Oklahoma
Oklahoma Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Oklahoma's Security Breach Notification Act, Okla. Stat. tit. 24, Sections 161 through 166, requires any business that holds Oklahoma residents' computerized personal information to provide notice without unreasonable delay after determining that a breach occurred or being notified of one. Senate Bill 626, effective January 1, 2026, expanded covered data to include biometric identifiers and created a formal Attorney General notification process.
Oklahoma's data breach notification requirements underwent a major overhaul with the passage of Senate Bill 626, effective January 1, 2026. The amended Security Breach Notification Act (Okla. Stat. tit. 24, Sections 161 through 166) expanded the definition of personal information, introduced a formal Attorney General notification requirement, established specific penalty caps, and created a "reasonable safeguards" affirmative defense that rewards businesses for proactive cybersecurity investments.
This guide covers the full scope of Oklahoma's breach notification requirements as amended by SB 626, including what personal information triggers the law, who must be notified, the timeline, enforcement penalties, exemptions, and how the law connects to the state's broader data privacy framework.

Who Must Comply With Oklahoma's Breach Notification Law
Oklahoma's breach notification law applies to any individual or entity that owns or licenses computerized data that includes personal information of Oklahoma residents. Section 163(A) keys coverage solely on owning or licensing that data. It contains no separate "conducts business in this state" element.
Third-party data maintainers who do not own or license the data but maintain it on behalf of another entity must notify the data owner of any breach as soon as practicable following determination of the breach. The data owner then carries the obligation to notify affected consumers and regulators.
Out-of-state businesses holding Oklahoma residents' data are fully subject to the law, because the duty follows the data rather than any physical presence in the state.
What Qualifies as a Security Breach
Under the amended statute, a breach of the security of a system means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by the entity as part of a database of personal information regarding multiple individuals, and that causes, or the entity reasonably believes has caused or will cause, identity theft or other fraud to a resident of Oklahoma.
The definition focuses on "unauthorized access and acquisition," meaning both elements must be present. Mere unauthorized access without actual acquisition of data does not trigger notification.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the entity for the purposes of the entity's business does not constitute a breach, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
The Encryption Safe Harbor
Oklahoma provides an encryption safe harbor, but with important conditions. Encrypted or redacted data does not trigger notification requirements, unless:
- The encrypted data is accessed and acquired in an unencrypted or unredacted form, or
- The breach involves a person with access to the encryption key, and the entity reasonably believes the breach has caused or will cause identity theft or other fraud
This means businesses cannot rely solely on encryption to avoid notification obligations if the encryption key was also compromised or if fraud is likely.

What Personal Information Triggers the Law
Under SB 626, the definition of personal information was significantly expanded. Personal information now means an individual's first name or first initial and last name in combination with any of the following data elements:
- Social Security number
- Driver license number or other unique identification number created or collected by a government entity (broadened under SB 626, which replaced the narrower "state identification card number issued in lieu of a driver license" language, so the element now reaches any unique government-issued ID number)
- Financial account number, credit card number, or debit card number, in combination with any required security code, access code, or password
- Biometric data (fingerprints, retinal scans, and other identifying biometric information) (new under SB 626)
- A unique electronic identifier or routing code in combination with a required security code, access code, or password that permits access to an individual's financial account (new under SB 626)
The addition of biometric data is significant for businesses that use fingerprint-based time clocks, facial recognition systems, or biometric authentication for mobile apps and secure facilities. These types of data are now fully covered by the notification statute.
Personal information does not include information that is lawfully obtained from publicly available sources or from federal, state, or local government records lawfully made available to the general public.
Notification Timeline
Oklahoma does not impose a single fixed deadline for notifying affected individuals. The statute requires notification "without unreasonable delay," consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the integrity of the system.
However, SB 626 introduced a specific 60-day deadline for Attorney General notification. When a breach affects 500 or more Oklahoma residents, the entity must notify the AG without unreasonable delay and no later than 60 days after providing notice to residents.
Law enforcement may request a delay if notification would impede a criminal investigation. Once law enforcement determines that notification will no longer be impeded, the entity must provide notice without unreasonable delay.
Who Must Be Notified
Affected Individuals
Every Oklahoma resident whose personal information was compromised in a manner that causes or is reasonably believed to cause identity theft or other fraud must receive notification.
