Insurance Data Security Act
· About Insurance Data Security Act
Key Takeaways
- The South Carolina Insurance Data Security Act applies to insurance licensees and requires a written information security program, incident response controls, and cybersecurity-event reporting to the South Carolina Department of Insurance. [1][3]
- The statute became effective on 1 January 2019, with a delayed implementation date for the core security-program requirements until 1 July 2019 and certain risk-assessment / third-party-security requirements until 1 July 2020. [3][5]
- A licensee that violates the chapter is subject to administrative penalties under Section 38-2-10, including up to $15,000 per violation for a company licensee and up to $30,000 per violation for a willful company violation, plus suspension or revocation. [8]
- The law reaches many out-of-state insurers doing business in South Carolina because it applies to licensees and includes captive and risk retention group issues in the broader insurance code, although some entities and activities are exempt or partially exempt. [1][2][13]
- As of the available 2026 materials, the core statute remains in force; a 2025–2026 bill to clarify captive insurance company applicability appears in legislative history, but it was not reflected in the code text as an enacted amendment in the sources reviewed. [1][2]
What It Is
The South Carolina Insurance Data Security Act is Chapter 99 of Title 38 of the South Carolina Code, a sector-specific cybersecurity law for insurance licensees that requires information security governance, risk management, incident handling, and notice obligations for cybersecurity events. [1][3] It is enforced through the South Carolina Department of Insurance and the Director’s administrative authority over licensees. [3][8]
The General Assembly enacted the law in 2018, and the Department of Insurance states that Governor Henry McMaster signed it on 3 May 2018; the statute became effective on 1 January 2019. [3][4] The code compilation reflects phased compliance, with licensees given until 1 July 2019 to implement Section 38-99-20 and until 1 July 2020 to implement Section 38-99-20(F), the part tied to annual risk assessment and related controls. [5]
For 2025–2026 status, the official code page remains active and the Department of Insurance still publishes cybersecurity guidance under the Act. [1][3] Legislative materials show a 2025–2026 Bill 4788 to clarify that the Act applies to captive insurance companies unless they qualify for certain exemptions, but the available sources do not show that proposal as enacted into the official chapter text. [2]
Who Must Comply
The Act applies to a licensee, meaning an insurer or other person licensed, authorized, registered, or certified under South Carolina’s insurance code that handles nonpublic information. [1][13] That scope is broad enough to include entities operating through South Carolina insurance authorization even if organized outside the state. [1][2]
The law has an extraterritorial effect in practice because the trigger is licensure or authorization under South Carolina insurance law, not physical headquarters. [1][13] This means an out-of-state insurer, producer, or other covered insurance entity can fall within the chapter if it holds the relevant South Carolina authority and handles covered information. [1][3]
There are exemptions and carve-outs. Section 38-99-70 recognizes exemptions for licensees already subject to and compliant with certain federal cybersecurity regimes or other specified statutes, rules, or guidelines, provided they also submit the required written compliance statement. [13] The legislative record also indicates that captive insurance company coverage has been debated, with 2025–2026 bill text seeking clarification rather than a clearly enacted repeal. [2]
Core Requirements
- Maintain a written information security program. Licensees must develop, implement, and maintain a comprehensive program based on the size and complexity of the licensee, the nature and scope of its activities, and the sensitivity of nonpublic information it handles. [1][3]
- Perform and document risk assessments. The program must include periodic risk identification and assessment, with controls designed to protect nonpublic information and information systems against unauthorized access, use, or disclosure. [1][5]
- Oversee service providers. Licensees must take reasonable steps to select and retain third-party service providers capable of maintaining appropriate safeguards and to require contractual protections where needed. [1]
- Detect, respond to, and investigate cybersecurity events. The statute requires procedures for prompt response, internal investigation, and reporting of cybersecurity events affecting a licensee’s information systems or the nonpublic information in its possession. [1][12]
- Notify the Department of Insurance when a reportable cybersecurity event occurs. The law requires notice to the regulator within the statutory timeframe when a cybersecurity event meets the reporting threshold. [1][12]
- Certify compliance annually. Licensees must file an annual certification of compliance with the Department, or identify deficiencies and remediation plans where permitted by the chapter and related regulatory materials. [3][9]
- Document and retain compliance evidence. The chapter contemplates records supporting the program, risk assessments, incident investigations, and board or senior-management oversight. [1][3]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Act effective | 1 January 2019 | Chapter 99 became operative statewide. [3] | | Core security-program implementation | 1 July 2019 | Licensees had to implement Section 38-99-20. [5] | | Risk assessment / Section 38-99-20(F) implementation | 1 July 2020 | The more detailed risk-assessment-related requirement became operative. [5] | | Ongoing annual certification | annually | Licensees must certify compliance to the Department. [3][9] |
