Oklahoma Privacy Law
Oklahoma’s comprehensive privacy statute is signed but not yet in force, and the law that governs today is narrower than most readers expect. The Security Breach Notification Act at 24 O.S. §§ 161 through 166 counts only three data elements as personal information, triggers only where the breach causes or is reasonably believed to cause identity theft or other fraud, and — unlike the statutes of most neighbouring states — requires no notice to the Attorney General at all. Senate Bill 546, approved by the Governor on March 20, 2026, changes that from January 1, 2027 by adding a new Title 75A to the Oklahoma Statutes.
The Oklahoma Consumer Data Privacy Act (OKCDPA)
Senate Bill 546, by Senator Brent Howard with Representative Josh West as principal House author, passed the House 84–4 on February 19, 2026 and the Senate 38–7 on March 16, 2026, and was approved by the Governor on March 20, 2026. It adds a new Title 75A to the Oklahoma Statutes, sections 300 through 316, and takes effect January 1, 2027. Section 311 gives the Attorney General exclusive authority to enforce it, section 313(E) forecloses any private right of action, and section 313(A) sets a civil penalty of up to $7,500.00 for each violation. Section 312 requires the Attorney General to give thirty days’ written notice identifying the specific provisions alleged to be violated before bringing an action, and bars the action entirely if the controller or processor cures within that window and certifies the cure in writing. That notice-and-cure step carries no expiry date, which distinguishes the Oklahoma Act from the 2026 statutes of Louisiana and Vermont, whose cure windows close.
Status: Enacted but not yet in force — the law takes effect January 1, 2027.
| Effective date | January 1, 2027 |
|---|---|
| Citation | SB 546 (2026), codified at 75A O.S. §§ 300 et seq. |
| Enforced by | Oklahoma Attorney General |
| Maximum penalty | Up to $7,500 per violation, plus court-awarded attorney fees and investigation expenses |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days’ written notice before suit, with no expiry date |
Who Must Comply
The OKCDPA reaches a business that conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents, and during a calendar year controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.
Section 315(B) exempts state agencies and their service providers, financial institutions and Gramm-Leach-Bliley data, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, purely personal or household processing, and personal data collected under the Controlled Substances Act listed-chemical rules at 21 U.S.C. § 830. Section 310 requires a documented data protection assessment for processing that presents a heightened risk of harm, and makes that assessment available to the Attorney General on written request without waiving privilege. Civil penalties collected under section 313 are deposited to the credit of the General Revenue Fund
Consumer Rights Under the OKCDPA
Residents of Oklahoma can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Oklahoma
Insurance Data Security Act (36 O.S. §§ 670–679)
Added by Laws 2024, c. 346 and effective July 1, 2024, this chapter is declared by § 36-671 to be the exclusive state law governing data security, cybersecurity-event investigation and notification to the Commissioner for licensees under the Insurance Commissioner’s jurisdiction. Section 36-675 sets a three-business-day clock: a licensee notifies the Insurance Commissioner without unreasonable delay and no later than three business days from determining a cybersecurity event has occurred, where Oklahoma is the licensee’s state of domicile or home state and the event has a reasonable likelihood of materially harming any material part of its normal operations or any consumer residing in the state, or where the licensee reasonably believes the nonpublic information of 250 or more Oklahoma consumers is involved and the event either triggers notice to another supervisory body or carries that same likelihood of material harm. The notice carries thirteen enumerated items, among them the identity of the source of the event, the period during which the information system was compromised, the results of any internal review identifying a lapse in automated controls or internal procedures, a copy of the licensee’s privacy policy, and the name of a contact person authorized to act for the licensee, with a continuing duty to supplement. Section 36-678(B) exempts a licensee with less than $5,000,000.00 in gross annual revenue, and treats HIPAA-compliant and Gramm-Leach-Bliley-compliant licensees as meeting the security-program requirement where they certify that compliance in writing to the Commissioner.
