EnglishEspañol
Oklahoma flag

Oklahoma

Oklahoma Data Privacy Laws: OKCDPA, Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

Oklahoma Data Privacy Laws: OKCDPA, Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does Oklahoma have a comprehensive consumer data privacy law?

Yes. Governor Kevin Stitt signed Senate Bill 546 on March 20, 2026, enacting the Oklahoma Consumer Data Privacy Act. The law takes effect January 1, 2027. It applies to businesses that process personal data of at least 100,000 Oklahoma consumers, or 25,000 consumers if more than 50% of gross revenue comes from selling personal data. It grants consumers rights to access, correct, delete, and port their personal data, plus the right to opt out of data sales, targeted advertising, and certain profiling.

What are the penalties for failing to notify consumers of a data breach in Oklahoma?

Under 24 O.S. §§ 161-166 as amended by SB 626, the Oklahoma Attorney General or a district attorney can seek civil penalties up to $150,000 per breach or series of similar breaches discovered in a single investigation. Entities that maintained reasonable security safeguards and provided proper notice have a complete affirmative defense and face no civil penalty; the $75,000 tier applies to entities that lacked reasonable safeguards but still gave proper notice. Enforcement may also include actual damages suffered by affected residents.

What types of personal information are covered under Oklahoma breach notification law?

As of January 1, 2026, Oklahoma's breach notification law covers Social Security numbers, driver's license and state ID numbers, financial account numbers combined with security codes or passwords, government-issued identification numbers such as passport numbers, electronic identifiers and credentials permitting access to financial accounts, biometric data such as fingerprints, retina scans, and iris scans used to authenticate an individual. The data must be unencrypted and combined with the individual's name to trigger the notification requirement.

How quickly must an Oklahoma business report a data breach?

Oklahoma law requires notification without unreasonable delay after discovering a breach. Delay is permitted only to determine scope, restore system integrity, or cooperate with law enforcement. When a breach affects 500 or more Oklahoma residents, the entity must also notify the Oklahoma Attorney General within 60 days after individual notifications are mailed. The AG notification must identify the breach date, types of information exposed, number of residents affected, and security safeguards in place at the time.

What rights will Oklahoma residents have under the new OKCDPA?

Beginning January 1, 2027, Oklahoma residents may confirm whether a covered business is processing their personal data, access a copy of that data, request correction of inaccuracies, request deletion, obtain a portable copy for transfer to another provider, and opt out of targeted advertising, personal data sales, and profiling that produces legal or similarly significant effects. Controllers must respond within 45 days. The AG handles enforcement exclusively; there is no private right of action.

What is the TAKE IT DOWN Act and how does it affect Oklahoma residents?

The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law requiring covered online platforms to remove nonconsensual intimate images (NCII), including AI-generated deepfakes, within 48 hours of a valid removal request. The FTC began enforcing platform obligations on May 19, 2026. Penalties exceed $53,000 per violation. Oklahoma residents who are victims of nonconsensual image distribution can submit a removal request directly to the platform's designated reporting mechanism and file a complaint with the FTC.

Can I be criminally charged for hacking a computer in Oklahoma?

Yes. The Oklahoma Computer Crimes Act (21 O.S. §§ 1951-1958) makes unauthorized computer access a crime. Felony violations, including unauthorized access to damage or copy data, computer fraud schemes, disrupting or denying computer services, and using a computer to put someone in fear of physical harm, carry a fine of between $5,000 and $100,000, imprisonment, or both. Since January 1, 2026 those violations are Class C2 felony offenses, so 21 O.S. § 20M sets the prison term: not more than 7 years for a defendant with no qualifying prior convictions, 2 to 10 years for one with one or two prior Class C or D convictions, and 2 to 12 years for one with three prior Class C or D convictions or any prior Class Y, A, or B conviction. Misdemeanor violations, such as bare unauthorized access, unauthorized use of computer services, or using a computer to harass, carry up to 30 days in jail and fines up to $5,000. Victims may also pursue civil remedies for damages.

Does the Oklahoma Insurance Data Security Act apply to my business?

The Insurance Data Security Act (36 O.S. §§ 670-679) applies to insurers, insurance producers, and other licensees regulated by the Oklahoma Insurance Commissioner. Licensees with less than $5 million in gross annual revenue are exempt. Entities already compliant with HIPAA or GLBA's Title V information security requirements are not required to comply with certain provisions. Covered licensees must maintain an information security program, conduct annual risk assessments, notify the Insurance Commissioner within three business days of a qualifying cybersecurity event, and file an annual data security attestation with the OID.

