{
 "jurisdiction_id": "US-SC",
 "jurisdiction": "United States – South Carolina",
 "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 46,
  "sub_modules": 57,
  "source_register": 16
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No omnibus statute or dedicated DPA, but a substantive new minors-focused statute and clear breach-notification/insurance-security instruments exist and are actively enforced.",
   "claims": [
    {
     "statement": "South Carolina has no dedicated data protection authority; privacy-adjacent enforcement is divided between the South Carolina Attorney General and the South Carolina Department of Consumer Affairs (SCDCA).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina's breach notification statute, S.C. Code §39-1-90, is enforced by the SCDCA and requires notice to the SCDCA only when a business provides notice to more than 1,000 persons at one time.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "South Carolina Legislature (summarized via DataGuidance)",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina has no comprehensive consumer-privacy statute analogous to GDPR or CPRA; a comprehensive privacy bill (House Bill 4696) has been introduced but not enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Federal Trade Commission Act Section 5 provides general unfair/deceptive-practices authority applicable nationally, including South Carolina, but is reactive rather than a comprehensive proactive privacy regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The South Carolina Attorney General is the enforcing authority for the state's new Age-Appropriate Design Code / Social Media Regulation Act (H.3431).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-carolina-bill-social-media-regulation-act-passed",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431 applies to any data controller that conducts business in South Carolina and owns, operates, controls, or provides an online service reasonably likely to be accessed by minors, subject to a revenue threshold, a 50,000-consumer processing threshold, or a 50%-of-revenue-from-data-sale threshold.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No general lawful-basis, consent, or special-category regime exists outside narrow sectoral carve-outs.",
   "claims": [
    {
     "statement": "South Carolina does not have a general statutory lawful-basis framework governing commercial data processing outside of insurance and minors' online services.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Under H.3431, covered online services must provide minors default privacy settings that opt out of personalized recommendation systems, except for optimizations based on the user's expressed preferences.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina's genetic-privacy protections are sectoral, addressed under Title 38, Chapter 93 of the South Carolina Code (Privacy of Genetic Information), applying in the insurance context rather than as a general special-category regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "South Carolina Legislature (summarized via DataGuidance)",
     "source_url": "https://www.dataguidance.com/legal-research/south-carolina-code-title-38-insurance",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina has no statutory definition or safe harbor for pseudonymised or anonymised data outside the insurance sector.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No general DSR framework exists; only narrow, minors-focused design-control rights under H.3431.",
   "claims": [
    {
     "statement": "South Carolina law does not provide a general right of access, rectification, erasure, restriction, objection, or data portability for consumers' personal data outside of the insurance and minors' online-service contexts.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431 requires covered online services to provide users, not limited to minors, accessible tools to disable design features such as infinite scroll, auto-playing videos, and gamification, with default protective settings for minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No statutory deadline exists for controller response to a data-subject rights request in South Carolina because no comprehensive statute establishes such rights.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Robust sectoral (insurance) security/breach duties and a new minors-specific audit/minimization regime exist, but no general accountability, DPO, ROPA, or retention framework applies economy-wide.",
   "claims": [
    {
     "statement": "South Carolina's Insurance Data Security Act (S.C. Code §38-99-10 et seq.) requires insurers, agents, and other licensed entities to establish a comprehensive written information security program, conduct risk assessments, provide staff training, and exercise due diligence in selecting third-party service providers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "South Carolina Legislature (summarized via DataGuidance)",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina's breach notification statute (§39-1-90) requires notification to the SCDCA only when a business provides notice to more than 1,000 persons at a single time, and does not impose a general accountability, DPIA, DPO, or ROPA obligation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "South Carolina Legislature (summarized via DataGuidance)",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431 includes data-minimization standards, opt-out rights around personalized recommendation systems, and a third-party audit requirement, with audits submitted to the Attorney General for public disclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/state-of-the-states-connecticut-s-digital-strategy-florida-s-foreign-adversary-privacy-unit-and-more",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No general statutory retention-limitation or disposal duty applies to commercial data processing in South Carolina outside sector-specific regimes such as insurance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No state-level cross-border transfer framework exists; this is a genuine regulatory gap at the state level, consistent with the seed disambiguation.",
   "claims": [
    {
     "statement": "South Carolina has not enacted any state-level cross-border data-transfer mechanism, adequacy determination, SCC/BCR regime, or data-localisation mandate; cross-border transfer governance affecting this jurisdiction is determined at the U.S. federal level rather than by state law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Insurance sector is comprehensively regulated at state level; other sectors rely entirely on federal sectoral statutes with no state overlay identified.",
   "claims": [
    {
     "statement": "HIPAA governs protected health information nationally, including in South Carolina, in the absence of a state comprehensive health-privacy statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationally, including South Carolina, as the primary sectoral financial-privacy framework absent a state comprehensive law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina has no state-specific eprivacy/telecoms data statute beyond application of the federal Telephone Consumer Protection Act; no dedicated state cookie law exists.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Credit-scoring and consumer-report data in South Carolina are governed by the federal Fair Credit Reporting Act; no state-specific credit-scoring privacy statute was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The South Carolina Insurance Data Security Act constitutes a sector-specific overlay for insurers, agents, and licensees modeled on the NAIC Insurance Data Security Model Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-cybersecurity-rules-take-effect-in-south-carolina/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina insurers must notify state insurance regulatory authorities of a cybersecurity event within 72 hours of confirming nonpublic information was disrupted, misused, or accessed without authorization, in addition to general breach-notification requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-cybersecurity-rules-take-effect-in-south-carolina/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Meaningful minors-focused dark-pattern and targeted-advertising prohibitions exist, but general adtech governance (cookies, opt-out signals, clean rooms, direct marketing) is absent.",
