🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-OK · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 11 sources retrieved model claude-sonnet-5 ·

United States – Oklahoma

US-OK schema gdpri-v2 trajectory: not recordedin transitionoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 30 claims · 11 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
30Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Regime is mid-transition: sectoral-only today, comprehensive omnibus law enacted but not yet effective (2027-01-01).

Primary frameworkFTC Act Section 5 (in force) + Oklahoma Security Breach Notification Act (in force) + Senate Bill 546 comprehensive consumer data privacy law (enacted, effective 2027-01-01)
Supervisory authorityOklahoma Attorney General
Traffic-light rationale — AmberRegime is mid-transition: sectoral-only today, comprehensive omnibus law enacted but not yet effective (2027-01-01).

Sub-modules (5)

Regulator And AuthorityAmber

The Oklahoma Attorney General (currently Gentner Drummond) is the designated state enforcement authority for consumer protection and will hold exclusive enforcement authority under SB 546 once effective. The FTC is the concurrent federal enforcement authority under Section 5.

Claims (1):

  • The current Oklahoma Attorney General, Gentner Drummond, was sworn in on 9 January 2023 and serves as the state's chief legal officer with consumer-protection enforcement authority.

Act And InstrumentsAmber

Current in-force instruments: FTC Act Section 5; Oklahoma Security Breach Notification Act (breach notice only). Enacted-not-yet-effective instrument: SB 546.

Claims (3):

  • The FTC Act prohibits companies and individuals from engaging in unfair or deceptive acts or practices in or affecting commerce, and constitutes the operative general federal privacy-enforcement baseline applicable to Oklahoma businesses absent a state omnibus law.
  • The Oklahoma Legislature enacted a comprehensive consumer data privacy law, Senate Bill 546, which passed the House on final passage 84-4 on 19 February 2026 and was substituted on the House floor with a compromise text aligning mostly with the Virginia Consumer Data Protection Act framework.
  • SB 546 was reported signed into law in March 2026 by the Oklahoma Governor; this is based on a secondary-source headline and was not corroborated against the primary enrolled-bill or Secretary of State record in this research pass.

Material ScopeAmber

SB 546 will apply to businesses controlling/processing personal data of at least 100,000 Oklahomans, or 25,000 consumers combined with deriving at least 50% of gross revenue from data sales.

Claims (1):

  • SB 546 covers businesses that control or process the personal data of at least 100,000 Oklahomans, or the data of at least 25,000 consumers while deriving at least 50% of gross revenue from data sales.

Territorial ScopeAmber

FTC Section 5 authority is not geographically limited within the US and reaches any entity engaged in commerce affecting Oklahoma consumers. SB 546's precise territorial-scope language (e.g., conducting business in the state or targeting state residents, per the typical Virginia-model formulation) was not independently verified against primary bill text in this research pass.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , e, n, r, o, l, l, e, d, , b, i, l, l, , t, e, x, t, , t, e, r, r, i, t, o, r, i, a, l, -, s, c, o, p, e, , c, l, a, u, s, e.

Claims (1):

  • FTC Act Section 5 unfair/deceptive-practices authority applies to conduct affecting commerce nationally, including transactions with Oklahoma consumers, regardless of where the responsible entity is established.

Regulator Registration And FilingRed

No general controller/processor registration or filing regime currently exists in Oklahoma, and none was identified as part of SB 546 in the secondary sources reviewed.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , S, B, , 5, 4, 6, , r, e, g, i, s, t, r, a, t, i, o, n, , o, r, , f, i, l, i, n, g, , o, b, l, i, g, a, t, i, o, n, ;, , O, k, l, a, h, o, m, a, , A, G, , d, a, t, a, , b, r, o, k, e, r, , r, e, g, i, s, t, r, y.

Category narrative125 words

As of the 2026-08-06 dispatch date, Oklahoma has no comprehensive consumer-privacy statute IN FORCE. The operative regime is sectoral/reactive: the federal FTC Act Section 5 unfair/deceptive-practices authority, applicable federal sectoral statutes (HIPAA, GLBA, COPPA), and the state's breach-notification-only statute. CRITICALLY, this materially updates the injected seed disambiguation: the Oklahoma Legislature has since ENACTED a comprehensive consumer data privacy law, Senate Bill 546 (SB 546), which passed the House 84-4 on 19 Feb 2026 and was reported signed into law in March 2026; it takes effect 1 Jan 2027 on a Virginia CDPA-modeled framework. Until that date the seed's 'no comprehensive statute' characterization remains technically accurate for the CURRENT in-force position, but is about to become obsolete and must not be treated as a durable finding.

