Security Breach Notification Act; requiring notice of security breach of certain information; modifying provisions. Effective date.
SB 626, the Security Breach Notification Act, requires businesses to notify Oklahomans when specific personal data used to verify identity (like Social Security numbers or account credentials) is compromised in a security breach. This law directly affects businesses and organizations that collect or store such identifying information, including credit bureaus, healthcare providers, and financial institutions. The key provision clarifies that notifications are mandated only when data enabling authentication of an individual is breached, not for all types of data. The law became effective on May 28, 2025, without the Governor's signature.
Bill status
signed
all 5 stages cleared
Introduction
Feb 2025
Committee Review
May 2025
Senate Passage
May 2025
House Passage
May 2025
Signed into Law
May 2025
Introduced Feb 3, 2025
Signed May 28, 2025
Maddy AI version diff · 6 comparisons
What changed between versions
Floor (House)
→
Floor (Senate)
·
3 edits
MINOR
The bill was transitioned from the House version to the Senate floor version, introducing specific formatting changes and committee amendments. The most significant substantive change is the addition of 'unique biometric data' (such as fingerprints or iris images) to the legal definition of 'personal information,' which expands the scope of data requiring security breach notifications. Additionally, the text includes a new clause requiring 'reasonable safeguards' to be considered based on an entity's size and the volume of data held.
Scope change
The scope of the bill was expanded to include biometric data as protected personal information, meaning security breaches involving fingerprints or facial recognition data now trigger notification requirements.
DEFINITION
Added 'unique biometric data' (fingerprints, retina, iris images) to the definition of personal information, expanding the types of data covered by the Security Breach Notification Act.
REQUIREMENT
Introduced a requirement for entities to implement 'reasonable safeguards' tailored to their size and the amount of personal information they hold.
TECHNICAL
Changed the document header from 'HOUSE OF REPRESENTATIVES' to 'SENATE FLOOR VERSION' and updated page numbering and formatting to reflect the Senate's version of the bill.
Floor votes · Senate Mar 27, 2025 · House May 7, 2025
How they voted
40–6
Passed · 3 other
Total votes 49
Mar 27, 2025
D
Democratic9
100% Yea
R
Republican40
77% Yea
Vote distribution
All Yea
All Nay
Mixed
No data
Full legislative history
Actions timeline
Total actions
28
Key actions
10
Committee
7
Amendments
2
May 20, 2025
Committee
Referred for enrollment
upper
May 20, 2025
Upper · Passed
Measure passed: Ayes: 36 Nays: 6
upper
May 20, 2025
Upper · Passed
HAs adopted
upper
May 8, 2025
Lower · Passed
Engrossed, signed, to Senate
lower
May 7, 2025
Committee
Referred for engrossment
lower
May 7, 2025
Lower · Passed
Third Reading, Measure passed: Ayes: 85 Nays: 2
lower
May 7, 2025
Lower · Passed
Amended
lower
Apr 17, 2025
Lower · Passed
CR; Do Pass Appropriations and Budget Committee
lower
Apr 8, 2025
Lower · Passed
Recommendation to the full committee; Do Pass Appropriations and Budget Judiciary Subcommittee
lower
Apr 2, 2025
Committee
Referred to Appropriations and Budget Judiciary Subcommittee
lower
Mar 31, 2025
Introduced
First Reading
lower
Mar 31, 2025
Upper · Passed
Engrossed to House
upper
Mar 27, 2025
Committee
Referred for engrossment
upper
Mar 27, 2025
Upper · Passed
Measure passed: Ayes: 38 Nays: 6
upper
Mar 27, 2025
Introduced
General Order, Amended
upper
Feb 13, 2025
Upper · Passed
Reported Do Pass Technology and Telecommunications committee; CR filed
upper
Feb 3, 2025
Introduced
First Reading
upper
2 primary · 0 co-sponsors
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about SB 626
Scope: OK
Hi! I can help you understand SB 626. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline