iQ Cookie  State Law Series

State 24 of 25 · Oklahoma

Cookie & Privacy Law in Oklahoma

Published August 2026
Effective Jan 1, 2027
Signed Mar 20, 2026

Law not yet in effect. Oklahoma’s OCDPA becomes enforceable January 1, 2027. This guide reflects the law as signed, current as of August 2026. Check back closer to the effective date for any updates.

Educational purposes only — not legal advice. This guide is intended to help you understand Oklahoma’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
OCDPA
SB 546
SIGNED
Mar 20, 2026
Effective Jan 1, 2027
CURE PERIOD
30 days
Permanent, no sunset
STATE RANK
#23
To enact a law

The short version

Oklahoma’s OCDPA (SB 546) was signed March 20, 2026 by Governor Stitt and takes effect January 1, 2027. Commentary at signing described it as mirroring the more lenient end of existing state privacy laws — a permanent cure period, a narrow monetary-only definition of "sale," and standard exemptions for employment and commercial data all point in that direction. As of this writing, there is no indication of pending amendments before the effective date.

Oklahoma does not have a separate cookie law. Cookie compliance flows from the OCDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

Oklahoma Legislature — Official Text
Oklahoma Consumer Data Privacy Act — SB 546 (2026)

Who does it apply to?

The OCDPA covers businesses that conduct business in Oklahoma or target Oklahoma residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more Oklahoma consumers during a calendar year.

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.

Government entities, nonprofits, GLBA financial institutions, HIPAA-covered entities, and higher-education institutions are exempt at the entity level, along with FCRA, HIPAA, FERPA, DPPA, and Controlled Substances Act data at the data level.

Consumer rights

Once in effect, Oklahoma residents whose data is covered by the OCDPA will be able to:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive a portable copy of their data
Opt out
Sale, targeted advertising, and significant profiling
Appeal
60-day response requirement

Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.

What makes Oklahoma different

A narrow, monetary-only definition of "sale." Unlike states that count any "valuable consideration" as a sale, Oklahoma limits it to actual monetary exchange — a materially narrower trigger for sale-related obligations than several peer states in this series, including Louisiana.

A permanent cure period from day one. The 30-day cure opportunity carries no sunset provision, giving Oklahoma businesses durable protection from the effective date forward rather than a countdown clock.

Scientific research data gets its own exemption. This carve-out, alongside the standard employment and commercial data exemptions, is not universal across the series and reflects the law’s generally business-friendly drafting.

Pseudonymous data gets exemptions from certain restrictions. Properly pseudonymized data receives lighter treatment under specific provisions — worth reviewing closely if your data architecture already separates identifiers from behavioral data.

No signs of pending amendments as of August 2026. Unlike Louisiana’s bill, which changed materially during the legislative process, Oklahoma’s OCDPA appears drafted and passed as a relatively stable, finished product — though this should still be reconfirmed closer to the effective date.

Sensitive data & children

Processing sensitive data will require opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health diagnosis
Sexual orientation
Citizenship / immigration status
Genetic / biometric data
Precise geolocation (1,750 ft)
Children’s data (under 13)

Controllers must comply with the federal Children’s Online Privacy Protection Rule (COPPA) for data from known children under 13. The law does not currently impose broader protections for the 13–17 age band beyond the general consumer rights framework.

What this will mean for your cookies

Cookie / data typeRequirementWhat to do
Sensitive data cookies (health, biometric, geolocation)Opt-in requiredGate these behind affirmative consent before they fire.
Sale cookies (monetary exchange only)Opt-out requiredProvide a clear opt-out mechanism for cookies tied to actual monetary sale.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism.
Profiling cookies (legal/significant effects)Opt-out requiredOffer an opt-out for profiling that materially affects consumers.
Any cookies — known childrenCOPPA-aligned consentVerifiable parental consent required.

Enforcement

$7,500
Max per violation, plus fees and costs
30 days
Permanent cure period
AG only
No private right of action

The Oklahoma Attorney General will have sole enforcement authority, with penalties up to $7,500 per violation after the cure period lapses, plus attorney fees and investigative costs. The permanent cure period gives compliant businesses meaningfully more runway than states with sunset dates.

Your action checklist

1

Check your thresholds now. 100,000+ consumers, or 25,000+ with over half your revenue from data sales — confirm which path applies before the January 2027 deadline.

2

Confirm what counts as a "sale" under your data practices. Oklahoma’s monetary-only definition may exclude some data-sharing arrangements that would count as sales elsewhere.

3

Audit sensitive data cookies. Health, biometric, and precise geolocation data will need opt-in consent before collection.

4

Build the standard rights infrastructure. Access, correction, deletion, portability, and opt-out workflows all apply.

5

Review whether pseudonymized data qualifies for lighter treatment. Worth a dedicated look if your architecture already separates identifiers from behavioral signals.

6

Recheck this guide closer to the effective date. This post reflects the law as signed in March 2026; confirm no amendments have been introduced before enforcement begins.

7

Review vendor contracts. Any processor handling Oklahoma resident data will need a written agreement specifying processing instructions and confidentiality obligations.

Getting ready for Oklahoma’s 2027 deadline?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 24 of 25  ·  Next: Vermont →