Security Breach Notification Act

OK Breach Act
active

Requires anyone owning or licensing computerized personal information of Oklahoma residents to notify affected residents without unreasonable delay after a breach that causes or is reasonably believed to cause identity theft or fraud. 2025 SB 626 (effective January 1, 2026) added biometric data and government ID numbers to personal information, a new Attorney General notice duty for breaches affecting 500 or more residents, and a safe harbor tied to 'reasonable safeguards'.

Jurisdiction

Oklahoma

Jurisdiction Type

state

Country

United States

Effective Date

11/1/2008

Enforcing Authority

Oklahoma Attorney General or a district attorney (exclusive), as an unlawful practice under the Oklahoma Consumer Protection Act; the primary state regulator for state-chartered or state-licensed financial institutions

Fines Under This Regulation

0

Total Fine Amount (USD)

--