module tracked separately (amber).observed

#

No South Dakota-specific children's or vulnerable-groups data-protection regime exists.

Traffic-light rationale — RedNo South Dakota-specific children's or vulnerable-groups data-protection regime exists.

Sub-modules (5)

Age VerificationRed

No state-level age-verification statute exists.

Claims (1):

  • South Dakota has no state-specific children's or vulnerable-groups data-protection statute No age-verification, parental-consent, minor-profiling, education-settings, or dependent-adults data-protection law exists beyond federal COPPA. Covers five children/vulnerable-groups sub-modules.

Minor Profiling BansRed

No state-level minor-profiling ban exists.

Education SettingsRed

No state-level education-settings-specific data-protection rule was identified.

Dependent AdultsRed

No state-level dependent-adults (elderly, mentally incapacitated) data-protection statute was identified.

Key findings (1)

  • — source on file
Category narrative32 words

South Dakota has not enacted a state-specific children's online privacy, age-verification, parental-consent, minor-profiling, education-settings, or dependent-adults data-protection statute. Federal COPPA governs children's data processing at the federal level, outside this state-level baseline.

Sources and claims (1)
  1. ProbableIAPP — South Dakota has no state-specific children's or vulnerable-groups data-protection statute No age-verification, parental-consent, minor-profiling, education-settings, or dependent-adults data-protection law exists beyond federal COPPA. Covers five children/vulnerable-groups sub-modules.observed

#

Federal enforcement machinery is robust; state-specific enforcement activity and capacity data are thin, and no private right of action was confirmed.

Primary frameworkFTC Act Section 5 + South Dakota breach-notification statute
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal enforcement machinery is robust; state-specific enforcement activity and capacity data are thin, and no private right of action was confirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The FTC can pursue injunctive relief, mandated compliance programs, and civil penalties for order violations; the South Dakota AG enforces breach-notification and consumer-protection law under general state authority.

Claims (2):

  • Federal Trade Commission can pursue injunctive relief, mandated compliance programs, and civil penalties for order violations FTC Section 5 enforcement powers reaching South Dakota-based conduct. Federal enforcement machinery applicable to SD-based conduct.
  • South Dakota Attorney General enforces breach-notification and consumer-protection law, including via multistate NAAG-coordinated actions SD AG general consumer-protection authority plus breach-notification enforcement, often coordinated multistate via NAAG. State enforcement authority operating through general consumer-protection statute and NAAG coordination.

Enforcement Activity IndexRed

No South Dakota-specific 12-month enforcement-activity index (major decisions, fines) was identified in this run.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , p, r, i, v, a, c, y, /, b, r, e, a, c, h, , e, n, f, o, r, c, e, m, e, n, t, , a, c, t, i, o, n, s, , 2, 0, 2, 5, -, 2, 0, 2, 6, ;, , n, o, , s, t, a, t, e, -, s, p, e, c, i, f, i, c, , e, n, f, o, r, c, e, m, e, n, t, , d, e, c, i, s, i, o, n, s, , w, e, r, e, , f, o, u, n, d, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..

Regulator Funding And CapacityRed

No South Dakota AG privacy-unit funding or headcount data was identified in this run.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , c, o, n, s, u, m, e, r, -, p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , f, u, n, d, i, n, g, /, s, t, a, f, f, i, n, g, , d, a, t, a, ;, , n, o, n, e, , i, d, e, n, t, i, f, i, e, d, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..

Collective Redress And Class ActionsRed

No South Dakota-specific collective-redress or class-action mechanism specific to data-protection claims was identified.

Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , d, a, t, a, -, b, r, e, a, c, h, , c, l, a, s, s, -, a, c, t, i, o, n, , m, e, c, h, a, n, i, s, m, s, ;, , n, o, n, e, , s, p, e, c, i, f, i, c, , t, o, , s, t, a, t, e, , b, r, e, a, c, h, , s, t, a, t, u, t, e, , i, d, e, n, t, i, f, i, e, d, ..

Private Right Of ActionAmber

South Dakota's breach-notification statute does not appear to create an express private right of action; enforcement responsibility rests with the Attorney General, though this was not independently confirmed against full statutory text.

Claims (1):

  • South Dakota breach-notification statute does not appear to create an express private right of action; enforcement responsibility rests with the Attorney General (not independently confirmed against full statutory text). Unverified negative finding on private right of action; flagged as open question in self_audit.

Recent Developments 180DAmber

Within the preceding 180 days, the principal South Dakota development is the introduction and reported signing into law of a genetic-data protection bill (reported March 2026).

Claims (1):

  • South Dakota genetic-data protection legislation (SB49) was introduced and signed into law within the preceding 180 days Reported March 2026 signing, now confirmed effective July 1, 2026, per challenger fold f-001. Most material recent development this cycle; enriched via challenger fold f-001.

