🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-SC · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

United States – South Carolina

US-SC schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No omnibus statute or dedicated DPA, but a substantive new minors-focused statute and clear breach-notification/insurance-security instruments exist and are actively enforced.

Primary frameworkNo comprehensive state privacy statute; federal FTC Act Section 5 + S.C. Code §39-1-90 (breach notification) + S.C. Code §38-99-10 et seq. (Insurance Data Security Act) + H.3431 (2026, Social Media Regulation and Age-Appropriate Design Code Act)
Traffic-light rationale — AmberNo omnibus statute or dedicated DPA, but a substantive new minors-focused statute and clear breach-notification/insurance-security instruments exist and are actively enforced.

Sub-modules (5)

Regulator And AuthorityAmber

Enforcement authority is split between the SC Attorney General (H.3431, general consumer protection) and SCDCA (breach notification).

Claims (2):

  • South Carolina has no dedicated data protection authority; privacy-adjacent enforcement is divided between the South Carolina Attorney General and the South Carolina Department of Consumer Affairs (SCDCA).
  • The South Carolina Attorney General is the enforcing authority for the state's new Age-Appropriate Design Code / Social Media Regulation Act (H.3431).

Act And InstrumentsAmber

Primary instruments: §39-1-90 breach law, §38-99-10 et seq. Insurance Data Security Act, and H.3431; no general omnibus act.

Claims (2):

  • South Carolina's breach notification statute, S.C. Code §39-1-90, is enforced by the SCDCA and requires notice to the SCDCA only when a business provides notice to more than 1,000 persons at one time.
  • South Carolina has no comprehensive consumer-privacy statute analogous to GDPR or CPRA; a comprehensive privacy bill (House Bill 4696) has been introduced but not enacted.

Material ScopeRed

No general material-scope definition exists absent an omnibus statute; scope is defined narrowly and sectorally (breach data, insurer nonpublic information, minors' online services).

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , c, o, m, p, r, e, h, e, n, s, i, v, e, , c, o, n, s, u, m, e, r, , p, r, i, v, a, c, y, , l, a, w, , 2, 0, 2, 6, , s, t, a, t, u, s, ;, , S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , b, r, e, a, c, h, , n, o, t, i, f, i, c, a, t, i, o, n, , s, t, a, t, u, t, e, , 2, 0, 2, 6.

Territorial ScopeAmber

H.3431 applies extraterritorially to any controller conducting business in South Carolina whose online service is reasonably likely to be accessed by minors, subject to disjunctive revenue/data-volume thresholds.

Claims (1):

  • H.3431 applies to any data controller that conducts business in South Carolina and owns, operates, controls, or provides an online service reasonably likely to be accessed by minors, subject to a revenue threshold, a 50,000-consumer processing threshold, or a 50%-of-revenue-from-data-sale threshold.

Regulator Registration And FilingRed

No state controller/processor registration or filing regime was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, g, i, s, t, r, a, t, i, o, n, , f, i, l, i, n, g, , r, e, q, u, i, r, e, m, e, n, t, s.

Category narrative86 words

South Carolina has no dedicated data-protection authority. Enforcement is split between the South Carolina Attorney General (general consumer protection and, since 2026, the new minors' online-safety/design-code statute) and the South Carolina Department of Consumer Affairs (SCDCA), which enforces the state's breach-notification statute. There is no state omnibus consumer-privacy law: a comprehensive bill (HB 4696) has been introduced but not enacted. The most consequential recent development is H.3431, the Social Media Regulation and Age-Appropriate Design Code Act, signed by Gov. McMaster and effective without a cure period.

Sources and claims (6)
  1. ConfirmedDataGuidanceSouth Carolina has no dedicated data protection authority; privacy-adjacent enforcement is divided between the South Carolina Attorney General and the South Carolina Department of Consumer Affairs (SCDCA).observed
  2. ConfirmedSouth Carolina Legislature (summarized via DataGuidance)South Carolina's breach notification statute, S.C. Code §39-1-90, is enforced by the SCDCA and requires notice to the SCDCA only when a business provides notice to more than 1,000 persons at one time.observed
  3. ConfirmedDataGuidanceSouth Carolina has no comprehensive consumer-privacy statute analogous to GDPR or CPRA; a comprehensive privacy bill (House Bill 4696) has been introduced but not enacted.observed
  4. ConfirmedFederal Trade CommissionFederal Trade Commission Act Section 5 provides general unfair/deceptive-practices authority applicable nationally, including South Carolina, but is reactive rather than a comprehensive proactive privacy regime.observed
  5. ConfirmedDataGuidanceThe South Carolina Attorney General is the enforcing authority for the state's new Age-Appropriate Design Code / Social Media Regulation Act (H.3431).observed
  6. ConfirmedIAPPH.3431 applies to any data controller that conducts business in South Carolina and owns, operates, controls, or provides an online service reasonably likely to be accessed by minors, subject to a revenue threshold, a 50,000-consumer processing threshold, or a 50%-of-revenue-from-data-sale threshold.observed

#

No general lawful-basis, consent, or special-category regime exists outside narrow sectoral carve-outs.

