Privacy Law Library

Oklahoma Consumer Data Privacy Act (data privacy provisions of 2026 SB 546)

OKCDPA

Comprehensive privacy · Children · Health · Genetic · Biometric · Location

Oklahoma's comprehensive consumer privacy law, signed March 20, 2026, gives Oklahoma residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, get consent before processing sensitive data (COPPA-compliant processing for known children), publish a privacy notice, and conduct data protection assessments for higher-risk processing. It takes effect January 1, 2027.

Where
Oklahoma
Citation
75A O.S. §§ 300-320 (Laws 2026, c. 8, SB 546)
Status
Enacted, not yet in force
In force since
2027-01-01
Enforced by
Oklahoma Attorney General (exclusive authority)
People can sue
No
Penalties
After a mandatory 30-day written notice and cure period, civil penalty of up to $7,500 per violation, plus injunctive relief and reasonable attorney fees and investigative expenses. The cure period does not sunset.
Applies to
  • Controllers and processors that conduct business in Oklahoma or produce products or services targeted to Oklahoma residents and that, in a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data
  • Exempt entities: state agencies, political subdivisions and their service providers; GLBA financial institutions and GLBA-regulated data; HIPAA covered entities and business associates; nonprofit organizations; institutions of higher education
  • Exempt data include PHI, health records, human-subjects research data, FCRA-regulated activity, DPPA and FERPA data, Farm Credit Act data, and employment-context data

What a privacy notice must say

  • Provide a reasonably accessible and clear privacy notice listing categories of personal data (including sensitive data), purposes, how to exercise and appeal rights, and categories of data and third parties shared with; clearly disclose any sale or targeted advertising and how to opt out.75A O.S. § 307 · From 2027-01-01

Rights it gives people

  • Consumers may confirm processing and access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects; a parent or guardian may act for a known child.75A O.S. § 301 · From 2027-01-01

Practices it requires

  • Offer two or more secure and reliable request methods and not require creation of a new account; controllers with a website must provide an online request mechanism (email suffices for online-only controllers with a direct consumer relationship).75A O.S. § 305 · From 2027-01-01
  • Limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes; do not process for incompatible purposes without consent or discriminate against consumers for exercising rights.75A O.S. § 306(A)(1), (B)(1)-(3) · From 2027-01-01
  • Obtain consumer consent before processing sensitive data (including genetic or biometric data used to identify someone and precise geolocation); process a known child's data only in accordance with COPPA.75A O.S. § 306(B)(4); § 300(29) · From 2027-01-01
  • Controllers holding de-identified data must take reasonable measures against re-identification, publicly commit not to re-identify, and contractually bind recipients.75A O.S. § 310(A) · From 2027-01-01
  • Respond to authenticated requests within 45 days (one 45-day extension allowed), free of charge up to twice a year, and explain any refusal with appeal instructions.75A O.S. § 302 · From 2027-01-01
  • Maintain a conspicuous appeal process and answer appeals in writing within 60 days; if an appeal is denied, give the consumer the Attorney General's online complaint mechanism.75A O.S. § 303 · From 2027-01-01

Security duties

  • Establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.75A O.S. § 306(A)(2) · From 2027-01-01

Other duties

  • Conduct and document data protection assessments for targeted advertising, sale, risky profiling, sensitive-data processing, and other heightened-risk processing; provide them to the Attorney General on a civil investigative demand. Applies only to processing that begins on or after January 1, 2027.75A O.S. § 309 · From 2027-01-01
  • Controller-processor contracts must set processing instructions, nature, purpose, duration, and data types, and bind processors to confidentiality, deletion or return, compliance information, assessments, and flow-down to subcontractors.75A O.S. § 308(B) · From 2027-01-01

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: The statute has no official short title; 'Oklahoma Consumer Data Privacy Act' / 'OKCDPA' is the name used by the Legislature's press release and commentators, not a codified short title. | Did not locate any 2026 amendment to 75A §§ 300-320 after enactment; OSCN shows only the original 2026 c. 8 history as of 2026-09-25.

Research reference, not legal advice.