Oklahoma Data Privacy Act: How to Prepare in 2026
ON THIS PAGE
- What Is Oklahoma’s New Privacy Law and When Does It Take Effect?
- Does Oklahoma’s Data Privacy Law Apply to Your Business?
- What Rights Do Oklahoma Consumers Have?
- What Does Oklahoma’s Privacy Law Mean for Cookies, Tracking and Advertising?
- When Does Oklahoma Require Consent?
- Does Oklahoma Require Websites to Honour Global Privacy Control?
- Privacy Notices, Assessments and Other Controller Obligations
- How Does Oklahoma Compare With GDPR and Other U.S. Privacy Laws?
- Oklahoma Privacy Compliance Checklist Before January 2027
- Oklahoma Privacy Law Enforcement and the 30-Day Cure Period
- Managing Oklahoma Website Privacy Controls With CookieScript
- Conclusion
- Frequently Asked Questions
Oklahoma Senate Bill 546 introduces new privacy obligations for covered businesses from January 1, 2027. Website operators should review how their cookies, pixels and other tracking technologies handle personal data, particularly where they support targeted advertising, data sales, profiling or sensitive-data processing, and ensure the required notices, consent mechanisms and opt-outs are in place.
For cookies and tracking, the key point is that Oklahoma does not impose a blanket prior-consent rule for every non-essential cookie. Instead, obligations depend on what a tracker collects, how the data is used, whether it supports targeted advertising or a monetary sale, and whether sensitive data is involved.
Website operators should therefore audit their cookies, pixels and tags, classify the underlying data flows, update disclosures, implement the required opt-outs and consent, and test that privacy choices actually change the processing.
What Is Oklahoma’s New Privacy Law and When Does It Take Effect?
Oklahoma’s new privacy law was enacted through Senate Bill 546. The Legislature finally enrolled the bill on March 17 and the Governor approved it on March 20, 2026.
SB 546 became 2026 Oklahoma Session Law Chapter 8 and establishes Oklahoma’s new Data Privacy provisions in Sections 300–320 of Title 75A of the Oklahoma Statutes. The provisions take effect on January 1, 2027.
The statute does not give itself an official short title or acronym. We use Oklahoma Data Privacy Act here as descriptive editorial shorthand for the law enacted through SB 546.
Does Oklahoma’s Data Privacy Law Apply to Your Business?
SB 546 applies only if the statutory scope test is met.
Subject to exemptions, it covers a controller or processor that conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents and, during a calendar year, either:
- Controls or processes personal data of at least 100,000 consumers, or
- Controls or processes personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.
These scope thresholds are set out in 75A O.S. § 314(A).
There is no standalone annual-revenue threshold.
A “consumer” is an Oklahoma resident acting in an individual or household context. Commercial and employment contexts are excluded.
The law also contains entity- and data-level exemptions. These include certain government bodies, GLBA-regulated financial institutions and data, HIPAA covered entities and business associates, organisations meeting the statute’s definition of a nonprofit organization, institutions of higher education and specified categories of regulated data.
A smaller company may fall outside the law simply because it does not meet the thresholds. That is not the same as a statutory small-business exemption.
What Rights Do Oklahoma Consumers Have?
Covered consumers can ask a controller to confirm whether their personal data is being processed and access that data. They can also correct inaccuracies, delete qualifying data and obtain certain data in a portable format.
Consumers can opt out of:
- Targeted advertising
- Sale of personal data
- Profiling — which Oklahoma defines as solely automated processing — in furtherance of decisions producing legal or similarly significant effects
These consumer rights are established in 75A O.S. § 301(B).
Controllers generally have 45 days to respond to a request. One additional 45-day extension is possible when reasonably necessary.
They must also provide an appeal process, with appeal decisions generally due within 60 days.
What Does Oklahoma’s Privacy Law Mean for Cookies, Tracking and Advertising?
Oklahoma is not a general prior-consent cookie law.
SB 546 regulates personal-data processing. It does not say that every non-essential cookie must remain blocked until a visitor clicks “Accept”.
Cookies, pixels and scripts matter because of the personal data they collect, infer, disclose or use. A tracker audit should cover technologies such as advertising pixels, analytics and conversion tags, remarketing tools, Third-Party Cookies, session-replay tools, social-media embeds and other scripts that collect or disclose personal data.
For each technology, ask:
- What personal data does it collect or infer?
- Who receives the data?
- Does the processing involve targeted advertising, a monetary sale or significant profiling?
- Does it involve sensitive data or a new purpose that may require consent?
