South Carolina Statutes

§ 38-99-40 — Notification requirements following cybersecurity event.

South Carolina·Title 38 INSURANCE·Ch. 99 INSURANCE DATA SECURITY ACT
(A)A licensee shall notify the director no later than seventy-two hours after determining that a cybersecurity event has occurred when either of the following criteria are met:
(1)South Carolina is the licensee's state of domicile in the case of an insurer, or the licensee's home state in the case of a producer; or (2) the licensee reasonably believes that the nonpublic information involved is of no less than two hundred and fifty consumers residing in this State, and the cybersecurity event:
(a)impacts the licensee of which notice is required to be provided to any governmental body, self-regulatory agency, or any other supervisory body pursuant to state or federal law; or (b) has a reasonable likelihood of materially harming a consumer residing in this State or a material part of the n

Free access — add to your briefcase to read the full text and ask questions with AI

South Carolina § 38-99-40 (Notification requirements following cybersecurity event.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Legislative History

HISTORY: 2018 Act No. 171 (H.4655), SECTION 3, eff January 1, 2019. Editor's Note 2018 Act No. 171, SECTIONS 1 and 2, provide as follows: "SECTION 1. The purpose and intent of this act is to establish standards for data security and standards for the investigation of and notification to the director of a cybersecurity event applicable to licensees. This act may not be construed to create or imply a private cause of action for a violation of its provisions nor may it be construed to curtail a private cause of action which would otherwise exist in the absence of this act. "SECTION 2. This act is known and may be cited as the 'South Carolina Insurance Data Security Act'."

Nearby Sections

10
View on official source ↗