🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-SD · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 11 sources retrieved model claude-sonnet-5 ·

United States – South Dakota

US-SD schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: AIC

Last updated · 10 categories · 0 claims · 11 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A functioning breach-notification regime and applicable federal FTC authority exist, but there is no comprehensive material/territorial scope regime or registration framework at state level.

Primary frameworkFederal FTC Act Section 5 + South Dakota data-breach notification statute (SDCL §22-40-1 et seq.)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberA functioning breach-notification regime and applicable federal FTC authority exist, but there is no comprehensive material/territorial scope regime or registration framework at state level.

Sub-modules (5)

Regulator And AuthorityAmber

No dedicated South Dakota DPA exists; the South Dakota Attorney General exercises general consumer-protection and breach-notification enforcement, while the FTC is the de facto federal privacy regulator reaching South Dakota-based conduct.

Claims (1):

  • CLM-US-SD-4f3a9c12 (claim on file)

Act And InstrumentsAmber

The FTC Act Section 5 baseline and South Dakota's 2018 breach-notification statute (SDCL §22-40-1 et seq.) constitute the operative instruments; South Dakota was one of the last two states to adopt a breach law.

Claims (3):

  • CLM-US-SD-7b6e2d88 (claim on file)
  • CLM-US-SD-1a9f5e33 (claim on file)
  • CLM-US-SD-8c2b7f01 (claim on file)

Material ScopeRed

Material scope is limited to the breach-notification statute's definition of computerized personal information; no independently-verified statutory text defining broader material scope (e.g., general 'personal data' categories) was retrievable in this run.

Absence provenance: not recorded. Searched: A, t, t, e, m, p, t, e, d, , t, o, , r, e, t, r, i, e, v, e, , f, u, l, l, , t, e, x, t, , o, f, , S, D, C, L, , C, h, a, p, t, e, r, , 2, 2, -, 4, 0, , d, e, f, i, n, i, n, g, , ', p, e, r, s, o, n, a, l, , i, n, f, o, r, m, a, t, i, o, n, ', , s, c, o, p, e, ;, , o, n, l, y, , s, e, c, o, n, d, a, r, y, , a, g, g, r, e, g, a, t, o, r, , c, i, t, a, t, i, o, n, s, , (, D, a, t, a, G, u, i, d, a, n, c, e, ), , w, e, r, e, , r, e, a, c, h, a, b, l, e, ,, , n, o, t, , f, u, l, l, , s, t, a, t, u, t, o, r, y, , t, e, x, t, ..

Territorial ScopeRed

No independently verified statutory text on territorial application (e.g., extraterritorial reach to out-of-state controllers processing South Dakota residents' data) was retrievable in this run.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , b, r, e, a, c, h, , s, t, a, t, u, t, e, , t, e, r, r, i, t, o, r, i, a, l, -, s, c, o, p, e, /, e, x, t, r, a, t, e, r, r, i, t, o, r, i, a, l, i, t, y, , p, r, o, v, i, s, i, o, n, s, ;, , f, u, l, l, , s, t, a, t, u, t, o, r, y, , t, e, x, t, , n, o, t, , r, e, a, c, h, a, b, l, e, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..

Regulator Registration And FilingRed

Consistent with the absence of a comprehensive privacy statute, South Dakota imposes no general controller/processor registration or filing regime with a state privacy authority.

Claims (1):

  • CLM-US-SD-3d4e6a77 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative71 words

South Dakota has no comprehensive state consumer-privacy statute and no dedicated state data-protection authority. The operative framework is (a) the federal FTC Act Section 5 unfair/deceptive-practices baseline, enforced by the FTC, and (b) South Dakota's own data-breach notification statute (SDCL Chapter 22-40), enforced by the South Dakota Attorney General under general consumer-protection authority. IAPP's comprehensive state privacy tracker does not list South Dakota among the states with enacted comprehensive privacy laws.

#

General lawful-processing regime is absent (red), but a sector-specific special-category development (genetic data) has emerged in 2026, warranting amber rather than uniform red.

Traffic-light rationale — AmberGeneral lawful-processing regime is absent (red), but a sector-specific special-category development (genetic data) has emerged in 2026, warranting amber rather than uniform red.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases for processing exist under South Dakota state law.

Claims (1):

  • CLM-US-SD-9e1c8b44 (claim on file)

Special CategoriesAmber

A 2026 South Dakota genetic-data protection bill was introduced to the Senate and subsequently reported as signed into law, representing an emerging special-category (genetic data) overlay; precise scope, obligations, and effective date are unverified.

