Security Breach Notification Act; prohibiting class action liability for private entity for cybersecurity event; providing exceptions. Effective date.
Summary
SB1716 amends Oklahoma’s Security Breach Notification Act to limit when private entities can be sued in class actions after a cybersecurity breach. Under the bill, the Attorney General or a district attorney retains exclusive authority to enforce most violations of the Act and may seek actual damages and civil penalties. The measure also creates a tiered penalty structure tied to whether the entity used reasonable safeguards and whether it provided the required breach notices.
The bill provides that a private entity is generally not liable in a class action arising from a system breach unless the breach was caused by willful and wanton conduct or gross negligence. If an entity used reasonable safeguards and gave the required notice, it is shielded from civil penalties and may use compliance as an affirmative defense. If it failed to use reasonable safeguards but still gave notice, it remains liable for actual damages and a reduced civil penalty. The bill also preserves exclusive enforcement by the primary state regulator for state-chartered or state-licensed financial institutions.
Impact
SB1716 would narrow private class-action exposure for businesses and other private entities subject to Oklahoma’s breach-notification requirements, while preserving public enforcement by the Attorney General, district attorneys, and, for certain financial institutions, the primary state regulator. It amends 24 O.S. 2021, Section 165, and affects how civil penalties and damages are assessed for violations of the Security Breach Notification Act, including a cap and reduced penalty framework based on safeguards and notice compliance. The bill is set to take effect November 1, 2026.
Sentiment
The bill appears to have broad support in the legislative process, passing the Senate 45-0 and the Senate Technology & Telecommunications Committee 8-0, and advancing in the House Civil Judiciary Committee by a 5-1 vote. The available transcript snippets show no substantive floor debate or extended opposition, suggesting the measure was generally viewed as a technical or policy refinement to Oklahoma’s data-breach enforcement scheme. The committee history indicates the bill was amended and continued through the process with little visible resistance.
Contention
The main point of contention is the bill’s restriction on class-action liability for private entities after a cybersecurity event. Supporters likely view this as a way to reduce litigation exposure and align penalties with the entity’s conduct, especially where reasonable safeguards and notice were provided. Potential opponents may be concerned that limiting class actions could reduce remedies for affected consumers and weaken deterrence for poor cybersecurity practices. The bill addresses this by preserving liability for gross negligence or willful and wanton conduct and by maintaining public enforcement authority, but the class-action limitation remains the most significant policy tradeoff.
Landlord and tenant; landlord's breach of rental agreement; providing tenant may bring action; liability for damages; withholding payment of rent in certain circumstances; procedure; effective date.
Motor vehicles; modifying list of entities requiring licensure; removing certain exception; requiring certain commercially reasonable data security standards; modifying entities not liable for certain actions. Effective date.