At a Glance
- Applies to businesses processing data on 100,000+ Oklahoma consumers annually, or 25,000+ where data sales exceed 50 percent of gross revenue
- Uses an opt-out model for targeted advertising, data sales, and qualifying profiling
- Requires affirmative consent for sensitive data, including biometric data and children’s data under 13
- Enforced solely by the Oklahoma Attorney General, with no private right of action
- Does not require honoring Global Privacy Control (GPC) or other universal opt-out signals
The Oklahoma Consumer Data Privacy Act (OCDPA) follows the Virginia VCDPA and Texas TDPSA model: an opt-out framework for most processing, affirmative consent for sensitive data, and enforcement handled solely by the Oklahoma Attorney General.
If your business already meets VCDPA or TDPSA requirements, the OCDPA shouldn’t require a full compliance overhaul. But its narrower “sale” definition and lack of GPC recognition are worth being aware of for your configuration.
The Checklist
1: Determine If Your Company Must Comply
The OCDPA applies if you meet either threshold below during a calendar year.
- Control or process the personal data of at least 100,000 Oklahoma consumers, or
- Control or process the personal data of at least 25,000 Oklahoma consumers and derive more than 50 percent of gross revenue from the sale of personal data
2: Update Your Privacy Notice
Your privacy notice needs to disclose data categories, processing purposes, third-party sharing, and how consumers can exercise their rights.
3: Inform Consumers of Their Rights
Oklahoma consumers can request access, correction, deletion, portability, and opt-out. They cannot be discriminated against for exercising any of them.
Note: The OCDPA does not include a right to revoke consent or a right to limit use of sensitive data.
4: Set Up Opt-Out Mechanisms for Sale and Targeted Advertising
Give consumers a clear way to opt out of targeted advertising, data sales, and qualifying profiling.
- Oklahoma defines “sale” as monetary consideration only, which is narrower than states that count other forms of value
- GPC recognition is not required, though it’s worth maintaining if you operate in the 12+ states that do require it
5: Obtain Affirmative Consent for Sensitive Data
Get affirmative, active consent before processing racial/ethnic origin, health data, biometric data, precise geolocation, and children’s data if they’re under 13.
6: Build Consumer Rights Request Workflows
Provide two secure request methods, respond within 45 days (one 45-day extension available), and support a 60-day appeal process.
7: Review Processor Contracts
Put written contracts in place with third-party processors covering processing instructions, data types, duration, and subprocessor obligations.
8: Conduct Data Protection Assessments
Assess high-risk processing, including targeted advertising, data sales, profiling, and sensitive data, for activity beginning on or after January 1, 2027.
9: Audit Consent Interfaces for Dark Patterns
Review consent banners and opt-out flows for manipulative design. The OCDPA explicitly prohibits dark patterns.
Get the full picture in the Oklahoma Consumer Data Privacy Act overview.