Sources and claims (6)
  1. ConfirmedNAAGThe current Oklahoma Attorney General, Gentner Drummond, was sworn in on 9 January 2023 and serves as the state's chief legal officer with consumer-protection enforcement authority.observed
  2. ConfirmedFederal Trade CommissionThe FTC Act prohibits companies and individuals from engaging in unfair or deceptive acts or practices in or affecting commerce, and constitutes the operative general federal privacy-enforcement baseline applicable to Oklahoma businesses absent a state omnibus law.observed
  3. ConfirmedIAPPThe Oklahoma Legislature enacted a comprehensive consumer data privacy law, Senate Bill 546, which passed the House on final passage 84-4 on 19 February 2026 and was substituted on the House floor with a compromise text aligning mostly with the Virginia Consumer Data Protection Act framework.observed
  4. ProbableDataGuidanceSB 546 was reported signed into law in March 2026 by the Oklahoma Governor; this is based on a secondary-source headline and was not corroborated against the primary enrolled-bill or Secretary of State record in this research pass.observed
  5. ConfirmedIAPPSB 546 covers businesses that control or process the personal data of at least 100,000 Oklahomans, or the data of at least 25,000 consumers while deriving at least 50% of gross revenue from data sales.observed
  6. ConfirmedFederal Trade CommissionFTC Act Section 5 unfair/deceptive-practices authority applies to conduct affecting commerce nationally, including transactions with Oklahoma consumers, regardless of where the responsible entity is established.observed

#

No in-force general lawful-basis regime; forthcoming SB 546 provisions in this area are analogized from the Virginia model rather than confirmed against OK bill text.

Primary frameworkNone in force; SB 546 (Virginia-CDPA-modeled) from 2027-01-01
Supervisory authorityOklahoma Attorney General
Traffic-light rationale — RedNo in-force general lawful-basis regime; forthcoming SB 546 provisions in this area are analogized from the Virginia model rather than confirmed against OK bill text.

Sub-modules (4)

Lawful BasesRed

No GDPR-style enumerated lawful-bases regime exists or is confirmed for SB 546; Virginia-model laws generally use a general opt-out processing standard rather than an enumerated lawful-basis list.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , l, a, w, f, u, l, , b, a, s, i, s, , /, , p, r, o, c, e, s, s, i, n, g, -, p, u, r, p, o, s, e, , p, r, o, v, i, s, i, o, n, s.

Special CategoriesAmber

Sensitive-data category definitions for SB 546 were not independently retrieved; Virginia-model laws typically include health, genetic, biometric, ethnicity/race, religion, sexual orientation/status, citizenship/immigration status, and precise geolocation as sensitive categories.

Claims (1):

  • SB 546's definition of sensitive/special-category personal data was not independently retrieved; a Virginia-CDPA-analogous definition (health, genetic, biometric, racial/ethnic origin, religion, sexual orientation, citizenship/immigration status, precise geolocation, data of known minors) is presumed but unconfirmed.

Pseudonymisation And AnonymisationRed

No Oklahoma-specific pseudonymisation/anonymisation safe-harbour provision was identified in this research pass.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , /, , d, e, -, i, d, e, n, t, i, f, i, c, a, t, i, o, n, , s, a, f, e, , h, a, r, b, o, u, r.

Category narrative62 words

No general enumerated lawful-basis or consent-threshold framework is currently in force in Oklahoma. SB 546 (effective 2027-01-01) is modeled on the Virginia CDPA, which uses an opt-out (not opt-in) general processing model with opt-in consent required specifically for processing 'sensitive data' categories; however, OK-specific bill-text language on consent thresholds and special-category definitions was not independently verified against primary sources in this pass.

Sources and claims (2)
  1. UncertainIAPPSB 546 is modeled mostly on the original framework of Virginia's Consumer Data Protection Act, which conditions processing of sensitive personal data on prior opt-in consent; the presence of an equivalent OK-specific opt-in requirement was not independently confirmed against SB 546 bill text.observed
  2. SpeculativeIAPPSB 546's definition of sensitive/special-category personal data was not independently retrieved; a Virginia-CDPA-analogous definition (health, genetic, biometric, racial/ethnic origin, religion, sexual orientation, citizenship/immigration status, precise geolocation, data of known minors) is presumed but unconfirmed.observed

#

Rights confirmed to exist in principle for 2027 commencement; procedural specifics not independently verified.