CMP categories require similar caution. Labels such as “Marketing”, “Analytics” and “Necessary” are implementation tools, not Oklahoma statutory categories.
Oklahoma’s data-minimisation rule also means a tracker review should ask whether the information needs to be collected at all.
What Counts as a Sale of Personal Data in Oklahoma?
Oklahoma uses a narrower sale definition than several other state privacy laws.
Under SB 546, a sale is an exchange of personal data by a controller to a third party for monetary consideration, unlike laws that also extend the definition to other valuable consideration.
The law excludes certain disclosures, including qualifying disclosures to processors, disclosures needed to provide a consumer-requested product or service, transfers to affiliates, certain consumer-directed or intentionally public disclosures, and transfers connected with mergers or similar transactions.
For websites, not every third-party tracker involves a statutory sale. The actual data flow and commercial arrangement need to be reviewed.
Targeted Advertising and Advertising Trackers
Oklahoma defines targeted advertising around ads selected using personal data obtained from a consumer’s activities over time and across non-affiliated websites or online applications to predict preferences or interests.
The definition excludes advertising based on activity within the controller’s own website or app, contextual advertising based on the current visit, ads shown in response to a consumer request, and processing performed solely to measure or report advertising performance, reach or frequency.
A remarketing pixel used to build audiences from cross-site behaviour may therefore raise a targeted-advertising issue, while analytics used solely for measurement may require a different analysis.
Targeted advertising and sale are separate legal classifications in Oklahoma. A disclosure can support targeted advertising even if no money changes hands and therefore no statutory sale occurs.
When Does Oklahoma Require Consent?
Affirmative consent applies in different circumstances from Oklahoma’s consumer opt-out rights.
Controllers generally must obtain consent before processing sensitive data under 75A O.S. § 306(B)(4). For personal data from a known child, the controller must instead process the data in accordance with the Children’s Online Privacy Protection Act (COPPA).
Sensitive data includes specified information concerning race or ethnicity, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship or immigration status, certain genetic and biometric data, personal data from a known child, and precise geolocation.
A child is someone under 13, and known-child data is treated as sensitive data. Compliance with COPPA’s verifiable parental-consent requirements for data collected online satisfies the corresponding parental-consent requirement under Oklahoma law.
Consent must involve a clear affirmative act showing a freely given, specific, informed and unambiguous agreement. Broad terms containing unrelated information do not qualify, nor do actions such as hovering, muting, pausing or closing content. Consent obtained through a dark pattern is not valid consent.
Consent may also be required before using personal data for a new purpose that is neither reasonably necessary nor compatible with the purpose originally disclosed.
Does Oklahoma Require Websites to Honour Global Privacy Control?
SB 546 does not itself require websites to recognise Global Privacy Control (GPC) or another universal opt-out preference signal.
A national website may still need to honour GPC because another state’s privacy law requires it, or because the organisation has chosen to apply a broader Privacy Policy.
As of August 31, 2026, we have not located SB 546-specific implementation guidance or a dedicated complaint mechanism for the new law. 75A O.S. § 311 requires the Oklahoma Attorney General to publish information about the Act and an online mechanism for consumer complaints. The Oklahoma Attorney General’s Consumer Protection Unit already accepts general consumer complaints. Businesses should recheck these materials before January 1, 2027.
Privacy Notices, Assessments and Other Controller Obligations
Privacy Notices
Covered controllers must provide a reasonably accessible and clear privacy notice describing:
- Categories of personal data processed
- Sensitive data, where applicable
- Purposes for processing
- How consumers exercise and appeal their rights
- Categories of personal data shared with third parties
- Categories of third parties receiving personal data
These requirements appear in 75A O.S. § 307(A)–(B).
If a controller sells personal data or processes data for targeted advertising, it must clearly and conspicuously disclose that processing and explain how consumers can opt out.
Compare the notice with the live tracker inventory whenever website technologies or data flows change.
Data Protection Assessments
Controllers must conduct and document assessments for certain higher-risk processing, including targeted advertising, sale, sensitive-data processing and profiling that creates one of the statute’s listed reasonably foreseeable risks.
The profiling assessment trigger is broader than the separate consumer opt-out right for profiling tied to significant decisions. See 75A O.S. § 309.
The assessment requirement applies to covered processing that commences on or after January 1, 2027 and is not retroactive. An assessment prepared under another law may also satisfy Oklahoma if it has a reasonably comparable scope and effect.
Where a website vendor acts as a processor, the relevant controller-processor contract terms should also be reviewed.
How Does Oklahoma Compare With GDPR and Other U.S. Privacy Laws?
