South Carolina Statutes

§ 38-99-20 — Information security program; compliance.

South Carolina § 38-99-20
JurisdictionSouth Carolina
Title 38INSURANCE
Ch. 99INSURANCE DATA SECURITY ACT

This text of South Carolina § 38-99-20 (Information security program; compliance.) is published on Counsel Stack Legal Research, covering South Carolina primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
S.C. Code Ann. § 38-99-20 (2026).

Text

(A)Commensurate with the size and complexity of the licensee, the nature and scope of the licensee's activities, including its use of third-party service providers, and the sensitivity of the nonpublic information used by the licensee or in the licensee's possession, custody, or control, each licensee shall develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment and that contains administrative, technical, and physical safeguards for the protection of nonpublic information and the licensee's information system.
(B)A licensee's information security program must be designed to:
(1)protect the security and confidentiality of nonpublic information and the security of the information system;
(2)protect against threats or

Free access — add to your briefcase to read the full text and ask questions with AI

Legislative History

HISTORY: 2018 Act No. 171 (H.4655), SECTION 3, eff January 1, 2019. Editor's Note 2018 Act No. 171, SECTIONS 1 to 2, and 4, provide as follows: "SECTION 1. The purpose and intent of this act is to establish standards for data security and standards for the investigation of and notification to the director of a cybersecurity event applicable to licensees. This act may not be construed to create or imply a private cause of action for a violation of its provisions nor may it be construed to curtail a private cause of action which would otherwise exist in the absence of this act. "SECTION 2. This act is known and may be cited as the 'South Carolina Insurance Data Security Act'." "SECTION 4. Licensees have until July 1, 2019, to implement Section 38-99-20 of this act and until July 1, 2020, to implement Section 38-99-20(F) of this act."

Nearby Sections

10
View on official source ↗

Cite This Page — Counsel Stack

Bluebook (online)
South Carolina § 38-99-20, Counsel Stack Legal Research, https://law.counselstack.com/statute/sc/99/38-99-20.