Law / United States / Oklahoma

Oklahoma

United States law applies in Oklahoma Oklahoma is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Oklahoma, described on this page below, applies here too.

All 11 named instruments researched to a stage, across four of the six areas of law we track: 5 in force and 6 enacted but not yet in force. As of 14 September 2026.

When they take effect10 of 11 carry a date, 1 does not. Earlier is before 2015.
Before 2015: 1 instrument (1 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 1 instrument (1 in force) ’25 2026: 1 instrument (1 in force) 2027: 6 instruments (6 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (156 words)

Oklahoma has no enacted AI-transparency, chatbot-disclosure, or election-deepfake statute reaching a private actor.

A broad Artificial Intelligence Bill of Rights proposal died in committee in 2024, and three 2026 measures, an AI-generated-media bill (HB 3299), an AI companion chatbot minor-access bill (HB 3544), and a state-agency AI-use bill (HB 3545, which would have bound government use only), each cleared at least one committee before dying at the Legislature's 2026 adjournment without final passage; Title 26's election code carries no synthetic-media or AI-disclosure provision as of the current codification.

Oklahoma does have an enacted AI-specific criminal prohibition: a 2025 amendment (Senate Bill 53) to the child sexual abuse material definition at 21 O.S. Section 1024.1 extends the offense to a visual depiction that appears to be a minor engaged in sexually explicit conduct regardless of whether an actual child, a computer-generated image, or an altered image, closing the prior definition's gap for AI-generated child sexual abuse material.

AI prohibited practices

Computer-generated child sexual abuse material prohibition (SB 53, 2025 amendment)

21 O.S. § 1024.1(A)(3), as amended by SB 53 (2025)official enrolled act text, Oklahoma Legislature

In force 11 months, effective 1 November 2025. Binds public and private bodies.

What this law does

Section 1024.1(A)(3), added by Senate Bill 53 (2025), extends Oklahoma's definition of child sexual abuse material to any visual depiction that appears to be a child engaged in sexually explicit conduct regardless of whether the depiction is of an actual child, a computer-generated image, or an image altered to appear to be a child, so long as the depiction is obscene.

This definition governs Sections 1021, 1021.1 through 1021.4, Sections 1022, 1023, and Sections 1040.8 through 1040.24 of Title 21. The amendment took effect November 1, 2025.

What it requires

Privacy law5 instruments, 1 in force, 4 enacted but not yet in force

Research summary (270 words)

Oklahoma enacted a comprehensive consumer personal-data-protection statute, the Oklahoma Consumer Data Privacy Act (Senate Bill 546, 60th Legislature, 2026 Regular Session), which will take effect January 1, 2027; every one of the act's substantive sections codifies at Title 75A, correcting an earlier record that placed it at Title 74, a different, government-only breach statute.

The Act applies to a controller or processor conducting business in Oklahoma, or targeting Oklahoma residents, that processes 100,000 consumers' personal data annually, or 25,000 consumers' data while deriving over half of gross revenue from data sales, and gives consumers rights to access, correct, delete, and port their data and to opt out of targeted advertising, sale, and qualifying profiling.

Genetic or biometric data processed to uniquely identify a person is sensitive data requiring opt-in consent, and the Act's biometric data definition excludes a photograph or a video or audio recording, and data generated from either, only until that data is generated to identify a specific individual, at which point a faceprint or voiceprint manufactured from a public recording for identification purposes falls back inside the definition.

The Attorney General has exclusive enforcement authority, subject to a 30-day cure period, and the Act expressly forecloses a private right of action for any violation.

Separately, Oklahoma's pre-existing Security Breach Notification Act, Okla. Stat. tit. 24, Secs. 161-166, most recently and substantially amended effective January 1, 2026, defines biometric data on a different, purpose-bound-to-authentication basis with no exclusion or clawback clause, applies to government and private entities alike, and likewise creates no private right of action, with the Attorney General or a district attorney holding exclusive enforcement authority.

Breach notification

Security Breach Notification Act

Okla. Stat. tit. 24, Secs. 162-166official Oklahoma statute text, Title 24 of the Oklahoma Statutes, Oklahoma State Courts Network

In force since 1 November 2008, effective 1 January 2026. Binds public and private bodies.

What this law does

An individual or entity, defined to include a government, governmental subdivision, agency, or instrumentality as well as a private organization, that owns or licenses computerized data including personal information must provide notice of a breach of security without unreasonable delay.

Personal information includes a name combined with a Social Security number, a driver's license or government-issued identification number, a financial account number, or unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data to authenticate a specific individual, and excludes information lawfully obtained from publicly available sources or government records.

Because this definition is purpose-bound to authentication rather than identification generally, and carries neither an exclusion nor a clawback clause, whether an identifier algorithmically derived from a public recording to identify, rather than authenticate access for, a person falls within it cannot be determined from the text; such an identifier would most likely fail the definition's own authentication threshold rather than being excluded by an express carve-out.