The General Data Protection Regulation (GDPR) governs personal-data processing and provides several lawful bases. Separately, the EU ePrivacy Directive addresses storing information on, and accessing information from, users’ devices.
Oklahoma follows a different model. It generally provides opt-out rights for targeted advertising, monetary sales and qualifying profiling, while requiring affirmative consent for sensitive-data and specified incompatible-purpose processing. It does not impose a general prior-consent rule for every non-essential cookie.
Oklahoma shares several features with the Virginia Consumer Data Protection Act (VCDPA), including similar scope thresholds, consumer opt-outs, sensitive-data consent, assessments and Attorney General enforcement.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), uses a broader sale concept involving monetary or other valuable consideration and separately regulates “sharing” for cross-context behavioural advertising. Oklahoma limits sale to monetary consideration and does not itself require GPC.
Oklahoma Privacy Compliance Checklist Before January 2027
- Confirm coverage and exemptions: Determine whether the Oklahoma law applies to the business.
- Inventory trackers: Identify cookies, pixels, tags, scripts and the personal data they collect or infer.
- Map disclosures: Record which third parties receive visitor data and why.
- Classify processing: Identify monetary sales, targeted advertising and relevant profiling.
- Identify sensitive data: Review geolocation, biometrics, health, child and other sensitive processing.
- Implement consent and opt-outs: Apply the appropriate controls to sensitive data, targeted advertising, sale and profiling tied to decisions producing legal or similarly significant effects.
- Update notices and rights workflows: Align privacy disclosures with actual processing and prepare consumer request and appeal procedures.
- Review contracts and assessments: Update processor terms and identify processing that requires a data protection assessment.
- Test privacy controls: Confirm that visitor choices actually change scripts and downstream processing.
- Re-scan before the effective date: Check for new trackers, integrations or processing changes.
Test the Website, Not Just the Banner
Use browser developer tools and tag-manager previews to confirm that opt-outs and consent choices actually affect cookies, scripts, pixels and third-party network requests.
Test the default state, relevant opt-outs, sensitive-data consent where applicable, later preference changes and your chosen multi-state GPC behaviour.
A banner that records a preference without changing the relevant data processing is not enough.
Oklahoma Privacy Law Enforcement and the 30-Day Cure Period
Oklahoma privacy law penalties: The Oklahoma Attorney General has exclusive authority to enforce SB 546 under 75A O.S. § 311.
Before bringing an enforcement action, the Attorney General generally must provide written notice and a 30-day opportunity to cure the alleged violation under 75A O.S. § 312.
An uncured violation, or a later breach of the required cure statement, can lead to a civil penalty of up to $7,500 per violation under 75A O.S. § 313. The Attorney General may also seek injunctive relief, and specified attorney fees and investigation or enforcement expenses may be awarded.
SB 546 does not create a private right of action.
Important: The 30-day cure process is an enforcement procedure, not a grace period for compliance. Covered organisations should be ready to comply from January 1, 2027.
The enacted 30-day cure provision currently has no statutory sunset date.
Managing Oklahoma Website Privacy Controls With CookieScript
Once a business has classified its processing, CookieScript provides tools for presenting visitor choices, controlling tracker behaviour, recording preferences and supporting different privacy configurations across jurisdictions.
CookieScript is a Consent Management Platform (CMP). It is also a Google-certified CMP with Gold tier status.
Depending on your plan, website setup and applicable privacy requirements, relevant features include:
- Cookie Banner for presenting privacy choices and configuring the banner shown to website visitors. Under Oklahoma law, the required configuration depends on the processing involved rather than a blanket rule requiring prior consent for every non-essential cookie.
- Global privacy regulation support for websites that need to manage privacy requirements across multiple jurisdictions, including the GDPR and ePrivacy Directive in Europe, CCPA and CPRA in California, LGPD in Brazil, and PIPEDA in Canada.
- Google Consent Mode v2 for websites that need to provide supported consent signals to Google tags. This is a Google ecosystem feature rather than a requirement created by Oklahoma SB 546.
- Google Tag Manager integration through the Community Template for websites using GTM to manage tags and privacy-related behaviour.
- Cookie Scanner for identifying cookies and related tracking technologies that should be included in a website data-flow review.
- User consents recording for retaining records of visitor cookie and privacy choices, which can support internal accountability, testing and troubleshooting.
- Third-party cookie blocking for controlling third-party technologies according to the privacy configuration chosen for the website.
- Geo targeting for applying different banner behaviour by visitor location. This can help a multi-state website present different privacy experiences, although geographic detection should not be treated as definitive proof of legal residency.