Primary frameworkSB 546 (effective 2027-01-01)
Supervisory authorityOklahoma Attorney General
Traffic-light rationale — AmberRights confirmed to exist in principle for 2027 commencement; procedural specifics not independently verified.

Sub-modules (5)

Access RightAmber

SB 546 contains standard data subject access rights as part of its rights package.

Claims (1):

  • SB 546 contains standard data subject access rights as part of the consumer rights package taking effect 1 January 2027.

Rectification And ErasureAmber

Correction and deletion rights are presumed included within the 'standard data subject access rights' described for SB 546, consistent with the Virginia-model rights package, but explicit bill-text confirmation was not obtained.

Claims (1):

  • Correction and deletion rights are presumed part of SB 546's standard consumer rights package but were not itemized separately in the secondary sources reviewed.

Restriction And ObjectionAmber

SB 546 explicitly provides opt-outs for targeted advertising and sale of personal data.

Claims (1):

  • SB 546 contains standard data subject access rights, including opt-outs for targeted advertising and data sales as defined under the bill.

Data PortabilityAmber

Portability is presumed part of the 'standard' rights package referenced for SB 546 but not independently itemized in sources reviewed.

Claims (1):

  • A data-portability right is presumed included in SB 546's standard rights package but was not independently itemized in sources reviewed.

Deadlines And Response WindowsRed

No OK-specific statutory response-window (e.g., 45-day) figure was independently confirmed for SB 546 in this research pass.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , c, o, n, s, u, m, e, r, , r, e, q, u, e, s, t, , r, e, s, p, o, n, s, e, , d, e, a, d, l, i, n, e.

Category narrative54 words

No enforceable consumer data-subject-rights framework currently exists in Oklahoma outside limited breach-notification entitlements. SB 546 will introduce standard rights (access, correction/deletion, portability, and opt-outs for targeted advertising and sale of personal data) modeled on other Virginia-style state laws, effective 1 Jan 2027, though granular procedural detail (response windows, appeal mechanisms) was not independently confirmed.

Sources and claims (4)
  1. ConfirmedIAPPSB 546 contains standard data subject access rights as part of the consumer rights package taking effect 1 January 2027.observed
  2. UncertainIAPPCorrection and deletion rights are presumed part of SB 546's standard consumer rights package but were not itemized separately in the secondary sources reviewed.observed
  3. ConfirmedIAPPSB 546 contains standard data subject access rights, including opt-outs for targeted advertising and data sales as defined under the bill.observed
  4. UncertainIAPPA data-portability right is presumed included in SB 546's standard rights package but was not independently itemized in sources reviewed.observed

#

DPIA obligation confirmed for 2027; DPO/ROPA/retention requirements not identified; sectoral security/breach duties (GLBA, HIPAA) are robustly in force today.

Primary frameworkGLBA Safeguards Rule + HIPAA Security Rule (in force) + SB 546 DPIA requirement (effective 2027-01-01)
Supervisory authorityOklahoma Attorney General
Traffic-light rationale — AmberDPIA obligation confirmed for 2027; DPO/ROPA/retention requirements not identified; sectoral security/breach duties (GLBA, HIPAA) are robustly in force today.

Sub-modules (7)

Accountability And DpiaAmber

SB 546 requires data protection assessments for a range of processing activities.

Claims (1):

  • SB 546 requires controllers to conduct data protection assessments for a range of processing activities, effective 1 January 2027.

Dpo RequirementsRed

No DPO-appointment threshold was identified for SB 546 or any current OK statute in this research pass.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, f, f, i, c, e, r, , a, p, p, o, i, n, t, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Ropa RequirementsRed

No records-of-processing (ROPA) obligation was identified for SB 546 in this research pass.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , r, e, c, o, r, d, s, , o, f, , p, r, o, c, e, s, s, i, n, g, , a, c, t, i, v, i, t, i, e, s, , r, e, q, u, i, r, e, m, e, n, t.

Joint Controller ArrangementsRed

No Oklahoma-specific joint-controller provision was identified; Virginia-model laws typically use standard controller/processor contract-clause requirements, but this was not independently confirmed for SB 546.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , /, , p, r, o, c, e, s, s, o, r, , c, o, n, t, r, a, c, t, , c, l, a, u, s, e.

Security MeasuresGreen

The GLBA Safeguards Rule requires covered financial institutions to maintain a written information-security program with administrative, technical and physical safeguards.

Claims (1):

  • The FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards designed to protect customer information.

