Changeflow GovPing Data Privacy & Cybersecurity Oklahoma Enacts Comprehensive State Privacy Law
Priority review Rule Added Final

Oklahoma Enacts Comprehensive State Privacy Law

Favicon for www.jdsupra.com JD Supra Privacy
Published January 1st, 2027
Detected March 28th, 2026
Email

Summary

Oklahoma has enacted its 21st state-level comprehensive privacy law, Enrolled Senate Bill No. 546, which will take effect on January 1, 2027. The law grants consumers specific privacy rights and imposes obligations on businesses regarding data processing, security, and disclosures, enforced by the Attorney General.

What changed

Oklahoma has officially passed Enrolled Senate Bill No. 546, establishing a comprehensive state privacy law set to become effective on January 1, 2027. This new legislation grants Oklahoma residents rights such as access, correction, deletion, and portability of their personal data, along with opt-out rights for targeted advertising and the sale of personal data. The law applies to controllers and processors doing business in Oklahoma or targeting its residents, meeting specific thresholds for data processing volume or revenue derived from data sales. It mandates data minimization, reasonable security measures, privacy notice disclosures, and data protection assessments for high-risk processing activities.

Businesses operating in or targeting Oklahoma residents must prepare for compliance by January 1, 2027. Key actions include establishing processes for consumer data requests, implementing opt-out mechanisms for targeted advertising and data sales, conducting data protection assessments for specified processing activities, and ensuring data minimization and security practices. The Oklahoma Attorney General will enforce the law, offering a 30-day cure period for violations, but there is no private right of action. Companies should review their data processing activities and vendor contracts to ensure alignment with the new requirements.

What to do next

  1. Review applicability of the law based on consumer data processing thresholds.
  2. Implement mechanisms for consumer data access, correction, deletion, and portability requests.
  3. Establish opt-out processes for targeted advertising and sale of personal data.
  4. Conduct data protection assessments for high-risk processing activities.

Penalties

Enforced by the Attorney General with a 30-day cure process; no private right of action.

Source document (simplified)

March 27, 2026

Oklahoma Joins Comprehensive State Privacy Law Landscape

LinkedIn Facebook X Send Embed On March 20, 2026, Oklahoma Governor Kevin Stitt signed into law Enrolled Senate Bill No. 546, a comprehensive privacy law that will go into effect on January 1, 2027—this makes Oklahoma the 21st state to enact a comprehensive privacy law. The bill follows the common model used in many state privacy statutes: it grants consumers baseline privacy rights, requires opt-outs for targeted advertising and certain disclosures, and expects companies to document and manage higher-risk processing.

In general, the law applies to a controller or processor doing business in Oklahoma, or targeting Oklahoma residents, and, during a calendar year, either controls or processes personal data of at least 100,000 consumers, or controls/processes personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.

Consumers have rights to access and confirm processing, correct inaccuracies, delete personal data (including data “provided by or obtained about” the consumer), obtain portable data the consumer provided, and opt out of targeted advertising, the sale of personal data, and certain profiling with significant effects.

“Sale” is the exchange of personal data for monetary consideration, with carve-outs including disclosures to processors, for requested services, and to affiliates. Notably, this is narrower than laws in states that include “valuable consideration” in the definition of sale. “Sensitive data” includesprecise geolocation, biometric data used for unique identification, and known children’s data, and generally requires opt-in consent.

The statute also calls for data minimization and reasonable security, required privacy notice disclosures (including clear disclosure of sale/targeted advertising, where applicable), and data protection assessments for targeted advertising, sale of personal data, sensitive data processing, and certain profiling/high-risk processing. It will be enforced by the Attorney General, includes a 30-day cure process, and provides no private right of action. Companies should use the lead time to confirm applicability and operationalize opt-outs, consent, consumer requests, vendor controls, and assessments.

[View source.]

Send Print Report

Latest Posts

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.
Attorney Advertising.

©
Robinson+Cole Data Privacy + Security Insider
2026

Written by:

Robinson+Cole Data Privacy + Security Insider Contact + Follow Roma Patel + Follow

PUBLISH YOUR CONTENT ON JD SUPRA

  • ✔ Increased readership
  • ✔ Actionable analytics
  • ✔ Ongoing writing guidance Join more than 70,000 authors publishing their insights on JD Supra

Start Publishing »

Published In:

Consumer Privacy Rights + Follow Data Privacy + Follow Data Protection + Follow New Legislation + Follow Opt-Outs + Follow Personal Data + Follow Regulatory Requirements + Follow State Privacy Laws + Follow Consumer Protection + Follow Privacy + Follow Science, Computers & Technology + Follow more

Robinson+Cole Data Privacy + Security Insider on:

Solve with 2Captcha

Solve with 2Captcha

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
OK AG
Published
January 1st, 2027
Compliance deadline
January 1st, 2027 (279 days)
Instrument
Rule
Legal weight
Binding
Stage
Final
Change scope
Substantive
Document ID
Enrolled Senate Bill No. 546

Who this affects

Applies to
Consumers Employers
Industry sector
5112 Software & Technology 5221 Commercial Banking 4231 Wholesale Trade
Activity scope
Data Processing Targeted Advertising Sale of Personal Data
Threshold
Controls or processes personal data of at least 100,000 consumers, OR controls/processes personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.
Geographic scope
US-OK US-OK

Taxonomy

Primary area
Data Privacy
Operational domain
Compliance
Compliance frameworks
CCPA/CPRA Dodd-Frank
Topics
Consumer Protection Consumer Finance

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when JD Supra Privacy publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.