Key findings (1)

  • — source on file
Category narrative62 words

The FTC holds broad federal investigative and enforcement powers under Section 5 reaching South Dakota-based conduct, while the South Dakota Attorney General enforces the state's breach-notification statute and general consumer-protection law, including through multistate NAAG-coordinated actions. The most significant 2026 South Dakota-specific development is the genetic-data protection bill signed into law; no South Dakota-specific enforcement-activity index or regulator funding/capacity data was identified.

Periodic update · new data 2026-09-28

Enforcement & Redress

South Dakota's enforcement architecture for data-protection matters escalated this cycle with the addition of a second civil-penalty track under the Genetic Data Privacy Act, SB49, which entered into force on 1 July 2026. The Act's civil penalties reach up to five thousand dollars per violation, operating alongside the states pre-existing breach-notification penalty regime, which allows civil penalties of up to ten thousand dollars per day per violation and treats violations of the breach-notification statute as deceptive trade practices.

Both enforcement tracks, the standing breach-notification regime and the new genetic-data statute, share a common structural feature: enforcement runs exclusively through the Attorney General's office, and neither statute creates a private right of action. This means individual South Dakota residents whose genetic data is mishandled, or whose personal information is compromised in a breach, cannot bring their own civil suit under either statute; redress depends entirely on the Attorney General choosing to pursue enforcement action.

The per-violation penalty structures differ meaningfully between the two tracks. The breach-notification regime's penalty accrues on a per-day, per-violation basis, up to ten thousand dollars, which can produce substantial cumulative penalties for a prolonged or unremediated breach affecting a large population. The Genetic Data Privacy Act's penalty, by contrast, is a flat per-violation amount of up to five thousand dollars, without the day-based multiplier, suggesting a somewhat less severe maximum penalty structure for genetic-data violations considered individually, though the practical effect will depend heavily on how the Attorney General defines a single violation for enforcement purposes under each statute.

This cycle's addition of a second enforceable penalty track is a material escalation of the states overall enforcement architecture for data-protection matters, even though both tracks remain AG-only with no private right of action, meaning the states overall enforcement model itself has not shifted toward a private-litigation-driven approach seen in some other US jurisdictions.

Outlook

The key forward-looking question for this module is whether the Attorney General brings any enforcement action under the new Genetic Data Privacy Act penalty track in a future cycle, which would be the first practical test of how the states genetic-data enforcement regime operates outside the statutory text itself. Observing how the Attorney General defines a single violation under each of the two now-parallel penalty tracks, particularly for incidents that could plausibly implicate both statutes, would also clarify the practical interaction between South Dakota's two data-protection enforcement regimes.

Sources and claims (4)
  1. ProbableFederal Trade Commission — Federal Trade Commission can pursue injunctive relief, mandated compliance programs, and civil penalties for order violations FTC Section 5 enforcement powers reaching South Dakota-based conduct. Federal enforcement machinery applicable to SD-based conduct.observed
  2. ProbableNAAG — South Dakota Attorney General enforces breach-notification and consumer-protection law, including via multistate NAAG-coordinated actions SD AG general consumer-protection authority plus breach-notification enforcement, often coordinated multistate via NAAG. State enforcement authority operating through general consumer-protection statute and NAAG coordination.observed
  3. UncertainDataGuidance (secondary aggregator citing primary statute) — South Dakota breach-notification statute does not appear to create an express private right of action; enforcement responsibility rests with the Attorney General (not independently confirmed against full statutory text). Unverified negative finding on private right of action; flagged as open question in self_audit.observed
  4. Probableunavailable — South Dakota genetic-data protection legislation (SB49) was introduced and signed into law within the preceding 180 days Reported March 2026 signing, now confirmed effective July 1, 2026, per challenger fold f-001. Most material recent development this cycle; enriched via challenger fold f-001.
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct29.41
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for South Dakota, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 20 claim(s) (20 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsdeadlines and response windows
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and enforcement_and_redress rest on T1 (FTC.gov) and T2 (NAAG, DataGuidance statute citation) anchors. lawful_processing_and_special_data, sectoral_watch, and algorithmic_biometric_and_surveillance_governance rely on a single T3 DataGuidance headline for the 2026 genetic-data bill, with full bill text unverified. data_subject_rights, cross_border_and_adequacy, adtech_and_commercial_privacy, and children_and_vulnerable_groups are grounded in T3 IAPP negative evidence (absence from comprehensive-law trackers) rather than direct T1 statutory text, since no comprehensive statute exists to cite directly.

Unresolved questions (4):

  • What is the bill number, precise scope (e.g., DTC genetic testing companies vs. general genetic data), obligations, and effective date of South Dakota's 2026 genetic-data protection legislation?
  • Does SDCL §22-40-1 et seq. include a specific notification deadline (e.g., number of days) and an Attorney-General notice threshold, and does it include an encryption safe harbor?
  • Does South Dakota's breach-notification statute create any private right of action, or is enforcement exclusively vested in the Attorney General?
  • Has the South Dakota legislature introduced any comprehensive consumer-privacy bill (CCPA/CPRA-style) in the 2026 session that has not yet been captured by IAPP's tracker?

Escalate to primary-source review: yes