Claims (1):

  • CLM-US-SD-2f7d3c99 (claim on file)

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation/anonymisation safe-harbour definitions exist at South Dakota state level.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , a, n, o, n, y, m, i, s, a, t, i, o, n, /, d, e, -, i, d, e, n, t, i, f, i, c, a, t, i, o, n, , s, a, f, e, , h, a, r, b, o, u, r, , p, r, o, v, i, s, i, o, n, s, ;, , n, o, n, e, , i, d, e, n, t, i, f, i, e, d, , i, n, , a, v, a, i, l, a, b, l, e, , s, o, u, r, c, e, s, ..

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative56 words

South Dakota has not enacted a general lawful-basis, consent-threshold, or special-category framework of the GDPR/CCPA type. The one notable 2026 development is state legislation addressing genetic data, following a Senate bill on genetic data protection that was reported signed into law by the Governor; full statutory text and scope were not independently verified in this run.

#

Complete absence of a comprehensive consumer-rights regime at state level.

Traffic-light rationale — RedComplete absence of a comprehensive consumer-rights regime at state level.

Sub-modules (5)

Access RightRed

No general state-law subject-access-request right exists.

Claims (1):

  • CLM-US-SD-6a8b1e22 (claim on file)

Rectification And ErasureRed

No general state-law rectification or erasure right exists.

Claims (1):

  • CLM-US-SD-6a8b1e22 (claim on file)

Restriction And ObjectionRed

No general state-law restriction or objection (including profiling opt-out) right exists.

Claims (1):

  • CLM-US-SD-6a8b1e22 (claim on file)

Data PortabilityRed

No general state-law portability right exists.

Claims (1):

  • CLM-US-SD-6a8b1e22 (claim on file)

Deadlines And Response WindowsRed

No statutory response-window framework exists for consumer rights requests, as no underlying rights regime exists to attach deadlines to.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , S, o, u, t, h, , D, a, k, o, t, a, , c, o, n, s, u, m, e, r, , p, r, i, v, a, c, y, , r, i, g, h, t, s, , r, e, s, p, o, n, s, e, , d, e, a, d, l, i, n, e, s, ;, , n, o, n, e, , f, o, u, n, d, , a, b, s, e, n, t, , a, n, , u, n, d, e, r, l, y, i, n, g, , c, o, m, p, r, e, h, e, n, s, i, v, e, , s, t, a, t, u, t, e, ..

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative30 words

South Dakota confers no general state-law rights of access, rectification, erasure, restriction, objection, or portability to consumers with respect to personal data, as no comprehensive consumer-privacy statute has been enacted.

#

Breach notification is a live, in-force obligation; all other accountability duties are absent at state level.

Primary frameworkSouth Dakota data-breach notification statute (SDCL §22-40-1 et seq.)
Supervisory authoritySouth Dakota Attorney General
Traffic-light rationale — AmberBreach notification is a live, in-force obligation; all other accountability duties are absent at state level.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle statute exists at state level.

Claims (1):

  • CLM-US-SD-0b3e7a55 (claim on file)

Dpo RequirementsRed

No DPO appointment threshold or independence requirement exists at state level.

Claims (1):

  • CLM-US-SD-0b3e7a55 (claim on file)

Ropa RequirementsRed

No records-of-processing-activities requirement exists at state level.

Claims (1):

  • CLM-US-SD-0b3e7a55 (claim on file)

Joint Controller ArrangementsRed

No joint-controller statutory framework exists at state level.

Claims (1):

  • CLM-US-SD-0b3e7a55 (claim on file)

Security MeasuresRed

No general technical/organisational security-measures statute exists beyond the implicit expectations underlying the breach-notification law.

Claims (1):

  • CLM-US-SD-0b3e7a55 (claim on file)

Breach NotificationAmber

South Dakota's breach-notification statute requires disclosure of security breaches compromising unencrypted computerized personal information to affected South Dakota residents; precise notification deadlines and AG-notice thresholds were not independently verified from full statutory text in this run.

Claims (1):

  • CLM-US-SD-5c9d4f66 (claim on file)

Retention And DisposalRed

No general statutory retention-limit or disposal-duty framework exists at state level.