Student Data Accessibility, Transparency and Accountability Act of 2013 (70 O.S. § 3-168)
Oklahoma governs school data through a statute with an unusual structural feature: new collections expire unless the political branches ratify them. Under § 3-168(C)(7)(a), any new student data collection proposed by the State Board of Education becomes a provisional requirement, must be submitted to the Governor and the Legislature for approval within one year, and if not approved by the end of the next legislative session it expires and is no longer required. Subsection (C)(3) bars the State Department of Education from transferring student or de-identified data to any federal, state or local agency or other entity outside Oklahoma absent State Board approval, subject to seven listed exceptions covering out-of-state transfers, national or multistate assessments, voluntary programs, out-of-state vendor contracts, migrant classification and the military student identifier. Subsection (C)(4) requires a detailed data security plan covering authentication of authorized access, privacy compliance standards, privacy and security audits, breach planning and notification, and data retention and disposition. Subsection (C)(6) requires contracts outsourcing databases, assessments or instructional supports to private vendors to carry express privacy and security provisions and penalties for noncompliance. Section 3-168(B)(6) provides that the state-assigned student testing number may not be or include a student’s Social Security number in whole or in part. The section was added by Laws 2013, c. 356 and amended by Laws 2015, c. 33 and Laws 2021, c. 66.
Oklahoma Consumer Protection Act (15 O.S. §§ 751–765)
The Consumer Protection Act is the general unfair-practices statute into which the breach law routes, and it is enforced by the Attorney General or a district attorney. Section 15-761.1(A) preserves a private right of action for damages, including costs and attorney’s fees, and directs the court, on the motion of a prevailing party after adjudication on the merits, to order a nonprevailing party who asserted a claim or defense in bad faith, not well grounded in fact or unwarranted by existing law to reimburse up to $10,000.00 in reasonable costs. Subsection (B) adds a civil penalty of up to $2,000.00 for each violation payable to the aggrieved consumer where the practice is also found unconscionable, recoverable in an individual action only, with four statutory factors bearing on unconscionability. Subsection (C) sets a civil penalty of up to $10,000.00 per violation for a person found in violation in a civil action or who wilfully violates an injunction. Subsection (E), as amended by Laws 2025, c. 486, § 347 with effect from January 1, 2026, makes a criminal conviction under the Act a D1 felony carrying imprisonment under 21 O.S. § 20N or a fine of up to $5,000.00, or both. Section 15-762 separately empowers the Attorney General to conduct studies and investigations in matters affecting consumer interest and to receive the assistance of any branch of state government.
Data Breach Notification in Oklahoma
The Security Breach Notification Act at 24 O.S. §§ 161 through 166, added by House Bill 2245 in 2008, is narrower than most state breach statutes in three separate ways. First, its definition of personal information at § 162(6) reaches only three data elements paired with a first name or initial and last name: a Social Security number, a driver licence or state identification card number issued in lieu of one, and a financial account, credit card or debit card number in combination with a required security code, access code or password. Second, § 162(1) builds a harm requirement into the definition of a breach itself — the unauthorized access and acquisition of unencrypted, unredacted computerized data must compromise security or confidentiality and cause, or be reasonably believed by the entity to have caused or to be about to cause, identity theft or other fraud to an Oklahoma resident. Third, § 163 directs disclosure to affected residents and, under subsection C, to the owner or licensee where the entity merely maintains the data, but names no state office as a recipient of notice. Substitute notice becomes available under § 162(7)(d) where the cost of notice would exceed $50,000.00 or the affected class exceeds 100,000 persons — thresholds several times those of neighbouring states — and consists of any two of e-mail notice, conspicuous website posting and notice to major statewide media. Section 164 deems an entity compliant where it follows its own notification procedures consistent with the Act’s timing, and deems a financial institution compliant where it follows the Federal Interagency Guidance.
Residents must be notified without unreasonable delay following discovery, except as needed to determine the scope of the breach and restore the reasonable integrity of the system. No notice to the Attorney General is required by the Security Breach Notification Act; the office’s role under 24 O.S. § 165 is enforcement rather than receipt of notice. Complaints are taken by the Oklahoma Attorney General, which enforces the statute.