Traffic-light rationale — RedNo general lawful-basis, consent, or special-category regime exists outside narrow sectoral carve-outs.

Sub-modules (4)

Lawful BasesRed

No general statutory lawful-basis framework exists in South Carolina.

Claims (1):

  • South Carolina does not have a general statutory lawful-basis framework governing commercial data processing outside of insurance and minors' online services.

Special CategoriesRed

Special/sensitive category protections are sectoral, limited to genetic information in the insurance context.

Claims (1):

  • South Carolina's genetic-privacy protections are sectoral, addressed under Title 38, Chapter 93 of the South Carolina Code (Privacy of Genetic Information), applying in the insurance context rather than as a general special-category regime.

Pseudonymisation And AnonymisationRed

No general statutory pseudonymisation/anonymisation definition or safe harbor was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , d, a, t, a, , s, t, a, t, u, t, e.

Claims (1):

  • South Carolina has no statutory definition or safe harbor for pseudonymised or anonymised data outside the insurance sector.
Category narrative47 words

South Carolina has no general lawful-basis or consent framework for commercial data processing. Consent-like mechanisms exist only within H.3431 (default opt-out of personalized recommendations for minors). Special-category/genetic data protections are confined to the insurance sector under Title 38, Chapter 93. No general pseudonymisation/anonymisation safe harbor was identified.

Sources and claims (4)
  1. ConfirmedDataGuidanceSouth Carolina does not have a general statutory lawful-basis framework governing commercial data processing outside of insurance and minors' online services.observed
  2. ConfirmedIAPPUnder H.3431, covered online services must provide minors default privacy settings that opt out of personalized recommendation systems, except for optimizations based on the user's expressed preferences.observed
  3. ProbableSouth Carolina Legislature (summarized via DataGuidance)South Carolina's genetic-privacy protections are sectoral, addressed under Title 38, Chapter 93 of the South Carolina Code (Privacy of Genetic Information), applying in the insurance context rather than as a general special-category regime.observed
  4. UncertainDataGuidanceSouth Carolina has no statutory definition or safe harbor for pseudonymised or anonymised data outside the insurance sector.observed

#

No general DSR framework exists; only narrow, minors-focused design-control rights under H.3431.

Traffic-light rationale — RedNo general DSR framework exists; only narrow, minors-focused design-control rights under H.3431.

Sub-modules (5)

Access RightRed

No general statutory right of access exists in South Carolina.

Claims (1):

  • South Carolina law does not provide a general right of access, rectification, erasure, restriction, objection, or data portability for consumers' personal data outside of the insurance and minors' online-service contexts.

Rectification And ErasureRed

No general right to rectify or delete personal data exists outside sectoral contexts.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , r, i, g, h, t, , t, o, , d, e, l, e, t, e, , r, e, c, t, i, f, y, , p, e, r, s, o, n, a, l, , d, a, t, a, , s, t, a, t, u, t, e.

Restriction And ObjectionRed

No general right to restrict processing or object to profiling exists for the general population; H.3431 provides minors-focused profiling opt-outs (see algorithmic_biometric module).

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , r, i, g, h, t, , t, o, , r, e, s, t, r, i, c, t, , p, r, o, c, e, s, s, i, n, g, , o, b, j, e, c, t, , p, r, o, f, i, l, i, n, g, , s, t, a, t, u, t, e.

Data PortabilityRed

No statutory data-portability right exists in South Carolina.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , r, i, g, h, t, , s, t, a, t, u, t, e.

Deadlines And Response WindowsRed

No statutory deadline for controller response to a data-subject request exists because no comprehensive statute establishes such rights.

