iQ Cookie State Law Series
Cookie & Privacy Law in Oklahoma
Law not yet in effect. Oklahoma’s OCDPA becomes enforceable January 1, 2027. This guide reflects the law as signed, current as of August 2026. Check back closer to the effective date for any updates.
Educational purposes only — not legal advice. This guide is intended to help you understand Oklahoma’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Oklahoma’s OCDPA (SB 546) was signed March 20, 2026 by Governor Stitt and takes effect January 1, 2027. Commentary at signing described it as mirroring the more lenient end of existing state privacy laws — a permanent cure period, a narrow monetary-only definition of "sale," and standard exemptions for employment and commercial data all point in that direction. As of this writing, there is no indication of pending amendments before the effective date.
Oklahoma does not have a separate cookie law. Cookie compliance flows from the OCDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.
Who does it apply to?
The OCDPA covers businesses that conduct business in Oklahoma or target Oklahoma residents, and meet at least one of these thresholds:
Controls or processes personal data of 100,000 or more Oklahoma consumers during a calendar year.
Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.
Government entities, nonprofits, GLBA financial institutions, HIPAA-covered entities, and higher-education institutions are exempt at the entity level, along with FCRA, HIPAA, FERPA, DPPA, and Controlled Substances Act data at the data level.
Consumer rights
Once in effect, Oklahoma residents whose data is covered by the OCDPA will be able to:
Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.
What makes Oklahoma different
A narrow, monetary-only definition of "sale." Unlike states that count any "valuable consideration" as a sale, Oklahoma limits it to actual monetary exchange — a materially narrower trigger for sale-related obligations than several peer states in this series, including Louisiana.
A permanent cure period from day one. The 30-day cure opportunity carries no sunset provision, giving Oklahoma businesses durable protection from the effective date forward rather than a countdown clock.
Scientific research data gets its own exemption. This carve-out, alongside the standard employment and commercial data exemptions, is not universal across the series and reflects the law’s generally business-friendly drafting.
Pseudonymous data gets exemptions from certain restrictions. Properly pseudonymized data receives lighter treatment under specific provisions — worth reviewing closely if your data architecture already separates identifiers from behavioral data.
No signs of pending amendments as of August 2026. Unlike Louisiana’s bill, which changed materially during the legislative process, Oklahoma’s OCDPA appears drafted and passed as a relatively stable, finished product — though this should still be reconfirmed closer to the effective date.
Sensitive data & children
Processing sensitive data will require opt-in consent before any collection begins. Sensitive data includes:
Controllers must comply with the federal Children’s Online Privacy Protection Rule (COPPA) for data from known children under 13. The law does not currently impose broader protections for the 13–17 age band beyond the general consumer rights framework.
What this will mean for your cookies
| Cookie / data type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (health, biometric, geolocation) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Sale cookies (monetary exchange only) | Opt-out required | Provide a clear opt-out mechanism for cookies tied to actual monetary sale. |
| Targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism. |
| Profiling cookies (legal/significant effects) | Opt-out required | Offer an opt-out for profiling that materially affects consumers. |
| Any cookies — known children | COPPA-aligned consent | Verifiable parental consent required. |
Enforcement
The Oklahoma Attorney General will have sole enforcement authority, with penalties up to $7,500 per violation after the cure period lapses, plus attorney fees and investigative costs. The permanent cure period gives compliant businesses meaningfully more runway than states with sunset dates.
Your action checklist
Check your thresholds now. 100,000+ consumers, or 25,000+ with over half your revenue from data sales — confirm which path applies before the January 2027 deadline.
Confirm what counts as a "sale" under your data practices. Oklahoma’s monetary-only definition may exclude some data-sharing arrangements that would count as sales elsewhere.
Audit sensitive data cookies. Health, biometric, and precise geolocation data will need opt-in consent before collection.
Build the standard rights infrastructure. Access, correction, deletion, portability, and opt-out workflows all apply.
Review whether pseudonymized data qualifies for lighter treatment. Worth a dedicated look if your architecture already separates identifiers from behavioral signals.
Recheck this guide closer to the effective date. This post reflects the law as signed in March 2026; confirm no amendments have been introduced before enforcement begins.
Review vendor contracts. Any processor handling Oklahoma resident data will need a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 24 of 25 · Next: Vermont →