How the OKCDPA Is Enforced
Breach violations are prosecuted as consumer-protection violations. Section 24-165(A) does not create a standalone remedy. It provides that a violation of the Security Breach Notification Act resulting in injury or loss to Oklahoma residents may be enforced by the Attorney General or a district attorney “in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act”, and subsection B makes that authority exclusive. The election available is between actual damages and a civil penalty capped at $150,000.00 per breach or per series of similar breaches discovered in one investigation.
Penalties, fees and where the money goes. Under § 313(B) of the Consumer Data Privacy Act the Attorney General may sue to recover the civil penalty, to restrain or enjoin the violation, or both. Subsection C allows the court to award reasonable attorney fees and other expenses incurred in investigating and bringing the action, and subsection D directs civil penalties collected to the State Treasury to the credit of the General Revenue Fund. Under the Consumer Protection Act the flow is different: § 15-761.1(D) provides that civil or contempt penalties recovered by the Attorney General or a district attorney are used for the furtherance of their duties and activities under that Act.
Recent Enforcement in Oklahoma
Oklahoma v. Temu — data-harvesting suit filed May 2026. The Attorney General’s office announced on May 11, 2026 that Attorney General Gentner Drummond had filed suit against the shopping application Temu in Cleveland County District Court on May 8, 2026. The office states that the application “illegally collects users’ data without their knowledge and consent”, and describes an application that “secretly infiltrates users’ devices to access and harvest sensitive information including the user’s precise physical location, the phone’s microphone and camera, and the user’s private activity on other apps installed on the phone, all without their knowledge or consent”. The office pairs those data-collection allegations with claims of intellectual-property misappropriation affecting the Oklahoma City Thunder, Oklahoma State University and the University of Oklahoma, bait-and-switch prize promotions, and non-disclosure of forced labour in the supply chain. The suit predates the Consumer Data Privacy Act’s January 1, 2027 effective date, and so proceeds on the office’s general consumer-protection authority rather than under Title 75A.
Pending Privacy Legislation
The 2026 session’s privacy output was Senate Bill 546 itself, which the Governor approved on March 20, 2026 for a January 1, 2027 start. Two duties in the Act fall on the state rather than on regulated parties and begin with it: section 311(B) requires the Attorney General to post on the office’s website information about the responsibilities of controllers and of processors and about consumers’ rights, together with an online mechanism through which a consumer may submit a complaint under the Act, and section 304 requires a controller’s appeal denial to point the consumer to that mechanism. The Act contains no rulemaking grant, so the text of Title 75A rather than an agency regulation supplies its detail. Oklahoma’s Insurance Data Security Act reached its own implementation milestones earlier, having been added by Laws 2024, c. 346 with effect from July 1, 2024.
Federal Privacy Laws That Apply in Oklahoma
Federal privacy law applies in Oklahoma by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The OKCDPA sits alongside those rules rather than displacing them: the Oklahoma Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Oklahoma Consumer Protection Act (15 O.S. §§ 751–765), which the Oklahoma Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Oklahoma Privacy Law FAQ
Does an Oklahoma data breach have to be reported to the Attorney General?
What has to happen before Oklahoma’s breach statute is triggered at all?
What can a failure to give breach notice cost in Oklahoma?
Which businesses will the Oklahoma Consumer Data Privacy Act reach on January 1, 2027?
Does the Oklahoma Consumer Data Privacy Act’s right to cure expire?
Can an Oklahoma resident sue over a privacy violation?
What limits Oklahoma schools’ handling of student data?
How quickly must an Oklahoma insurance licensee report a cybersecurity event?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Oklahoma SB 546 (2026) — bill information and legislative actions legislation
- Enrolled Senate Bill 546 (2026) — Oklahoma Consumer Data Privacy Act legislation
- Enrolled House Bill 2245 (2008) — Security Breach Notification Act, 24 O.S. §§ 161–166 legislation
- Oklahoma Statutes Title 15 — Consumer Protection Act, §§ 751–765 statute
- Oklahoma Statutes Title 36 — Insurance Data Security Act, §§ 670–679 statute
- Oklahoma Statutes Title 70 — Student Data Accessibility, Transparency and Accountability Act, § 3-168 statute
- Oklahoma Attorney General — Drummond files lawsuit against Temu over data collection agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.