Security Breach Notification Act; prohibiting class action liability for private entity for cybersecurity event; providing exceptions. Effective date.
Summary
SB1716 amends Oklahoma’s Security Breach Notification Act to limit when private entities can face class-action liability after a cybersecurity breach. Under the bill, the Attorney General or a district attorney remains the primary enforcer for violations that injure Oklahoma residents, and may seek actual damages and civil penalties. The measure also preserves a separate enforcement path for state-chartered or state-licensed financial institutions, which would be regulated exclusively by their primary state regulator.
The bill creates a liability framework tied to the entity’s conduct and breach-notification compliance. A private entity that uses reasonable safeguards and gives the required notice would not be subject to civil penalties and could use that compliance as an affirmative defense. If an entity fails to use reasonable safeguards but still provides notice, it would avoid the higher penalty but could still face actual damages and a reduced civil penalty. Most notably, private entities would generally be shielded from class-action liability unless the breach resulted from willful and wanton conduct or gross negligence.
Impact
The bill narrows private litigation exposure under the Security Breach Notification Act and reinforces public enforcement by the Attorney General and district attorneys. It also sets specific civil penalty amounts and standards for how penalties are assessed, while carving out financial institutions for exclusive enforcement by their primary state regulator. In practical terms, the bill would affect businesses and other private entities that handle personal information, as well as consumers affected by data breaches, by shifting enforcement away from class actions and toward state regulators and prosecutors.
Sentiment
The available voting history shows strong support for the bill in committee and on the Senate floor, with unanimous or near-unanimous approval at the stages shown. The Technology and Telecommunications Committee advanced it 8-0, and the Senate passed it 45-0 on third reading. The House Civil Judiciary Committee also advanced it, though with an amended committee substitute and one dissenting vote, suggesting broad support overall with some concern about the details of the liability changes.
Contention
The main point of contention is the bill’s restriction on class-action lawsuits against private entities after a security breach. Supporters appear to favor limiting litigation exposure and channeling enforcement through public officials and regulators, while opponents or skeptics may be concerned that the bill makes it harder for affected individuals to pursue collective remedies. Another likely issue is the bill’s distinction between entities that use reasonable safeguards and those that do not, as well as the special treatment of financial institutions, which are exempted from the general enforcement scheme.
Landlord and tenant; landlord's breach of rental agreement; providing tenant may bring action; liability for damages; withholding payment of rent in certain circumstances; procedure; effective date.
Motor vehicles; modifying list of entities requiring licensure; removing certain exception; requiring certain commercially reasonable data security standards; modifying entities not liable for certain actions. Effective date.