Notice to the Attorney General is required within 60 days of consumer notice for a breach affecting 500 or more residents (1,000 or more for a credit-bureau-maintained breach); smaller breaches are exempt from Attorney General notice entirely.

The Attorney General or a district attorney has exclusive authority to enforce a violation causing injury or loss, in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act, and may recover actual damages and a civil penalty of up to $150,000 per breach; the statute creates no private right of action, and reasonable safeguards plus compliant notice is an affirmative defense against the state's own civil-penalty action, not a private plaintiff's claim.

Originally enacted by Laws 2008, House Bill 2245, effective November 1, 2008, and most recently and substantially amended by Laws 2025, Senate Bill 626, effective January 1, 2026.

What it requires

Comprehensive regime

Oklahoma Consumer Data Privacy Act, general applicability and exemptions

Okla. Stat. tit. 75A, Secs. 314-315official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

The Oklahoma Consumer Data Privacy Act (SB 546 Secs. 15-16) applies to a controller or processor that conducts business in Oklahoma, or produces a product or service targeted to Oklahoma residents, and that during a calendar year controls or processes the personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50 percent of gross revenue from selling personal data.

The Act exempts state agencies and political subdivisions and their service providers, Gramm-Leach-Bliley Act (GLBA)-regulated financial institutions, Health Insurance Portability and Accountability Act (HIPAA) and HITECH covered entities and business associates, nonprofits, institutions of higher education, purely personal or household processing, and Controlled Substances Act listed-chemicals data.

Signed into law in the 2026 Regular Session of the 60th Legislature after passing the House on February 19, 2026 and the Senate on March 16, 2026; Section 22 of the enrolled act sets the effective date as January 1, 2027, not yet reached.

What it requires

Data subject rights

Oklahoma Consumer Data Privacy Act, consumer rights

Okla. Stat. tit. 75A, Secs. 301-303official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

SB 546 Secs. 2-4 give an Oklahoma consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy in a digital format, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect.

A controller must respond within 45 days of a request, extendable once by 45 more days with notice to the consumer, must fulfill a request free of charge up to twice annually, and may charge a fee for a manifestly unfounded, excessive, or repetitive request only if the controller bears the burden of showing the request is such. A declined request may be appealed through a process the Act requires the controller to establish.

What it requires

Enforcement supervision

Oklahoma Consumer Data Privacy Act, Attorney General enforcement

Okla. Stat. tit. 75A, Secs. 312-313official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

The Oklahoma Attorney General has authority to enforce SB 546. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated (SB 546 Sec. 13); no sunset date for this cure period appears in the sections read.

A controller or processor who violates the Act after that cure period, or who breaches its own written statement of cure, is liable for a civil penalty of up to $7,500 per violation, and the Attorney General may seek to recover it and to restrain or enjoin the violation. The Act expressly forecloses a private right of action for a violation of the Act or any other provision of law.

What it requires

Sensitive categories

Oklahoma Consumer Data Privacy Act, sensitive data and biometric data definitions

Okla. Stat. tit. 75A, Sec. 300(3), (29)official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

SB 546 Sec. 1 classifies genetic or biometric data processed to uniquely identify a person as sensitive data, requiring the consumer's prior opt-in consent before a controller may process it.

Biometric data means data from automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, or eye retina or iris, or other unique biological pattern or characteristic, used to identify a specific individual; the definition excludes a physical or digital photograph, a video or audio recording, or data generated from either, unless that data is generated to identify a specific individual, at which point it falls back inside the definition.

A faceprint or voiceprint deliberately extracted from a public photograph or recording for identification purposes is therefore biometric data, and sensitive data, under this Act, the same clawback structure as Kentucky's and New Hampshire's comprehensive acts.

What it requires

Scraping law3 instruments, 2 in force, 1 enacted but not yet in force

Research summary (233 words)

Oklahoma diverges from the federal baseline in three respects. Its Computer Crimes Act (21 O.S. Section 1953) tracks a without-authorization or exceeding-authorization standard closer to the federal Computer Fraud and Abuse Act (CFAA)'s structure than California's broader test, and it expressly exempts authorized security testing of a computer system's own vulnerabilities and a parent's monitoring or denial of a child's computer or internet access.

The Oklahoma Consumer Data Privacy Act (Senate Bill 546, effective January 1, 2027, already covered as a privacy-topic instrument) excludes from its personal data definition information lawfully available through a government record or that a business reasonably believes is lawfully available to the public through widely distributed media, by the consumer, or by a person the consumer disclosed it to, unless restricted to a specific audience, a definition that will reach most scraped public personal data once the Act takes effect.

