All about Oklahoma’s Security Breach Notification Act’s newest reform: SB 626

Amendments to Oklahoma’s Security Breach Notification Act went into effect on January 1, 2026. These changes follow a movement by state governments and regulatory bodies to reform and update their data breach statutes to improve reporting, incident tracking, and consumer protection.

The Act applies to covered entities who are individuals or entities who own or license computerized data that includes personal information of Oklahoma residents. Third parties who maintain data of Oklahoma residents that they do not own, are required to notify the data owner immediately following the discovery of a breach.  

The Act defines a “breach” as the unauthorized access and acquisition of unencrypted and unredacted computerized data that (1) compromises the security or confidentiality of personal information, and that (2) causes or is reasonably believed to have caused an Oklahoma resident to be the victim of identity theft or other fraud. 

The Act before SB 626

The previous version of the Act defined “personal information” as an individual’s first name or first initial and last name, in combination with one or more of the following data elements:

    • Social Security number.
    • Driver’s license or state identification card number.
    • Financial account or payment card number plus a security code, access code, or password that would permit access to a financial account.

The definition of “personal information” did not include medical or health insurance information. Additionally, notices to individuals were to be issued “without unreasonable delay.” The Act did not require notice to the Oklahoma Attorney General’s office or to the three credit reporting agencies (TransUnion, Experian, and Equifax).

The original Act includes a “safe harbor” provision which allows the good-faith acquisition of personal information by an employee or agent, provided that the information is not used for any purpose other than the lawful purposes for which the information was originally obtained. The information may also not be “subject to further unauthorized acquisition.”  There is also an “encryption” safe harbor. Under the original statute, potentially affected individuals did not have to be notified of a breach if their personal information was encrypted and if the encryption key was not available.

Changes effective now

Here is a summary of the changes that took effect on January 1, 2026.

Expanded definition of “personal information.” Personal information, or “PI,” is now defined as an individual’s first name or first initial and last name, in combination with any one of the following data elements that relate to the individual, if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology to make the name or data elements unreadable:

    • Social Security number.
    • Driver’s license or state identification card number.
    • Financial account or payment card number plus a security code, access code, or password that would permit access to a financial account.
    • Biometric data and electronic identification numbers.
    • Email addresses or internet account numbers.

“Biometric data” is generally defined as” unique physical or behavioral characteristics used to identify and verify an individual’s identity”, including fingerprints, retinal scans, and “other” unique physical or digital representations.

“Electronic identifiers” include routing codes in combination with any required security code, access code, or password that would permit access to an individual’s financial account.

The amended definition of PI does not include medical information or health insurance information – data elements that are included in many other states’ breach notification laws. 

Safe harbor provision. The safe harbor provision was modified by striking the word “further” so that the “good faith acquisition” cannot be subject to unauthorized acquisition at all.

Notice to Oklahoma Attorney General and credit reporting agencies. The Oklahoma Attorney General’s office now requires notice of breaches without “unreasonable delay,” but not later than 60 days after individual notifications are issued to more than 500 Oklahoma residents.  

The notice must include the type of personal information exposed, the number of Oklahoma residents affected, the estimated monetary impact of the breach (to the extent that the impact can be determined), and any reasonable safeguards that the entity employs.

If more than 1,000 Oklahoma residents are individually notified, the covered entity must also notify the three credit bureau agencies.

Civil penalty caps. SB 626 also establishes penalty caps for covered entities. There is a cap of $150,000 per breach for entities who fail to comply with notice requirements and did not implement “reasonable safeguards.” If an entity failed to put into place “reasonable safeguards” but did provide timely notification, the cap is $75,000 per breach.

The “reasonable safeguards” defense. SB 626 introduces a “reasonable safeguards” affirmative defense. If an entity shows that it implemented reasonable safeguards during the breach and provided compliant notice, it may not be subject to civil penalties. The reasonable safeguards are measured against the entity’s size and the amount of PI maintained. “Reasonable safeguards” include the following:

  • Regular risk assessments.
  • Multiple, overlapping layers of technical and physical protections designed to deter, detect and respond to threats of unauthorized access.
  • Employee training in handling PI.
  • An incident response plan.

Federal compliance exemptions

The text of SB 626 acknowledges that certain entities may have their own notice procedures as part of information privacy or security policies based on the Gramm-Leach-Bliley Act, the Health Insurance Portability and Accountability Act, or those established by their functional federal regulator. If so, those entities are exempt from the Oklahoma requirements as long their internal procedures are as thorough as the state requirements.

“Before and after”

Here’s a handy table to track the “before SB 626” and after of the Oklahoma Security Breach Notification Act:

Issue  

Before SB 626

After SB 626

PI

Only SSN, Driver’s License/State ID, and Financial Account

+ Biometric data and electronic credentials that allow access to a financial account

AG Notice

Not a requirement

Required if 500+ affected individuals notified (subject to federal compliance exemptions)

Notice deadline to AG

N/A

No more than 60 days after individual notice

Penalty cap

N/A

$150,000 per breach ($75,000 with “reasonable safeguards”)

“Reasonable Safeguards” defense

N/A

Full defense available

CRA Notice

N/A

Required if 1,000+ residents notified

The Constangy Cybersecurity & Data Privacy Team helps businesses of all sizes and industries develop a comprehensive incident response plan or support with a breach. We are here to help! The Constangy Cyber Team is available 24/7. Contact us at breachresponse@constangy.com or by phone at 877-DTA-BRCH.

  • Lauren Godfrey wearing a gray blazer over a white top, accessorized with a cross necklace and drop earrings, arms crossed, posed against a light blue and white geometric background.
    Partner

    Lauren guides clients through data security incidents, leading initial assessments and coordinating forensic and remediation efforts to contain, investigate, and resolve issues. She helps clients develop privacy, incident ...

  • A confident woman wearing glasses and a gray business suit smiles with her arms crossed against a transparent background. Her professional attire and posture suggest a business or leadership context.
    Associate Attorney

    With a background in data privacy, intellectual property, and regulatory compliance, Sydney brings a thoughtful, practical approach to managing sensitive matters in fast-paced environments.

    Before joining Constangy, Sydney ...

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek