EnglishEspañol
Oklahoma flag

Oklahoma

Oklahoma Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

Oklahoma Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Oklahoma have a biometric privacy law like Illinois BIPA?

No. Oklahoma does not have a standalone biometric privacy statute with a private right of action. Biometric data is protected through the Security Breach Notification Act (24 O.S. 161-166, as amended by SB 626) and the Oklahoma Consumer Data Privacy Act (SB 546, effective January 1, 2027). Neither law allows individuals to sue directly for biometric privacy violations.

Can my employer collect my fingerprints in Oklahoma without my consent?

Under current Oklahoma law (2026), there is no state statute that specifically requires private employers to obtain consent before collecting biometric data. However, the OCDPA will require affirmative consent for processing biometric data starting January 1, 2027, for businesses meeting the law's applicability thresholds. State agencies already must obtain prior consent under the OMES Biometric Data Security Standard.

What happens if a company loses my biometric data in a data breach?

Under the Security Breach Notification Act as amended by SB 626, the company must notify you without unreasonable delay. If the breach affects 500 or more Oklahoma residents, the company must also notify the Attorney General within 60 days. The AG or a district attorney can bring an enforcement action with civil penalties up to $150,000 per breach, except where the company is a state-chartered or state-licensed financial institution, which its primary state regulator enforces instead.

What biometric data is protected under Oklahoma law?

The breach notification law covers 'unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data' used to authenticate a specific individual. The REAL ID statute (47 O.S. 6-110.3) uses a broader definition that includes voice data, iris recognition, retinal scans, fingerprints, palm prints, keystroke dynamics, hand geometry, and DNA/RNA.

Can I file a lawsuit if someone misuses my biometric data in Oklahoma?

Oklahoma law does not provide a private right of action for biometric privacy violations. Enforcement rests with the Attorney General, joined by district attorneys under the breach notification law, and with the primary state regulator where the violator is a state-chartered or state-licensed financial institution. You can file a complaint with the Oklahoma Attorney General, which may lead to an investigation and enforcement action.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the breach-notification data-element list (medical and health insurance information are not covered), clarified that the $75,000 figure is a fixed penalty rather than a lower cap, noted that violations by state-chartered and state-licensed financial institutions are enforced by their primary state regulator instead of the Attorney General, and corrected the scope and citation of the OMES state agency biometric standard.

Removed an unsupported claim that motor-vehicle biometric data must be deleted from state databases; the cited statute contains no such requirement.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. SB 626 Enrolled (Security Breach Notification Act Amendments)(oklegislature.gov).gov
  2. SB 626 Bill Information(oklegislature.gov).gov
  3. SB 546 Bill Information (Oklahoma Consumer Data Privacy Act)(oklegislature.gov).gov
  4. 47 O.S. 6-110.3 (REAL ID Biometric Data Prohibition)(oscn.net).gov
  5. OMES Biometric Data Security Standard(oklahoma.gov).gov
  6. Oklahoma Attorney General - Consumer Protection(oag.ok.gov).gov
  7. Oklahoma Legislators Seek Emergency Court Order on Personal Data Transfer(oksenate.gov).gov
  8. NIST FIPS 140-2 Security Requirements for Cryptographic Modules(csrc.nist.gov).gov
  9. OMES Policy, Standards & Publications(oklahoma.gov).gov
  10. Oklahoma Statutes Title 24, Sections 161-166 (Security Breach Notification Act, compiled)(oklegislature.gov)
Share: