Skip to main content

Data Protection Map

Oklahoma

Data Breach Requirements: Okla. Stat. tit. 24, § 162 et seq.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

The term “personal information” means an individual’s first name or first initial and last name in combination with to any one or more of the following data elements that relate to the individual if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or are encrypted, redacted, or otherwise altered by any method or technology but the keys to unencrypt, unredact, or otherwise read the data elements have been obtained through the breach of security:

a. Social Security number;

b. Driver’s license number or other unique identification number created or collected by a government entity;

c. Financial account number, credit card or debit card number, in combination with any required expiration date, security code, access code, or password that would permit access to an individual’s financial accounts.

d. A unique electronic identifier or routing code in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or

e. A unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data to authenticate a specific individual.


Security Breach Definition

The term “breach of the security of a system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state.


Good Faith Exception

Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or the entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to unauthorized disclosure.


Risk of Harm Analysis

An individual or entity must disclose the breach of the security of the system if encrypted or redacted information is accessed and acquired in an unencrypted or unredacted form or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such breach has caused or will cause identity theft or other fraud to any resident of this state.


Notification Timeline

Except as provided in subsection D (security and investigation exceptions) or in order to take any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the system, the disclosure shall be made without unreasonable delay.


Security and Investigation Exceptions

A breach notification may be delayed if a law enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation or homeland or national security. Notice must be made without unreasonable delay after the law enforcement agency determines that notification will no longer impede the investigation or jeopardize national or homeland security.


Notification Content Requirements

N/A


Delivery Methods

A breach notice may be provided by one of the following methods:
a. Written notice to the postal address in the records of the individual or entity;
b. Telephone notice;
c. Electronic notice; or
d. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000.00, or that the affected class of residents to be notified exceeds 100,000 persons, or that the individual or the entity does not have sufficient contact information or consent to provide notice as described in subparagraph a, b or c of this paragraph.


Substitute Notice

Substitute notice consists of any two of the following:
(1) Email notice if the individual or the entity has email addresses for the members of the affected class of residents;
(2) Conspicuous posting of the notice on the Internet website of the individual or the entity if the individual or the entity maintains a public Internet website; or
(3) Notice to major statewide media.


Notice to Government Agencies

An individual or entity required to provide a data breach notice under the law shall also provide notice to the Attorney General of such breach without unreasonable delay but in no event more than sixty (60) days after providing notice to impacted residents. The notice shall include the date of the breach, the date of its determination, the nature of the breach, the type of personal information exposed, the number of residents of this state affected, the estimated monetary impact of the breach to the extent such impact can be determined, and any reasonable safeguards the entity employs. This obligation does not apply if a breach of a security system where fewer than five hundred (500) residents of this state are affected within a single breach.


Consumer Reporting Agencies

N/A


Preemption and Compliance

The following entities shall be deemed in compliance with the law: A financial institution that complies with the Gramm-Leach-Bliley Act, the federal notification requirements prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice; An entity that complies with the notification requirements prescribed by the Oklahoma Hospital Cybersecurity Protection Act of 2023 or the Health Insurance Portability and Accountability Act of 1996 (HIPAA); and, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional federal regulator and, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional federal regulator.


Data Processor Obligations

An individual or entity that maintains computerized data that includes personal information that the individual or entity does not own or license shall notify the owner or licensee of the information of any breach of the security of the system. This should be done as soon as practicable following determination, if the personal information was or if the entity reasonably believes it was accessed and acquired by an unauthorized person.


Other Information

An individual or entity that uses reasonable safeguards and provides a data breach notice under the law shall not be subject to civil penalties and may use such compliance as an affirmative defense in a civil action filed under the Security Breach Notification Act. An individual or entity that fails to use reasonable safeguards but provides a data breach notice under the law shall not be subject to the civil penalty set forth in subsection B of this law, but shall be subject to actual damages and a civil penalty of Seventy-five Thousand Dollars ($75,000.00).