Claims (1):

  • No statutory deadline exists for controller response to a data-subject rights request in South Carolina because no comprehensive statute establishes such rights.
Category narrative47 words

South Carolina provides no general consumer right of access, rectification, erasure, restriction, objection, or portability. The only individual-facing control rights exist within H.3431, which requires user-facing design controls (usage timers, spending caps, engagement-metric visibility controls, etc.) for minors and, more narrowly, for all users of covered services.

Sources and claims (3)
  1. ConfirmedDataGuidanceSouth Carolina law does not provide a general right of access, rectification, erasure, restriction, objection, or data portability for consumers' personal data outside of the insurance and minors' online-service contexts.observed
  2. ConfirmedIAPPH.3431 requires covered online services to provide users, not limited to minors, accessible tools to disable design features such as infinite scroll, auto-playing videos, and gamification, with default protective settings for minors.observed
  3. ConfirmedDataGuidanceNo statutory deadline exists for controller response to a data-subject rights request in South Carolina because no comprehensive statute establishes such rights.observed

#

Robust sectoral (insurance) security/breach duties and a new minors-specific audit/minimization regime exist, but no general accountability, DPO, ROPA, or retention framework applies economy-wide.

Primary frameworkS.C. Code §38-99-10 et seq. (Insurance Data Security Act); S.C. Code §39-1-90 (breach notification); H.3431 (minors' data minimization/audit)
Traffic-light rationale — AmberRobust sectoral (insurance) security/breach duties and a new minors-specific audit/minimization regime exist, but no general accountability, DPO, ROPA, or retention framework applies economy-wide.

Sub-modules (7)

Accountability And DpiaAmber

H.3431 imposes data-minimization standards and a third-party audit requirement submitted to the Attorney General, functioning as a DPIA analogue for children's data.

Claims (1):

  • H.3431 includes data-minimization standards, opt-out rights around personalized recommendation systems, and a third-party audit requirement, with audits submitted to the Attorney General for public disclosure.

Dpo RequirementsRed

No DPO appointment requirement exists in South Carolina law.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, f, f, i, c, e, r, , r, e, q, u, i, r, e, m, e, n, t, , s, t, a, t, u, t, e.

Ropa RequirementsRed

No records-of-processing-activities requirement exists in South Carolina law.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , r, e, c, o, r, d, s, , o, f, , p, r, o, c, e, s, s, i, n, g, , a, c, t, i, v, i, t, i, e, s, , r, e, q, u, i, r, e, m, e, n, t.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists in South Carolina.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , d, a, t, a, , p, r, o, c, e, s, s, i, n, g, , s, t, a, t, u, t, e.

Security MeasuresAmber

The Insurance Data Security Act requires a comprehensive written information security program, risk assessments, staff training, and third-party diligence for insurers.

Claims (1):

  • South Carolina's Insurance Data Security Act (S.C. Code §38-99-10 et seq.) requires insurers, agents, and other licensed entities to establish a comprehensive written information security program, conduct risk assessments, provide staff training, and exercise due diligence in selecting third-party service providers.

Breach NotificationAmber

The general breach statute (§39-1-90) requires SCDCA notification only above a 1,000-person threshold; insurers face an additional 72-hour cyber-event notice requirement to state insurance regulators.

Claims (1):

  • South Carolina's breach notification statute (§39-1-90) requires notification to the SCDCA only when a business provides notice to more than 1,000 persons at a single time, and does not impose a general accountability, DPIA, DPO, or ROPA obligation.

Retention And DisposalRed

No general statutory retention-limitation or disposal duty applies outside sector-specific regimes.

Claims (1):

  • No general statutory retention-limitation or disposal duty applies to commercial data processing in South Carolina outside sector-specific regimes such as insurance.
Category narrative54 words

General accountability, DPIA, DPO, ROPA, and retention obligations do not exist outside the insurance sector. The Insurance Data Security Act imposes security-program, risk-assessment, training, and vendor-diligence duties on insurers. H.3431 imposes children's-data-specific data-minimization, opt-out, and third-party audit obligations functioning as a DPIA analogue for covered services. The breach-notification statute imposes narrow notification duties only.

