Oregon Privacy Law
Oregon wrote two exceptions into its comprehensive law that no other state has. The first is at the front: under ORS 646A.572(1)(b) a motor vehicle manufacturer and its affiliates are covered for any personal data obtained from a consumer’s use of a vehicle or a vehicle component, notwithstanding the threshold numbers entirely. The second is at the back: when the legislature let the cure period lapse, it kept a version of it alive for a single class of controller — noncommercial educational broadcast stations funded by the Corporation for Public Broadcasting or serving as emergency-alert primary entry points — and then repealed that carve-out on July 1, 2026. The Department of Justice publishes what it finds. Its first-year report records 214 complaints, 38 cure matters opened and closed, and a specific finding that companies claiming to offer the named-third-party right were not handling those requests correctly.
The Oregon Consumer Privacy Act (OCPA)
Passed as Senate Bill 619 on June 23, 2023 with what the Department of Justice describes as strong bipartisan support, the OCPA took effect July 1, 2024 for for-profit entities and July 1, 2025 for nonprofit entities. The department states that the Act was based on and shares many commonalities with the Colorado and Connecticut laws as those were originally drafted. Section 646A.572(1)(a) sets the usual two-branch threshold and excludes payment-transaction-only data from the count. Subsection (1)(b) then sets it aside for one industry: notwithstanding those numbers, and subject only to the exemptions in subsections (2) and (3), the Act applies to a motor vehicle manufacturer and any affiliate of a motor vehicle manufacturer that controls or processes any personal data obtained from a consumer’s use of a motor vehicle or any component of one. Section 646A.578 requires a controller to provide an effective means of revoking consent that is at least as easy as the means by which consent was given, and to cease processing as soon as practicable and not later than fifteen days after receiving the revocation. Section 646A.589(7) gives the Attorney General exclusive authority and forecloses a private right of action.
| Effective date | July 1, 2024 |
|---|---|
| Citation | Or. Rev. Stat. §§ 646A.570 to 646A.589 |
| Enforced by | Oregon Attorney General, Department of Justice Privacy Unit |
| Maximum penalty | Up to $7,500 for each violation under Or. Rev. Stat. § 646A.589(4)(a) |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days, lapsed January 1, 2026 except for certain public broadcast stations; that carve-out was repealed July 1, 2026 |
Who Must Comply
The OCPA reaches a business that conducts business in Oregon or provides products or services to Oregon residents, and during a calendar year controls or processes, and the personal data of 100,000 or more consumers, other than data processed solely to complete a payment transaction, or the personal data of 25,000 or more consumers while deriving 25% or more of annual gross revenue from selling personal data — with motor vehicle manufacturers covered regardless of these numbers.
Motor vehicle manufacturers are covered whatever their size, actions are brought in Multnomah County or where the violation occurred within a five-year limitation period, and recoveries go to the Department of Justice Protection and Education Revolving Account.
Consumer Rights Under the OCPA
Residents of Oregon can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Oregon
Data broker registration (Or. Rev. Stat. § 646A.593)
Oregon requires data brokers to register with the Department of Consumer and Business Services rather than with the Attorney General, and defines the trade by reference to what is assembled rather than by revenue. Section 646A.593(1)(a) defines “brokered personal data” as computerized data elements about a resident individual that are categorized or organized for sale or licensing to another person, and lists them: the individual’s name or that of a member of their immediate family or household; the individual’s address or that of such a member; date or place of birth; the maiden name of the individual’s mother; biometric information; a Social Security number or the number of any other government-issued identification; and other information that, alone or combined with other information that is sold or licensed, can reasonably be associated with the individual. Subsection (1)(b) defines “business entity” to include a resident individual who regularly engages in commercial activity to generate income, and corporations and nonprofit corporations alike. The section supplies the method of registration, a penalty for failing to register, and rulemaking authority. The Attorney General’s enforcement reports identify data brokers, and people search sites as a subset of them, as the largest single source of complaints under the comprehensive law.
Identity theft prevention and security freezes (Or. Rev. Stat. §§ 646A.600 to 646A.628)
The identity-theft series carries Oregon’s security-freeze regime alongside the breach provisions. Section 646A.606 sets the requirements for a security freeze, the proof of authority needed and the effect of the freeze; § 646A.608 sets the deadline for placing one, the creation of a protective record, the use and release of information, confirmation, personal identification numbers and the process for lifting and removing a freeze; and § 646A.610 provides that fees are not permitted. Sections 646A.612 through 646A.618 govern the conditions for lifting or removing a freeze, its effect on the use of consumer reports and protective records, the effect of a request for a frozen consumer report, and the prohibition on changes to a frozen report together with the entities required to place one. Section 646A.620 prohibits printing, displaying or posting Social Security numbers subject to enumerated exemptions, and § 646A.622 requires the development of safeguards for personal information — a section the comprehensive law then cross-references, requiring a controller’s safeguards to protect the confidentiality, integrity and accessibility of personal data to the extent appropriate for its volume and nature.
Unlawful Trade Practices Act (Or. Rev. Stat. § 646.605 et seq.)
Oregon’s general unfair-practices statute is the chapter into which the privacy sections were codified — the OCPA sits at ORS 646A.570 to 646A.589 in the trade-practices series — and it supplies the Department of Justice’s civil investigative demand and enforcement infrastructure. Section 646A.589(3) allows the Attorney General to investigate by demand and to use the materials obtained in any resulting action or administrative proceeding; subsection (4)(b) allows the court to award the Attorney General reasonable attorney fees, expert witness fees and costs of investigation on prevailing, and allows fees to a prevailing defendant where the court finds the Attorney General had no objectively reasonable basis for asserting the claim or for appealing. Subsection (6) preserves other remedies and permits a claim under another provision of law to be joined to the Attorney General’s claim under subsection (4).