Breach NotificationAmber

Oklahoma's general Security Breach Notification Act requires notification of affected residents following a breach of computerized personal information; sector-specific breach rules (HIPAA Breach Notification Rule, GLBA Safeguards Rule notification-event requirement) also apply. Precise OK statutory citation/timelines were not independently re-verified against primary text in this pass.

Claims (2):

  • Financial institutions subject to the FTC Safeguards Rule must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving unauthorized acquisition of at least 500 consumers' unencrypted information.
  • Oklahoma maintains a general Security Breach Notification Act requiring notice to affected residents following a breach of computerized personal information; the precise statutory citation and notification timeline were not independently re-verified against primary statutory text in this research pass.

Retention And DisposalRed

No general Oklahoma data-retention-limit or disposal-duty statute was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , g, e, n, e, r, a, l, , d, a, t, a, , r, e, t, e, n, t, i, o, n, /, d, i, s, p, o, s, a, l, , s, t, a, t, u, t, e.

Category narrative63 words

SB 546 will require data protection assessments (DPIAs) for a range of processing activities from 2027. Current in-force accountability obligations are sectoral: GLBA Safeguards Rule imposes security-program duties on financial institutions; HIPAA imposes security/breach duties on healthcare covered entities/business associates; the Oklahoma Security Breach Notification Act imposes breach-notice duties generally. No general DPO-appointment threshold, ROPA requirement, or retention-limit regime was identified for Oklahoma.

Sources and claims (4)
  1. ConfirmedIAPPSB 546 requires controllers to conduct data protection assessments for a range of processing activities, effective 1 January 2027.observed
  2. ConfirmedFederal Trade CommissionThe FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards designed to protect customer information.observed
  3. ConfirmedFederal Trade CommissionFinancial institutions subject to the FTC Safeguards Rule must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving unauthorized acquisition of at least 500 consumers' unencrypted information.observed
  4. ProbableIAPPOklahoma maintains a general Security Breach Notification Act requiring notice to affected residents following a breach of computerized personal information; the precise statutory citation and notification timeline were not independently re-verified against primary statutory text in this research pass.observed

#

No comprehensive cross-border transfer/adequacy regime exists at the US-OK level; this is a genuine regulatory gap, not an omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer/adequacy regime exists at the US-OK level; this is a genuine regulatory gap, not an omission.

Sub-modules (6)

Transfer MechanismsRed

No formal transfer-mechanism regime (adequacy/SCCs/BCRs/derogations) applies to Oklahoma as a matter of state or applicable federal general-commercial-data law.

Claims (1):

  • The United States, including Oklahoma, has no GDPR-style cross-border transfer mechanism regime (adequacy, SCCs, BCRs) applicable to general commercial personal data.

Adequacy ReceivedRed

Not applicable; the US does not operate an adequacy-reception framework.

Absence provenance: not recorded. Searched: U, S, -, O, K, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, s, , r, e, c, e, i, v, e, d.

Adequacy GrantedRed

Not applicable; the US does not issue GDPR-style adequacy determinations.

Absence provenance: not recorded. Searched: U, S, -, O, K, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, s, , g, r, a, n, t, e, d.

Sccs And BcrsRed

No SCC/BCR-equivalent regime exists at Oklahoma state level; use of EU-style SCCs by OK-based entities would arise only as counterparties to EU GDPR-regulated transfers, outside this JID's own instrument.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , s, t, a, t, e, , S, C, C, /, B, C, R, , f, r, a, m, e, w, o, r, k.

Transfer Impact AssessmentRed

No TIA requirement exists under Oklahoma or applicable federal general-commercial-data law.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Data LocalisationRed

No general data-localisation mandate applies to commercial personal data in Oklahoma.

Claims (1):

  • No data-localisation mandate applies to general commercial personal data processed by Oklahoma-based or Oklahoma-serving entities.
Category narrative52 words

The United States has no GDPR-style cross-border transfer/adequacy framework, and Oklahoma has no state-level data-localisation mandate or transfer-impact-assessment requirement for general commercial personal data. No adequacy decisions have been received from or granted to other regimes at the US-OK level (adequacy is not a concept used in the US federal/state privacy architecture).

Sources and claims (2)
  1. ConfirmedFederal Trade CommissionThe United States, including Oklahoma, has no GDPR-style cross-border transfer mechanism regime (adequacy, SCCs, BCRs) applicable to general commercial personal data.observed
  2. ConfirmedFederal Trade CommissionNo data-localisation mandate applies to general commercial personal data processed by Oklahoma-based or Oklahoma-serving entities.observed

#

Federal sectoral overlays (HIPAA, GLBA, COPPA) are well-established, robustly sourced (T1), and in force.

