South Dakota buyer guide
Outsourcing software development from South Dakota
A South Dakota guide to international software and AI outsourcing: genetic-material consent, supplier custody, breach evidence, future interoperability, cost, and exit.

South Dakota outsourcing at a glance
| Proposed work | First buyer decision | Evidence required before access |
|---|---|---|
| Ordinary software, automation, analytics, support, or AI work outside the special material, genetic, social-platform, or breach lanes | Prove the clean boundary and keep acceptance and release with the buyer | Work package, identities and locations, repositories, synthetic data, secrets, dependencies, build path, tests, acceptance, release owner, recovery, and exit |
| Direct-to-consumer genetic testing product or service | Determine whether the actual company, consumer, biological sample, genetic data, activity, and exception fall within sections 37-24-59 through 37-24-64 | Applicability record, sample and data inventory, consumer-facing notices, consent purpose, service providers, custody locations, security program, access, deletion, revocation, destruction, and reconciliation evidence |
| Service provider handling a covered sample, genetic data, or consumer identity | Map the exact contract, possession, service, confidentiality obligation, people, tools, locations, copies, and return path | Named contributors, chain of custody, data lineage, instruction, permitted action, access, confidentiality, transfer, incident route, revocation propagation, deletion or destruction, and buyer verification |
| Possible breach involving South Dakota personal or protected information | Return preserved technical facts immediately; do not let the supplier decide whether the statutory breach or harm path is satisfied | Discovery time, information holder, data elements, encryption and key facts, acquisition indicators, scope, investigation, containment, resident estimate, notice owners, written determination path, and updates |
| Large social-media portability or interoperability work | Confirm the statutory service and threshold, then build a dated transition for July 1, 2027 rather than claiming a current universal interface duty | User choice, data and social-graph inventory, subset and date selection, machine-readable format, one-time or continuing transfer, receiving service, permission, privacy, security, abuse controls, logs, revocation, and exit |
| South Dakota operations across the federal Central-Mountain boundary | Name the actual buyer location before promising overlap, support, consent handling, destruction, incident, or release coverage | Buyer city and IANA zone, contributor cities and zones, dated overlap, daylight transitions, authority window, backup owner, handoff packet, incident path, and maintenance owner |
These lanes are decision prompts, not legal conclusions. A company, sample, record, operation, service, research context, health context, platform, or event may be excluded from one rule and covered by another. Federal, contractual, customer, destination-country, or other-state requirements can still apply. Preserve the reasoning and route conclusions through qualified owners.
The distinct South Dakota model: consent-to-material custody
The South Dakota-specific operating lesson is simple to state and difficult to fake: a digital permission must remain connected to the physical material, every derived data copy, every provider, and the final destruction evidence.
Many software inventories begin when a JSON record enters an application. A direct-to-consumer genetic testing service can begin earlier, with a biological sample, shipment, receiving event, accession or internal identifier, preparation step, analysis, derived genetic data, quality record, result, storage decision, disclosure, research decision, marketing decision, deletion request, revocation, or destruction. If the software supplier sees only a dataset, the buyer can lose the material-to-data relationship needed to make consent and destruction real.
Use four related but independent control paths:
- Material custody: the physical sample’s receipt, identity link, permitted use, custody location, handler, transformation, residual material, storage, transfer, and destruction.
- Genetic-data processing: fields, derivation, purpose, system, model, result, copy, disclosure, recipient, retention, access, deletion, and evidence.
- Consent and revocation: exact permission, version, time, purpose, channel, downstream effect, withdrawal, execution deadline, exception, and proof.
- Future interoperability: only for an actually covered large social-media service, with a separate July 1, 2027 transition for export and third-party access rather than a hidden extension of the current genetic-data lane.
A buyer-owned consent-to-material gate should stop an operation when the permission, material, data, purpose, provider, recipient, or location does not match. It should also stop when revocation cannot reach a sample, derived dataset, model input, export, cache, backup, or service provider. The supplier can implement and operate approved steps. The buyer retains coverage, consent design, exception, external disclosure, destruction acceptance, incident characterization, production, and exit authority.
