Children; covered entities; data protection impact assessment; personal data of children; Attorney General; effective date.
HB1762 creates a new Oklahoma law focused on online privacy and data practices for children. It applies to certain for-profit entities that offer online products, services, or features to Oklahoma users and process children’s personal data. Covered entities would be required to complete and maintain data protection impact assessments for products reasonably likely to be accessed by children, review those assessments when processing changes, and provide them to the Attorney General upon request. The bill also requires high-privacy default settings for children, clear age-appropriate disclosures, and accessible tools for children or parents to exercise privacy rights and report concerns.
The bill goes beyond disclosure requirements and imposes substantive limits on how children’s data may be used. It prohibits processing children’s personal data in ways inconsistent with the child’s best interest, restricts profiling by default, limits collection and use of data not necessary to provide the service, bars certain uses of precise geolocation data, and prohibits dark patterns that pressure children to surrender privacy or take harmful actions. It also requires an obvious signal when a child is being monitored or tracked, including by a parent or guardian using tracking tools.
HB1762 would add a new child online privacy framework to Title 10 of the Oklahoma Statutes, creating duties for covered online businesses and corresponding enforcement authority for the Attorney General. It establishes civil penalties of up to $2,500 per affected child for negligent violations and up to $7,500 per affected child for intentional violations, while making clear there is no private right of action. The bill also exempts certain HIPAA-regulated health information, clinical trial data, telecommunications services, and physical products, and it limits application to larger entities meeting specified consumer-data thresholds or revenue-from-data-sales thresholds. The act would take effect November 1, 2025, and requires initial impact assessments by January 1, 2026 for products likely to be accessed by children after the end of 2025.
The available context shows no committee transcript or recorded vote history, so there is no documented public debate in the provided materials. Based on the bill text, the measure appears to be framed as a child-protection and privacy bill, with a strong regulatory approach aimed at limiting exploitative data practices and design features. The inclusion of Attorney General-only enforcement and a cure period suggests an effort to balance enforcement with compliance flexibility.
The main points of potential contention are the breadth of the bill’s restrictions and the compliance burden on online businesses. Covered entities would need to assess whether products are “reasonably likely to be accessed” by children, determine whether design features, algorithms, advertising, profiling, and geolocation practices are in a child’s best interest, and maintain confidential impact assessments subject to Attorney General review. Another likely issue is the bill’s broad definition of covered entities and its limits on profiling, targeted advertising, and dark patterns, which could be viewed as significant constraints on product design and monetization. At the same time, the bill narrows enforcement to the Attorney General, excludes a private right of action, and includes exemptions and a cure process, which may reduce some opposition from industry while preserving the bill’s core protections.