Sources and claims (4)
  1. ConfirmedSouth Carolina Legislature (summarized via DataGuidance)South Carolina's Insurance Data Security Act (S.C. Code §38-99-10 et seq.) requires insurers, agents, and other licensed entities to establish a comprehensive written information security program, conduct risk assessments, provide staff training, and exercise due diligence in selecting third-party service providers.observed
  2. ConfirmedSouth Carolina Legislature (summarized via DataGuidance)South Carolina's breach notification statute (§39-1-90) requires notification to the SCDCA only when a business provides notice to more than 1,000 persons at a single time, and does not impose a general accountability, DPIA, DPO, or ROPA obligation.observed
  3. ProbableIAPPH.3431 includes data-minimization standards, opt-out rights around personalized recommendation systems, and a third-party audit requirement, with audits submitted to the Attorney General for public disclosure.observed
  4. ConfirmedDataGuidanceNo general statutory retention-limitation or disposal duty applies to commercial data processing in South Carolina outside sector-specific regimes such as insurance.observed

#

No state-level cross-border transfer framework exists; this is a genuine regulatory gap at the state level, consistent with the seed disambiguation.

Traffic-light rationale — RedNo state-level cross-border transfer framework exists; this is a genuine regulatory gap at the state level, consistent with the seed disambiguation.

Sub-modules (6)

Transfer MechanismsRed

No state-level transfer mechanism exists.

Claims (1):

  • South Carolina has not enacted any state-level cross-border data-transfer mechanism, adequacy determination, SCC/BCR regime, or data-localisation mandate; cross-border transfer governance affecting this jurisdiction is determined at the U.S. federal level rather than by state law.

Adequacy ReceivedRed

Not applicable at state level; adequacy is a federal/international-level determination.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , a, d, e, q, u, a, c, y, , d, e, t, e, r, m, i, n, a, t, i, o, n, , c, r, o, s, s, -, b, o, r, d, e, r, , d, a, t, a, , t, r, a, n, s, f, e, r.

Adequacy GrantedRed

Not applicable at state level.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , a, d, e, q, u, a, c, y, , d, e, t, e, r, m, i, n, a, t, i, o, n, , c, r, o, s, s, -, b, o, r, d, e, r, , d, a, t, a, , t, r, a, n, s, f, e, r.

Sccs And BcrsRed

No state-level SCC/BCR framework exists.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , s, t, a, n, d, a, r, d, , c, o, n, t, r, a, c, t, u, a, l, , c, l, a, u, s, e, s, , b, i, n, d, i, n, g, , c, o, r, p, o, r, a, t, e, , r, u, l, e, s.

Transfer Impact AssessmentRed

No state-level TIA requirement exists.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Data LocalisationRed

No state-level data-localisation mandate was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , s, t, a, t, u, t, e.

Category narrative36 words

South Carolina has enacted no state-level cross-border transfer mechanism, adequacy determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data-flow governance affecting South Carolina entities is determined at the U.S. federal level, not by state law.

Sources and claims (1)
  1. ProbableDataGuidanceSouth Carolina has not enacted any state-level cross-border data-transfer mechanism, adequacy determination, SCC/BCR regime, or data-localisation mandate; cross-border transfer governance affecting this jurisdiction is determined at the U.S. federal level rather than by state law.observed

#

Insurance sector is comprehensively regulated at state level; other sectors rely entirely on federal sectoral statutes with no state overlay identified.

Primary frameworkS.C. Code §38-99-10 et seq. (Insurance Data Security Act); HIPAA; GLBA (federal)
Traffic-light rationale — AmberInsurance sector is comprehensively regulated at state level; other sectors rely entirely on federal sectoral statutes with no state overlay identified.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA governs financial institutions' nonpublic personal information nationally, including South Carolina, absent a state comprehensive law.

Claims (1):

  • The Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationally, including South Carolina, as the primary sectoral financial-privacy framework absent a state comprehensive law.

Health Sector OverlayAmber

HIPAA governs protected health information nationally, including South Carolina.

Claims (1):

  • HIPAA governs protected health information nationally, including in South Carolina, in the absence of a state comprehensive health-privacy statute.

Telecoms And EprivacyRed

No state-specific eprivacy/telecoms data statute exists beyond federal TCPA application.

Claims (1):

  • South Carolina has no state-specific eprivacy/telecoms data statute beyond application of the federal Telephone Consumer Protection Act; no dedicated state cookie law exists.

Employment DataRed

No South Carolina employment-data-specific privacy statute was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , e, m, p, l, o, y, m, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , s, t, a, t, u, t, e.

Credit And ScoringRed

Credit-scoring data is governed by the federal Fair Credit Reporting Act; no state-specific statute was identified.

Claims (1):

  • Credit-scoring and consumer-report data in South Carolina are governed by the federal Fair Credit Reporting Act; no state-specific credit-scoring privacy statute was identified.

EducationRed

No South Carolina education-sector-specific student-data-privacy statute was identified this run.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , e, d, u, c, a, t, i, o, n, , s, t, a, t, u, t, e.