Build a material, data, and permission ledger
Create the ledger before a provider receives code or data. Use one row for every collection, shipment, receipt, accession, analysis, transformation, model call, support view, disclosure, export, retention job, revocation, deletion, destruction, incident action, and return.
Record at least:
- buyer entity, product, direct-to-consumer service, consumer context, system, environment, accountable owner, and applicable lane;
- material identifier, material type at a non-medical operational level, collection event, custody location, handler, permitted use, remaining quantity state, storage, transfer, and destruction state;
- genetic-data fields, source material, derivation, result, purpose, consumer identity link, de-identification decision, model or analytics use, copies, recipients, logs, backups, retention, and deletion;
- consent ID, consumer-facing notice version, permission language, purpose, affirmative action, time, channel, research or marketing branch where relevant, revocation method, and execution status;
- provider entity, subprovider, contributor name, relationship, city, country, account, device, network path, approved hours, sample possession, data possession, and identity information;
- permitted reads, writes, transformations, analysis, model calls, exports, disclosures, support actions, and transfers, plus prohibited actions and stop conditions;
- repository, branch, dependency, build, artifact, test, provenance, deployment, monitoring, release, rollback, and acceptance evidence;
- breach signal, evidence location, investigation owner, consumer or Attorney General decision owner, communications owner, backup, and update cadence;
- access start and expiry, retention minimum and maximum, legal hold, return, deletion, destruction, reconciliation, exception, and acceptance; and
- change triggers: new product, purpose, consent, sample use, data field, derivation, research plan, marketing use, model, recipient, provider, country, privilege, environment, retention period, or interface.
The ledger is not merely a spreadsheet. Enforce approved rows through custody scans or events, identity groups, scoped tokens, purpose-bound services, data views, network rules, model policy, protected logs, consent state, deletion jobs, destruction work queues, CI checks, deployment approvals, and offboarding. Reconcile system facts back to the ledger on a maintained cadence.
Lane one: ordinary delivery remains bounded
Work outside the special genetic, interoperability, or breach perimeter still exposes code, credentials, business logic, vulnerabilities, customer configuration, and production power. A clean ordinary lane should include:
- synthetic, masked, minimized, or deliberately constructed test records;
- no biological-sample identifiers or real genetic data unless a separately approved lane requires them;
- separate development, test, support, and production accounts;
- no production secrets in source, tickets, screenshots, prompts, test fixtures, or chat;
- allowlisted dependencies, automated composition checks, and documented exceptions;
- protected branches, peer review, reproducible builds, artifact provenance, and buyer-controlled release;
- acceptance cases for normal, failed, degraded, rollback, restoration, and reconciliation paths; and
- buyer-held repositories, build definitions, environment inventory, runbooks, decisions, and recovery material.
The supplier may implement, test, document, and recommend. The buyer should retain scope, architecture exceptions, data admission, production credentials, risk acceptance, public statements, deployment, and final acceptance. If ordinary work needs a real material identifier or genetic record, create an approved operation rather than silently widening access.
Use the project brief generator to define the outcome, systems, information boundary, evidence, and acceptance. Use the provider scorecard to compare custody, consent, security, continuity, and exit rather than relying on sector claims or hourly rates.
Lane two: make the 2026 genetic-material protections executable
South Dakota’s codified chapter 37-24 now includes sections 37-24-59 through 37-24-64 from the 2026 enactment. The definitions and exceptions matter. Determine whether the actual entity is a direct-to-consumer genetic testing company, whether the person is a covered consumer, whether the item is a biological sample or genetic data as defined, whether the activity fits the law, and whether a health, medical, education, forensic, research, hospital, or other listed exception applies. Do not infer the answer from the word “genetic.”