   "claims": [
    {
     "statement": "H.3431 prohibits the use of dark patterns by covered online services, adopting an expansive and indeterminate definition of the practice.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431 prohibits targeted advertising to minors on covered online services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-carolina-bill-social-media-regulation-act-passed",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina has no state-specific cookie-consent statute distinct from H.3431's minors-focused design provisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No South Carolina statute addresses data clean rooms or data-collaboration rooms.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431's private right of action for dark-pattern violations arises by reference to South Carolina's general consumer-protection statute, subject to the standard limits of that statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Substantive but narrow (minors-only) profiling restrictions exist and are under active litigation; general ADM/biometric/genetic/AI governance is absent.",
   "claims": [
    {
     "statement": "H.3431 restricts behavioral profiling of minors through surveillance data and requires default opt-out from personalized recommendation systems for minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/usa-epic-files-amicus-brief-defending-south-carolinas",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "NetChoice, LLC filed suit seeking an injunction against South Carolina's Age-Appropriate Design Code's restrictions on behavioral profiling of minors via surveillance data; EPIC filed an amicus brief defending the law on April 13, 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/usa-epic-files-amicus-brief-defending-south-carolinas",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina has no general statute governing automated decision-making transparency outside of H.3431's children-specific audit and minimization requirements.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina has no dedicated biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "South Carolina's genetic-data protections are confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code and do not extend to a general genetic-data protection regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "South Carolina Legislature (summarized via DataGuidance)",
     "source_url": "https://www.dataguidance.com/legal-research/south-carolina-code-title-38-insurance",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified beyond the general absence of a comprehensive privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Substantively strong and very recent minors' regime, but novel, untested (active NetChoice litigation), and offers no cure period, creating material compliance and legal-durability risk.",
   "claims": [
    {
     "statement": "H.3431 requires covered social media companies, beginning March 1, 2026, to make commercially reasonable efforts to verify the age of account holders or apply minor-protective accommodations to all account holders.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-carolina-bill-social-media-regulation-and-age",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431 conditions minors' social media account holding on parental consent obtained by the platform.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-carolina-bill-social-media-regulation-and-age",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A predecessor South Carolina bill (HB 4842) defined 'child' as a consumer under 18 years of age; whether H.3431 as finally enacted retains this exact definition was not independently confirmed against the final statutory text this run.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431 requires default protective settings for minors on design features including usage timers, spending caps, blocking interactions from non-connected accounts, hiding engagement metrics, disabling search-engine indexing, and restricting geolocation visibility, while extending baseline access to these tools to all users.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "COPPA applies nationally, including South Carolina, to operators collecting personal information from children under 13, operating alongside the state's own minors-focused design-code law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-south-carolina/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Clear AG enforcement powers and a narrow private right of action exist for the new minors' law, but general privacy enforcement capacity and redress mechanisms remain largely undeveloped, and the flagship 2026 law faces active constitutional litigation.",
   "claims": [
    {
     "statement": "The South Carolina Attorney General is empowered to enforce H.3431, with the statute providing for severe penalties for violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-carolina-bill-social-media-regulation-act-passed",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "H.3431's dark-patterns provisions carry a private right of action by reference to South Carolina's general consumer-protection statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-are-you-personally-liable-under-south-carolina-s-new-design-code",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "NetChoice, LLC filed suit against South Carolina seeking to enjoin enforcement of H.3431; EPIC filed an amicus brief defending the law on April 13, 2026, and the law remains in effect pending the litigation's outcome.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/usa-epic-files-amicus-brief-defending-south-carolinas",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The South Carolina Attorney General's office joined a multistate $80 million enforcement settlement against Block, Inc. (Cash App) for Bank Secrecy Act/anti-money-laundering violations, reflecting active state AG involvement in financial-data-adjacent enforcement, though the action arose under BSA/AML rather than data-protection statutes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "South Carolina Attorney General's Office (via NAAG)",
     "source_url": "https://www.naag.org/wp-content/uploads/2025/10/2025.01.21-SC-Press-Release.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Beyond H.3431's reference to the state's consumer-protection statute for dark-pattern violations, South Carolina does not provide a general private right of action for other data-privacy harms.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/south-carolina?topic=notes",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The South Carolina Attorney General's Office comprises more than 200 employees and nearly 75 attorneys managing thousands of active case files, though no privacy-specific unit or headcount was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/attorney-general/alan-wilson/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}