Primary frameworkHIPAA + GLBA + COPPA (federal sectoral overlays, in force)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — GreenFederal sectoral overlays (HIPAA, GLBA, COPPA) are well-established, robustly sourced (T1), and in force.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA requires financial institutions to explain information-sharing practices and safeguard sensitive data; the FTC Safeguards Rule imposes information-security-program obligations.

Claims (1):

  • The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, applicable to covered Oklahoma-based financial institutions.

Health Sector OverlayGreen

HIPAA Privacy, Security, and Breach Notification Rules govern covered entities and business associates handling protected health information; the FTC Act and FTC Health Breach Notification Rule fill gaps for non-HIPAA-covered health data (e.g., health apps).

Claims (2):

  • The HIPAA Privacy Rule sets limits and conditions on uses and disclosures of protected health information by covered entities and business associates and provides individuals with rights regarding their health information.
  • The FTC Act's obligations apply to HIPAA-covered entities and business associates, as well as to companies that collect, use, or share health information that are not required to comply with HIPAA, filling coverage gaps for non-HIPAA health data.

Telecoms And EprivacyRed

No Oklahoma-specific telecoms/eprivacy overlay (cookie-consent-style regime) was identified; federal TCPA-type protections were not independently re-verified in this pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , t, e, l, e, c, o, m, s, /, e, p, r, i, v, a, c, y, , o, v, e, r, l, a, y.

Employment DataRed

No Oklahoma-specific employment-data privacy statute was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , e, m, p, l, o, y, m, e, n, t, , d, a, t, a, , p, r, i, v, a, c, y, , s, t, a, t, u, t, e.

Credit And ScoringAmber

The federal Fair Credit Reporting Act (FCRA) applies nationally including Oklahoma, but a dedicated verification pass on FCRA text/enforcement for this run was not performed.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, -, s, p, e, c, i, f, i, c, , c, r, e, d, i, t, /, s, c, o, r, i, n, g, , o, v, e, r, l, a, y, , b, e, y, o, n, d, , F, C, R, A.

EducationAmber

The federal Family Educational Rights and Privacy Act (FERPA) applies nationally including Oklahoma; no OK-specific education-sector privacy overlay was identified.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , e, d, u, c, a, t, i, o, n, -, s, e, c, t, o, r, , p, r, i, v, a, c, y, , o, v, e, r, l, a, y, , b, e, y, o, n, d, , F, E, R, P, A.

InsuranceRed

No Oklahoma-specific insurance-sector data-privacy overlay (e.g., genetic-information-and-insurance statute) was identified in this research pass; a search for an Oklahoma Genetic Information Privacy Act returned no confirming results.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , G, e, n, e, t, i, c, , I, n, f, o, r, m, a, t, i, o, n, , P, r, i, v, a, c, y, , A, c, t, , /, , i, n, s, u, r, a, n, c, e, , g, e, n, e, t, i, c, -, t, e, s, t, i, n, g, , s, t, a, t, u, t, e.

Category narrative59 words

Federal sectoral overlays are the dominant operative source of data-protection obligation for Oklahoma entities today: HIPAA governs health-care covered entities/business associates; GLBA (Privacy Rule + Safeguards Rule) governs financial institutions; COPPA governs operators collecting data from children under 13. No Oklahoma-specific sectoral overlays (telecoms/eprivacy, employment data, credit-scoring, education, insurance) beyond these federal baselines were identified in this research pass.

Sources and claims (3)
  1. ConfirmedFederal Trade CommissionThe Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, applicable to covered Oklahoma-based financial institutions.observed
  2. ConfirmedFederal Trade CommissionThe HIPAA Privacy Rule sets limits and conditions on uses and disclosures of protected health information by covered entities and business associates and provides individuals with rights regarding their health information.observed
  3. ConfirmedFederal Trade CommissionThe FTC Act's obligations apply to HIPAA-covered entities and business associates, as well as to companies that collect, use, or share health information that are not required to comply with HIPAA, filling coverage gaps for non-HIPAA health data.observed

#

Targeted-advertising/sale opt-out confirmed for 2027; universal opt-out signal recognition explicitly absent; cookie law and dark-patterns provisions unconfirmed.