The Oklahoma Deceptive Trade Practices Act (78 O.S. Sections 51 to 55), in force since 1965, gives any person damaged or likely to be damaged by a deceptive trade practice a private injunctive and damages action, an available but untested track for a scraping-adjacent unfair-competition claim. No Oklahoma court decision applying any of these three statutes to a scraping or automated-collection fact pattern was located.

Copyright, text-and-data-mining, database rights, and ToS enforceability add nothing beyond the federal position already covered in the national document; robots.txt carries no independent legal weight under Oklahoma law.

Computer misuse

Oklahoma Computer Crimes Act, prohibited acts and penalties

21 O.S. § 1953official text, Oklahoma State Courts Network (OSCN), Oklahoma Statutes Citationized

In force since 29 March 1984. Binds public and private bodies.

What this law does

Section 1953 makes it unlawful to willfully and without authorization gain or attempt to gain access to a computer, computer system, or computer network, to willfully exceed the limits of authorization, or to willfully and without authorization use or disrupt computer services, tracking a without-authorization or exceeding-authorization standard rather than California's broader without permission test.

A violation of the access, fraud, disruption, or harassment paragraphs is a Class C2 felony punishable under Section 1955; bare unauthorized access, unauthorized use of computer services, or using a computer to annoy, abuse, threaten, or harass another person is a misdemeanor. The statute expressly exempts a parent, guardian, or foster parent monitoring or denying a child's computer or internet access, and exempts authorized testing evaluating a computer system's own security.

What it requires

Personal data

Oklahoma Consumer Data Privacy Act, publicly available information exemption

Okla. Stat. tit. 75A, § 300.3(27)official enrolled act text, Oklahoma Legislature

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

The Oklahoma Consumer Data Privacy Act, which takes effect January 1, 2027, excludes publicly available information from its definition of personal data: information lawfully made available through a government record, or that a business has a reasonable basis to believe is lawfully made available to the general public through widely distributed media, by a consumer, or by a person to whom a consumer disclosed it, unless the consumer restricted the information to a specific audience.

The Act's provisions do not apply to a state agency or political subdivision of Oklahoma, or a service provider processing data on their behalf.

What it requires

Unfair competition

Oklahoma Deceptive Trade Practices Act

78 O.S. §§ 51-55official text, Oklahoma Statutes, Title 78 complete-title compilation (Oklahoma Senate)

In force. Binds public and private bodies.

What this law does

The Oklahoma Deceptive Trade Practices Act lists specific deceptive practices in the course of business, vocation, or occupation, including passing off goods or services as another's and making false representations of source, sponsorship, approval, or affiliation, and gives any person damaged or likely to be damaged by a deceptive trade practice a private right of action for an injunction and, where damages are proved, actual damages.

What it requires

Age gating law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (151 words)

Oklahoma has required age verification for websites publishing material harmful to minors since November 2024 under SB 1959, and enacted a comprehensive privacy law in March 2026, the Oklahoma Consumer Data Privacy Act (SB 546), which once it takes effect on January 1, 2027 will treat personal data collected from a known child under 13 as sensitive data that cannot be processed without consent and COPPA compliant handling.

A social media minor access bill (HB 1275) passed the House 64 to 30 in March 2025 but stalled in the Senate, where its enacting clause was stricken in committee in April 2025; it saw no further action and died when the 60th Legislature adjourned sine die in May 2026. A companion Senate bill (SB 931) requiring social media age verification and parental supervisory tools also died without a Senate floor vote. Oklahoma has no app store or device level age verification law.

Adult content age verification (AV)

SB 1959, age verification for material harmful to minors

Okla. Stat. tit. 15, sections 791 to 791.4 (2024 Senate Bill 1959)official enrolled bill text on the Oklahoma Legislature website

In force since 1 November 2024. Binds private bodies.

What this law does

Makes a commercial entity that knowingly publishes or distributes material harmful to minors, where more than a third of the site's content meets that definition, civilly liable to a minor's parent or guardian unless it performs reasonable age verification to confirm a visitor is 18 or older, defined as a digitized identification card, an independent third party verification service checking commercial databases, or a commercially reasonable method relying on transactional data.

It also requires the entity to let internet and cellular subscribers request that access to the site be blocked, and bars retaining a user's identifying information after access is granted.

Note and primary source

Age-appropriate design code

SB 546, Oklahoma Consumer Data Privacy Act

Okla. Stat. tit. 75A, section 300 et seq. (2026 Senate Bill 546, Oklahoma Consumer Data Privacy Act)official Oklahoma Legislature bill information page

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Comprehensive consumer privacy law whose minor specific protection is that personal data collected from a known child, defined as an individual younger than 13, is sensitive data that a controller may not process without consent and, for a known child, must handle in accordance with COPPA. It contains no separate targeted advertising or sale restriction for minors 13 and older.

Passed the House 84 to 4 on February 19, 2026 and the Senate 38 to 7 on March 16, 2026, and signed by Governor Stitt on March 20, 2026.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.