InsuranceGreen

The Insurance Data Security Act models the NAIC Insurance Data Security Model Law and requires a 72-hour cybersecurity-event notice to state insurance regulators.

Claims (2):

  • The South Carolina Insurance Data Security Act constitutes a sector-specific overlay for insurers, agents, and licensees modeled on the NAIC Insurance Data Security Model Law.
  • South Carolina insurers must notify state insurance regulatory authorities of a cybersecurity event within 72 hours of confirming nonpublic information was disrupted, misused, or accessed without authorization, in addition to general breach-notification requirements.
Category narrative54 words

South Carolina's data-protection landscape is dominated by sectoral overlays: federal HIPAA, GLBA, and COPPA apply nationally in the absence of a state omnibus law; the state's own Insurance Data Security Act imposes NAIC-model security obligations and a 72-hour cyber-incident notice to insurance regulators; no state-specific telecoms/eprivacy, employment-data, credit-scoring, or education-sector privacy statute was identified.

Sources and claims (6)
  1. ProbableDataGuidanceHIPAA governs protected health information nationally, including in South Carolina, in the absence of a state comprehensive health-privacy statute.observed
  2. ProbableDataGuidanceThe Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationally, including South Carolina, as the primary sectoral financial-privacy framework absent a state comprehensive law.observed
  3. UncertainDataGuidanceSouth Carolina has no state-specific eprivacy/telecoms data statute beyond application of the federal Telephone Consumer Protection Act; no dedicated state cookie law exists.observed
  4. UncertainDataGuidanceCredit-scoring and consumer-report data in South Carolina are governed by the federal Fair Credit Reporting Act; no state-specific credit-scoring privacy statute was identified.observed
  5. ConfirmedIAPPThe South Carolina Insurance Data Security Act constitutes a sector-specific overlay for insurers, agents, and licensees modeled on the NAIC Insurance Data Security Model Law.observed
  6. ConfirmedIAPPSouth Carolina insurers must notify state insurance regulatory authorities of a cybersecurity event within 72 hours of confirming nonpublic information was disrupted, misused, or accessed without authorization, in addition to general breach-notification requirements.observed

#

Meaningful minors-focused dark-pattern and targeted-advertising prohibitions exist, but general adtech governance (cookies, opt-out signals, clean rooms, direct marketing) is absent.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act)
Supervisory authoritySouth Carolina Attorney General
Traffic-light rationale — AmberMeaningful minors-focused dark-pattern and targeted-advertising prohibitions exist, but general adtech governance (cookies, opt-out signals, clean rooms, direct marketing) is absent.

Sub-modules (6)

Cookies And TrackersRed

No state-specific cookie-consent statute exists.

Claims (1):

  • South Carolina has no state-specific cookie-consent statute distinct from H.3431's minors-focused design provisions.

Dark PatternsAmber

H.3431 prohibits dark patterns via an expansive, indeterminate definition enforceable through the state consumer-protection statute.

Claims (2):

  • H.3431 prohibits the use of dark patterns by covered online services, adopting an expansive and indeterminate definition of the practice.
  • H.3431's private right of action for dark-pattern violations arises by reference to South Carolina's general consumer-protection statute, subject to the standard limits of that statute.

Opt Out SignalsRed

No statutory recognition of Global Privacy Control or DAA opt-out signals was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n.

Clean Rooms And DcrRed

No South Carolina statute addresses data clean rooms or data-collaboration rooms.

Claims (1):

  • No South Carolina statute addresses data clean rooms or data-collaboration rooms.

Cross Context AdvertisingAmber

H.3431 prohibits targeted advertising to minors on covered online services.

Claims (1):

  • H.3431 prohibits targeted advertising to minors on covered online services.

Direct MarketingRed

No state-specific direct-marketing consent/suppression statute beyond federal TCPA/CAN-SPAM was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, i, r, e, c, t, , m, a, r, k, e, t, i, n, g, , c, o, n, s, e, n, t, , s, u, p, p, r, e, s, s, i, o, n, , s, t, a, t, u, t, e.

Category narrative48 words

H.3431 prohibits dark patterns and targeted advertising directed at minors, with a private right of action for dark-pattern violations arising via the state's general consumer-protection statute. No general state cookie-consent law, GPC-recognition requirement, or clean-room/data-collaboration-room regime exists, and no state-specific direct-marketing consent statute beyond federal TCPA/CAN-SPAM was identified.

