Oklahoma enacted a comprehensive consumer personal-data-protection statute, the Oklahoma Consumer Data Privacy Act (Senate Bill 546, 60th Legislature, 2026 Regular Session), which will take effect January 1, 2027; every one of the act's substantive sections codifies at Title 75A, correcting an earlier record that placed it at Title 74, a different, government-only breach statute.
The Act applies to a controller or processor conducting business in Oklahoma, or targeting Oklahoma residents, that processes 100,000 consumers' personal data annually, or 25,000 consumers' data while deriving over half of gross revenue from data sales, and gives consumers rights to access, correct, delete, and port their data and to opt out of targeted advertising, sale, and qualifying profiling.
Genetic or biometric data processed to uniquely identify a person is sensitive data requiring opt-in consent, and the Act's biometric data definition excludes a photograph or a video or audio recording, and data generated from either, only until that data is generated to identify a specific individual, at which point a faceprint or voiceprint manufactured from a public recording for identification purposes falls back inside the definition.
The Attorney General has exclusive enforcement authority, subject to a 30-day cure period, and the Act expressly forecloses a private right of action for any violation.
Separately, Oklahoma's pre-existing Security Breach Notification Act, Okla. Stat. tit. 24, Secs. 161-166, most recently and substantially amended effective January 1, 2026, defines biometric data on a different, purpose-bound-to-authentication basis with no exclusion or clawback clause, applies to government and private entities alike, and likewise creates no private right of action, with the Attorney General or a district attorney holding exclusive enforcement authority.