A violation of the chapter is subject to Section 38-2-10 penalties. For a company licensee, the Department may impose up to $15,000 per violation for a negligent violation and up to $30,000 per violation for a willful violation, with possible suspension or revocation. [8] For an individual licensee, the stated maximums are up to $2,500 per violation for a negligent violation and up to $5,000 per violation for a willful violation, with possible suspension or revocation of the license. [8]
The statute also creates regulatory exposure beyond monetary fines, including license suspension or revocation, which can be imposed alone or with a fine. [8] Because the penalties are administrative and tied to the insurance licensing regime, a compliance failure can affect market access, not just cash liability. [8]
How to Comply
- Map your covered entities and data. Identify every South Carolina-insured business line, license status, and category of nonpublic information in scope under Chapter 99. [1][3]
- Build or refresh the written security program. Align the program to the company’s size, complexity, and information risk, and use ISO 27001 controls as the baseline for policy structure, access control, asset inventory, supplier management, logging, and continual improvement. [1]
- Run a formal risk assessment. Use NIST CSF 2.0 functions to organize the assessment and remediation plan across Govern, Identify, Protect, Detect, Respond, and Recover, then document residual risk and executive sign-off. [5]
- Strengthen third-party oversight. Inventory service providers that touch nonpublic information, contract for cybersecurity obligations, and verify monitoring and breach-notification rights. [1]
- Implement incident response and reporting playbooks. Pre-write criteria for reportable cybersecurity events, regulatory notification steps, evidence preservation, legal review, and consumer communications. [1][12]
- Add board and senior-management oversight. Present at least annual cybersecurity reporting to leadership, including material risks, incidents, remediation status, and certification readiness. [1][3]
- Use ISO 42001 where AI or automated controls are part of the security stack. If the insurer uses AI for fraud monitoring, access review, or SOC tooling, ISO 42001 helps govern model risk, lifecycle controls, and accountability even though the statute itself is technology-neutral. [1]
- Prepare the annual certification package early. Maintain audit-ready evidence for policies, tests, training, incidents, vendor due diligence, and remediation so the annual filing is a verification exercise rather than a scramble. [3][9]
Related Regulations
- Gramm-Leach-Bliley Act Safeguards Rule: This federal rule overlaps with the Act’s security-program and vendor-management requirements, and entities already subject to it may qualify for some state-law exemption treatment if they meet the chapter’s conditions. [13]
- South Carolina insurance breach-notification provisions: General state insurance breach rules can overlap with Chapter 99 incident response and notice duties, so companies should harmonize reporting triggers and timelines. [1][12]
- NAIC Insurance Data Security Model Law: The South Carolina act closely tracks the model framework, so multistate insurers often build one control set and map state-specific reporting and certification differences. [3]
- State data-breach notification laws: If a cybersecurity event affects South Carolina residents outside the insurance context, separate breach-notification duties may also apply, creating parallel notice workflows. [12]
- Captive insurance statutes: The 2025–2026 legislative materials suggest ongoing attention to whether captive insurers are fully in scope, so captive structures should confirm current applicability before relying on an exemption theory. [2]
FAQ
Does the South Carolina Insurance Data Security Act apply to companies outside South Carolina?
Yes, if the company is a South Carolina licensee, authorized person, or otherwise within the insurance code’s scope. The statute is tied to licensure and regulated insurance activity, so location outside the state does not avoid coverage. [1][13]
Does the law require annual certification?
Yes. The Department of Insurance states that licensees must submit an annual certification of compliance, and the chapter’s compliance framework is built around ongoing documentation rather than one-time implementation. [3][9]
What is a reportable cybersecurity event?
A reportable cybersecurity event is one that affects a licensee’s information system or nonpublic information and meets the chapter’s reporting threshold. The statute requires investigation and, when applicable, notice to the Department within the prescribed period. [1][12]
Are captives covered?
The answer is unsettled in the legislative materials reviewed. A 2025–2026 bill sought to clarify that the Act applies to captive insurance companies unless they qualify for certain exemptions, which indicates the issue remains active rather than clearly resolved in the sources available. [2]
What happens if a licensee violates the Act?
Violations are subject to administrative penalties under Section 38-2-10, including fines and possible license suspension or revocation. For companies, the statutory maximum reaches $15,000 per negligent violation and $30,000 per willful violation. [8]
Does compliance with another cybersecurity law automatically satisfy this Act?
Sometimes, but only if the licensee fits a statutory exemption and satisfies the chapter’s conditions, including any required written compliance statement. The exemption is not automatic merely because another framework exists. [13]
Sources
- South Carolina Code, Chapter 99, Insurance Data Security Act
- South Carolina Department of Insurance, Cybersecurity
- South Carolina Legislature, 2025–2026 Bill 4788, previous version
- South Carolina Code, Section 38-99-30, Investigation of cybersecurity events
- South Carolina Code, Section 38-99-70, Exemptions
- South Carolina Department of Insurance, Industry Presentation on the Insurance Data Security Law
- South Carolina Law Review, analysis of the Act
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)