Oklahoma — Comprehensive Law

Oklahoma Privacy Law

Oklahoma’s comprehensive privacy statute is signed but not yet in force, and the law that governs today is narrower than most readers expect. The Security Breach Notification Act at 24 O.S. §§ 161 through 166 counts only three data elements as personal information, triggers only where the breach causes or is reasonably believed to cause identity theft or other fraud, and — unlike the statutes of most neighbouring states — requires no notice to the Attorney General at all. Senate Bill 546, approved by the Governor on March 20, 2026, changes that from January 1, 2027 by adding a new Title 75A to the Oklahoma Statutes.

The Oklahoma Consumer Data Privacy Act (OKCDPA)

Senate Bill 546, by Senator Brent Howard with Representative Josh West as principal House author, passed the House 84–4 on February 19, 2026 and the Senate 38–7 on March 16, 2026, and was approved by the Governor on March 20, 2026. It adds a new Title 75A to the Oklahoma Statutes, sections 300 through 316, and takes effect January 1, 2027. Section 311 gives the Attorney General exclusive authority to enforce it, section 313(E) forecloses any private right of action, and section 313(A) sets a civil penalty of up to $7,500.00 for each violation. Section 312 requires the Attorney General to give thirty days’ written notice identifying the specific provisions alleged to be violated before bringing an action, and bars the action entirely if the controller or processor cures within that window and certifies the cure in writing. That notice-and-cure step carries no expiry date, which distinguishes the Oklahoma Act from the 2026 statutes of Louisiana and Vermont, whose cure windows close.

Status: Enacted but not yet in force — the law takes effect January 1, 2027.

Effective dateJanuary 1, 2027
CitationSB 546 (2026), codified at 75A O.S. §§ 300 et seq.
Enforced byOklahoma Attorney General
Maximum penaltyUp to $7,500 per violation, plus court-awarded attorney fees and investigation expenses
Private right of actionNo, enforcement by the state only
Right to cure30 days’ written notice before suit, with no expiry date

Who Must Comply

The OKCDPA reaches a business that conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents, and during a calendar year controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.

Section 315(B) exempts state agencies and their service providers, financial institutions and Gramm-Leach-Bliley data, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, purely personal or household processing, and personal data collected under the Controlled Substances Act listed-chemical rules at 21 U.S.C. § 830. Section 310 requires a documented data protection assessment for processing that presents a heightened risk of harm, and makes that assessment available to the Attorney General on written request without waiving privilege. Civil penalties collected under section 313 are deposited to the credit of the General Revenue Fund

Consumer Rights Under the OKCDPA

Residents of Oklahoma can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Oklahoma

Insurance Data Security Act (36 O.S. §§ 670–679)

Added by Laws 2024, c. 346 and effective July 1, 2024, this chapter is declared by § 36-671 to be the exclusive state law governing data security, cybersecurity-event investigation and notification to the Commissioner for licensees under the Insurance Commissioner’s jurisdiction. Section 36-675 sets a three-business-day clock: a licensee notifies the Insurance Commissioner without unreasonable delay and no later than three business days from determining a cybersecurity event has occurred, where Oklahoma is the licensee’s state of domicile or home state and the event has a reasonable likelihood of materially harming any material part of its normal operations or any consumer residing in the state, or where the licensee reasonably believes the nonpublic information of 250 or more Oklahoma consumers is involved and the event either triggers notice to another supervisory body or carries that same likelihood of material harm. The notice carries thirteen enumerated items, among them the identity of the source of the event, the period during which the information system was compromised, the results of any internal review identifying a lapse in automated controls or internal procedures, a copy of the licensee’s privacy policy, and the name of a contact person authorized to act for the licensee, with a continuing duty to supplement. Section 36-678(B) exempts a licensee with less than $5,000,000.00 in gross annual revenue, and treats HIPAA-compliant and Gramm-Leach-Bliley-compliant licensees as meeting the security-program requirement where they certify that compliance in writing to the Commissioner.

Student Data Accessibility, Transparency and Accountability Act of 2013 (70 O.S. § 3-168)

Oklahoma governs school data through a statute with an unusual structural feature: new collections expire unless the political branches ratify them. Under § 3-168(C)(7)(a), any new student data collection proposed by the State Board of Education becomes a provisional requirement, must be submitted to the Governor and the Legislature for approval within one year, and if not approved by the end of the next legislative session it expires and is no longer required. Subsection (C)(3) bars the State Department of Education from transferring student or de-identified data to any federal, state or local agency or other entity outside Oklahoma absent State Board approval, subject to seven listed exceptions covering out-of-state transfers, national or multistate assessments, voluntary programs, out-of-state vendor contracts, migrant classification and the military student identifier. Subsection (C)(4) requires a detailed data security plan covering authentication of authorized access, privacy compliance standards, privacy and security audits, breach planning and notification, and data retention and disposition. Subsection (C)(6) requires contracts outsourcing databases, assessments or instructional supports to private vendors to carry express privacy and security provisions and penalties for noncompliance. Section 3-168(B)(6) provides that the state-assigned student testing number may not be or include a student’s Social Security number in whole or in part. The section was added by Laws 2013, c. 356 and amended by Laws 2015, c. 33 and Laws 2021, c. 66.

