Data privacy; establishing consumer rights; appeal process; privacy notice; data protection assessments; penalties; liability. Effective date.
SB546 creates a comprehensive Oklahoma consumer data privacy law that applies to certain businesses operating in or targeting the state. It gives consumers rights to confirm, access, correct, delete, and obtain portable copies of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling decisions. The bill also requires controllers to provide privacy notices, establish secure request methods and an appeal process, limit data collection to what is reasonably necessary, and obtain consent before processing sensitive data in most cases.
The bill imposes parallel obligations on processors through written contracts with controllers, including confidentiality, deletion/return of data, cooperation with assessments, and support for consumer requests and breach response. It also requires data protection assessments for targeted advertising, data sales, profiling, sensitive data, and other high-risk processing, and it sets special rules for de-identified and pseudonymous data. Enforcement is assigned exclusively to the Attorney General, with a 30-day cure period before suit and civil penalties of up to $7,500 per violation; the bill expressly bars private lawsuits. Numerous exemptions carve out state agencies, nonprofits, higher education, financial institutions covered by GLBA, HIPAA-regulated entities, and a wide range of health, education, employment, research, and other data categories.
The general sentiment reflected in the voting history is strongly favorable. The bill advanced through committee and floor votes with broad bipartisan support, including unanimous committee approval in the Senate Technology & Telecommunications Committee and the House Government Modernization and Technology Committee, a 46-0 Senate third reading vote, an 81-4 House third reading vote, and a 38-7 Senate fourth reading vote. No committee transcripts were provided, so there is no recorded debate summary beyond the vote margins.
The main points of contention appear to be the scope of the law and the balance between privacy rights and business/regulatory burdens. The bill’s exemptions and carve-outs suggest concern about avoiding overlap with existing federal regimes such as HIPAA, FERPA, GLBA, and the FCRA, as well as preserving research, employment, and internal business uses. Other likely pressure points include the Attorney General-only enforcement model, the absence of a private right of action, the cure period before penalties, and the operational burden of consumer request handling, data protection assessments, and contract requirements for processors.
The bill would add a new Title 75A consumer privacy framework in Oklahoma law, establishing statutory rights and duties for controllers and processors that handle personal data of Oklahoma residents. It would regulate collection, use, disclosure, sale, targeted advertising, profiling, sensitive data processing, privacy notices, consumer request procedures, appeals, processor contracts, and data protection assessments, while also creating enforcement authority and civil penalties for violations. The measure would not apply to a broad set of exempt entities and data types, including many health, education, financial, employment, and research records, and it would take effect on July 1, 2026.
The bill appears to have been received positively overall, with strong support at each recorded stage of the legislative process. Committee and floor votes were overwhelmingly in favor, including several unanimous or near-unanimous votes, indicating broad agreement on the need for a consumer privacy statute. The absence of recorded committee testimony limits insight into detailed public arguments, but the vote history suggests the bill was viewed as a workable privacy measure rather than a controversial overhaul.
The likely areas of disagreement are the breadth of the compliance obligations and the extent of exemptions. Businesses and data handlers may view the consumer rights, notice requirements, processor contract mandates, and data protection assessments as costly or administratively complex, while privacy advocates may focus on whether the exemptions are too broad or whether the lack of a private right of action weakens enforcement. The bill’s cure period, AG-only enforcement, and carve-outs for loyalty programs, internal operations, research, and de-identified/pseudonymous data also reflect compromise points that could draw scrutiny from both consumer and industry stakeholders.