Data Breach Notification in Oregon
The Oregon Consumer Information Protection Act at ORS 646A.600 to 646A.628 splits the notification duty between the covered entity and its vendors, which is what distinguishes it from the surrounding states. Section 646A.604(1) requires a covered entity subject to a breach, or receiving notice of one from a vendor, to notify the consumer to whom the personal information pertains, and to notify the Attorney General in writing or electronically where the number of consumers it must notify exceeds 250. Subsection (2)(a) then places a hard ten-day clock on vendors: a vendor that discovers a breach or has reason to believe one has occurred must notify the covered entity with which it has a contract as soon as practicable and not later than ten days after that discovery or belief. Subsection (2)(b) extends the duty down a chain of subcontracted vendors, and subsection (2)(c) requires the vendor itself to notify the Attorney General where the breach involved the personal information of more than 250 consumers or a number of consumers the vendor could not determine, unless the covered entity has already done so. Subsection (3)(a) sets the outer limit for the covered entity’s consumer notice at forty-five days from discovering or receiving notification of the breach; subsection (3)(b) requires reasonable measures first to determine contact information, determine the scope of the breach and restore the reasonable integrity, security and confidentiality of the personal information; and subsection (3)(c) permits delay only on a written law enforcement request that notification would impede a criminal investigation. Elsewhere in the same series, ORS 646A.620 restricts printing, displaying or posting Social Security numbers and ORS 646A.622 requires the development of safeguards for personal information.
Residents must be notified in the most expeditious manner possible, without unreasonable delay, and not later than 45 days after discovering or receiving notification of the breach. Notify the Attorney General where the number of consumers to be notified exceeds 250. Complaints are taken by the Oregon Attorney General, which enforces the statute.
Recent Enforcement in Oregon
Oregon DOJ Privacy Unit — first-year enforcement report, August 2025. The Department of Justice published an enforcement report covering the OCPA’s first twelve months in August 2025, following a six-month report and a first-quarter 2025 report. It states that the Privacy Unit received 214 consumer privacy complaints through the Privacy Complaint Portal in that year, of which 130 passed the initial screening for OCPA relevance; of those 130 the department took no further action on 39 relating to entities or information the Act exempts, such as government entities or data covered by HIPAA. From the remaining 91 relevant complaints the Privacy Unit “initiated and closed 38 OCPA cure letter matters” as of July 1, with other matters remaining open and therefore confidential. The department describes the cure notice as a letter mandated by the Act until January 1, 2026 where the potential violations are curable, giving entities a chance to correct compliance issues before further enforcement steps.
Named-third-party right — a documented compliance failure. The department’s first-year report singles out the right that made Oregon distinctive. It states that the OCPA “was the first comprehensive privacy law to provide its citizens with access to a ‘list of specific third parties, other than natural persons, to which the controller has disclosed … [t]he consumer’s personal data’”, citing ORS 646A.574(1)(a)(B), and explains that the provision helps individuals track where their data has gone so they can follow up with deletion or other requests. It then reports that many of the companies about which the Privacy Unit received complaints fail to comply with the requirement in one way or another more than a year after the Act took effect, and that 19 of the complaints received describe companies which claim to provide the right but do not handle such requests correctly. The report identifies four other themes: problems with people search sites as a subset of data brokers; entities requiring consumers to perform significant effort to exercise rights, with incomplete options for copy or deletion; a reminder to audit the functionality of privacy request mechanisms; and clarifications about the role and extent of the provisions for authorized agents.
Pending Privacy Legislation
Chapter 417, Oregon Laws 2025, effective June 24, 2025, is the amendment that matters most and it worked by subtraction. Its section 5 was added to and made a part of ORS 646A.570 to 646A.589, restating the thirty-day notice-and-cure duty; subsection (2) then confined that duty from January 1, 2026 to noncommercial educational broadcast stations meeting the funding or emergency-alert criteria and distributing journalism content at no cost; and section 6 repealed section 5 outright on July 1, 2026. The Department of Justice separately states that from January 1, 2026 controllers are barred from selling precise geolocation data and from selling the personal data of children under 16 or using it for targeted advertising and certain profiling. The Act’s nonprofit coverage arrived on its own schedule, taking effect July 1, 2025, a year after the for-profit date. The enforcement section at ORS 646A.589 carries amendment notes for 2023 c.369 §§ 9 and 11 and 2024 c.64 §§ 1 and 2.
Federal Privacy Laws That Apply in Oregon
Federal privacy law applies in Oregon by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The OCPA sits alongside those rules rather than displacing them: the Oregon Attorney General, Department of Justice Privacy Unit enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.
Oregon Privacy Law FAQ
Are car manufacturers covered by Oregon’s privacy law regardless of size?
Does Oregon still have a cure period under the OCPA?
How quickly must an Oregon vendor report a breach to its customer?
Where does Oregon register its data brokers?
How long does an Oregon consumer have to revoke consent, and how fast must processing stop?
Where are OCPA enforcement actions brought, and how long does the state have?
What did Oregon find when it looked at the named-third-party right?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Or. Rev. Stat. ch. 646A — Trade Regulation (OCPA at 646A.570 to 646A.589; breach at 646A.600 to 646A.628; data brokers at 646A.593) statute
- Or. Rev. Stat. ch. 646 — Trade Practices and Antitrust Regulation statute
- Oregon DOJ — Enforcement Report: The Oregon Consumer Privacy Act, The First Year (Aug. 2025) agency
- Oregon DOJ — Quarterly Enforcement Report, Q3 2025 agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.