Law / United States / Oklahoma

Security Breach Notification Act

Okla. Stat. tit. 24, Secs. 162-166

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 November 2008, effective 1 January 2026.

A breach notification rule binding public and private bodies.

As of 28 August 2026.

What it requires

  • Provide notice of a breach of security involving personal information without unreasonable delay.
  • Notify the Oklahoma Attorney General within 60 days of consumer notice if the breach affects 500 or more Oklahoma residents (1,000 or more for a breach maintained by a credit bureau).
  • Do not assume a bare identification use of a recording-derived identifier is covered biometric data under this statute. Its definition is bound to authentication use, not identification generally, and carries no exclusion or clawback clause either way.

If you get it wrong

Private right of actionNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

An individual or entity, defined to include a government, governmental subdivision, agency, or instrumentality as well as a private organization, that owns or licenses computerized data including personal information must provide notice of a breach of security without unreasonable delay.

Personal information includes a name combined with a Social Security number, a driver's license or government-issued identification number, a financial account number, or unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data to authenticate a specific individual, and excludes information lawfully obtained from publicly available sources or government records.

Because this definition is purpose-bound to authentication rather than identification generally, and carries neither an exclusion nor a clawback clause, whether an identifier algorithmically derived from a public recording to identify, rather than authenticate access for, a person falls within it cannot be determined from the text; such an identifier would most likely fail the definition's own authentication threshold rather than being excluded by an express carve-out.

Notice to the Attorney General is required within 60 days of consumer notice for a breach affecting 500 or more residents (1,000 or more for a credit-bureau-maintained breach); smaller breaches are exempt from Attorney General notice entirely.

The Attorney General or a district attorney has exclusive authority to enforce a violation causing injury or loss, in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act, and may recover actual damages and a civil penalty of up to $150,000 per breach; the statute creates no private right of action, and reasonable safeguards plus compliant notice is an affirmative defense against the state's own civil-penalty action, not a private plaintiff's claim.

Originally enacted by Laws 2008, House Bill 2245, effective November 1, 2008, and most recently and substantially amended by Laws 2025, Senate Bill 626, effective January 1, 2026.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics

Read the law

official Oklahoma statute text, Title 24 of the Oklahoma Statutes, Oklahoma State Courts Network

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app