Primary frameworkSB 546 (effective 2027-01-01)
Supervisory authorityOklahoma Attorney General
Traffic-light rationale — AmberTargeted-advertising/sale opt-out confirmed for 2027; universal opt-out signal recognition explicitly absent; cookie law and dark-patterns provisions unconfirmed.

Sub-modules (6)

Cookies And TrackersRed

No Oklahoma-specific cookie/tracker consent law was identified.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , c, o, o, k, i, e, , c, o, n, s, e, n, t, , s, t, a, t, u, t, e.

Dark PatternsRed

Dark-pattern prohibitions were proposed in earlier Oklahoma privacy bill drafts (2021-era HB 1602 lineage) but confirmation of an equivalent provision surviving into enacted SB 546 was not obtained.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , d, a, r, k, , p, a, t, t, e, r, n, s, , p, r, o, v, i, s, i, o, n.

Opt Out SignalsAmber

SB 546 omits recognition of universal opt-out mechanisms.

Claims (1):

  • SB 546 omits some of the more common provisions passed by other states in recent years, including recognition of universal opt-out mechanisms and enhanced children's privacy protections.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule was identified for Oklahoma.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , c, l, e, a, n, , r, o, o, m, , /, , d, a, t, a, , c, o, l, l, a, b, o, r, a, t, i, o, n, , r, o, o, m, , r, e, g, u, l, a, t, i, o, n.

Cross Context AdvertisingAmber

SB 546 provides opt-outs for targeted advertising and data sales as defined under the bill.

Claims (1):

  • SB 546 provides consumer opt-outs for targeted advertising and data sales as defined under the bill, effective 1 January 2027.

Direct MarketingRed

No Oklahoma-specific direct-marketing consent/suppression regime beyond general federal FTC Act oversight was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , d, i, r, e, c, t, , m, a, r, k, e, t, i, n, g, , c, o, n, s, e, n, t, /, s, u, p, p, r, e, s, s, i, o, n, , s, t, a, t, u, t, e.

Category narrative42 words

No Oklahoma cookie-consent law, dark-patterns prohibition, or clean-room regulation currently exists. SB 546 will introduce an opt-out right for targeted advertising and sale of personal data from 1 Jan 2027, but explicitly omits recognition of universal opt-out signals (e.g., Global Privacy Control).

Sources and claims (2)
  1. ConfirmedIAPPSB 546 omits some of the more common provisions passed by other states in recent years, including recognition of universal opt-out mechanisms and enhanced children's privacy protections.observed
  2. ConfirmedIAPPSB 546 provides consumer opt-outs for targeted advertising and data sales as defined under the bill, effective 1 January 2027.observed

#

No confirmed Oklahoma-specific regime in this domain; evidence is thin to absent across all sub-modules.

Traffic-light rationale — RedNo confirmed Oklahoma-specific regime in this domain; evidence is thin to absent across all sub-modules.

Sub-modules (6)

Profiling RestrictionsAmber

A profiling opt-out is plausible by analogy to the Virginia-model framework underlying SB 546, but was not independently confirmed in the sources reviewed.

Claims (1):

  • SB 546's Virginia-CDPA-modeled framework may include a profiling opt-out right consistent with other Virginia-model state laws, but an OK-specific profiling-restriction clause was not independently confirmed in the sources reviewed.

Automated Decision Making TransparencyRed

No ADM transparency/explanation-right provision was confirmed for SB 546.

Absence provenance: not recorded. Searched: S, B, , 5, 4, 6, , a, u, t, o, m, a, t, e, d, , d, e, c, i, s, i, o, n, -, m, a, k, i, n, g, , t, r, a, n, s, p, a, r, e, n, c, y, , p, r, o, v, i, s, i, o, n.

Ai Risk AssessmentsRed

No Oklahoma AI-specific risk-assessment statute was identified.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , A, I, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , s, t, a, t, u, t, e.

Biometric RegimeRed

No Oklahoma biometric-data statute analogous to Illinois BIPA was identified.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , b, i, o, m, e, t, r, i, c, , i, n, f, o, r, m, a, t, i, o, n, , p, r, i, v, a, c, y, , s, t, a, t, u, t, e.

Genetic DataRed

A search for an Oklahoma Genetic Information Privacy Act returned no Oklahoma-specific results (only other-state examples such as Maryland).

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , G, e, n, e, t, i, c, , I, n, f, o, r, m, a, t, i, o, n, , P, r, i, v, a, c, y, , A, c, t, , 2, 0, 2, 3.

