USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Oklahoma Privacy & Data Security Laws

Every statute below can apply to a business handling Oklahoma residents' data, depending on your revenue, the number of Oklahoma consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Not yet effective — signed Mar 20, 2026, effective Jan 1, 2027
Oklahoma Computer Data Privacy Act
OCDPA
Verify details

Newly enacted, not yet in force. Standard model: applies at 100,000+ Oklahoma consumers, or 25,000+ if 50%+ of revenue comes from selling personal data. Notable for a narrow "sale" definition (monetary consideration only) and a non-sunsetting cure period.

Okla. Stat. (2026 SB 546, exact codification pending)Read statute →

Data Security & Breach Notification · 1

Varies by state
Oklahoma data breach notification law
OK Breach Notification

SB 626 (effective Jan 1, 2026) broadened the definition of covered personal information (adding government IDs, unique electronic identifiers, and biometric data) and created a new formal 60-day AG notice process for breaches affecting 500+ residents. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

24 Okla. Stat. §§ 161–166, as amended by 2026 SB 626Read statute →