Oregon — Comprehensive Law

Oregon Privacy Law

Oregon wrote two exceptions into its comprehensive law that no other state has. The first is at the front: under ORS 646A.572(1)(b) a motor vehicle manufacturer and its affiliates are covered for any personal data obtained from a consumer’s use of a vehicle or a vehicle component, notwithstanding the threshold numbers entirely. The second is at the back: when the legislature let the cure period lapse, it kept a version of it alive for a single class of controller — noncommercial educational broadcast stations funded by the Corporation for Public Broadcasting or serving as emergency-alert primary entry points — and then repealed that carve-out on July 1, 2026. The Department of Justice publishes what it finds. Its first-year report records 214 complaints, 38 cure matters opened and closed, and a specific finding that companies claiming to offer the named-third-party right were not handling those requests correctly.

The Oregon Consumer Privacy Act (OCPA)

Passed as Senate Bill 619 on June 23, 2023 with what the Department of Justice describes as strong bipartisan support, the OCPA took effect July 1, 2024 for for-profit entities and July 1, 2025 for nonprofit entities. The department states that the Act was based on and shares many commonalities with the Colorado and Connecticut laws as those were originally drafted. Section 646A.572(1)(a) sets the usual two-branch threshold and excludes payment-transaction-only data from the count. Subsection (1)(b) then sets it aside for one industry: notwithstanding those numbers, and subject only to the exemptions in subsections (2) and (3), the Act applies to a motor vehicle manufacturer and any affiliate of a motor vehicle manufacturer that controls or processes any personal data obtained from a consumer’s use of a motor vehicle or any component of one. Section 646A.578 requires a controller to provide an effective means of revoking consent that is at least as easy as the means by which consent was given, and to cease processing as soon as practicable and not later than fifteen days after receiving the revocation. Section 646A.589(7) gives the Attorney General exclusive authority and forecloses a private right of action.

Effective dateJuly 1, 2024
CitationOr. Rev. Stat. §§ 646A.570 to 646A.589
Enforced byOregon Attorney General, Department of Justice Privacy Unit
Maximum penaltyUp to $7,500 for each violation under Or. Rev. Stat. § 646A.589(4)(a)
Private right of actionNo, enforcement by the state only
Right to cure30 days, lapsed January 1, 2026 except for certain public broadcast stations; that carve-out was repealed July 1, 2026

Who Must Comply

The OCPA reaches a business that conducts business in Oregon or provides products or services to Oregon residents, and during a calendar year controls or processes, and the personal data of 100,000 or more consumers, other than data processed solely to complete a payment transaction, or the personal data of 25,000 or more consumers while deriving 25% or more of annual gross revenue from selling personal data — with motor vehicle manufacturers covered regardless of these numbers.

Motor vehicle manufacturers are covered whatever their size, actions are brought in Multnomah County or where the violation occurred within a five-year limitation period, and recoveries go to the Department of Justice Protection and Education Revolving Account.

Consumer Rights Under the OCPA

Residents of Oregon can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Oregon

Data broker registration (Or. Rev. Stat. § 646A.593)

Oregon requires data brokers to register with the Department of Consumer and Business Services rather than with the Attorney General, and defines the trade by reference to what is assembled rather than by revenue. Section 646A.593(1)(a) defines “brokered personal data” as computerized data elements about a resident individual that are categorized or organized for sale or licensing to another person, and lists them: the individual’s name or that of a member of their immediate family or household; the individual’s address or that of such a member; date or place of birth; the maiden name of the individual’s mother; biometric information; a Social Security number or the number of any other government-issued identification; and other information that, alone or combined with other information that is sold or licensed, can reasonably be associated with the individual. Subsection (1)(b) defines “business entity” to include a resident individual who regularly engages in commercial activity to generate income, and corporations and nonprofit corporations alike. The section supplies the method of registration, a penalty for failing to register, and rulemaking authority. The Attorney General’s enforcement reports identify data brokers, and people search sites as a subset of them, as the largest single source of complaints under the comprehensive law.

Identity theft prevention and security freezes (Or. Rev. Stat. §§ 646A.600 to 646A.628)

The identity-theft series carries Oregon’s security-freeze regime alongside the breach provisions. Section 646A.606 sets the requirements for a security freeze, the proof of authority needed and the effect of the freeze; § 646A.608 sets the deadline for placing one, the creation of a protective record, the use and release of information, confirmation, personal identification numbers and the process for lifting and removing a freeze; and § 646A.610 provides that fees are not permitted. Sections 646A.612 through 646A.618 govern the conditions for lifting or removing a freeze, its effect on the use of consumer reports and protective records, the effect of a request for a frozen consumer report, and the prohibition on changes to a frozen report together with the entities required to place one. Section 646A.620 prohibits printing, displaying or posting Social Security numbers subject to enumerated exemptions, and § 646A.622 requires the development of safeguards for personal information — a section the comprehensive law then cross-references, requiring a controller’s safeguards to protect the confidentiality, integrity and accessibility of personal data to the extent appropriate for its volume and nature.

Unlawful Trade Practices Act (Or. Rev. Stat. § 646.605 et seq.)

Oregon’s general unfair-practices statute is the chapter into which the privacy sections were codified — the OCPA sits at ORS 646A.570 to 646A.589 in the trade-practices series — and it supplies the Department of Justice’s civil investigative demand and enforcement infrastructure. Section 646A.589(3) allows the Attorney General to investigate by demand and to use the materials obtained in any resulting action or administrative proceeding; subsection (4)(b) allows the court to award the Attorney General reasonable attorney fees, expert witness fees and costs of investigation on prevailing, and allows fees to a prevailing defendant where the court finds the Attorney General had no objectively reasonable basis for asserting the claim or for appealing. Subsection (6) preserves other remedies and permits a claim under another provision of law to be joined to the Attorney General’s claim under subsection (4).