State Surveillance CarveoutsRed

No Oklahoma-specific state-surveillance carveout provision was researched in this pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , s, t, a, t, e, , s, u, r, v, e, i, l, l, a, n, c, e, , /, , n, a, t, i, o, n, a, l, -, s, e, c, u, r, i, t, y, , c, a, r, v, e, o, u, t, , i, n, , p, r, i, v, a, c, y, , l, a, w.

Category narrative42 words

No Oklahoma-specific biometric-privacy statute (analogous to Illinois BIPA), genetic-data statute, AI-risk-assessment law, or ADM-transparency regime was identified in this research pass. Profiling-related opt-outs may exist within SB 546's rights package by analogy to the Virginia model, but this was not independently confirmed.

Sources and claims (1)
  1. UncertainIAPPSB 546's Virginia-CDPA-modeled framework may include a profiling opt-out right consistent with other Virginia-model state laws, but an OK-specific profiling-restriction clause was not independently confirmed in the sources reviewed.observed

#

COPPA federal baseline robustly confirmed; SB 546 explicitly omits enhanced children's protections; other sub-modules largely unconfirmed/absent.

Primary frameworkCOPPA (federal, in force)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberCOPPA federal baseline robustly confirmed; SB 546 explicitly omits enhanced children's protections; other sub-modules largely unconfirmed/absent.

Sub-modules (5)

Age VerificationRed

No Oklahoma-specific age-verification statute (e.g., social-media age-verification law) was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , a, g, e, , v, e, r, i, f, i, c, a, t, i, o, n, , /, , s, o, c, i, a, l, , m, e, d, i, a, , m, i, n, o, r, s, , l, a, w.

Minor Profiling BansAmber

SB 546 explicitly omits enhanced children's privacy protections found in some other state comprehensive privacy laws.

Claims (1):

  • SB 546 omits enhanced children's privacy protections found in some other states' comprehensive privacy laws, leaving COPPA as the primary child-data safeguard in Oklahoma.

Education SettingsAmber

The federal FERPA regime applies nationally including Oklahoma; no OK-specific education-settings privacy rule was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , e, d, u, c, a, t, i, o, n, -, s, e, t, t, i, n, g, s, -, s, p, e, c, i, f, i, c, , p, r, i, v, a, c, y, , r, u, l, e, , b, e, y, o, n, d, , F, E, R, P, A.

Dependent AdultsRed

No Oklahoma-specific dependent-adults data-protection provision was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , /, , e, l, d, e, r, l, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Category narrative45 words

The federal COPPA regime applies nationally including Oklahoma, requiring parental consent for collection of personal information from children under 13. SB 546 explicitly does NOT add enhanced children's-privacy provisions beyond this federal baseline. No Oklahoma-specific age-verification, minor-profiling ban, education-settings rule, or dependent-adults protection was identified.

Sources and claims (2)
  1. ConfirmedFederal Trade CommissionThe Children's Online Privacy Protection Act (COPPA) gives parents control over what information websites can collect from their children, applicable to covered Oklahoma-serving operators.observed
  2. ConfirmedIAPPSB 546 omits enhanced children's privacy protections found in some other states' comprehensive privacy laws, leaving COPPA as the primary child-data safeguard in Oklahoma.observed

#

Enforcement architecture for the 2027 regime is well-characterized (exclusive AG enforcement, cure period, no private right of action); current enforcement-activity and regulator-capacity data are thin.

Primary frameworkSB 546 (effective 2027-01-01) + FTC Act Section 5 (in force)
Supervisory authorityOklahoma Attorney General
Traffic-light rationale — AmberEnforcement architecture for the 2027 regime is well-characterized (exclusive AG enforcement, cure period, no private right of action); current enforcement-activity and regulator-capacity data are thin.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

SB 546 grants the Oklahoma Attorney General exclusive enforcement authority with a non-sunsetting 30-day cure provision.

Claims (1):

  • SB 546 will take force 1 January 2027 and offers a 30-day cure provision under exclusive Attorney General enforcement that does not sunset.

Enforcement Activity IndexRed

No Oklahoma-specific privacy-enforcement action tally (breach-notification enforcement or FTC actions specifically targeting OK entities) was identified in this research pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , p, r, i, v, a, c, y, /, b, r, e, a, c, h, , e, n, f, o, r, c, e, m, e, n, t, , a, c, t, i, o, n, s, , 2, 0, 2, 5, -, 2, 0, 2, 6.

Regulator Funding And CapacityRed

No specific funding or headcount data for the Oklahoma AG's Consumer Protection Unit relevant to privacy enforcement was researched in this pass.

