SB 546 creates a comprehensive consumer data privacy law for Oklahoma, to be codified in Title 75A. It defines key terms such as personal data, sensitive data, controller, processor, targeted advertising, sale of personal data, profiling, and de-identified data, and establishes a framework for how covered businesses may collect, use, share, and secure consumer information. The bill gives Oklahoma residents rights to confirm whether their data is being processed, access it, correct inaccuracies, delete it, obtain a portable copy in certain circumstances, and opt out of targeted advertising, the sale of personal data, and certain profiling decisions.
The bill also requires covered controllers to provide clear privacy notices, limit data collection to what is reasonably necessary, maintain reasonable data security practices, obtain consent before processing sensitive data, and conduct data protection assessments for higher-risk processing activities. It imposes parallel obligations on processors through written contracts and cooperation requirements, and it includes detailed exemptions for health information, financial data, education records, employment-related data, research, and other categories already regulated by federal law. Enforcement is assigned exclusively to the Attorney General, with a notice-and-cure process before penalties can be sought, and civil penalties can reach $7,500 per violation; the bill expressly bars private lawsuits.
The bill’s impact on state law is to add a new statewide privacy regime governing certain businesses that operate in Oklahoma or target Oklahoma residents, provided they meet the bill’s data-volume or revenue thresholds. It would affect companies that collect or monetize consumer data, especially those engaged in targeted advertising, data sales, profiling, or handling sensitive information. It also limits contractual waivers of consumer privacy rights, creates new compliance duties for privacy notices and consumer request systems, and sets a July 1, 2026 effective date.
The general sentiment reflected in the voting history is strongly favorable and noncontroversial. The bill passed the Senate committee 7-0, passed Senate third reading 46-0, and passed the House committee 8-0, indicating broad bipartisan support. No committee transcripts were provided, so there is no recorded floor or committee debate to suggest significant opposition.
The main points of contention inherent in the bill, rather than in the recorded discussion, are the scope of business coverage, the breadth of consumer rights, and the compliance burden on controllers and processors. Potentially sensitive issues include the opt-out rights for targeted advertising and data sales, the consent requirement for sensitive data, the Attorney General’s exclusive enforcement authority, and the extensive exemptions for health, financial, educational, and employment data. The bill also balances consumer protections against business and research interests by including a cure period, no private right of action, and multiple operational exemptions.
SB 546 would create a new chapter of Oklahoma privacy law in Title 75A that applies to certain controllers and processors meeting specified business and data thresholds. It would require covered entities to provide privacy notices, honor consumer access/correction/deletion/portability/opt-out requests, limit data collection and use, secure personal data, conduct data protection assessments, and impose contractual and oversight duties on processors. It also preempts private enforcement by limiting enforcement to the Attorney General and authorizes civil penalties and injunctive relief for violations after a cure period.
The available voting record shows overwhelming support and no recorded opposition: the bill passed Senate committee 7-0, Senate third reading 46-0, and House committee 8-0. With no committee transcripts provided, there is no evidence of substantive public disagreement in the materials supplied. Overall, the bill appears to have been viewed as a broadly acceptable consumer privacy measure.
The likely areas of contention are the bill’s regulatory reach and compliance obligations for businesses that process large volumes of consumer data, especially those involved in targeted advertising, data sales, and profiling. Privacy advocates would likely favor the consumer rights and consent requirements, while businesses may be concerned about operational costs, notice requirements, data protection assessments, and restrictions on data use. The bill’s broad exemptions for health, financial, education, employment, research, and nonprofit contexts, along with the exclusive Attorney General enforcement model and no private right of action, reflect compromises that may have been intended to reduce opposition.