Claims (1):

  • CLM-US-SD-0b3e7a55 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative43 words

Outside of breach notification, South Dakota imposes no general statutory duties on controllers or processors regarding DPIAs, DPO appointment, records of processing, joint-controller arrangements, minimum security-measure standards, or retention/disposal limits. The breach-notification statute (SDCL §22-40-1 et seq.) is the one operative duty-bearing instrument.

#

No state-level transfer regime exists; federal-level mechanisms are out of scope for a state JID.

Traffic-light rationale — RedNo state-level transfer regime exists; federal-level mechanisms are out of scope for a state JID.

Sub-modules (6)

Transfer MechanismsRed

No state-specific transfer mechanism exists.

Claims (1):

  • CLM-US-SD-4d8f2c11 (claim on file)

Adequacy ReceivedRed

Not applicable at state level; adequacy determinations are a federal/EU-level construct.

Claims (1):

  • CLM-US-SD-4d8f2c11 (claim on file)

Adequacy GrantedRed

Not applicable at state level.

Claims (1):

  • CLM-US-SD-4d8f2c11 (claim on file)

Sccs And BcrsRed

No state-level SCC/BCR framework exists.

Claims (1):

  • CLM-US-SD-4d8f2c11 (claim on file)

Transfer Impact AssessmentRed

No state-level TIA requirement exists.

Claims (1):

  • CLM-US-SD-4d8f2c11 (claim on file)

Data LocalisationRed

No state-level data-localisation mandate exists.

Claims (1):

  • CLM-US-SD-4d8f2c11 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative35 words

South Dakota has no state-specific cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Any cross-border transfer analysis (e.g., EU-U.S. Data Privacy Framework) operates at the federal level, outside this state-level baseline.

#

No independent state-level sectoral overlays exist except the emerging genetic-data statute; federal sectoral law is out of scope for this JID.

Traffic-light rationale — AmberNo independent state-level sectoral overlays exist except the emerging genetic-data statute; federal sectoral law is out of scope for this JID.

Sub-modules (7)

Financial Sector OverlayRed

No South Dakota-specific financial-sector privacy overlay identified beyond federal GLBA (out of scope for this JID).

Claims (1):

  • CLM-US-SD-7e1a9b33 (claim on file)

Health Sector OverlayAmber

No South Dakota-specific health-sector privacy overlay beyond federal HIPAA (out of scope), except the 2026 genetic-data protection legislation which touches health-adjacent genetic information.

Claims (2):

  • CLM-US-SD-7e1a9b33 (claim on file)
  • CLM-US-SD-3c6d8e77 (claim on file)

Telecoms And EprivacyRed

No South Dakota-specific telecoms/ePrivacy overlay identified.

Claims (1):

  • CLM-US-SD-7e1a9b33 (claim on file)

Employment DataRed

No South Dakota-specific employment-data privacy overlay identified.

Claims (1):

  • CLM-US-SD-7e1a9b33 (claim on file)

Credit And ScoringRed

No South Dakota-specific credit/scoring privacy overlay identified beyond federal FCRA (out of scope).

Claims (1):

  • CLM-US-SD-7e1a9b33 (claim on file)

EducationRed

No South Dakota-specific education-sector privacy overlay identified.

Claims (1):

  • CLM-US-SD-7e1a9b33 (claim on file)

InsuranceRed

No South Dakota-specific insurance-sector privacy overlay identified.

Claims (1):

  • CLM-US-SD-7e1a9b33 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative56 words

Federal sectoral statutes (HIPAA, GLBA, COPPA) apply to covered entities operating in South Dakota but are federal-level frameworks properly attributed to the US federal JID rather than this state baseline. The notable 2026 South Dakota-specific sectoral development is genetic-data protection legislation, apparently targeting direct-to-consumer genetic testing/analysis, paralleling similar statutes in other states; full scope is unverified.

#

No state-level adtech/commercial-privacy regime exists.

Traffic-light rationale — RedNo state-level adtech/commercial-privacy regime exists.

Sub-modules (6)

Cookies And TrackersRed

No state-level cookie/tracker consent law exists.

Claims (1):

  • CLM-US-SD-9f2b4a88 (claim on file)

Dark PatternsRed

No state-level dark-pattern prohibition exists.

Claims (1):

  • CLM-US-SD-9f2b4a88 (claim on file)

Opt Out SignalsRed

No state-level universal opt-out-signal (e.g., GPC) recognition requirement exists.

Claims (1):

  • CLM-US-SD-9f2b4a88 (claim on file)

Clean Rooms And DcrRed

No state-level clean-room/data-collaboration-room rules exist.

