Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View

South Dakota's Data Protection Law: A Comprehensive Guide

Published December 18, 2024 / Updated January 7, 2026

Contributors

Anas Baig

Product Marketing Manager at Securiti

Muhammad Ismail

Assoc. Data Privacy Analyst at Securiti

Adeel Hasan

Sr. Data Privacy Analyst at Securiti

CIPM, CIPP/Canada

Currently, South Dakota doesn't have a comprehensive data privacy law. You can visit our US State Privacy Laws Tracker to stay updated on the progress of privacy-related bills across the US.

Data protection laws have become a necessity in the current era. More and more countries are formulating or implementing such laws to enhance data safeguards and provide consumers with privacy rights.

Data privacy and protection laws exist in the United States at different levels.

Federal and sectoral laws like the Children’s Online Privacy Protection Act and the Fair Credit Reporting Act have limited material and territorial scopes. State-level comprehensive data privacy laws, with wider application and scope, include the California Consumer Protection Act and the Colorado Privacy Act.

However, not every state has an established comprehensive privacy law. In such an event, businesses operating in the state should still follow the best compliance practices to stay compliant with federal and sectoral laws and build customer trust.

The blog aims to offer readers a brief overview of the current status of data privacy laws in South Dakota.

Understanding South Dakota's Data Protection Law

South Dakota Breach Notification Law (Section 22-40-20 of South Dakota Codified Laws) mandates that organizations must notify data owners not later than sixty days from the discovery or notification of the breach of system security unless a longer period of time is required due to the legitimate needs of law enforcement, in the event their system security is breached due to any unauthorized access, compromising the security, confidentiality, and integrity of the data. Notification laws are common in most states as the regulation enables organizations to be proactive in preventing and mitigating data breach incidents and also notifying the impacted individuals so they may take necessary measures to protect their sensitive data accordingly.

The Children’s Online Privacy Protection Act (COPPA) is a federal data protection law that emphasizes protecting minors' privacy, i.e., children under the age of 13 years of age. The privacy of minors is taken seriously not only in the US but also in other countries globally. Hence, businesses must implement appropriate privacy and security controls around the data of minors to prevent any legal consequences.

Similar other laws, such as the Fair Credit Reporting Act (FCRA) and Gramm-Leach-Bliley Act (GLBA), exist to protect certain categories of personal and sensitive personal data.

Best Practices

  • Businesses must learn more about federal, sectoral, and state-specific laws and examine the territorial scope.
  • Businesses must conduct a thorough data asset and sensitive data discovery process to identify all data in the environment. Further data classification and cataloging enable businesses to categorize the data with labels and tags.
  • Businesses should also create and automate privacy policies that inform users about data collection and processing practices and purposes.
  • Appropriate security measures should be employed, such as data security policies, access policies and controls, etc.
  • Businesses must minimize their data collection to only what is reasonably necessary and specific to the purpose. This allows businesses to reduce risks associated with collecting large volumes.

Conclusion

Though South Dakota has yet to establish a state-wide data privacy law, it recognizes the importance of residents’ data protection. Hence, businesses must proactively streamline their privacy practices to meet compliance and build trust.

Share
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox

Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
Scaling Privacy Operations for the Agentic Era View More
Scaling Privacy Operations for the Agentic Era
Why Trusted AI Requires Operational Governance AI is creating extraordinary opportunities for organizations to move faster, unlock value from data, and transform how work...
View More
Building Sovereign AI with HPE Private Cloud AI and Veeam Securiti Gencore AI
How HPE Private Cloud AI, NVIDIA acceleration, and Veeam Securiti Gencore AI support secure, governed enterprise AI with policy enforcement across RAG, assistant, and agentic workflows.
View More
Data Breach Incident Response Checklist: A Practical Guide for Modern Enterprises
Discover the practical steps to building a successful data breach response plan with this comprehensive Data Breach Incident Response Checklist.
Top 5 Best Practices to Prevent a Data Breach View More
Top 5 Best Practices to Prevent a Data Breach
Discover the best practices to prevent a data breach and stay off the regulatory radar. Adopt robust data security measures today to avoid noncompliance...
View More
Securing Enterprise SaaS AI Agents: A Practical Guide for Security and Governance Leaders
A practical guide for security and governance leaders to secure SaaS AI agents - manage shadow AI, enforce least privilege, prevent data leakage, and...
The Adaptive Privacy Playbook: From Silos to Unified Command View More
The Adaptive Privacy Playbook: From Silos to Unified Command
Transform fragmented privacy operations into a unified, adaptive program. Centralize controls, automate compliance and gain real-time visibility across data and AI systems.
How Securiti Complements Purview Across the Data Estate View More
How Securiti Complements Purview Across the Data Estate
Discover how to extend Microsoft Purview beyond M365, close governance gaps, enforce policies consistently, and secure data across your enterprise.
View More
ROT Data Minimization
Eliminate redundant, obsolete, and trivial (ROT) data to improve AI accuracy, reduce storage costs, and minimize security and compliance risks at scale.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New