Security Breach Notification Act; requiring notice of security breach of certain information; modifying provisions. Effective date.
SB626 revises Oklahoma’s Security Breach Notification Act to update and expand the rules governing when businesses, government entities, and other organizations must notify affected residents after a data breach. The bill modernizes key definitions, including “personal information,” “encrypted,” “redact,” and “reasonable safeguards,” and clarifies that a breach involves unauthorized access to unencrypted and unredacted personal data that is reasonably believed to create a risk of identity theft or fraud. It also specifies that good-faith access by employees or agents is not a breach if the information is used lawfully and not further disclosed without authorization.
The bill requires notice to affected residents without unreasonable delay and adds a new requirement that certain breaches also be reported to the Attorney General within 60 days after resident notice. That Attorney General notice must include details such as the date of the breach, the date it was determined, the type of information exposed, the number of residents affected, estimated monetary impact if known, and the safeguards used. SB626 also creates exemptions from the Attorney General reporting requirement for smaller breaches, including breaches affecting fewer than 500 Oklahoma residents, and fewer than 1,000 residents for credit bureaus. It further recognizes compliance with certain federal or sector-specific notification regimes, including financial institutions, HIPAA-covered entities, and entities regulated by a primary federal regulator, as compliance with the state act.
The bill’s impact on state law is to strengthen and update Oklahoma’s data breach notification framework while also creating clearer compliance pathways and some liability protections. It changes the effective date of the act’s applicability to breaches occurring on or after January 1, 2026, and makes personal information submitted to the Attorney General confidential. It also modifies enforcement by the Attorney General or district attorneys, adjusts civil penalties, and provides that entities using reasonable safeguards and giving required notice are shielded from civil penalties, while entities that fail to use reasonable safeguards but still notify may face reduced penalties and actual damages. State-chartered or state-licensed financial institutions remain subject to exclusive enforcement by their primary state regulator.
Overall, the bill appears to have been received favorably by both chambers, passing the Senate and House with substantial margins. The vote totals suggest broad bipartisan support, though not unanimity, indicating general agreement on the need to modernize breach reporting rules and align them more closely with current cybersecurity and privacy practices. The absence of committee transcript material limits insight into detailed floor debate, but the voting pattern suggests the bill was viewed as a practical update rather than a controversial overhaul.
The main points of contention likely center on the new Attorney General reporting requirement, the confidentiality of breach submissions, and the liability provisions tied to “reasonable safeguards.” Businesses and regulated entities may view the added reporting obligations and potential penalties as burdensome, while consumer-protection advocates may support the stronger disclosure and oversight requirements. The exemptions for smaller breaches and for entities already subject to federal or specialized notification rules appear designed to reduce duplication and may have helped secure broad support.
SB626 amends 24 O.S. 2021, Sections 162 through 166, of the Security Breach Notification Act. It updates statutory definitions, imposes new or clarified notice obligations to residents and the Attorney General, creates confidentiality protections for information submitted to the Attorney General, recognizes compliance with certain federal breach-notification regimes as compliance with Oklahoma law, and revises civil-penalty and liability provisions. The bill also changes the act’s applicability date to breaches occurring on or after January 1, 2026, thereby replacing the prior 2008 applicability date.
The bill appears to have enjoyed generally positive and pragmatic support in both the Senate and House, as reflected by strong passage margins at each stage. The vote history suggests lawmakers broadly agreed that Oklahoma’s breach-notification law needed updating to reflect current cybersecurity practices, clearer definitions, and more structured reporting. The lack of recorded committee discussion prevents a detailed read on debate, but the final votes indicate the measure was not highly polarizing.
Likely areas of disagreement include the new requirement to notify the Attorney General, the scope of exemptions for smaller breaches, and the bill’s liability framework. Covered entities and businesses may have been concerned about added administrative burdens, disclosure of sensitive breach details, and potential exposure to penalties, while consumer advocates likely favored stronger transparency and enforcement. The carve-outs for financial institutions, HIPAA-covered entities, and federally regulated entities may also have been a point of negotiation, balancing state oversight with existing federal compliance regimes.