Claims (1):

  • CLM-US-SD-9f2b4a88 (claim on file)

Cross Context AdvertisingRed

No state-level 'sale'/'share' cross-context-advertising framework exists.

Claims (1):

  • CLM-US-SD-9f2b4a88 (claim on file)

Direct MarketingRed

No state-level direct-marketing consent/suppression statute exists beyond general federal telemarketing/spam law.

Claims (1):

  • CLM-US-SD-9f2b4a88 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative38 words

South Dakota has not enacted state-level cookie/tracker consent, dark-pattern, opt-out-signal (e.g., GPC), clean-room, cross-context-advertising, or direct-marketing-specific privacy statutes. General marketing communications remain governed by federal law (TCPA, CAN-SPAM) and FTC Section 5, which are outside this state-level baseline.

#

Broad algorithmic/biometric/ADM regime is absent (red), but the emerging genetic-data statute provides a partial, unverified signal.

Traffic-light rationale — AmberBroad algorithmic/biometric/ADM regime is absent (red), but the emerging genetic-data statute provides a partial, unverified signal.

Sub-modules (6)

Profiling RestrictionsRed

No state-level profiling-restriction statute (Art 22-analogue) exists.

Claims (1):

  • CLM-US-SD-1e5c7d22 (claim on file)

Automated Decision Making TransparencyRed

No state-level ADM transparency or explanation-right requirement exists.

Claims (1):

  • CLM-US-SD-1e5c7d22 (claim on file)

Ai Risk AssessmentsRed

No state-level AI-specific risk-assessment law exists.

Claims (1):

  • CLM-US-SD-1e5c7d22 (claim on file)

Biometric RegimeRed

No state-level biometric-data statute (facial recognition, fingerprint, gait) exists.

Claims (1):

  • CLM-US-SD-1e5c7d22 (claim on file)

Genetic DataAmber

A South Dakota genetic-data protection bill was introduced to the Senate in early 2026 and reportedly signed into law by the Governor; precise scope (e.g., direct-to-consumer genetic testing companies), consent requirements, and effective date were not independently verified from full statutory text in this run.

Claims (2):

  • CLM-US-SD-2f7d3c99 (claim on file)
  • CLM-US-SD-3c6d8e77 (claim on file)

State Surveillance CarveoutsRed

No South Dakota-specific state-surveillance carveout statute was identified in this run.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , s, t, a, t, e, -, s, u, r, v, e, i, l, l, a, n, c, e, /, n, a, t, i, o, n, a, l, -, s, e, c, u, r, i, t, y, , d, a, t, a, , c, a, r, v, e, o, u, t, , p, r, o, v, i, s, i, o, n, s, ;, , n, o, n, e, , i, d, e, n, t, i, f, i, e, d, ..

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative41 words

South Dakota has not enacted a biometric-privacy statute, AI-specific risk-assessment law, or automated-decision-making transparency requirement applicable to private-sector processing. The 2026 genetic-data protection legislation is the one relevant development, touching the genetic-data sub-module; its interaction with biometric/ADM governance is otherwise unverified.

#

No South Dakota-specific children's or vulnerable-groups data-protection regime exists.

Traffic-light rationale — RedNo South Dakota-specific children's or vulnerable-groups data-protection regime exists.

Sub-modules (5)

Age VerificationRed

No state-level age-verification statute exists.

Claims (1):

  • CLM-US-SD-8a4f6b99 (claim on file)

Minor Profiling BansRed

No state-level minor-profiling ban exists.

Claims (1):

  • CLM-US-SD-8a4f6b99 (claim on file)

Education SettingsRed

No state-level education-settings-specific data-protection rule was identified.

Claims (1):

  • CLM-US-SD-8a4f6b99 (claim on file)

Dependent AdultsRed

No state-level dependent-adults (elderly, mentally incapacitated) data-protection statute was identified.

Claims (1):

  • CLM-US-SD-8a4f6b99 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative32 words

South Dakota has not enacted a state-specific children's online privacy, age-verification, parental-consent, minor-profiling, education-settings, or dependent-adults data-protection statute. Federal COPPA governs children's data processing at the federal level, outside this state-level baseline.

#

Federal enforcement machinery is robust; state-specific enforcement activity and capacity data are thin, and no private right of action was confirmed.

