Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Adult content age verification (AV)
Makes a commercial entity that knowingly publishes or distributes material harmful to minors, where more than a third of the site's content meets that definition, civilly liable to a minor's parent or guardian unless it performs reasonable age verification to confirm a visitor is 18 or older, defined as a digitized identification card, an independent third party verification service checking commercial databases, or a commercially reasonable method relying on transactional data.
It also requires the entity to let internet and cellular subscribers request that access to the site be blocked, and bars retaining a user's identifying information after access is granted.
Note and primary source →
Age-appropriate design code
Comprehensive consumer privacy law whose minor specific protection is that personal data collected from a known child, defined as an individual younger than 13, is sensitive data that a controller may not process without consent and, for a known child, must handle in accordance with COPPA. It contains no separate targeted advertising or sale restriction for minors 13 and older.
Passed the House 84 to 4 on February 19, 2026 and the Senate 38 to 7 on March 16, 2026, and signed by Governor Stitt on March 20, 2026.
Note and primary source →
Breach notification
cite Okla. Stat. tit. 24, Secs. 162-166
stage IN FORCE in force since 2008-11-01
effective 2026-01-01
source official Oklahoma statute text, Title 24 of the Oklahoma Statutes, Oklahoma State Courts Network
An individual or entity, defined to include a government, governmental subdivision, agency, or instrumentality as well as a private organization, that owns or licenses computerized data including personal information must provide notice of a breach of security without unreasonable delay.
Personal information includes a name combined with a Social Security number, a driver's license or government-issued identification number, a financial account number, or unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data to authenticate a specific individual, and excludes information lawfully obtained from publicly available sources or government records.
Because this definition is purpose-bound to authentication rather than identification generally, and carries neither an exclusion nor a clawback clause, whether an identifier algorithmically derived from a public recording to identify, rather than authenticate access for, a person falls within it cannot be determined from the text; such an identifier would most likely fail the definition's own authentication threshold rather than being excluded by an express carve-out.
Notice to the Attorney General is required within 60 days of consumer notice for a breach affecting 500 or more residents (1,000 or more for a credit-bureau-maintained breach); smaller breaches are exempt from Attorney General notice entirely.
The Attorney General or a district attorney has exclusive authority to enforce a violation causing injury or loss, in the same manner as an unlawful practice under the Oklahoma Consumer Protection Act, and may recover actual damages and a civil penalty of up to $150,000 per breach; the statute creates no private right of action, and reasonable safeguards plus compliant notice is an affirmative defense against the state's own civil-penalty action, not a private plaintiff's claim.
Originally enacted by Laws 2008, House Bill 2245, effective November 1, 2008, and most recently and substantially amended by Laws 2025, Senate Bill 626, effective January 1, 2026.
What it asks of an app →
Comprehensive regime
cite Okla. Stat. tit. 75A, Secs. 314-315
stage IMMINENT in force in 125 days
effective 2027-01-01
source official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)
The Oklahoma Consumer Data Privacy Act (SB 546 Secs. 15-16) applies to a controller or processor that conducts business in Oklahoma, or produces a product or service targeted to Oklahoma residents, and that during a calendar year controls or processes the personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50 percent of gross revenue from selling personal data.
The Act exempts state agencies and political subdivisions and their service providers, GLBA-regulated financial institutions, HIPAA and HITECH covered entities and business associates, nonprofits, institutions of higher education, purely personal or household processing, and Controlled Substances Act listed-chemicals data.
Signed into law in the 2026 Regular Session of the 60th Legislature after passing the House on February 19, 2026 and the Senate on March 16, 2026; Section 22 of the enrolled act sets the effective date as January 1, 2027, not yet reached.
What it asks of an app →
Data subject rights
cite Okla. Stat. tit. 75A, Secs. 301-303
stage IMMINENT in force in 125 days
effective 2027-01-01
source official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)
SB 546 Secs. 2-4 give an Oklahoma consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy in a digital format, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect.
A controller must respond within 45 days of a request, extendable once by 45 more days with notice to the consumer, must fulfill a request free of charge up to twice annually, and may charge a fee for a manifestly unfounded, excessive, or repetitive request only if the controller bears the burden of showing the request is such. A declined request may be appealed through a process the Act requires the controller to establish.
What it asks of an app →
Enforcement supervision
cite Okla. Stat. tit. 75A, Secs. 312-313
stage IMMINENT in force in 125 days
effective 2027-01-01
source official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)
The Oklahoma Attorney General has authority to enforce SB 546. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated (SB 546 Sec. 13); no sunset date for this cure period appears in the sections read.
A controller or processor who violates the Act after that cure period, or who breaches its own written statement of cure, is liable for a civil penalty of up to $7,500 per violation, and the Attorney General may seek to recover it and to restrain or enjoin the violation. The Act expressly forecloses a private right of action for a violation of the Act or any other provision of law.
What it asks of an app →
Sensitive categories
cite Okla. Stat. tit. 75A, Sec. 300(3), (29)
stage IMMINENT in force in 125 days
effective 2027-01-01
source official Oklahoma enrolled bill text, Senate Bill 546, 60th Legislature (2026 Regular Session)
SB 546 Sec. 1 classifies genetic or biometric data processed to uniquely identify a person as sensitive data, requiring the consumer's prior opt-in consent before a controller may process it.
Biometric data means data from automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, or eye retina or iris, or other unique biological pattern or characteristic, used to identify a specific individual; the definition excludes a physical or digital photograph, a video or audio recording, or data generated from either, unless that data is generated to identify a specific individual, at which point it falls back inside the definition.
A faceprint or voiceprint deliberately extracted from a public photograph or recording for identification purposes is therefore biometric data, and sensitive data, under this Act, the same clawback structure as Kentucky's and New Hampshire's comprehensive acts.
What it asks of an app →