Sources and claims (5)
  1. ConfirmedIAPPH.3431 prohibits the use of dark patterns by covered online services, adopting an expansive and indeterminate definition of the practice.observed
  2. ConfirmedDataGuidanceH.3431 prohibits targeted advertising to minors on covered online services.observed
  3. UncertainDataGuidanceSouth Carolina has no state-specific cookie-consent statute distinct from H.3431's minors-focused design provisions.observed
  4. UncertainDataGuidanceNo South Carolina statute addresses data clean rooms or data-collaboration rooms.observed
  5. ConfirmedIAPPH.3431's private right of action for dark-pattern violations arises by reference to South Carolina's general consumer-protection statute, subject to the standard limits of that statute.observed

#

Substantive but narrow (minors-only) profiling restrictions exist and are under active litigation; general ADM/biometric/genetic/AI governance is absent.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act)
Supervisory authoritySouth Carolina Attorney General
Traffic-light rationale — AmberSubstantive but narrow (minors-only) profiling restrictions exist and are under active litigation; general ADM/biometric/genetic/AI governance is absent.

Sub-modules (6)

Profiling RestrictionsAmber

H.3431's core purpose is to regulate the use of surveillance data to behaviorally profile minors.

Claims (2):

  • H.3431 restricts behavioral profiling of minors through surveillance data and requires default opt-out from personalized recommendation systems for minors.
  • NetChoice, LLC filed suit seeking an injunction against South Carolina's Age-Appropriate Design Code's restrictions on behavioral profiling of minors via surveillance data; EPIC filed an amicus brief defending the law on April 13, 2026.

Automated Decision Making TransparencyRed

No general ADM-transparency or explanation-right statute exists outside H.3431's minors-specific profiling opt-outs.

Claims (1):

  • South Carolina has no general statute governing automated decision-making transparency outside of H.3431's children-specific audit and minimization requirements.

Ai Risk AssessmentsRed

No AI-specific risk-assessment statute exists; H.3431's audit requirement is the closest analogue, limited to minors' data.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , A, I, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , s, t, a, t, u, t, e.

Biometric RegimeRed

No dedicated biometric-privacy statute (e.g., facial recognition or fingerprint regulation) analogous to Illinois' BIPA exists in South Carolina.

Claims (1):

  • South Carolina has no dedicated biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act.

Genetic DataAmber

Genetic-data protection is confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code.

Claims (1):

  • South Carolina's genetic-data protections are confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code and do not extend to a general genetic-data protection regime.

State Surveillance CarveoutsRed

No South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified.

Claims (1):

  • No South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified beyond the general absence of a comprehensive privacy statute.
Category narrative61 words

H.3431 restricts behavioral profiling of minors via surveillance data and mandates default opt-outs from personalized recommendation systems; this is currently subject to a First Amendment challenge by NetChoice, LLC, with EPIC defending the law via amicus brief. No general ADM-transparency, AI-risk-assessment, biometric-privacy, or broad genetic-data statute exists; genetic data protection is confined to the insurance sector. No state-surveillance carve-out was identified.

Sources and claims (6)
  1. ConfirmedDataGuidanceH.3431 restricts behavioral profiling of minors through surveillance data and requires default opt-out from personalized recommendation systems for minors.observed
  2. ConfirmedDataGuidanceNetChoice, LLC filed suit seeking an injunction against South Carolina's Age-Appropriate Design Code's restrictions on behavioral profiling of minors via surveillance data; EPIC filed an amicus brief defending the law on April 13, 2026.observed
  3. ConfirmedDataGuidanceSouth Carolina has no general statute governing automated decision-making transparency outside of H.3431's children-specific audit and minimization requirements.observed
  4. ConfirmedDataGuidanceSouth Carolina has no dedicated biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act.observed
  5. ProbableSouth Carolina Legislature (summarized via DataGuidance)South Carolina's genetic-data protections are confined to the insurance sector under Title 38, Chapter 93 of the South Carolina Code and do not extend to a general genetic-data protection regime.observed
  6. UncertainDataGuidanceNo South Carolina-specific state-surveillance carve-out or national-security exemption to privacy obligations was identified beyond the general absence of a comprehensive privacy statute.observed

#

Substantively strong and very recent minors' regime, but novel, untested (active NetChoice litigation), and offers no cure period, creating material compliance and legal-durability risk.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act, 2026)
Supervisory authoritySouth Carolina Attorney General
Traffic-light rationale — AmberSubstantively strong and very recent minors' regime, but novel, untested (active NetChoice litigation), and offers no cure period, creating material compliance and legal-durability risk.

