Privacy
Oklahoma consumer data privacy act (SB 546, 2026)
The act applies to a controller or processor that conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents and that, during a calendar year, controls or processes personal data of at least 100,000 consumers, or controls or processes personal data of at least 25,000 consumers and derives over 50 percent of gross revenue from the sale of personal data. It does not apply to state agencies and political subdivisions, financial institutions or data subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofit organizations, or institutions of higher education. Governor Kevin Stitt approved the bill on March 20, 2026, and it takes effect January 1, 2027.
What the website needs
- A covered controller must provide a reasonably accessible and clear privacy notice that lists the categories of personal data processed (including any sensitive data), the purpose of processing, how consumers can exercise their rights and appeal a decision, and, if applicable, the categories of personal data shared with third parties and the categories of those third parties (Section 8).
- A controller that sells personal data or processes it for targeted advertising must clearly and conspicuously disclose that processing in the privacy notice, along with how a consumer can opt out (Section 8(B)).
- A controller must offer two or more secure and reliable methods for consumers to submit rights requests and may not require a consumer to create a new account (Section 6).
- A controller that maintains a website must provide a mechanism on the website for consumers to submit requests; a controller that operates exclusively online and has a direct relationship with the consumer only has to provide an email address (Section 6(C) and (D)).


