HB1012 creates the “Oklahoma Computer Data Privacy Act,” a broad consumer data privacy framework for certain for-profit businesses operating in Oklahoma. The bill defines key data privacy terms such as personal information, biometric information, genetic information, de-identified information, service provider, third party, and verifiable consumer request. It applies to businesses above specified size or data-use thresholds, including those with more than $15 million in annual gross revenue, those handling personal information of 50,000 or more consumers/households/devices, or those deriving 25% or more of revenue from selling personal information.
The bill gives Oklahoma consumers several rights over their personal information. These include the right to request disclosure of categories and specific items of data collected, the right to request deletion, the right to learn what data was sold or disclosed and to whom, and the right to opt out of sale of personal information. It also requires businesses to provide notice before collecting data directly from consumers, maintain online privacy policies, designate methods for consumer requests, verify requests, respond within set timeframes, and protect de-identified information from re-identification. The bill also restricts discriminatory treatment of consumers who exercise privacy rights, allows certain financial incentives with opt-in consent, and imposes security and training obligations on businesses.
HB1012 would significantly affect state law by codifying a comprehensive privacy regime in Title 17 of the Oklahoma Statutes and preempting local ordinances or rules on the collection or sale of consumer personal information. It also includes exemptions for publicly available information, certain health and medical information governed by HIPAA and related laws, financial institutions covered by GLBA, consumer reporting agencies, research activities, and data collected or sold wholly outside Oklahoma. The bill provides that federal law controls in the event of conflict, and that the state law affording the greatest privacy protection prevails in conflicts with other Oklahoma statutes.
The general sentiment reflected in the available voting history is favorable. The bill received a 7-1 “DO PASS” recommendation in the House Government Modernization and Technology Committee, suggesting substantial support for stronger consumer privacy protections. No committee transcript is available, so there is no recorded debate to indicate broader concerns or support beyond the vote itself.
The main points of contention inherent in the bill are the scope of compliance obligations for businesses, the opt-in model for data collection and sale, and the breadth of consumer rights and enforcement provisions. Businesses subject to the act would need to revise privacy notices, request workflows, verification procedures, deletion processes, and internal training, while the Attorney General would gain authority to seek injunctive relief and civil penalties. The bill also draws clear lines around exemptions for health, financial, research, and media-related activities, indicating likely sensitivity around balancing privacy rights with operational, journalistic, and regulated-industry needs.
HB1012 would add a new consumer privacy chapter to Title 17 of the Oklahoma Statutes and create enforceable duties for covered businesses that collect, sell, or disclose personal information. It would require notice, consent, access, deletion, opt-out, and security practices, while also limiting re-identification of de-identified data and prohibiting retaliation against consumers who exercise privacy rights. The bill authorizes Attorney General enforcement, civil penalties, and injunctive relief, and it preempts local government rules on consumer data sales and collection.
The available legislative history suggests generally positive sentiment toward the bill, with the House Government Modernization and Technology Committee voting 7-1 to recommend passage. That vote indicates broad support for consumer privacy protections, though the absence of transcript material means there is no detailed record of the arguments made for or against the measure. The bill’s structure also suggests an effort to balance privacy rights with business, research, and regulated-industry exemptions.
Likely areas of contention include the bill’s opt-in requirement for collection and sale of personal information, the compliance burden on covered businesses, and the scope of Attorney General enforcement and penalties. Businesses may object to the operational costs of notice, verification, deletion, and privacy-policy obligations, while privacy advocates would likely support the stronger consumer controls. Additional tension may arise around exemptions for health care, financial institutions, media entities, and research, as well as the bill’s limits on re-identification and its preemption of local privacy rules.