Description

Introduced Oklahoma Personal Data Protection Act (HB 3447)

The Oklahoma Personal Data Protection Act (HB 3447) is introduced in the Oklahoma House of Representatives. The Act introduces the consumers' right to request access or correction of personal data and establishes the notice requirements for data controllers. Moreover, the Act details the types of data processing that require consent, the forbidden data processing practices and the purposes for which data controllers are authorised to disclose personal data to third parties. Finally, data controllers are required to develop a privacy policy and conduct privacy and security risk assessments.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2022-02-07
under deliberation

The Oklahoma Personal Data Protection Act (HB 3447) is introduced in the Oklahoma House of Represen…

2022-05-27
rejected

On 27 May 2022, the Oklahoma Personal Data Protection Act (HB 3447) was rejected after failing to p…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data collection
Regulatory tool
User right to rectification of personal data
User right to access personal data
User notification requirement
User or public reporting requirement
User consent: Opt-in requirement
Sanctions
Regulated subjects
1
personal data (all forms): data processing
Regulatory tool
User right to rectification of personal data
User right to access personal data
User notification requirement
User or public reporting requirement
User consent: Opt-in requirement
Sanctions
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
Risk or other impact assessment requirement
User right to rectification of personal data
User right to access personal data
User notification requirement
User or public reporting requirement
User consent: Opt-in requirement
Sanctions
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data collection

personal data (all forms): data processing

personal data (all forms): storage (any form)