For a covered operation, section 37-24-60 connects public notice, express consent, security, consumer access, account and genetic-data deletion, biological-sample destruction, and consent revocation. Different activities can need separately understood permissions. The operational system should preserve which permission authorized which action, rather than storing one undifferentiated boolean.
Build a permission capsule containing:
- consumer and product context;
- material and data categories;
- exact purpose and action;
- notice and consent versions;
- affirmative action, time, channel, and evidence;
- permitted company and service-provider operations;
- transfer, disclosure, research, or marketing branch where applicable;
- storage and retention decision;
- access, deletion, sample-destruction, and revocation mechanisms;
- downstream systems and providers; and
- expiry, supersession, exception, and review owner.
Then link it to technical controls. A sample-receipt event should not enable analysis unless the approved permission exists. A model job should admit only the fields and purpose in its instruction. An export should require the correct recipient and disclosure decision. A consumer request should locate active data, derived values, exports, provider copies, retained evidence, and the physical sample state.
Section 37-24-61 gives the current revocation lane a concrete outside boundary: the company must honor consent revocation within thirty days, and when consent to store a biological sample is revoked, destroy the sample within thirty days of receipt. Do not interpret that as permission to wait thirty days operationally or as a universal rule for excluded contexts. Stop new use promptly, route the request, calculate the applicable deadline, execute across systems and providers, reconcile, record justified residuals or holds, and return buyer-approved evidence.
Service-provider confidentiality must follow possession
Section 37-24-62 addresses a service provider under contract with a direct-to-consumer genetic testing company and applies the same confidentiality obligations described there to biological samples, genetic data, and consumer-identity information in the provider’s possession. That makes the real custody graph more important than the prime vendor’s marketing description.
Map every edge:
| Custody edge | Evidence the buyer should require |
|---|---|
| Company to collection or transport provider | Exact entity, material identifier method, custody event, permitted route, loss/tamper signal, exception, handoff acceptance, and return or destruction |
| Company to analysis provider | Sample and data scope, purpose, people, facility and system location, access, output, residual material, derived data, quality evidence, retention, revocation, and destruction |
| Company to cloud, data, or AI provider | Fields, identity link, storage and processing region, model and training setting, logs, support access, subproviders, replicas, export, deletion, and incident route |
| Provider to subprovider | Advance approval, exact service, location, flow-down, technical controls, evidence rights, change notice, incident relay, revocation propagation, and offboarding |
| Provider back to buyer | Accepted result, lineage, consent reference, custody reconciliation, security evidence, exception, deletion or destruction status, and unresolved risk |
Use named accounts, least privilege, managed devices, short-lived credentials, approved endpoints, network boundaries, encryption, protected logs, export controls, and monitored administrative activity. Confidentiality language does not repair a system where any support account can browse every consumer or where a provider can retain a private copy after revocation.
Separate deletion of data from destruction of material
Deleting an account is not the same as deleting genetic data, and neither proves destruction of a biological sample. Model them as separate state machines.
For data, inventory primary records, derived values, results, analytics, prompts, model inputs and outputs, search indexes, caches, queues, logs, exports, support systems, replicas, backups, and provider copies. Record deletion execution, backup aging, exception or hold, subprovider confirmation, reconciliation, and consumer-facing completion.
For material, record the approved identifier, current custodian, storage state, permitted remaining use, movement, destruction authorization, method at an appropriate evidence level, operator or system event, date, exception, reconciliation, and buyer acceptance. Do not expose unnecessary genetic or identity information in the destruction record.
The buyer needs a two-part completion packet:
- Data disposition: each system and provider, executed action, residual, reason, expiry, and proof.
- Material disposition: each custody item or approved batch, destruction or other authorized state, discrepancy, exception, and acceptance.
If either part is missing, the revocation is not operationally complete.
