Skip to Main Content
U.S. Consumer Data Privacy Law Guide: Oklahoma

This state-specific guide covers data privacy law, rules, and regulations that professionals and clients often encounter or have questions about in Oklahoma.

Overview


Last updated: August 2026

Please note this is a highlighted overview and not a complete overview of privacy laws for this state. If you would like a complete review of this state's privacy laws or a multi-state privacy compliance cheat sheet on specific topics, please contact Vivien Peaden at vpeaden@bakerdonelson.com.

Disclaimer: These materials do not constitute legal advice and should not be substituted for the advice of legal counsel.

The Oklahoma Consumer Data Privacy Act (OCDPA)

Effective Date: January 1, 2027.1

1. Applicability Thresholds:2

Subject to certain entity-level and data-level exemptions, the OCDPA applies to any controller or processor doing business in Oklahoma or producing products or services targeted to Oklahoma residents that, during a calendar year, meets any of the following criteria:

  • Controls or processes personal data of at least 100,000 Oklahoma consumers; or
  • Controls or processes personal data of at least 25,000 consumers and derives more than 50 percent of gross revenue from the sale of personal data.

2. Exemptions and Key Definitions:

  • Entity-level Exemptions3: State agencies and political subdivisions (including state government contractors); GLBA-covered financial institutions; HIPAA-covered entities and business associates; all non-profit organizations (without a size limit); and institutions of higher education.
     
  • Data-level Exemptions4: Certain data are exempt, including data collected in a commercial (B2B), employment, or benefits context, as well as personal data collected and used for purposes of the federal policy under the Controlled Substances Act.
     
  • Sales of Personal Data5: "Sales of personal data" is narrowly defined as "the exchange of personal data for monetary consideration by the Controller to a third party."
     
  • Sensitive Data6: "Sensitive data" is broadly defined in the OCDPA and includes:
    • Data revealing racial or ethnic origin, religious belief, health diagnosis, sexual orientation, or immigration status;
    • Genetic or biometric data processed to uniquely identify an individual;
    • Personal data of children under age 13; and
    • Precise geolocation data (i.e., data locating an individual within a radius of no more than 1,750 feet).

The OCDPA requires Controllers to obtain consumer consent before processing sensitive data. For a known child, processing must comply with the federal Children's Online Privacy Protection Act (COPPA).

3. Controller Obligations:

In addition to responding to Consumer rights, a Controller must comply with the following:

  • Data Processing Agreement (DPA)7: Processing activities by a supplier (Processor) shall be governed by a written contract, known as the DPA, between the Controller and Processor. The DPA must include clear instructions for data processing, the nature and duration of processing, and the types of data processed, among other requirements.
     
  • Data Protection Assessment8: Yes. The OCDPA requires Controllers to conduct and document a data protection assessment for the following high-risk processing activities: (1) targeted advertising; (2) sale of personal data; (3) profiling that presents a reasonably foreseeable risk of harm; (4) processing sensitive data; and (5) any processing that presents a heightened risk of harm to consumers.
     
  • Privacy Notice9: A Controller must provide consumers with a privacy notice that includes the categories of personal data processed, including, if applicable, any sensitive data; purposes for processing; the processes for consumer requests, appeals, and opting out of data sales; and, if applicable, the categories of personal data shared with third parties and the categories of those third-party recipients.
     
  • Data Minimization and Purpose Limitation of Data Processing10: The OCDPA requires Controllers to limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for processing. Controllers may not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes, unless the Controller obtains the consumer's consent.

4. Consumer Rights:11

Subject to certain exceptions, Oklahoma consumers have the following rights under the OCDPA:

  • Confirm whether a Controller is processing their personal data and access that data;
  • Correct inaccuracies in the consumer's personal data;
  • Delete personal data provided by or obtained about the consumer;
  • Obtain a copy of the personal data previously provided by the consumer to the Controller in a digital format (known as Data Portability), where the processing is carried out by automated means;
  • Opt out of processing the consumer's personal data for targeted advertising, the sale of personal data, and Profiling in furtherance of "a decision that produces a legal or similarly significant effect concerning the consumer"; and
  • Appeal a Controller's refusal to take action on a consumer request; the Controller must respond in writing within 60 days after receiving the appeal and include the reason or reasons for the decision.

5. Enforcement and Penalties:12

Private Right of Action: None

Penalties: Up to $7,500 per violation. The court may also award reasonable attorney fees and other expenses incurred by the Attorney General in investigating and bringing an action.

Cure Period:13 30-day cure period following receipt of a notice of violation from the Oklahoma Attorney General.

---

1 Okla. SB546, § 22.

2 Okla. SB546, § 15.

3 Okla. SB546, § 15(B).

4 Okla. SB546, § 16.

5 Okla. SB546, § 1(28).

6 Okla. SB546, § 1(29).

7 Okla. SB546, § 9(B).

8 Okla. SB546, § 10.

9 Okla. SB546, § 8(A).

10 Okla. SB546, § 7(A) & § 7(B)(1).

11 Okla. SB546, § 2(B).

12 Okla. SB546, §§ 12–14.

13 Okla. SB546, § 13.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept