{
 "jurisdiction_id": "US-OK",
 "jurisdiction": "United States – Oklahoma",
 "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 30,
  "sub_modules": 57,
  "source_register": 11
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Regime is mid-transition: sectoral-only today, comprehensive omnibus law enacted but not yet effective (2027-01-01).",
   "claims": [
    {
     "statement": "The current Oklahoma Attorney General, Gentner Drummond, was sworn in on 9 January 2023 and serves as the state's chief legal officer with consumer-protection enforcement authority.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/attorney-general/gentner-drummond/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC Act prohibits companies and individuals from engaging in unfair or deceptive acts or practices in or affecting commerce, and constitutes the operative general federal privacy-enforcement baseline applicable to Oklahoma businesses absent a state omnibus law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Oklahoma Legislature enacted a comprehensive consumer data privacy law, Senate Bill 546, which passed the House on final passage 84-4 on 19 February 2026 and was substituted on the House floor with a compromise text aligning mostly with the Virginia Consumer Data Protection Act framework.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546 was reported signed into law in March 2026 by the Oklahoma Governor; this is based on a secondary-source headline and was not corroborated against the primary enrolled-bill or Secretary of State record in this research pass.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/oklahoma-comprehensive-data-privacy-bill-signed-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546 covers businesses that control or process the personal data of at least 100,000 Oklahomans, or the data of at least 25,000 consumers while deriving at least 50% of gross revenue from data sales.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "FTC Act Section 5 unfair/deceptive-practices authority applies to conduct affecting commerce nationally, including transactions with Oklahoma consumers, regardless of where the responsible entity is established.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No in-force general lawful-basis regime; forthcoming SB 546 provisions in this area are analogized from the Virginia model rather than confirmed against OK bill text.",
   "claims": [
    {
     "statement": "SB 546 is modeled mostly on the original framework of Virginia's Consumer Data Protection Act, which conditions processing of sensitive personal data on prior opt-in consent; the presence of an equivalent OK-specific opt-in requirement was not independently confirmed against SB 546 bill text.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546's definition of sensitive/special-category personal data was not independently retrieved; a Virginia-CDPA-analogous definition (health, genetic, biometric, racial/ethnic origin, religion, sexual orientation, citizenship/immigration status, precise geolocation, data of known minors) is presumed but unconfirmed.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Speculative",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights confirmed to exist in principle for 2027 commencement; procedural specifics not independently verified.",
   "claims": [
    {
     "statement": "SB 546 contains standard data subject access rights as part of the consumer rights package taking effect 1 January 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Correction and deletion rights are presumed part of SB 546's standard consumer rights package but were not itemized separately in the secondary sources reviewed.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546 contains standard data subject access rights, including opt-outs for targeted advertising and data sales as defined under the bill.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A data-portability right is presumed included in SB 546's standard rights package but was not independently itemized in sources reviewed.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "DPIA obligation confirmed for 2027; DPO/ROPA/retention requirements not identified; sectoral security/breach duties (GLBA, HIPAA) are robustly in force today.",
   "claims": [
    {
     "statement": "SB 546 requires controllers to conduct data protection assessments for a range of processing activities, effective 1 January 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards designed to protect customer information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Financial institutions subject to the FTC Safeguards Rule must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving unauthorized acquisition of at least 500 consumers' unencrypted information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oklahoma maintains a general Security Breach Notification Act requiring notice to affected residents following a breach of computerized personal information; the precise statutory citation and notification timeline were not independently re-verified against primary statutory text in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/state-data-breach-notification-chart",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer/adequacy regime exists at the US-OK level; this is a genuine regulatory gap, not an omission.",
   "claims": [
    {
     "statement": "The United States, including Oklahoma, has no GDPR-style cross-border transfer mechanism regime (adequacy, SCCs, BCRs) applicable to general commercial personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No data-localisation mandate applies to general commercial personal data processed by Oklahoma-based or Oklahoma-serving entities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "green",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Federal sectoral overlays (HIPAA, GLBA, COPPA) are well-established, robustly sourced (T1), and in force.",
   "claims": [
    {
     "statement": "The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, applicable to covered Oklahoma-based financial institutions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The HIPAA Privacy Rule sets limits and conditions on uses and disclosures of protected health information by covered entities and business associates and provides individuals with rights regarding their health information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/mobile-health-apps-interactive-tool",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC Act's obligations apply to HIPAA-covered entities and business associates, as well as to companies that collect, use, or share health information that are not required to comply with HIPAA, filling coverage gaps for non-HIPAA health data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/mobile-health-apps-interactive-tool",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Targeted-advertising/sale opt-out confirmed for 2027; universal opt-out signal recognition explicitly absent; cookie law and dark-patterns provisions unconfirmed.",
   "claims": [
    {
     "statement": "SB 546 omits some of the more common provisions passed by other states in recent years, including recognition of universal opt-out mechanisms and enhanced children's privacy protections.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546 provides consumer opt-outs for targeted advertising and data sales as defined under the bill, effective 1 January 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No confirmed Oklahoma-specific regime in this domain; evidence is thin to absent across all sub-modules.",
   "claims": [
    {
     "statement": "SB 546's Virginia-CDPA-modeled framework may include a profiling opt-out right consistent with other Virginia-model state laws, but an OK-specific profiling-restriction clause was not independently confirmed in the sources reviewed.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "COPPA federal baseline robustly confirmed; SB 546 explicitly omits enhanced children's protections; other sub-modules largely unconfirmed/absent.",
   "claims": [
    {
     "statement": "The Children's Online Privacy Protection Act (COPPA) gives parents control over what information websites can collect from their children, applicable to covered Oklahoma-serving operators.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://consumer.ftc.gov/business-guidance/privacy-security",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546 omits enhanced children's privacy protections found in some other states' comprehensive privacy laws, leaving COPPA as the primary child-data safeguard in Oklahoma.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oklahoma/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement architecture for the 2027 regime is well-characterized (exclusive AG enforcement, cure period, no private right of action); current enforcement-activity and regulator-capacity data are thin.",
   "claims": [
    {
     "statement": "SB 546 will take force 1 January 2027 and offers a 30-day cure provision under exclusive Attorney General enforcement that does not sunset.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Because SB 546 vests exclusive enforcement in the Attorney General, no consumer collective-redress or class-action mechanism is created directly by the Act.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "SB 546 does not create a private right of action, enforcement being exclusive to the Oklahoma Attorney General under a non-sunsetting 30-day cure provision.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "On 19 February 2026, the Oklahoma House approved final passage of Senate Bill 546 on an 84-4 vote, sending the state's first comprehensive consumer data privacy law toward enactment.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-long-winding-road-oklahoma-closes-in-on-comprehensive-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}