Attorney General
Under SB 626, the Oklahoma Attorney General must be notified when a breach affects 500 or more Oklahoma residents. The AG notification must be made without unreasonable delay and no later than 60 days after providing notice to affected residents. Section 163(E)(1) specifies the contents. The notice must include:
- The date of the breach
- The date of its determination
- The nature of the breach
- The type of personal information exposed
- The number of Oklahoma residents affected
- The estimated monetary impact of the breach, to the extent it can be determined
- Any reasonable safeguards the entity employs
Credit Bureaus
Oklahoma's law does not require notifying consumer reporting agencies about a breach at another business. The only credit-bureau-specific provision runs the other way: a breach at an entity that is itself a credit bureau is exempt from the Attorney General notification duty unless it affects 1,000 or more Oklahoma residents, a higher threshold than the 500-resident exemption that applies to other entities.
Methods of Notification
Businesses can provide notification through:
- Written notice sent to the individual's last known mailing address
- Electronic notice consistent with the federal E-SIGN Act
- Telephone notice directly to the affected individual
Substitute Notice
Substitute notice is available if the entity demonstrates that:
- The cost of providing notice would exceed $50,000, or
- The affected class exceeds 100,000 persons, or
- The entity does not have sufficient contact information or consent
Oklahoma's substitute notice thresholds are notably lower than most states ($50,000 cost and 100,000 persons vs. the more common $250,000 and 500,000). Substitute notice must include any two of the following: email notice (where available), conspicuous posting on the entity's website, or notification to major statewide media.

Enforcement and Penalties
Civil Penalties
SB 626 established the enforcement structure in Section 165:
- Up to $150,000 per breach. The Attorney General or a district attorney may obtain actual damages plus a civil penalty not to exceed $150,000 per breach, or per series of breaches of a similar nature determined in a single investigation. That figure is a ceiling, not a fixed or default amount. Section 165(B) directs that penalties be based on the magnitude of the breach, the extent to which the entity's own behavior contributed to it, and any failure to provide the notice Section 163 requires
- $75,000 per breach for an entity that fails to use reasonable safeguards but does provide the required notice. That entity is not subject to the Section 165(B) penalty at all, but under Section 165(C)(2) it is subject to actual damages and a civil penalty of $75,000
The Reasonable Safeguards Affirmative Defense
One of SB 626's most significant additions is the "reasonable safeguards" affirmative defense. An entity that demonstrates it implemented reasonable safeguards at the time of the breach and provided notice in accordance with the statute is not subject to civil penalties and can raise compliance as an affirmative defense in civil actions.
Reasonable safeguards are defined as policies and practices that ensure personal information is secure, taking into consideration the entity's size and the type and amount of personal information maintained. Qualifying measures include:
- Conducting regular risk assessments
- Implementing technical and physical layered defenses
- Training employees on handling personal information
- Establishing an incident response plan
This provision incentivizes businesses to invest in proactive cybersecurity measures rather than treating breach notification as a purely reactive obligation.
No Private Right of Action
Oklahoma's breach notification statute does not create a private right of action. Individuals cannot sue businesses directly under this law for breach notification failures. Enforcement is handled by the Attorney General.
Exemptions
Federal Compliance Exemptions
Entities that maintain their own notification procedures as part of an information privacy or security policy are deemed in compliance, provided those procedures are consistent with the timing requirements of the Security Breach Notification Act. Section 164(A) sets a timing test, not a general test of how thorough the procedures are.
Financial institutions that comply with the Gramm-Leach-Bliley Act's interagency guidance on breach notification, entities that comply with the Oklahoma Hospital Cybersecurity Protection Act of 2023 or with HIPAA's breach notification requirements, and entities that comply with the notification rules of their own primary or functional federal regulator are all deemed in compliance with Oklahoma's individual-notice requirements. That safe harbor applies only if the entity also provides the Attorney General notice required under Section 163(E).
