Security Breach Notification Act
OK Breach Act
Breach notification · Data security · Biometric
Requires anyone owning or licensing computerized personal information of Oklahoma residents to notify affected residents without unreasonable delay after a breach that causes or is reasonably believed to cause identity theft or fraud. 2025 SB 626 (effective January 1, 2026) added biometric data and government ID numbers to personal information, a new Attorney General notice duty for breaches affecting 500 or more residents, and a safe harbor tied to 'reasonable safeguards'.
- Where
- Oklahoma
- Citation
- 24 O.S. §§ 161-166
- Status
- In force
- In force since
- 2008-11-01
- Last amended
- 2026-01-01
- Enforced by
- Oklahoma Attorney General or a district attorney (exclusive), as an unlawful practice under the Oklahoma Consumer Protection Act; the primary state regulator for state-chartered or state-licensed financial institutions
- People can sue
- No
- Penalties
- Actual damages plus a civil penalty up to $150,000 per breach (or series of similar breaches in one investigation), scaled to magnitude and fault. An entity that used reasonable safeguards and gave required notice faces no civil penalty and has an affirmative defense; one that gave notice but lacked reasonable safeguards faces actual damages and a $75,000 civil penalty.
- Applies to
- Individuals and entities (including governments and their agencies) that own, license, or maintain computerized data including personal information of Oklahoma residents
- Personal information: first name or initial and last name plus SSN, driver license or other government ID number, financial account or card number with required access code, electronic identifier or routing code with access code, or unique biometric data used for authentication
What a privacy notice must say
- Notice may be written, telephonic, or electronic; substitute notice (any two of email, website posting, statewide media) is allowed if cost exceeds $50,000, more than 100,000 residents are affected, or contact information is insufficient.24 O.S. § 162(7)
Security duties
- Using 'reasonable safeguards' (risk assessments, layered technical and physical defenses, employee training, and an incident response plan, scaled to entity size and data) plus proper notice shields an entity from civil penalties.24 O.S. §§ 162(8), 165(C) · From 2026-01-01
Breach duties
- Notify each affected Oklahoma resident without unreasonable delay after determining a breach of unencrypted, unredacted personal information that causes or is reasonably believed to cause identity theft or other fraud.24 O.S. § 163(A)
- Notice is also required when encrypted or redacted data is acquired in usable form or the breach involves a person with access to the encryption key.24 O.S. § 163(B)
- A person maintaining data it does not own or license must notify the owner or licensee as soon as practicable after determining a breach.24 O.S. § 163(C)
- Notify the Attorney General within 60 days after notifying residents, stating the breach date, determination date, nature of breach, data types, number of Oklahomans affected, estimated monetary impact, and safeguards used.24 O.S. § 163(E)(1) · Only if: Not required if fewer than 500 residents are affected (fewer than 1,000 for a credit bureau breach) · From 2026-01-01
- Notice may be delayed at a law enforcement agency's direction that notice would impede an investigation or national or homeland security.24 O.S. § 163(D)
Other duties
- Entities following their own consistent notice procedures, or GLBA, HIPAA, Oklahoma Hospital Cybersecurity Protection Act of 2023, or primary federal regulator notice rules, are deemed compliant with resident notice if they also notify the Attorney General.24 O.S. § 164
Sources
- Official text
- 24 O.S. § 162, Definitions (OSCN)
- 24 O.S. § 163, Breach notice to individuals and Attorney General (OSCN)
- 24 O.S. § 164, Compliance (OSCN)
- 24 O.S. § 165, Enforcement (OSCN)
- 24 O.S. § 166, Application (OSCN)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.