- Consent events for website or tag-management logic that needs to respond when visitors make or change privacy choices.
Additional tools for multilingual websites, automation, reporting and consent management include:
- 42 languages for multilingual Cookie Banners and cookie information.
- Automatic monthly scans for regularly rescanning a website as cookies and tracking technologies change. This can help catch trackers added after the original Oklahoma privacy review.
- Automatic script blocking for controlling applicable third-party scripts according to the website’s configured privacy rules.
- Advanced reporting for analysing Cookie Banner interactions, acceptance, rejection and category preferences.
- Cookie Banner sharing for sharing banner access between accounts where supported by the selected plan.
- IAB TCF 2.3 integration for websites that use the IAB Europe Transparency & Consent Framework. This is relevant to applicable advertising ecosystems and jurisdictions rather than being an Oklahoma-specific requirement.
- Privacy Policy Generator for helping create or update a Privacy Policy for a website or business. Businesses remain responsible for making sure the final notice reflects their actual processing and Oklahoma disclosure obligations.
- Cookie Policy Generator for creating cookie-policy information that can accompany the website’s privacy disclosures.
CookieScript helps operationalise privacy choices after a business has classified its actual processing. It does not determine whether a tracker legally constitutes a sale, targeted advertising, profiling or sensitive-data processing under Oklahoma law.
A 14-day free trial of the Plus plan is also available with no credit card required.
Conclusion
Oklahoma compliance starts with understanding what each website technology does with personal data, not simply whether it sets a cookie. Covered businesses should align trackers, disclosures, opt-outs and sensitive-data consent with SB 546 before January 1, 2027, then perform a final scan and check for new Attorney General guidance.
Frequently Asked Questions
When does Oklahoma’s new data privacy law take effect?
SB 546 takes effect on January 1, 2027, as stated in Section 22 of the final enrolled bill. The law was enacted in March 2026, providing a preparation period before its requirements take effect. For broader context, state requirements and effective dates vary across U.S. state privacy laws.
Which businesses are covered by Oklahoma’s privacy law?
Subject to exemptions, the law generally applies to businesses that control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving more than 50% of gross revenue from personal-data sales. There is no standalone annual-revenue threshold. The Oklahoma thresholds are set out in 75A O.S. § 314(A). Coverage thresholds vary considerably across U.S. state privacy laws.
Does Oklahoma require Cookie Consent?
Not universally. Oklahoma generally uses opt-out rights for targeted advertising, personal-data sales and qualifying profiling under 75A O.S. § 301(B), while sensitive-data processing generally requires consent under 75A O.S. § 306(B)(4). The distinction between opt-out and opt-in consent is particularly important when comparing U.S. privacy laws with European cookie rules.
Can Oklahoma consumers opt out of targeted advertising?
Yes. Oklahoma consumers can opt out of processing for targeted advertising under 75A O.S. § 301(B)(5). Whether a particular advertising or analytics technology qualifies depends on how it is actually used. The interaction between GPC signals, consent and advertising technologies is also relevant for websites operating across multiple U.S. states.
What counts as a sale of personal data in Oklahoma?
Oklahoma defines a sale as the exchange of personal data by a controller to a third party for monetary consideration, subject to statutory exclusions. The definition appears in 75A O.S. § 300. This is narrower than some other state definitions, making the distinction between data sales and related opt-out rights important for multi-state websites.
Does Oklahoma require websites to honour Global Privacy Control?
No. SB 546 gives consumers opt-out rights for targeted advertising, sale and qualifying profiling under 75A O.S. § 301(B)(5), but it does not itself require automatic recognition of Global Privacy Control (GPC) or another universal opt-out mechanism. Requirements for GPC and universal opt-out mechanisms across U.S. states differ by jurisdiction.
When does Oklahoma require opt-in consent?
Controllers generally must obtain consent before processing sensitive data under 75A O.S. § 306(B)(4). For personal data from a known child, the controller must process that data in accordance with COPPA. The Federal Trade Commission’s COPPA guidance explains the federal verifiable-parental-consent requirements, while this guide to children’s privacy, cookies and tracking provides additional practical context.
What is Oklahoma’s 30-day cure period, and does the law create a private right of action?
The Oklahoma Attorney General generally must provide written notice and a 30-day opportunity to cure before bringing an enforcement action under 75A O.S. § 312. Under 75A O.S. § 313, uncured violations or breaches of the required cure statement may result in civil penalties of up to $7,500 per violation, and the statute does not create a private right of action. Enforcement models differ across U.S. state privacy laws.