The Oklahoma Consumer Data Privacy Act takes effect on 1 January 2027. It is a Virginia-model comprehensive privacy statute: opt-out for targeted advertising, sale and certain profiling; opt-in consent for sensitive data; the now-standard bundle of access, correction, deletion, portability and appeal; mandatory processor terms; and enforcement by the Attorney General.
Read in isolation it is unremarkable. Oklahoma is the latest entry in a pattern that has repeated roughly a dozen times since 2021, and a privacy programme built for Virginia, Colorado, Connecticut and their successors will find few genuine surprises in it.
Read in context it is more interesting, because of what else lands in the same window. 1 January 2027 is also the date California’s ADMT regulations become operative, the date California’s AB 1043 device-level age assurance obligations begin, and the date New York’s RAISE Act frontier-model obligations take effect. 25 January 2027 is when the New York SAFE for Kids Act obligations bite. 13 May 2027 is India’s full DPDP compliance date.
That concentration is the story. Oklahoma on its own is a configuration change. Oklahoma landing on the same morning as an automated decision-making regime, a device-level age signal regime and a national AI statute is a capacity problem.
What the OCDPA requires
Applicability
The OCDPA applies to persons conducting business in Oklahoma, or producing products or services targeted to Oklahoma residents, that during a calendar year either:
- control or process the personal data of at least 100,000 Oklahoma consumers, or
- control or process the personal data of at least 25,000 Oklahoma consumers and derive more than 50% of gross revenue from the sale of personal data.
The 100,000 threshold is at the higher end of the state-law range and, given Oklahoma’s population, is a meaningfully narrowing filter. A national consumer business will generally clear it. A regional business, a B2B software company, or a service provider without a direct consumer relationship frequently will not.
Run the number before you run the project. A material share of organisations that opened an Oklahoma workstream will find, on measuring, that they do not meet the threshold. The measurement itself is worth doing properly — by identifiable Oklahoma consumers, across the calendar year, aggregated across business units and brands.
Rights and timelines
Consumers get access, correction, deletion, portability, and opt-outs from targeted advertising, sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.
The response timeline is 45 days, extendable by a further 45 where reasonably necessary. The appeal timeline is 60 days, with a requirement to inform the consumer of the ability to contact the Attorney General if the appeal is denied.
For an organisation already operating a multi-state DSAR programme, this is a configuration entry. For an organisation that handles requests manually, a twenty-first jurisdiction with its own timelines is where the manual process finally breaks.
Sensitive data
Affirmative consent is required before processing sensitive personal data — including biometric data, precise geolocation, and data of a known child under 13.
This is the provision that most frequently produces a genuine gap rather than a paperwork gap, because sensitive-data opt-in requires the organisation to know, at the point of collection, that a data element falls into a sensitive category. Precise geolocation in particular is routinely collected by mobile SDKs whose behaviour the product team has not examined recently.
Processor contracts
Where personal data is disclosed to a processor, the relationship must be governed by a written contract requiring confidentiality, deletion or return of personal data at the controller’s direction, cooperation with audits or assessments, and flow-down of equivalent obligations to subprocessors.
If your data processing addendum is already drafted to the Virginia/Colorado/Connecticut common denominator, Oklahoma is covered. If you have been signing whatever the vendor’s paper says, this is another jurisdiction in which that choice becomes a violation rather than a risk.
Exemptions
The OCDPA carves out HIPAA-covered entities, nonprofits, and institutions of higher education at the entity level, and exempts specific data categories including protected health information, medical records, and personal data subject to the FCRA, the Driver’s Privacy Protection Act, and FERPA.
Entity-level exemptions matter more than data-level ones for scoping. A HIPAA-covered entity is out entirely; a business associate generally is not.
The Q1 2027 stack
Here is the concentration, laid out. Each row is a separate programme with a separate owner in most organisations.
| Date | Obligation | Who it hits |
|---|---|---|
| 1 Jan 2027 | Oklahoma OCDPA | Controllers over threshold |
| 1 Jan 2027 | CCPA ADMT — pre-use notice, opt-out, access, human appeal | Anyone using automation for significant decisions about Californians |
| 1 Jan 2027 | California AB 1043 — device/OS-level age signals | App developers and OS/app store operators |
| 1 Jan 2027 | New York RAISE Act — safety protocols, 72-hour incident reporting, DFS disclosure | Frontier developers over $500m revenue |
| 25 Jan 2027 | NY SAFE for Kids Act — algorithmic feeds and night notifications for under-18s | Covered social platforms |
| 13 May 2027 | India DPDP full substantive compliance | Anyone offering goods or services to Indian data principals |
| 2 Dec 2027 | EU AI Act Annex III high-risk obligations (deferred) | High-risk AI providers and deployers |
Three of the first four are on the same calendar day, and they draw on the same scarce internal resources: privacy engineering, product engineering, legal review and the consent/preference infrastructure.
That is why the twenty-first state law is harder than the twentieth. The marginal cost of adding a Virginia-model state to a mature programme is genuinely low — but it is only low if the programme is not simultaneously absorbing an automated decision-making regime and an age-assurance regime with the same headcount.
What actually generalises across the wave
The states have converged enough that building to the union of requirements is now cheaper than building per-state. The design targets that hold across the whole set:
Universal opt-out signal support. Global Privacy Control recognition is mandatory in a growing subset of states and is the cheapest way to satisfy several opt-out obligations at once. If you do not honour GPC, that is a single defect generating violations in multiple jurisdictions simultaneously.
Rights fulfilment at the strictest common timeline. Operating every jurisdiction at 45 days with a 60-day appeal removes per-state timeline logic, which is where multi-state DSAR programmes generate errors.
Sensitive-data opt-in as the default posture. Rather than maintaining a per-state map of which categories require consent, treat biometrics, precise geolocation, health inference, and known-child data as opt-in everywhere. The compliance saving from doing otherwise is small; the error rate from maintaining the map is not.
A single processor DPA drafted to the union. Confidentiality, deletion/return, audit cooperation, subprocessor flow-down, plus the additional terms Colorado and Connecticut require. One paper, all states.
Data minimisation as a control, not a principle. California’s enforcement posture through 2026 — the $1.275 million GM/OnStar action being the clearest example — has established that collecting more than is necessary is independently actionable. That theory travels to every state with a necessity limitation, which is all of them.
Threshold monitoring as a recurring control. Applicability thresholds are measured per calendar year. An organisation below the Oklahoma threshold in 2026 may be above it in 2027 without anyone noticing, because nobody owns the measurement. Assign it, run it annually, document the result.
The programme question worth asking now
This site has tracked the state privacy patchwork through 2026’s twenty-state landscape, the March 2026 bill wave, and the 1 July 2026 effective dates. The direction is not in doubt: the count keeps rising, the substance keeps converging, and federal preemption keeps not arriving.
The useful question in August 2026 is therefore not “how do we comply with Oklahoma”. It is:
Can our privacy programme absorb a new Virginia-model state as a configuration change, executed by an operations owner, without a legal project?
If the answer is yes, Oklahoma costs a few days and the January capacity goes to ADMT and age assurance, which genuinely need it.
If the answer is no — if each new state still triggers a legal review, a policy redraft, a DPA renegotiation and an engineering ticket — then the twenty-first law will consume the capacity that 1 January 2027 needs elsewhere, and the constraint will not be Oklahoma. It will be everything Oklahoma is standing in front of.
This article is provided for informational purposes only and does not constitute legal advice.



