Law / United States /
Oklahoma
Oklahoma Consumer Data Privacy Act, Attorney General enforcement
Okla. Stat. tit. 75A, Secs. 312-313
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 100 days, effective 1 January 2027.
An enforcement supervision rule binding private bodies.
As of 28 August 2026.
What it requires
- Expect Oklahoma Consumer Data Privacy Act violations to be enforced only by the Oklahoma Attorney General, never by a private plaintiff. The Act expressly forecloses a private right of action.
- Cure a noticed violation within 30 days of Attorney General notice to avoid a civil penalty of up to $7,500 per violation.
If you get it wrong
Private right of actionNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Oklahoma Attorney General has authority to enforce SB 546. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated (SB 546 Sec. 13); no sunset date for this cure period appears in the sections read.
A controller or processor who violates the Act after that cure period, or who breaches its own written statement of cure, is liable for a civil penalty of up to $7,500 per violation, and the Attorney General may seek to recover it and to restrain or enjoin the violation. The Act expressly forecloses a private right of action for a violation of the Act or any other provision of law.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.