Oklahoma Consumer Protection Act (15 O.S. §§ 751–765)

The Consumer Protection Act is the general unfair-practices statute into which the breach law routes, and it is enforced by the Attorney General or a district attorney. Section 15-761.1(A) preserves a private right of action for damages, including costs and attorney’s fees, and directs the court, on the motion of a prevailing party after adjudication on the merits, to order a nonprevailing party who asserted a claim or defense in bad faith, not well grounded in fact or unwarranted by existing law to reimburse up to $10,000.00 in reasonable costs. Subsection (B) adds a civil penalty of up to $2,000.00 for each violation payable to the aggrieved consumer where the practice is also found unconscionable, recoverable in an individual action only, with four statutory factors bearing on unconscionability. Subsection (C) sets a civil penalty of up to $10,000.00 per violation for a person found in violation in a civil action or who wilfully violates an injunction. Subsection (E), as amended by Laws 2025, c. 486, § 347 with effect from January 1, 2026, makes a criminal conviction under the Act a D1 felony carrying imprisonment under 21 O.S. § 20N or a fine of up to $5,000.00, or both. Section 15-762 separately empowers the Attorney General to conduct studies and investigations in matters affecting consumer interest and to receive the assistance of any branch of state government.

Data Breach Notification in Oklahoma

The Security Breach Notification Act at 24 O.S. §§ 161 through 166, added by House Bill 2245 in 2008, is narrower than most state breach statutes in three separate ways. First, its definition of personal information at § 162(6) reaches only three data elements paired with a first name or initial and last name: a Social Security number, a driver licence or state identification card number issued in lieu of one, and a financial account, credit card or debit card number in combination with a required security code, access code or password. Second, § 162(1) builds a harm requirement into the definition of a breach itself — the unauthorized access and acquisition of unencrypted, unredacted computerized data must compromise security or confidentiality and cause, or be reasonably believed by the entity to have caused or to be about to cause, identity theft or other fraud to an Oklahoma resident. Third, § 163 directs disclosure to affected residents and, under subsection C, to the owner or licensee where the entity merely maintains the data, but names no state office as a recipient of notice. Substitute notice becomes available under § 162(7)(d) where the cost of notice would exceed $50,000.00 or the affected class exceeds 100,000 persons — thresholds several times those of neighbouring states — and consists of any two of e-mail notice, conspicuous website posting and notice to major statewide media. Section 164 deems an entity compliant where it follows its own notification procedures consistent with the Act’s timing, and deems a financial institution compliant where it follows the Federal Interagency Guidance.

Residents must be notified without unreasonable delay following discovery, except as needed to determine the scope of the breach and restore the reasonable integrity of the system. No notice to the Attorney General is required by the Security Breach Notification Act; the office’s role under 24 O.S. § 165 is enforcement rather than receipt of notice. Complaints are taken by the Oklahoma Attorney General, which enforces the statute.

How the OKCDPA Is Enforced

Breach violations are prosecuted as consumer-protection violations. Section 24-165(A) does not create a standalone remedy. It provides that a violation of the Security Breach Notification Act resulting in injury or loss to Oklahoma residents may be enforced by the Attorney General or a district attorney “in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act”, and subsection B makes that authority exclusive. The election available is between actual damages and a civil penalty capped at $150,000.00 per breach or per series of similar breaches discovered in one investigation.

Penalties, fees and where the money goes. Under § 313(B) of the Consumer Data Privacy Act the Attorney General may sue to recover the civil penalty, to restrain or enjoin the violation, or both. Subsection C allows the court to award reasonable attorney fees and other expenses incurred in investigating and bringing the action, and subsection D directs civil penalties collected to the State Treasury to the credit of the General Revenue Fund. Under the Consumer Protection Act the flow is different: § 15-761.1(D) provides that civil or contempt penalties recovered by the Attorney General or a district attorney are used for the furtherance of their duties and activities under that Act.

Recent Enforcement in Oklahoma

Oklahoma v. Temu — data-harvesting suit filed May 2026. The Attorney General’s office announced on May 11, 2026 that Attorney General Gentner Drummond had filed suit against the shopping application Temu in Cleveland County District Court on May 8, 2026. The office states that the application “illegally collects users’ data without their knowledge and consent”, and describes an application that “secretly infiltrates users’ devices to access and harvest sensitive information including the user’s precise physical location, the phone’s microphone and camera, and the user’s private activity on other apps installed on the phone, all without their knowledge or consent”. The office pairs those data-collection allegations with claims of intellectual-property misappropriation affecting the Oklahoma City Thunder, Oklahoma State University and the University of Oklahoma, bait-and-switch prize promotions, and non-disclosure of forced labour in the supply chain. The suit predates the Consumer Data Privacy Act’s January 1, 2027 effective date, and so proceeds on the office’s general consumer-protection authority rather than under Title 75A.

