South Dakota · verified official-source register

South Dakota Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

South Dakota case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Blackbaud

Date
2023-10-05
Amount
$495 million multistate settlement; South Dakota's share is almost $372,000 (announced as $372,000)
Legal basis
state consumer protection laws, breach notification laws, and HIPAA rules

Why the action was brought

Blackbaud’s 2020 data breach exposed the personal and financial information of consumers connected to more than 13,000 customers. The lawsuit alleged that Blackbaud violated state consumer protection, breach notification, and HIPAA requirements, failed to implement reasonable data security, did not remediate known security gaps, and failed to provide timely, complete, or accurate breach information.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Equifax

Date
2019-07-22
Amount
Consumer Restitution Fund of up to $425 million, including $300 million dedicated to consumer redress and up to an additional $125 million; $175 million payment to the states, including $1,000,000.00 for South Dakota
Legal basis
No statutes or laws cited in the document

Why the action was brought

Equifax’s 2017 data breach exposed social security numbers, names, dates of birth, addresses, credit card numbers, and some driver’s license numbers of more than 147 million consumers. Equifax failed to maintain a reasonable security system, patch a critical software vulnerability, and replace monitoring software, allowing attackers to remain undetected for 76 days.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Target Corporation

Date
not stated in the official release
Amount
$18.5 million settlement; South Dakota’s share: $174,248
Legal basis
none stated

Why the action was brought

Cyber attackers accessed Target’s gateway server through credentials stolen from a third-party vendor, exploited weaknesses in Target’s system, accessed a customer service database, installed malware, and captured full names, telephone numbers, email and mailing addresses, payment card numbers, expiration dates, CVV1 codes, and encrypted debit PINs, creating potential financial harm.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.