Preserve the general security-breach lane
South Dakota Codified Laws 22-40-19 through 22-40-26 define a separate information-holder breach path. Section 22-40-19 defines the covered information holder, personal and protected information, encryption, unauthorized person, and breach. Section 22-40-20 addresses resident notice, the outside sixty-day period, law-enforcement delay, a documented harm determination after appropriate investigation and Attorney General notice, a three-year minimum for that written determination, and Attorney General notice when the breach exceeds the stated resident threshold.
Do not use sixty days as the supplier’s first-alert allowance. Contract for immediate credible-signal relay so the information holder can investigate and decide. The first capsule should include:
- discovery time, reporter, affected service, system, environment, and information holder;
- data elements, resident estimate, encryption and key facts, authorized-use boundaries, and acquisition indicators;
- affected identities, endpoints, networks, applications, databases, models, exports, providers, and backups;
- preserved logs, snapshots, code, build, configuration, tickets, and communications;
- containment, credential rotation, service impact, continuity option, restoration, and reconciliation;
- observed, inferred, reported, and unknown facts kept distinct;
- next step, named investigation owner, qualified notice owner, update cadence, and evidence location; and
- any written determination, supporting investigation record, approval, retention, and production owner.
The genetic-material lane and breach lane can activate together, but one does not replace the other. A possible unauthorized disclosure can require both consent/custody remediation and information-holder analysis. Qualified buyer owners decide statutory characterization, notice, law enforcement, consumer communication, regulator contact, and return to service.
Build the July 1, 2027 interoperability lane separately
The 2026 enactment codified future-effective sections in chapter 53-12 for certain social-media services with more than one hundred million active monthly users and the stated primary-focus boundary. The current codified page labels the relevant sections effective July 1, 2027. Do not describe them as a universal current duty for every app, community, marketplace, or buyer.
For an actually covered transition, build a separate interface inventory:
- user-held personal data and social-graph elements;
- data ownership and relationship semantics;
- all-versus-subset selection, types, dates, and since-last-transfer state;
- portable and machine-readable format;
- public technical standard and licensing or patent restriction review;
- one-time versus continuing export, recurrence, pause, revocation, and failure recovery;
- permission for third-party access and notification of new or updated content;
- originating service, receiving service, user identity binding, authentication, authorization, and consent;
- privacy, security, abuse, safety, integrity, fraud, illegal-activity, and legal-obligation controls;
- logs, reconciliation, duplicate handling, deletion, account closure, provider change, and exit; and
- rollout date, feature flag, owner, test cohort, incident route, and evidence.
Do not merge this with the genetic-material interface merely because both involve user data. A genetic testing service and a covered large social-media service use different definitions, data, permissions, timing, recipients, risks, and exceptions. Shared components such as identity, consent receipts, audit logs, and deletion orchestration must preserve lane-specific semantics.
Name the Central or Mountain operating location
Federal regulation describes South Dakota’s Central-Mountain boundary. “South Dakota time” is therefore not a complete schedule. Record the buyer’s actual city or site and a maintained IANA zone, then compare it with every contributor city for the dates that matter.
Create an authority calendar with:
- normal collaboration window and named people;
- consumer-request, revocation, sample-destruction, incident, support, deployment, and rollback coverage;
- daily decision cutoff and written handoff time;
- action limits when the buyer owner is offline;
- urgent route, acknowledgment target, backup owner, and escalation chain;
- daylight-transition, holiday, leave, and severe-disruption coverage; and
- change windows, freezes, continuity exercises, and exit dates.
Do not solve overlap by making unnamed contributors work permanently unhealthy hours. Use sustainable windows, written evidence packets, and explicit offline authority. A decision-ready handoff contains the current material or data state, consent reference, change, tests, risk, unresolved question, evidence links, next authorized action, and named approver.
Verify contributor, intellectual-property, and model chains
Record the contracting entity, every subprovider, every contributor’s employer or contractor relationship, physical work city and country, device, account, system, data destination, model provider, support route, and backup operator. Reapprove changes before access moves.