Sub-modules (5)

Age VerificationAmber

H.3431 requires commercially reasonable age-verification efforts by covered social media companies from March 1, 2026.

Claims (1):

  • H.3431 requires covered social media companies, beginning March 1, 2026, to make commercially reasonable efforts to verify the age of account holders or apply minor-protective accommodations to all account holders.

Minor Profiling BansAmber

See algorithmic_biometric_and_surveillance_governance.profiling_restrictions for the core minors' profiling-ban claims.

Claims (1):

  • A predecessor South Carolina bill (HB 4842) defined 'child' as a consumer under 18 years of age; whether H.3431 as finally enacted retains this exact definition was not independently confirmed against the final statutory text this run.

Education SettingsRed

No South Carolina education-setting-specific student-data-privacy statute was identified this run.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , e, d, u, c, a, t, i, o, n, , s, t, a, t, u, t, e.

Dependent AdultsRed

No South Carolina statute specifically protecting dependent adults' (elderly, mentally incapacitated) personal data was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, , e, l, d, e, r, l, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Category narrative64 words

South Carolina's most developed data-protection regime is minors-focused: H.3431 (effective Feb. 5, 2026, with an additional social-media age-verification duty from March 1, 2026) requires age assurance, restricts minors' account creation absent parental consent, mandates default protective design settings, and prohibits targeted advertising and dark patterns aimed at minors. COPPA applies federally to under-13s alongside this state regime. No education-setting-specific or dependent-adult-specific statute was identified.

Sources and claims (5)
  1. ConfirmedDataGuidanceH.3431 requires covered social media companies, beginning March 1, 2026, to make commercially reasonable efforts to verify the age of account holders or apply minor-protective accommodations to all account holders.observed
  2. ProbableDataGuidanceH.3431 conditions minors' social media account holding on parental consent obtained by the platform.observed
  3. UncertainDataGuidanceA predecessor South Carolina bill (HB 4842) defined 'child' as a consumer under 18 years of age; whether H.3431 as finally enacted retains this exact definition was not independently confirmed against the final statutory text this run.observed
  4. ConfirmedIAPPH.3431 requires default protective settings for minors on design features including usage timers, spending caps, blocking interactions from non-connected accounts, hiding engagement metrics, disabling search-engine indexing, and restricting geolocation visibility, while extending baseline access to these tools to all users.observed
  5. ProbableDataGuidanceCOPPA applies nationally, including South Carolina, to operators collecting personal information from children under 13, operating alongside the state's own minors-focused design-code law.observed

#

Clear AG enforcement powers and a narrow private right of action exist for the new minors' law, but general privacy enforcement capacity and redress mechanisms remain largely undeveloped, and the flagship 2026 law faces active constitutional litigation.

Primary frameworkH.3431 (Social Media Regulation and Age-Appropriate Design Code Act)
Traffic-light rationale — AmberClear AG enforcement powers and a narrow private right of action exist for the new minors' law, but general privacy enforcement capacity and redress mechanisms remain largely undeveloped, and the flagship 2026 law faces active constitutional litigation.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG enforces H.3431 with severe penalties for violations.

Claims (1):

  • The South Carolina Attorney General is empowered to enforce H.3431, with the statute providing for severe penalties for violations.

Enforcement Activity IndexAmber

The AG's office recently joined a multistate $80 million BSA/AML settlement with Block, Inc./Cash App, illustrating active AG enforcement capacity, though not privacy-specific.

Claims (1):

  • The South Carolina Attorney General's office joined a multistate $80 million enforcement settlement against Block, Inc. (Cash App) for Bank Secrecy Act/anti-money-laundering violations, reflecting active state AG involvement in financial-data-adjacent enforcement, though the action arose under BSA/AML rather than data-protection statutes.

Regulator Funding And CapacityAmber

The AG's office comprises over 200 employees and nearly 75 attorneys managing thousands of case files, but no privacy-specific unit or headcount figure was identified.

Claims (1):

  • The South Carolina Attorney General's Office comprises more than 200 employees and nearly 75 attorneys managing thousands of active case files, though no privacy-specific unit or headcount was identified.

Collective Redress And Class ActionsRed

General South Carolina class-action procedure applies but no privacy-specific collective-redress mechanism was identified.

