#
A functioning breach-notification regime and applicable federal FTC authority exist, but there is no comprehensive material/territorial scope regime or registration framework at state level.
Sub-modules (5)
Regulator And AuthorityAmber
No dedicated South Dakota DPA exists; the South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement, while the FTC is the de facto federal privacy regulator reaching South Dakota-based conduct.
Claims (1):
- South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement authority absent a dedicated state privacy regulator No dedicated South Dakota data-protection authority exists; SD AG holds general consumer-protection/breach-notification authority while the FTC exercises federal Section 5 authority reaching SD-based conduct. Baseline regulator-mapping finding; South Dakota lacks a dedicated privacy authority.
Act And InstrumentsAmber
The FTC Act Section 5 baseline and South Dakota's 2018 breach-notification statute (SDCL §22-40-1 et seq.) constitute the operative instruments; South Dakota was one of the last two states to adopt a breach law.
Claims (3):
- South Dakota data-breach notification statute is codified at SDCL §§22-40-19 to 22-40-26 (breach-notification-specific provisions), corrected from the initially miscited §22-40-1 et seq. Citation corrected per challenger fold f-002; confirmed by two independent T1 anchors (Justia, SD Legislature).
- South Dakota breach-notification statute enactment was adopted in 2018, making South Dakota one of the last two US states to enact a data-breach notification law. Historical enactment context for the breach-notification statute.
- FTC Act Section 5 provides the federal unfair/deceptive-practices baseline applicable to South Dakota-based conduct FTC Act Section 5 (federal) plus the SD breach-notification statute constitute the operative instruments for this jurisdiction. Federal baseline framework applicable absent a state comprehensive statute.
Material ScopeRed
Material scope is limited to the breach-notification statute's definition of computerized personal information; no independently-verified statutory text defining broader material scope (e.g., general 'personal data' categories) was retrievable in this run.
Absence provenance: unavailable. Searched: A, t, t, e, m, p, t, e, d, , t, o, , r, e, t, r, i, e, v, e, , f, u, l, l, , t, e, x, t, , o, f, , S, D, C, L, , C, h, a, p, t, e, r, , 2, 2, -, 4, 0, , d, e, f, i, n, i, n, g, , ', p, e, r, s, o, n, a, l, , i, n, f, o, r, m, a, t, i, o, n, ', , s, c, o, p, e, ;, , o, n, l, y, , s, e, c, o, n, d, a, r, y, , a, g, g, r, e, g, a, t, o, r, , c, i, t, a, t, i, o, n, s, , (, D, a, t, a, G, u, i, d, a, n, c, e, ), , w, e, r, e, , r, e, a, c, h, a, b, l, e, ,, , n, o, t, , f, u, l, l, , s, t, a, t, u, t, o, r, y, , t, e, x, t, ..
Territorial ScopeRed
No independently verified statutory text on territorial application (e.g., extraterritorial reach to out-of-state controllers processing South Dakota residents' data) was retrievable in this run.
Absence provenance: unavailable. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , b, r, e, a, c, h, , s, t, a, t, u, t, e, , t, e, r, r, i, t, o, r, i, a, l, -, s, c, o, p, e, /, e, x, t, r, a, t, e, r, r, i, t, o, r, i, a, l, i, t, y, , p, r, o, v, i, s, i, o, n, s, ;, , f, u, l, l, , s, t, a, t, u, t, o, r, y, , t, e, x, t, , n, o, t, , r, e, a, c, h, a, b, l, e, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..
Regulator Registration And FilingRed
Consistent with the absence of a comprehensive privacy statute, South Dakota imposes no general controller/processor registration or filing regime with a state privacy authority.
Claims (1):
- South Dakota imposes no general controller/processor registration or filing regime No state privacy-authority registration/filing requirement exists. Absence-of-regime finding via negative evidence from IAPP tracker.
Key findings (1)
- — source on file
no periodic updates on record for this sub-brief
Sources and claims (5)
- ProbableFederal Trade Commission — South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement authority absent a dedicated state privacy regulator No dedicated South Dakota data-protection authority exists; SD AG holds general consumer-protection/breach-notification authority while the FTC exercises federal Section 5 authority reaching SD-based conduct. Baseline regulator-mapping finding; South Dakota lacks a dedicated privacy authority.observed
- Probableunavailable — South Dakota data-breach notification statute is codified at SDCL §§22-40-19 to 22-40-26 (breach-notification-specific provisions), corrected from the initially miscited §22-40-1 et seq. Citation corrected per challenger fold f-002; confirmed by two independent T1 anchors (Justia, SD Legislature).
- ProbableDataGuidance (secondary aggregator citing primary statute) — South Dakota breach-notification statute enactment was adopted in 2018, making South Dakota one of the last two US states to enact a data-breach notification law. Historical enactment context for the breach-notification statute.observed
- ProbableFederal Trade Commission — FTC Act Section 5 provides the federal unfair/deceptive-practices baseline applicable to South Dakota-based conduct FTC Act Section 5 (federal) plus the SD breach-notification statute constitute the operative instruments for this jurisdiction. Federal baseline framework applicable absent a state comprehensive statute.observed
- ProbableIAPP — South Dakota imposes no general controller/processor registration or filing regime No state privacy-authority registration/filing requirement exists. Absence-of-regime finding via negative evidence from IAPP tracker.observed