Pending Privacy Legislation

The 2026 session’s privacy output was Senate Bill 546 itself, which the Governor approved on March 20, 2026 for a January 1, 2027 start. Two duties in the Act fall on the state rather than on regulated parties and begin with it: section 311(B) requires the Attorney General to post on the office’s website information about the responsibilities of controllers and of processors and about consumers’ rights, together with an online mechanism through which a consumer may submit a complaint under the Act, and section 304 requires a controller’s appeal denial to point the consumer to that mechanism. The Act contains no rulemaking grant, so the text of Title 75A rather than an agency regulation supplies its detail. Oklahoma’s Insurance Data Security Act reached its own implementation milestones earlier, having been added by Laws 2024, c. 346 with effect from July 1, 2024.

Federal Privacy Laws That Apply in Oklahoma

Federal privacy law applies in Oklahoma by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The OKCDPA sits alongside those rules rather than displacing them: the Oklahoma Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Oklahoma Consumer Protection Act (15 O.S. §§ 751–765), which the Oklahoma Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Oklahoma Privacy Law FAQ

Does an Oklahoma data breach have to be reported to the Attorney General?
The Security Breach Notification Act does not require it. Section 24-163 directs disclosure to any Oklahoma resident whose unencrypted, unredacted personal information was or is reasonably believed to have been accessed and acquired, and subsection C directs an entity holding data it does not own to tell the owner or licensee, but the Act names no state office as a recipient of notice. The Attorney General’s role appears at § 24-165, which makes the office — or a district attorney — the enforcer of a violation that results in injury or loss.
What has to happen before Oklahoma’s breach statute is triggered at all?
Section 24-162(1) writes a harm test into the definition of a breach. The unauthorized access and acquisition of unencrypted and unredacted computerized data must compromise the security or confidentiality of personal information and cause, or the individual or entity must reasonably believe it has caused or will cause, identity theft or other fraud to an Oklahoma resident. Section 24-163(B) extends the duty to encrypted information accessed and acquired in unencrypted form, or where the breach involves a person with access to the encryption key, on the same reasonable-belief standard.
What can a failure to give breach notice cost in Oklahoma?
Section 24-165(B) gives the Attorney General or a district attorney exclusive authority to bring the action, and allows recovery of either actual damages or a civil penalty not exceeding $150,000.00 per breach of the security of the system, or per series of breaches of a similar nature discovered in a single investigation. Subsection C carves out state-chartered and state-licensed financial institutions, whose violations are enforceable exclusively by their primary state regulator. Subsection A directs that the action proceed in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act.
Which businesses will the Oklahoma Consumer Data Privacy Act reach on January 1, 2027?
Section 314(A) applies the Act to a controller or processor that conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents and that, during a calendar year, either controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers while deriving over fifty percent of gross revenue from the sale of personal data. Section 314(B) then removes state agencies and political subdivisions and their service providers, financial institutions and Gramm-Leach-Bliley data, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, and purely personal or household processing.
Does the Oklahoma Consumer Data Privacy Act’s right to cure expire?
No date is attached to it. Section 312 requires the Attorney General, before bringing an action under section 313, to notify the controller or processor in writing no later than thirty days beforehand, identifying the specific provisions alleged to have been or to be violated. The action is barred if within that thirty-day period the recipient cures the identified violation and provides a written statement that it cured the violation, supplied supporting documentation showing how, and that no further violations will occur. Unlike the equivalent provisions in the Louisiana and Vermont statutes enacted the same year, section 312 carries no sunset date.
Can an Oklahoma resident sue over a privacy violation?
It depends which statute is at issue. Section 313(E) of the Consumer Data Privacy Act states that nothing in the Act provides a basis for, or is subject to, a private right of action for a violation of the Act or any other provision of law, and section 311(A) gives the Attorney General exclusive enforcement authority. The Oklahoma Consumer Protection Act is different: § 15-761.1(A) preserves a private right of action for damages, costs and attorney’s fees, and subsection B adds a civil penalty of up to $2,000.00 per violation payable to the aggrieved consumer where the practice is found unconscionable, recoverable in an individual action only.
What limits Oklahoma schools’ handling of student data?
Section 70-3-168(C)(3) bars the State Department of Education from transferring student or de-identified data to any agency or entity outside Oklahoma without State Board of Education approval, subject to seven listed exceptions including out-of-state transfers and enrolments, national or multistate assessments, voluntary programs, out-of-state vendor contracts, migrant classification and the military student identifier. Subsection (C)(7)(a) makes any newly proposed collection provisional: it must go to the Governor and the Legislature for approval within one year, and expires if not approved by the end of the next legislative session.
How quickly must an Oklahoma insurance licensee report a cybersecurity event?
Section 36-675(A) sets three business days from the determination that a cybersecurity event involving nonpublic information has occurred, running to the Insurance Commissioner rather than the Attorney General. It applies where Oklahoma is the licensee’s state of domicile or home state and the event has a reasonable likelihood of materially harming its normal operations or an Oklahoma consumer, or where the licensee reasonably believes 250 or more Oklahoma consumers’ nonpublic information is involved and the event either triggers notice to another supervisory body or carries that likelihood of material harm. Section 36-671 makes the chapter the exclusive state law on the point for licensees.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.