HB1012 creates the “Oklahoma Computer Data Privacy Act,” a broad consumer privacy framework governing how certain for-profit businesses collect, use, share, sell, and delete personal information belonging to Oklahoma residents. The bill defines a wide range of covered data, including identifiers, online activity, geolocation, biometric and genetic information, financial and medical information, and inferences drawn from that data. It applies primarily to larger businesses or data brokers meeting specified revenue or data-processing thresholds, and it also reaches affiliated entities sharing a brand name or consumer database.
The bill gives consumers several rights, including the right to request disclosure of what personal information a business has collected, the right to request deletion, the right to learn what information was sold or disclosed and to whom, and the right to opt out of the sale of personal information. It also requires businesses to provide notice before collecting data, maintain privacy policies, designate methods for consumer requests, verify requesters, respond within set timeframes, and protect de-identified information from re-identification. The bill includes exemptions for publicly available information, certain health and research data, financial institutions covered by federal law, and other categories already regulated under federal privacy regimes.
HB1012 would significantly amend state law by codifying a new privacy chapter in Title 17 of the Oklahoma Statutes and by preempting local ordinances on the collection or sale of consumer personal information. It also establishes enforcement authority for the Oklahoma Attorney General, including injunctive relief and civil penalties of up to $2,500 per violation or $7,500 for intentional violations, with collected penalties deposited into a dedicated General Revenue Fund account for administration and enforcement. The act would take effect one year after enactment.
The general sentiment reflected in the available voting history appears favorable at the committee level, as the House Government Modernization and Technology Committee advanced the bill 7-1 on a do-pass vote. The bill’s structure and findings suggest a strong consumer-protection orientation, emphasizing individual control over personal data and rejecting a purely opt-out model in favor of opt-in consent for collection and sale in key circumstances.
The main points of contention are likely to center on the bill’s breadth and compliance burden for businesses, especially the opt-in collection requirement, limits on data sales, restrictions on re-identification, and the potential for civil penalties. The bill also draws clear lines around exemptions and preemption, which may be important to industries such as healthcare, financial services, publishers, and internet service providers. Another possible area of debate is the balance between consumer privacy rights and business uses of data for marketing, analytics, research, and financial incentives.
HB1012 would add a comprehensive consumer data privacy regime to Oklahoma law, creating new statutory rights for residents and new compliance duties for covered businesses. It would regulate collection, sale, disclosure, deletion, opt-out/opt-in consent, privacy notices, request handling, de-identified data, and security practices, while also limiting local regulation through express preemption and giving the Attorney General enforcement authority with civil penalties and injunctive relief.
Available context suggests generally positive momentum for the bill, with a 7-1 do-pass recommendation from the House Government Modernization and Technology Committee. The bill’s findings and structure reflect a strong pro-privacy, consumer-protection posture, indicating support for stronger control over personal data. No committee transcript is available, so the record does not show detailed debate, but the lone dissent and the bill’s extensive business obligations suggest some concern about regulatory burden or implementation costs.
Likely points of contention include the bill’s opt-in consent model for data collection and sale, the scope of covered businesses, and the compliance obligations imposed on companies that collect or monetize consumer data. Businesses may object to the deletion, disclosure, verification, and notice requirements, as well as the civil penalty structure and restrictions on re-identification and data-sharing practices. Exemptions for healthcare, financial institutions, research, and media entities may also be debated, along with the bill’s preemption of local privacy ordinances and its treatment of financial incentives tied to consumer data.