The agreement should distinguish buyer background material, provider background material, new deliverables, open-source and commercial dependencies, material custody records, genetic data, derived data, prompts, models, evaluation sets, results, documentation, and operating evidence. Address confidentiality, inventions, assignments, licenses, further transfer, moral-rights treatment where relevant, assistance, repositories, credentials, and exit.
Verify the rights chain under the relevant destination-country law using current official sources such as the WIPO directory and national IP office. A South Dakota governing-law clause is important but does not by itself prove that every contributor’s rights reached the buyer.
For AI, record every model and tool, provider, region, input, output, retention setting, training or improvement setting, support access, subprovider, evaluation, monitoring, incident route, deletion path, and replacement plan. A supplier must not put covered genetic data into a general AI tool because the tool is convenient or described as private in a sales deck.
Compare complete cost
Use outcome-based scenarios rather than a supposed South Dakota outsourcing rate.
Supplier delivery cost includes discovery, engineering, design, data work, AI, QA, delivery leadership, documentation, support, incident work, custody operations, consent integration, deletion or destruction integration, and transition.
Buyer-retained cost includes product decisions, applicability and qualified review, consent and notice design, sample and data inventory, provider approval, security, acceptance, production, incident and consumer communication, destruction acceptance, records production, and benefits realization.
Platform and control cost includes identity, devices, repositories, CI, artifacts, environments, test data, custody systems, consent records, deletion orchestration, protected logs, monitoring, model evaluation, evidence storage, backup, recovery, egress, and provider exit.
Model expected delivery, control-intensive delivery, and failure or transition. Include rework, decision delay, provider replacement, data reconciliation, residual material, breach investigation, consumer remediation, and recovery. Compare total cost across the decision horizon, not hourly rate alone.
Run a six-to-eight-week consent-to-custody pilot
Use a representative but bounded work package. Prefer synthetic or deliberately constructed records and neutral material tokens until the team proves controls. If real covered material or data is necessary, admit the minimum under a specifically approved operation.
Week 1: classify and baseline
- approve entities, product, material, data, permission, providers, locations, systems, lanes, owners, and stop conditions;
- inventory code, interfaces, environments, consent states, copies, custody events, models, known defects, recovery, and exit state; and
- define measurable outcome, acceptance, evidence, revocation, destruction, incident, and portability cases.
Week 2: establish the gate
- issue named least-privilege access with expiry;
- configure material and data boundaries, consent checks, logs, evidence store, review, build, release, deletion, and destruction queues; and
- rehearse access, revocation, incident relay, rollback, recovery, and account removal.
Weeks 3–6: deliver accepted increments
- demonstrate working changes at least weekly;
- reconcile permission, material, data, provider, test, build, and acceptance evidence;
- measure lead time, accepted throughput, defects, rework, buyer hours, permission mismatches, custody discrepancies, revocation latency, evidence completeness, and schedule sustainability; and
- stop and reclassify any new purpose, material use, field, model, recipient, provider, location, privilege, or retention need.
Weeks 7–8: exercise reversal
- revoke one permission, stop new use, delete the test account and data, destroy or reconcile the neutral material token, and obtain evidence;
- inject a suspected breach, preserve facts, classify lanes, contain, restore, and run buyer decisions;
- test a one-time future interoperability export only in an isolated transition fixture if relevant; and
- have a replacement team build, explain, operate, recover, and close the work from buyer-held material.
Scale only when the system proves the decision, not because a demo looks polished.
Put operating promises into the agreement
The agreement and work order should cover:
- exact entities, product, service, systems, environments, material, data, purpose, permissions, roles, locations, providers, contributors, and change approval;
- custody, confidentiality, security, access, processing, transfer, disclosure, research or marketing branch where relevant, model use, evidence, incident, revocation, deletion, destruction, return, and closeout;
- buyer-retained applicability, consent design, exception, external notice, law-enforcement, production, destruction acceptance, recovery, and communication decisions;
- service levels for signal relay, evidence updates, consumer-request support, revocation propagation, deletion, material destruction support, restoration, and transition;
- IP, confidentiality, pre-existing material, open source, commercial dependencies, repositories, credentials, records, and assistance;
- fees, currency, taxes, invoicing, acceptance, change control, suspension, termination, transition, and record production; and
- order of precedence among the agreement, privacy or data terms, security schedule, custody schedule, work order, instruction, approved exception, and future transition plan.
