Full Breakdown
Oklahoma Enacts Consumer Data Privacy Act
3/28/2026, 8:25:11 PM
Overview of the Oklahoma Consumer Data Privacy Act
On March 20, 2026, Oklahoma Governor Kevin Stitt signed Senate Bill 546 into law, establishing the Oklahoma Consumer Data Privacy Act (OCDPA). This legislation positions Oklahoma as the 20th state to implement a comprehensive consumer data privacy statute, set to take effect on January 1, 2027. The OCDPA is characterized as business-friendly, featuring higher applicability thresholds and broad exemptions, particularly for nonprofit organizations.
Key Provisions and Applicability
The OCDPA applies to entities that conduct business in Oklahoma or target Oklahoma residents, specifically those that either control or process the personal data of at least 100,000 consumers or 25,000 consumers while deriving over 50% of their revenue from data sales. This revenue threshold is notably higher than the 25% standard seen in other states. The law defines "consumer" narrowly, excluding individuals in employment or commercial contexts, and outlines specific categories of sensitive data requiring consumer consent for processing.
Consumer Rights Under the OCDPA
Oklahoma consumers are granted several rights, including:
- Right of Confirmation and Access: Consumers can confirm whether their data is being processed and access that data.
- Right to Correct: Consumers may correct inaccuracies in their data.
- Right to Delete: Consumers can request the deletion of their personal data.
- Right to Data Portability: Consumers may obtain their data in a portable format.
- Right to Opt Out: Consumers can opt out of data processing for targeted advertising and sales.
These rights are subject to authentication, differing from California's approach, which does not require verification for opt-outs.
Obligations for Controllers and Processors
Controllers are required to implement data minimization practices, ensure data security, and provide clear privacy notices detailing data processing activities. Notably, if sensitive data is processed, explicit consent must be obtained. The law mandates that controllers must also conduct data protection assessments for high-risk processing activities.
Enforcement and Penalties
The Oklahoma Attorney General holds exclusive enforcement authority under the OCDPA, with a permanent 30-day cure period for violations. If a violation is not remedied within this timeframe, the Attorney General can seek statutory damages of up to $7,500 per violation. Unlike other states, there is no private right of action for consumers.
Criticism and Comparison to Other States
While the OCDPA introduces important consumer protections, it has been criticized for not being as robust as laws in states like California, which allows consumers a private right of action. Critics argue that the lack of universal opt-out mechanisms and the requirement for consumers to identify companies selling their data before requesting deletion may hinder effective data privacy management.
Conclusion and Implications
The enactment of the OCDPA reflects a growing trend among states to enhance consumer data privacy protections, albeit with a business-friendly approach that may limit its effectiveness compared to more stringent laws. As the effective date approaches, businesses operating in Oklahoma will need to adapt their privacy practices to comply with the new requirements, ensuring they are prepared for the evolving landscape of data privacy regulation.