What Changed Under SB 626 (Summary)
For businesses already familiar with Oklahoma's earlier breach notification law, here are the key changes effective January 1, 2026:
| Feature | Before SB 626 | After SB 626 |
|---|---|---|
| Personal information | SSN, driver license or state ID card number, financial accounts | Added biometric data and unique electronic identifiers, and broadened the driver license element to any unique identification number created or collected by a government entity |
| AG notification | Not required | Required at 500+ affected residents |
| AG deadline | N/A | 60 days after consumer notice |
| Penalty cap | None specified | Up to $150,000 per breach plus actual damages; $75,000 plus actual damages if notice given without safeguards; $0 if notice given with safeguards |
| Reasonable safeguards defense | Not available | Full affirmative defense |
| CRA notification | N/A | Not required (credit bureaus get a 1,000-resident AG-notice exemption, vs. 500 for other entities) |
This article provides general legal information about Oklahoma data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Oklahoma for guidance specific to your situation.
More Oklahoma Laws
Frequently Asked Questions
When does Oklahoma's amended data breach notification law take effect?
Senate Bill 626 took effect on January 1, 2026. Section 166 applies the Act to the determination or notification of a breach of the security of the system that occurs on or after that date. SB 626 replaced the earlier reference to discovery with determination or notification, so a breach determined before January 1, 2026 but notified on or after that date falls under the amended Act.
How quickly must a business notify Oklahoma residents of a data breach?
Oklahoma requires notification to affected individuals without unreasonable delay. For Attorney General notification (required when 500 or more residents are affected), the deadline is within 60 days of providing notice to residents.
Does Oklahoma's breach notification law now cover biometric data?
Yes. SB 626 expanded the definition of personal information to include biometric data such as fingerprints and retinal scans. Businesses using biometric authentication systems (fingerprint time clocks, facial recognition) must now treat that data as protected under the breach notification statute.
What is the reasonable safeguards affirmative defense in Oklahoma?
Under SB 626, businesses that can demonstrate they implemented reasonable safeguards (risk assessments, layered defenses, employee training, and an incident response plan) and provided timely notice are not subject to civil penalties at all and can use compliance as an affirmative defense in civil actions. Entities that lacked reasonable safeguards but still provided timely notice are subject to actual damages and a civil penalty of $75,000 rather than the penalty of up to $150,000 per breach that Section 165(B) authorizes.
Can individuals sue a business in Oklahoma for failing to provide breach notification?
No. Oklahoma's breach notification statute does not create a private right of action. Only the Attorney General can bring enforcement actions. However, individuals may have claims under other legal theories such as negligence or breach of contract.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Attorney General notice contents, the driver license data element, the civil penalty structure, the own-procedures safe harbor standard, and the effective-date trigger to match the enrolled text of SB 626 and the current Sections 162 through 166, and removed a coverage requirement the statute does not contain.
Corrected this page's description of Oklahoma's SB 626 breach-notification penalty and exemption structure: reasonable safeguards plus timely notice is a full defense against civil penalties (not merely a reduced cap), removed a fabricated requirement to notify consumer reporting agencies (the actual rule is a higher AG-notice exemption threshold for breaches at credit bureaus), corrected the financial-account-tied definition of the electronic-identifier data element, fixed substitute notice to require any two of three methods rather than all three, and clarified that the federal-compliance safe harbors (GLBA, HIPAA/Oklahoma Hospital Cybersecurity Protection Act, primary federal regulator) require Attorney General notice to apply.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Oklahoma Statutes, Title 24: DEBTOR AND CREDITOR
§ 163Duty to provide notice of breachIn forcecited in 3 of our articles
A. An individual or entity that owns or licenses computerized data that includes personal information shall provide notice of any breach of the security of the system following determination or notification of the breach of the security of the system to any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. Except as provided in subsection D of this section or in order to take any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the system, the disclosure shall be made without unreasonable delay. B.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oklegislature.gov
Also relied on in: Oklahoma Data Privacy Laws: OKCDPA, Breach Notification & Consumer Rights (2026), Oklahoma Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Oklahoma SB 626 (Enrolled) - Security Breach Notification Act Amendment(oklegislature.gov).gov
- SB 626 Bill Information - Oklahoma Legislature(oklegislature.gov).gov
- Oklahoma Office of the Attorney General(oklahoma.gov).gov
- Oklahoma OMES - Cybersecurity Breaches(oklahoma.gov).gov
- Okla. Stat. tit. 24, Sections 161 through 166, Security Breach Notification Act (Oklahoma Statutes Title 24)(oklegislature.gov)