Test clauses against actions. Who can approve a new analysis purpose? Which system stops use on revocation? Who controls the physical destruction queue? Can a provider delete investigation evidence? Which owner enables a future recurring export? If the answer is unowned or technically impossible, the clause is not an operating control.
South Dakota outsourcing red flags
Pause or reject a proposal when:
- “South Dakota compliant” appears without the exact entity, service, material, data, operation, exception, date, source, and reviewer;
- a single consent flag authorizes collection, analysis, storage, transfer, research, marketing, and model improvement;
- physical sample custody disappears after the first data record is created;
- the provider cannot identify every copy, derived value, export, model path, custodian, and subprovider;
- deletion of an account is offered as proof that a biological sample was destroyed;
- revocation stops the user interface but not supplier jobs, stored material, exports, models, caches, or backups;
- the supplier’s confidentiality promise does not flow to the real people, systems, and subproviders in possession;
- a sales team describes the July 2027 interoperability provisions as a current universal platform requirement;
- a recurring export has no receiving-service verification, pause, revocation, failure recovery, or reconciliation;
- breach notice waits for the supplier’s final legal conclusion or uses sixty days as a first-alert target;
- “Central time coverage” ignores South Dakota’s Mountain-zone operations and actual buyer city;
- the supplier controls the only repository, build, consent ledger, custody record, log, backup, or runbook; or
- exit produces source code without material reconciliation, data disposition, revoked access, recovery proof, and accepted evidence.
Frequently asked questions
Can a South Dakota company outsource software development overseas?
Yes. Classify the actual work and keep buyer control of information, material, consent, providers, access, production, incidents, recovery, intellectual property, and exit. Other federal, state, sector, contractual, export, sanctions, employment, tax, and destination-country requirements may apply.
Does the 2026 genetic-material law apply to every genetic or health workflow?
No. The current codified provisions define direct-to-consumer genetic testing company, consumer, biological sample, genetic data, service provider, and consent, and list exceptions. Determine the actual facts using the current text and qualified review.
Does a service provider inherit confidentiality duties?
Section 37-24-62 addresses a service provider under contract with a direct-to-consumer genetic testing company and the covered biological samples, genetic data, and identity information in its possession. Map the actual contract and custody; do not infer universal coverage from the provider label.
Is deleting genetic data enough when storage consent is revoked?
Not when the applicable request also concerns storage of the biological sample. Data deletion and physical sample destruction need separate execution and reconciliation evidence. Section 37-24-61 states a thirty-day outside requirement for the covered revocation and sample-destruction path.
Do all social platforms need the interoperability interface now?
No. The codified provisions are separately scoped and marked effective July 1, 2027 for the stated large-service boundary. Prepare a dated transition only if the actual service fits; do not apply it to every app or present it as current.
How quickly should an overseas supplier report a possible breach?
Immediately under the operational contract. The buyer needs time to investigate and determine which statutory and contractual clocks apply. The sixty-day outside path in section 22-40-20 is not a supplier first-alert allowance.
Is South Dakota entirely in Central time?
No. The federal Central-Mountain boundary crosses the state. Use the actual buyer city or site, an IANA identifier, contributor cities, and the relevant dates before promising overlap or incident coverage.
Which delivery country is best for a South Dakota buyer?
There is no universal best country. Compare named contributors and locations for capability, sustainable overlap, legal and IP chain, data and material route, provider controls, continuity, complete cost, incident support, and exit. Use the country-selection model before choosing providers.
What should the first pilot prove?