Updates

Corrected the Computer Crimes Act felony penalty (a first offense carries up to 7 years under the Class C2 schedule effective January 1, 2026, not a flat 10 years), removed a breach-notice content requirement Oklahoma law does not impose, added the real substitute notice thresholds and methods, and clarified that residents must be notified of any qualifying breach while the 500-resident floor and 60-day clock apply only to the Attorney General notice.

Corrected the Security Breach Notification Act's civil-penalty structure (using reasonable security safeguards is a complete defense to any penalty, not a reduction to $75,000; the $75,000 tier applies to entities that lacked safeguards but still gave proper notice), removed inaccurate claims that medical and health-insurance information are covered data elements under the amended breach-notification law, corrected the Oklahoma Computer Crimes Act's list of prohibited acts and felony paragraph count to match the current statute, and fixed two citation errors (SB 626 became law without the Governor's signature rather than being signed, and the affirmative-defense citation is 24 O.S. Sec. 165(C)).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Major refresh: Updated SB 546 status from pending Senate concurrence to signed into law March 20, 2026 by Governor Kevin Stitt, effective January 1, 2027. Added comprehensive OKCDPA section covering $7,500 per-violation penalties, permanent 30-day cure period, no private right of action, sensitive data categories, no universal opt-out/GPC requirement, and data protection assessment requirements. Added TAKE IT DOWN Act (Pub. L. 119-12) section with FTC enforcement beginning May 19, 2026. Added AG Drummond v. Temu enforcement action (filed May 2026). Updated Insurance Data Security Act compliance timeline (primary deadline July 1, 2025; 673(F) access controls deadline July 1, 2026; annual attestations due April 15). Replaced all Justia citations with government and authoritative sources. Added SourcesList and UpdatesLog components. Updated title and meta to reflect enacted OKCDPA. Previous title: Oklahoma Data Privacy Laws: Breach Notification and Consumer Rights (2026).

Reviewed and approved by an editor

Sources and References

  1. Oklahoma SB 546: Oklahoma Consumer Data Privacy Act, enrolled text(oklegislature.gov).gov
  2. Oklahoma House: Major Data Privacy Bill Signed into Law (March 23, 2026)(okhouse.gov).gov
  3. Oklahoma SB 626 Enrolled: Security Breach Notification Act amendments(oklegislature.gov).gov
  4. Oklahoma SB 626 Bill Information, 2025 session(oklegislature.gov).gov
  5. Oklahoma Statutes Title 21: Oklahoma Computer Crimes Act (sections 1951-1958)(oklegislature.gov).gov
  6. Oklahoma Insurance Data Security Act, Oklahoma Insurance Department(oid.ok.gov).gov
  7. Oklahoma Insurance Department Bulletin No. 2024-10: Insurance Data Security Act compliance(oid.ok.gov).gov
  8. Oklahoma Attorney General Consumer Protection Unit(oklahoma.gov).gov
  9. AG Drummond files lawsuit against Temu for data theft (May 2026)(oklahoma.gov).gov
  10. Drummond lauds Senate passage of critical cybersecurity bill (SB 626)(oklahoma.gov).gov
  11. Oklahoma State Department of Education: Student Data Privacy and Security(oklahoma.gov).gov
  12. Oklahoma State Department of Health: HIPAA Privacy Notice(oklahoma.gov).gov
  13. FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
  14. TAKE IT DOWN Act, FTC Legal Library(ftc.gov).gov
  15. TAKE IT DOWN Act: S. 146, 119th Congress full text(congress.gov).gov
  16. Gramm-Leach-Bliley Act, 15 U.S.C. section 6801 (Cornell LII)(law.cornell.edu)
  17. NCSL Security Breach Notification Laws: 50-state comparison(ncsl.org)
  18. Hunton Andrews Kurth: Oklahoma Enacts Comprehensive Consumer Privacy Law (March 2026)(hunton.com)
  19. Troutman Pepper: Oklahoma Enacts Consumer Data Privacy Law (March 2026)(troutmanprivacy.com)
  20. WilmerHale: Oklahoma Enacts Nation's Twentieth State Comprehensive Privacy Law (March 2026)(wilmerhale.com)
  21. 24 O.S. § 163 (Breach of Security - Notice to Individuals, to Attorney General)(oscn.net)
  22. 24 O.S. § 164 (Notice Procedures Deemed in Compliance)(oscn.net)
  23. 24 O.S. § 162 (Security Breach Notification Act Definitions, including substitute notice)(oscn.net)
  24. 21 O.S. § 20M (Class C2 Criminal Offenses - Punishment)(oscn.net)
Share: