Who Is Covered?
An individual or entity that owns or licenses computerized data of a resident of Oklahoma whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. Okla. Stat. tit. 24, § 163(A).
“Entity” includes corporations, business trusts, estates, partnerships, limited partnerships, limited liability partnerships, limited liability companies, associations, organizations, joint ventures, governments, governmental subdivisions, agencies, or instrumentalities, or any other legal entity, whether for profit or not-for-profit. Okla. Stat. tit. 24, § 162(2).
What Information Is Protected?
“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the individual if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or are encrypted, redacted, or otherwise altered by any method or technology but the keys to unencrypt, unredact, or otherwise read the data elements have been obtained through the breach of security::
- Social security number,
- Driver license number or other unique identification number created or collected by a government entity,
- Financial account number, or credit card or debit card number, in combination with any required expiration date, security code, access code, or password that would permit access to an individual’s financial account,
- Unique electronic identifier or routing code in combination with any required security code, access code, or password that would permit access to an individual’s financial account, or
- Unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data to authenticate a specific individual. Okla. Stat. tit. 24, § 162(6).
What Is A “Breach”?
“Breach of the security of a system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. Okla. Stat. tit. 24, § 162(1).
What Triggers Notification?
Determination or notification of the breach of the security of the system involving the personal information of an Oklahoma resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. Okla. Stat. tit. 24, § 163(A).
How Is Notice Provided To Individuals?
Timing: The disclosure must be made without unreasonable delay. Okla. Stat. tit. 24, § 163(A).
Delivery: Notice may be by:
- Written notice to the postal address in the records of the individual or entity,
- Telephone notice,
- Electronic notice, or
- Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000, or that the affected class of residents to be notified exceeds 100,000 persons, or that the individual or the entity does not have sufficient contact information or consent to provide notice as described in subparagraph a, b or c of this paragraph. Substitute notice consists of any two of the following: (a) email notice if the individual or the entity has email addresses for the members of the affected class of residents, (b) conspicuous posting of the notice on the Internet website of the individual or the entity if the individual or the entity maintains a public Internet website, or (c) notice to major statewide media. Okla. Stat. tit. 24, § 162(7).
Content: None specified.
Is Notice To The Government Required?
Yes, if 500 or more residents are affected. Notice must be given to the Attorney General without unreasonable delay but in no event more than 60 days after providing notice to impacted residents. Notice to the Attorney General is not required in the event of a breach of a security system maintained by a credit bureau where fewer than 1,000 residents are affected within a single breach.
The notice must include the date of the breach, the date of its determination, the nature of the breach, the type of personal information exposed, the number of residents of this state affected, the estimated monetary impact of the breach to the extent such impact can be determined, and any reasonable safeguards the entity employs. Okla. Stat. tit. 24, § 163(E)
Is Notice To Credit Reporting Agencies Required?
No.
Are There Security Measure Standards?
Yes. “Reasonable safeguards” are policies and practices that ensure personal information is secure, taking into consideration an entity’s size and the type and amount of personal information. The term includes, but is not limited to, conducting risk assessments, implementing technical and physical layered defenses, employee training on handling personal information, and establishing an incident response plan. Okla. Stat. tit. 24, § 162(8).
An individual or entity that uses reasonable safeguards and provides notice as required shall not be subject to civil penalties and may use such compliance as an affirmative defense in a civil action filed under the Security Breach Notification Act.
An individual or entity that fails to use reasonable safeguards but provides notice as required shall not be subject to the civil penalty but shall be subject to actual damages and a civil penalty of Seventy-five Thousand Dollars ($75,000.00). Okla. Stat. tit. 24, § 165(C)(1), (2).
What Are The Possible Consequences Of A Violation?
The Attorney General or a district attorney have exclusive authority to bring action and may obtain either actual damages for a violation of the act or a civil penalty not to exceed $150,000 per breach of the security of the system or series of breaches of a similar nature that are discovered in a single investigation. Okla. Stat. tit. 24, § 165(B).
Are There Any Exemptions/Exceptions?
The following entities will be deemed to be in compliance:
- An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and that is consistent with the timing requirements of this act if it notifies residents of this state in accordance with its procedures in the event of a breach of security of the system.
- A financial institution that complies with the notification requirements prescribed by the Gramm-Leach-Bliley Act and federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice.
- An entity that complies with the notification requirements or procedures pursuant to the rules, regulation, procedures, or guidelines established by the primary or functional federal regulator of the entity. Okla. Stat. tit. 24, § 164.