It should prove a real accepted outcome, bounded authority, permission-to-operation linkage, custody and data reconciliation, revocation propagation, separate deletion and destruction, immediate incident evidence, buyer-controlled release, recovery, and complete exit.
The exit test
Before scale, prove the buyer can continue without the supplier. Retrieve and validate:
- repositories, branches, accepted artifacts, build definitions, dependencies, provenance, release history, rollback packages, and open defects;
- material inventory, custody events, locations, handlers, permitted states, discrepancies, residual material, destruction or return evidence, and acceptance;
- genetic-data inventory, lineage, derived values, results, exports, prompts, models, evaluations, logs, replicas, backups, deletion, and justified residuals;
- notices, consent versions, permission events, downstream propagation, revocation records, consumer-request evidence, exceptions, and completion;
- future interoperability inventories, standards, one-time or continuing transfer states, receiving services, permissions, security controls, logs, reconciliation, pause, and closure where relevant;
- breach evidence, investigation, decisions, written determinations, retention, restoration, remediation, and communication ownership;
- identities, contributors, subproviders, locations, contracts, confidentiality and IP chain, devices, accounts, tokens, secrets, and revocation proof;
- architecture, interfaces, environments, monitoring, runbooks, recovery results, risks, decisions, owners, and support history; and
- invoices, acceptance, transition obligations, returned property, deletion and destruction evidence, holds, and unresolved claims.
Have a replacement team reproduce a build, explain one material and permission decision, locate every artifact for a representative consumer, propagate revocation, reconcile data and a neutral sample token, investigate a simulated event, restore a failed component, and execute a controlled release from buyer-held material. If it cannot, the engagement is not portable.
The durable South Dakota outsourcing model is the one in which consent remains connected to material, data, provider possession, purpose, revocation, destruction, incident evidence, and exit—while the outside-U.S. team remains useful, bounded, and replaceable.
Evidence ledger
Sources used on this page
- South Dakota Codified Laws, Chapter 37-24 — Deceptive Trade Practices and Consumer Protection — South Dakota Legislature. Supports: Current codified direct-to-consumer genetic testing definitions, notice, express-consent, security, access, deletion, biological-sample destruction, revocation, service-provider confidentiality, enforcement, and exception provisions effective in 2026. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 2026 Senate Bill 49, enrolled — Genetic data and material protections — South Dakota Legislature. Supports: Enrolled text and enactment history for the 2026 genetic-material protections added as sections 37-24-59 through 37-24-64. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- SDCL 22-40-19 — Security-breach definitions — South Dakota Legislature. Supports: Current breach, encryption, information-holder, personal-information, protected-information, and unauthorized-person definitions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- SDCL 22-40-20 — Notice of breach of system security — South Dakota Legislature. Supports: Current resident and Attorney General breach-notice path, outside sixty-day limit, law-enforcement delay, harm determination, investigation, and three-year determination-record provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- South Dakota Codified Laws, Chapter 53-12 — Electronic Transactions — South Dakota Legislature. Supports: Codified future-effective July 1, 2027 social-media portability, third-party interoperability, social-graph export, one-time and recurring transfer, privacy, security, and exception provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 2026 Senate Bill 111, enrolled — Social-media interoperability — South Dakota Legislature. Supports: Enrolled 2026 text and explicit July 1, 2027 effective date for the large-social-media-service portability and interoperability transition. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 49 CFR 71.7 — Boundary line between central and mountain zones — Electronic Code of Federal Regulations. Supports: Current federal description of the Central-Mountain time-zone boundary through South Dakota and treatment of boundary municipalities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained identifiers and transition rules for calculating dated overlap between the actual South Dakota buyer location and every proposed contributor city. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained methodology for secure-development requirements, protected environments, provenance, release integrity, vulnerability response, and buyer-supplier evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for investigating contributor and assignment questions rather than assuming a South Dakota contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: September 30, 2026. Corrections: hello@outsourcing.ai.