Absence provenance: not recorded. Searched: O, k, l, a, h, o, m, a, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , C, o, n, s, u, m, e, r, , P, r, o, t, e, c, t, i, o, n, , U, n, i, t, , f, u, n, d, i, n, g, /, h, e, a, d, c, o, u, n, t.

Collective Redress And Class ActionsAmber

SB 546's exclusive AG enforcement model implies no collective/class-action mechanism for consumers under the Act itself.

Claims (1):

  • Because SB 546 vests exclusive enforcement in the Attorney General, no consumer collective-redress or class-action mechanism is created directly by the Act.

Private Right Of ActionAmber

SB 546 provides exclusive Attorney General enforcement, precluding a private right of action under the Act; whether the existing breach-notification statute separately allows a private right of action was not independently confirmed.

Claims (1):

  • SB 546 does not create a private right of action, enforcement being exclusive to the Oklahoma Attorney General under a non-sunsetting 30-day cure provision.

Recent Developments 180DAmber

Within the 180 days preceding the dispatch date (2026-08-06), Oklahoma's House gave final passage to SB 546 on 19 February 2026 (84-4 vote), and the bill was reported signed into law in March 2026 — the single most material recent development for this JID.

Claims (1):

  • On 19 February 2026, the Oklahoma House approved final passage of Senate Bill 546 on an 84-4 vote, sending the state's first comprehensive consumer data privacy law toward enactment.
Category narrative59 words

Under SB 546, enforcement will be exclusive to the Oklahoma Attorney General, with a non-sunsetting 30-day cure period and no private right of action. Current in-force enforcement relies on FTC Section 5 authority and AG breach-notification enforcement. This is a recent development (SB 546 legislative passage and reported signature occurred within the last ~180 days of the dispatch date).

Sources and claims (4)
  1. ConfirmedIAPPSB 546 will take force 1 January 2027 and offers a 30-day cure provision under exclusive Attorney General enforcement that does not sunset.observed
  2. ProbableIAPPBecause SB 546 vests exclusive enforcement in the Attorney General, no consumer collective-redress or class-action mechanism is created directly by the Act.observed
  3. ConfirmedIAPPSB 546 does not create a private right of action, enforcement being exclusive to the Oklahoma Attorney General under a non-sunsetting 30-day cure provision.observed
  4. ConfirmedIAPPOn 19 February 2026, the Oklahoma House approved final passage of Senate Bill 546 on an 84-4 vote, sending the state's first comprehensive consumer data privacy law toward enactment.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Oklahoma
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s), 11 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1 coverage exists for federal sectoral overlays (FTC Act Section 5, GLBA Safeguards Rule, HIPAA, COPPA) which govern Oklahoma today. Strong T3 (IAPP/DataGuidance) coverage exists for the newly enacted SB 546 comprehensive privacy law (thresholds, targeted-advertising/sale opt-out, DPIA requirement, 30-day cure period, exclusive AG enforcement, omission of universal opt-out signals and enhanced children's protections). Coverage is weak-to-absent for: SB 546 primary bill-text detail (sensitive-data definitions, consent-threshold mechanics, response-window deadlines, DPO/ROPA/retention provisions), Oklahoma's specific breach-notification statutory citation/timeline, cross-border/adequacy (genuine regulatory gap, not a coverage failure), biometric/genetic/AI-specific state law (none identified), and enforcement-activity/regulator-capacity metrics. This run materially corrects the injected seed's disambiguation, which characterized Oklahoma as having no comprehensive statute; that was true at seed-compilation time but is superseded by SB 546's 2026 enactment.

Unresolved questions (7):

  • Has Governor Stitt's signature on SB 546 been confirmed against the primary enrolled-bill/Secretary of State record, and what is the resulting Oklahoma Statutes title/section citation?
  • Does SB 546 require opt-in consent specifically for processing of sensitive/special-category data, mirroring the Virginia CDPA?
  • What are SB 546's specific consumer-request response-window deadlines (e.g., 45-day initial response, extension provisions)?
  • Does SB 546 include DPO-appointment thresholds or a records-of-processing (ROPA) obligation?
  • What is the precise statutory citation and notification timeline for the Oklahoma Security Breach Notification Act?
  • Does Oklahoma have any biometric-, genetic-, or AI-specific state statute not surfaced in this research pass?
  • What enforcement activity (if any) has the Oklahoma Attorney General undertaken under the existing breach-notification statute in the past 12 months?

Escalate to primary-source review: yes