Absence provenance: not recorded. Searched: S, o, u, t, h, , C, a, r, o, l, i, n, a, , c, l, a, s, s, , a, c, t, i, o, n, , d, a, t, a, , p, r, i, v, a, c, y, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s.

Private Right Of ActionAmber

A private right of action exists only for H.3431 dark-pattern violations via the state consumer-protection statute; no general privacy private right of action exists.

Claims (2):

  • H.3431's dark-patterns provisions carry a private right of action by reference to South Carolina's general consumer-protection statute.
  • Beyond H.3431's reference to the state's consumer-protection statute for dark-pattern violations, South Carolina does not provide a general private right of action for other data-privacy harms.

Recent Developments 180DAmber

The dominant recent development is the NetChoice v. South Carolina litigation over H.3431, with EPIC's April 13, 2026 amicus brief defending the law, which remains in force pending resolution.

Claims (1):

  • NetChoice, LLC filed suit against South Carolina seeking to enjoin enforcement of H.3431; EPIC filed an amicus brief defending the law on April 13, 2026, and the law remains in effect pending the litigation's outcome.
Category narrative88 words

The South Carolina Attorney General enforces H.3431 with severe statutory penalties and, for dark-pattern violations, a private right of action via the state's general consumer-protection statute. NetChoice has sued to enjoin the law's enforcement, with EPIC defending it; the law remains in force pending that litigation. The AG's office also participates in multistate financial-sector enforcement (e.g., the Block/Cash App BSA/AML settlement), though this arises under AML rather than data-protection statutes. No general private right of action for broader data-privacy harms, and no dedicated privacy-enforcement funding/headcount data, were identified.

Sources and claims (6)
  1. ConfirmedDataGuidanceThe South Carolina Attorney General is empowered to enforce H.3431, with the statute providing for severe penalties for violations.observed
  2. ConfirmedIAPPH.3431's dark-patterns provisions carry a private right of action by reference to South Carolina's general consumer-protection statute.observed
  3. ConfirmedDataGuidanceNetChoice, LLC filed suit against South Carolina seeking to enjoin enforcement of H.3431; EPIC filed an amicus brief defending the law on April 13, 2026, and the law remains in effect pending the litigation's outcome.observed
  4. ConfirmedSouth Carolina Attorney General's Office (via NAAG)The South Carolina Attorney General's office joined a multistate $80 million enforcement settlement against Block, Inc. (Cash App) for Bank Secrecy Act/anti-money-laundering violations, reflecting active state AG involvement in financial-data-adjacent enforcement, though the action arose under BSA/AML rather than data-protection statutes.observed
  5. ProbableDataGuidanceBeyond H.3431's reference to the state's consumer-protection statute for dark-pattern violations, South Carolina does not provide a general private right of action for other data-privacy harms.observed
  6. ConfirmedNAAGThe South Carolina Attorney General's Office comprises more than 200 employees and nearly 75 attorneys managing thousands of active case files, though no privacy-specific unit or headcount was identified.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – South Carolina
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 16 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (insurance security/breach), sectoral_watch (insurance), adtech/children/algorithmic modules (H.3431) are grounded in T1 statutory anchors (S.C. Code §39-1-90, §38-99-10 et seq., §38-93, H.3431) corroborated by T2 secondary reporting (DataGuidance, IAPP). lawful_processing_and_special_data, data_subject_rights, and cross_border_and_adequacy rely primarily on T2/T3 absence-confirmation sourcing (DataGuidance jurisdiction overview, IAPP breach chart) since no comprehensive statute exists to anchor T1 findings. Federal sectoral overlays (HIPAA, GLBA, COPPA) are asserted at Probable confidence based on general federal-law knowledge rather than a fresh statutory-text search this run.

Unresolved questions (5):

  • Whether House Bill 4696 (comprehensive consumer privacy bill) remains pending, has died, or has been reintroduced in the current South Carolina legislative session.
  • The exact statutory definition of 'minor'/'child' under H.3431 as finally enacted, versus the under-18 definition found in predecessor bill HB 4842.
  • Current procedural status of NetChoice, LLC v. South Carolina (challenging H.3431) since the EPIC amicus filing of April 13, 2026, including whether a preliminary injunction has been granted or denied.
  • Full primary-source verification of S.C. Code §39-1-90's definitions and thresholds directly against the South Carolina Code of Laws (scstatehouse.gov), rather than via secondary summarization.
  • Whether SC Department of Insurance has issued implementing regulations under the Insurance Data Security Act beyond the 2019 cybersecurity rules.

Escalate to primary-source review: yes