South Carolina · verified official-source register

South Carolina Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

South Carolina case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Marriott International, Inc.

Date
2024-10-09
Amount
$52 million; South Carolina will receive $767,458.00
Legal basis
state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

Marriott’s Starwood guest reservation database was breached after intruders remained undetected from July 2014 through September 2018, affecting 131.5 million U.S. guest records, including contact, birth-date, reservation, preference, passport, and payment-card information. Attorneys general alleged Marriott failed to implement reasonable data security, remediate deficiencies, and comply with applicable breach-notification requirements.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

23andMe

Date
2026-07-17
Amount
$18 million recovery from available bankruptcy funds; South Carolina will receive $280,000. The settlement includes $150 million in allowed claims for states and a separate $46.75 million class-action settlement for affected U.S. consumers.
Legal basis
No statutes or laws cited in the document.

Why the action was brought

A 2023 data breach compromised genetic data and other customer information for 6.9 million consumers worldwide, including 80,181 South Carolinians; some data was sold on the dark web. Investigators found inadequate credential-stuffing safeguards, rate limiting, intrusion prevention, logging, monitoring, vulnerability remediation, unusual-login investigation, and design-feature testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Blackbaud

Date
2023-10-05
Amount
$49.5 million payment to states; South Carolina will receive $730,449.00
Legal basis
State consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s customers’ contact and demographic information, Social Security numbers, driver’s license numbers, financial, employment and wealth information, donation history, and protected health information were exposed in a 2020 ransomware event. Attorneys general alleged Blackbaud failed to implement reasonable security, remediate known gaps, and provide timely, complete, accurate breach information, delaying or preventing consumer notification.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.