Law note · Oklahoma
Security Breach Notification Act
An individual or entity, defined to include a government, governmental subdivision, agency, or instrumentality as well as a private organization, that owns or licenses computerized data including personal information must provide notice of a breach of security without unreasonable delay.
Personal information includes a name combined with a Social Security number, a driver's license or government-issued identification number, a financial account number, or unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data to authenticate a specific individual, and excludes information lawfully obtained from publicly available sources or government records.
Because this definition is purpose-bound to authentication rather than identification generally, and carries neither an exclusion nor a clawback clause, whether an identifier algorithmically derived from a public recording to identify, rather than authenticate access for, a person falls within it cannot be determined from the text; such an identifier would most likely fail the definition's own authentication threshold rather than being excluded by an express carve-out.
Notice to the Attorney General is required within 60 days of consumer notice for a breach affecting 500 or more residents (1,000 or more for a credit-bureau-maintained breach); smaller breaches are exempt from Attorney General notice entirely.
The Attorney General or a district attorney has exclusive authority to enforce a violation causing injury or loss, in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act, and may recover actual damages and a civil penalty of up to $150,000 per breach; the statute creates no private right of action, and reasonable safeguards plus compliant notice is an affirmative defense against the state's own civil-penalty action, not a private plaintiff's claim.
Originally enacted by Laws 2008, House Bill 2245, effective November 1, 2008, and most recently and substantially amended by Laws 2025, Senate Bill 626, effective January 1, 2026.
What it asks of an app
- Provide notice of a breach of security involving personal information without unreasonable delay.
- Notify the Oklahoma Attorney General within 60 days of consumer notice if the breach affects 500 or more Oklahoma residents (1,000 or more for a breach maintained by a credit bureau).
- Do not assume a bare identification use of a recording-derived identifier is covered biometric data under this statute. Its definition is bound to authentication use, not identification generally, and carries no exclusion or clawback clause either way.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_biometrics
Primary source: official Oklahoma statute text, Title 24 of the Oklahoma Statutes, Oklahoma State Courts Network