Primary frameworkFTC Act Section 5 + South Dakota breach-notification statute
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal enforcement machinery is robust; state-specific enforcement activity and capacity data are thin, and no private right of action was confirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The FTC can pursue injunctive relief, mandated compliance programs, and civil penalties for order violations; the South Dakota AG enforces breach-notification and consumer-protection law under general state authority.

Claims (2):

  • CLM-US-SD-6d3e9c44 (claim on file)
  • CLM-US-SD-2b7f1a66 (claim on file)

Enforcement Activity IndexRed

No South Dakota-specific 12-month enforcement-activity index (major decisions, fines) was identified in this run.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , p, r, i, v, a, c, y, /, b, r, e, a, c, h, , e, n, f, o, r, c, e, m, e, n, t, , a, c, t, i, o, n, s, , 2, 0, 2, 5, -, 2, 0, 2, 6, ;, , n, o, , s, t, a, t, e, -, s, p, e, c, i, f, i, c, , e, n, f, o, r, c, e, m, e, n, t, , d, e, c, i, s, i, o, n, s, , w, e, r, e, , f, o, u, n, d, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..

Regulator Funding And CapacityRed

No South Dakota AG privacy-unit funding or headcount data was identified in this run.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , c, o, n, s, u, m, e, r, -, p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , f, u, n, d, i, n, g, /, s, t, a, f, f, i, n, g, , d, a, t, a, ;, , n, o, n, e, , i, d, e, n, t, i, f, i, e, d, , v, i, a, , a, l, l, o, w, l, i, s, t, e, d, , s, o, u, r, c, e, s, ..

Collective Redress And Class ActionsRed

No South Dakota-specific collective-redress or class-action mechanism specific to data-protection claims was identified.

Absence provenance: not recorded. Searched: S, e, a, r, c, h, e, d, , f, o, r, , S, o, u, t, h, , D, a, k, o, t, a, , d, a, t, a, -, b, r, e, a, c, h, , c, l, a, s, s, -, a, c, t, i, o, n, , m, e, c, h, a, n, i, s, m, s, ;, , n, o, n, e, , s, p, e, c, i, f, i, c, , t, o, , s, t, a, t, e, , b, r, e, a, c, h, , s, t, a, t, u, t, e, , i, d, e, n, t, i, f, i, e, d, ..

Private Right Of ActionAmber

South Dakota's breach-notification statute does not appear to create an express private right of action; enforcement responsibility rests with the Attorney General, though this was not independently confirmed against full statutory text.

Claims (1):

  • CLM-US-SD-0c8b6a11 (claim on file)

Recent Developments 180DAmber

Within the preceding 180 days, the principal South Dakota development is the introduction and reported signing into law of a genetic-data protection bill (reported March 2026).

Claims (1):

  • CLM-US-SD-5f9d3e88 (claim on file)

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative62 words

The FTC holds broad federal investigative and enforcement powers under Section 5 reaching South Dakota-based conduct, while the South Dakota Attorney General enforces the state's breach-notification statute and general consumer-protection law, including through multistate NAAG-coordinated actions. The most significant 2026 South Dakota-specific development is the genetic-data protection bill signed into law; no South Dakota-specific enforcement-activity index or regulator funding/capacity data was identified.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – South Dakota
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 28 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsdeadlines and response windows
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and enforcement_and_redress rest on T1 (FTC.gov) and T2 (NAAG, DataGuidance statute citation) anchors. lawful_processing_and_special_data, sectoral_watch, and algorithmic_biometric_and_surveillance_governance rely on a single T3 DataGuidance headline for the 2026 genetic-data bill, with full bill text unverified. data_subject_rights, cross_border_and_adequacy, adtech_and_commercial_privacy, and children_and_vulnerable_groups are grounded in T3 IAPP negative evidence (absence from comprehensive-law trackers) rather than direct T1 statutory text, since no comprehensive statute exists to cite directly.

Unresolved questions (4):

  • What is the bill number, precise scope (e.g., DTC genetic testing companies vs. general genetic data), obligations, and effective date of South Dakota's 2026 genetic-data protection legislation?
  • Does SDCL §22-40-1 et seq. include a specific notification deadline (e.g., number of days) and an Attorney-General notice threshold, and does it include an encryption safe harbor?
  • Does South Dakota's breach-notification statute create any private right of action, or is enforcement exclusively vested in the Attorney General?
  • Has the South Dakota legislature introduced any comprehensive consumer-privacy bill (CCPA/CPRA-style) in the 2026 session that has not yet been captured by IAPP's tracker?

Escalate to primary-source review: yes