Oklahoma Consumer Data Privacy Act (data privacy provisions of 2026 SB 546)
OKCDPA
Comprehensive privacy · Children · Health · Genetic · Biometric · Location
Oklahoma's comprehensive consumer privacy law, signed March 20, 2026, gives Oklahoma residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, get consent before processing sensitive data (COPPA-compliant processing for known children), publish a privacy notice, and conduct data protection assessments for higher-risk processing. It takes effect January 1, 2027.
- Where
- Oklahoma
- Citation
- 75A O.S. §§ 300-320 (Laws 2026, c. 8, SB 546)
- Status
- Enacted, not yet in force
- In force since
- 2027-01-01
- Enforced by
- Oklahoma Attorney General (exclusive authority)
- People can sue
- No
- Penalties
- After a mandatory 30-day written notice and cure period, civil penalty of up to $7,500 per violation, plus injunctive relief and reasonable attorney fees and investigative expenses. The cure period does not sunset.
- Applies to
- Controllers and processors that conduct business in Oklahoma or produce products or services targeted to Oklahoma residents and that, in a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data
- Exempt entities: state agencies, political subdivisions and their service providers; GLBA financial institutions and GLBA-regulated data; HIPAA covered entities and business associates; nonprofit organizations; institutions of higher education
- Exempt data include PHI, health records, human-subjects research data, FCRA-regulated activity, DPPA and FERPA data, Farm Credit Act data, and employment-context data
What a privacy notice must say
- Provide a reasonably accessible and clear privacy notice listing categories of personal data (including sensitive data), purposes, how to exercise and appeal rights, and categories of data and third parties shared with; clearly disclose any sale or targeted advertising and how to opt out.75A O.S. § 307 · From 2027-01-01
Rights it gives people
- Consumers may confirm processing and access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects; a parent or guardian may act for a known child.75A O.S. § 301 · From 2027-01-01
Practices it requires
- Offer two or more secure and reliable request methods and not require creation of a new account; controllers with a website must provide an online request mechanism (email suffices for online-only controllers with a direct consumer relationship).75A O.S. § 305 · From 2027-01-01
- Limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes; do not process for incompatible purposes without consent or discriminate against consumers for exercising rights.75A O.S. § 306(A)(1), (B)(1)-(3) · From 2027-01-01
- Obtain consumer consent before processing sensitive data (including genetic or biometric data used to identify someone and precise geolocation); process a known child's data only in accordance with COPPA.75A O.S. § 306(B)(4); § 300(29) · From 2027-01-01
- Controllers holding de-identified data must take reasonable measures against re-identification, publicly commit not to re-identify, and contractually bind recipients.75A O.S. § 310(A) · From 2027-01-01
- Respond to authenticated requests within 45 days (one 45-day extension allowed), free of charge up to twice a year, and explain any refusal with appeal instructions.75A O.S. § 302 · From 2027-01-01
- Maintain a conspicuous appeal process and answer appeals in writing within 60 days; if an appeal is denied, give the consumer the Attorney General's online complaint mechanism.75A O.S. § 303 · From 2027-01-01
Security duties
- Establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.75A O.S. § 306(A)(2) · From 2027-01-01
Other duties
- Conduct and document data protection assessments for targeted advertising, sale, risky profiling, sensitive-data processing, and other heightened-risk processing; provide them to the Attorney General on a civil investigative demand. Applies only to processing that begins on or after January 1, 2027.75A O.S. § 309 · From 2027-01-01
- Controller-processor contracts must set processing instructions, nature, purpose, duration, and data types, and bind processors to confidentiality, deletion or return, compliance information, assessments, and flow-down to subcontractors.75A O.S. § 308(B) · From 2027-01-01
Sources
- Official text
- 75A O.S. §§ 300-320, Data Privacy (OSCN index)
- 75A O.S. § 311 with historical data (Laws 2026, SB 546, c. 8, eff. Jan. 1, 2027) (OSCN)
- Enrolled Senate Bill 546 (Oklahoma Legislature)
- SB 546 bill history, approved by Governor 03/20/2026 (Oklahoma Legislature)
- Oklahoma House news release, Mar. 23, 2026
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The statute has no official short title; 'Oklahoma Consumer Data Privacy Act' / 'OKCDPA' is the name used by the Legislature's press release and commentators, not a codified short title. | Did not locate any 2026 amendment to 75A §§ 300-320 after enactment; OSCN shows only the original 2026 c. 8 history as of 2026-09-25.
Research reference, not legal advice.