Data Breach Notification in Oregon

The Oregon Consumer Information Protection Act at ORS 646A.600 to 646A.628 splits the notification duty between the covered entity and its vendors, which is what distinguishes it from the surrounding states. Section 646A.604(1) requires a covered entity subject to a breach, or receiving notice of one from a vendor, to notify the consumer to whom the personal information pertains, and to notify the Attorney General in writing or electronically where the number of consumers it must notify exceeds 250. Subsection (2)(a) then places a hard ten-day clock on vendors: a vendor that discovers a breach or has reason to believe one has occurred must notify the covered entity with which it has a contract as soon as practicable and not later than ten days after that discovery or belief. Subsection (2)(b) extends the duty down a chain of subcontracted vendors, and subsection (2)(c) requires the vendor itself to notify the Attorney General where the breach involved the personal information of more than 250 consumers or a number of consumers the vendor could not determine, unless the covered entity has already done so. Subsection (3)(a) sets the outer limit for the covered entity’s consumer notice at forty-five days from discovering or receiving notification of the breach; subsection (3)(b) requires reasonable measures first to determine contact information, determine the scope of the breach and restore the reasonable integrity, security and confidentiality of the personal information; and subsection (3)(c) permits delay only on a written law enforcement request that notification would impede a criminal investigation. Elsewhere in the same series, ORS 646A.620 restricts printing, displaying or posting Social Security numbers and ORS 646A.622 requires the development of safeguards for personal information.

Residents must be notified in the most expeditious manner possible, without unreasonable delay, and not later than 45 days after discovering or receiving notification of the breach. Notify the Attorney General where the number of consumers to be notified exceeds 250. Complaints are taken by the Oregon Attorney General, which enforces the statute.

Recent Enforcement in Oregon

Oregon DOJ Privacy Unit — first-year enforcement report, August 2025. The Department of Justice published an enforcement report covering the OCPA’s first twelve months in August 2025, following a six-month report and a first-quarter 2025 report. It states that the Privacy Unit received 214 consumer privacy complaints through the Privacy Complaint Portal in that year, of which 130 passed the initial screening for OCPA relevance; of those 130 the department took no further action on 39 relating to entities or information the Act exempts, such as government entities or data covered by HIPAA. From the remaining 91 relevant complaints the Privacy Unit “initiated and closed 38 OCPA cure letter matters” as of July 1, with other matters remaining open and therefore confidential. The department describes the cure notice as a letter mandated by the Act until January 1, 2026 where the potential violations are curable, giving entities a chance to correct compliance issues before further enforcement steps.

Named-third-party right — a documented compliance failure. The department’s first-year report singles out the right that made Oregon distinctive. It states that the OCPA “was the first comprehensive privacy law to provide its citizens with access to a ‘list of specific third parties, other than natural persons, to which the controller has disclosed … [t]he consumer’s personal data’”, citing ORS 646A.574(1)(a)(B), and explains that the provision helps individuals track where their data has gone so they can follow up with deletion or other requests. It then reports that many of the companies about which the Privacy Unit received complaints fail to comply with the requirement in one way or another more than a year after the Act took effect, and that 19 of the complaints received describe companies which claim to provide the right but do not handle such requests correctly. The report identifies four other themes: problems with people search sites as a subset of data brokers; entities requiring consumers to perform significant effort to exercise rights, with incomplete options for copy or deletion; a reminder to audit the functionality of privacy request mechanisms; and clarifications about the role and extent of the provisions for authorized agents.

Pending Privacy Legislation

Chapter 417, Oregon Laws 2025, effective June 24, 2025, is the amendment that matters most and it worked by subtraction. Its section 5 was added to and made a part of ORS 646A.570 to 646A.589, restating the thirty-day notice-and-cure duty; subsection (2) then confined that duty from January 1, 2026 to noncommercial educational broadcast stations meeting the funding or emergency-alert criteria and distributing journalism content at no cost; and section 6 repealed section 5 outright on July 1, 2026. The Department of Justice separately states that from January 1, 2026 controllers are barred from selling precise geolocation data and from selling the personal data of children under 16 or using it for targeted advertising and certain profiling. The Act’s nonprofit coverage arrived on its own schedule, taking effect July 1, 2025, a year after the for-profit date. The enforcement section at ORS 646A.589 carries amendment notes for 2023 c.369 §§ 9 and 11 and 2024 c.64 §§ 1 and 2.

Federal Privacy Laws That Apply in Oregon

Federal privacy law applies in Oregon by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The OCPA sits alongside those rules rather than displacing them: the Oregon Attorney General, Department of Justice Privacy Unit enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.

Oregon Privacy Law FAQ

Are car manufacturers covered by Oregon’s privacy law regardless of size?
Yes. Section 646A.572(1)(b) provides that notwithstanding the threshold numbers in paragraph (a)(A) and (B), and subject to the exemptions in subsections (2) and (3), ORS 646A.570 to 646A.589 apply to a motor vehicle manufacturer and any affiliate of a motor vehicle manufacturer that controls or processes any personal data obtained from a consumer’s use of a motor vehicle or any component of a motor vehicle. No other applicability provision in the Act sets a threshold aside for a named industry.
Does Oregon still have a cure period under the OCPA?
No. Section 5 of chapter 417, Oregon Laws 2025 required the Attorney General to notify a controller of a curable violation and to allow thirty days before bringing an action, but subsection (2) narrowed that duty from January 1, 2026 to controllers that are noncommercial educational broadcast stations as defined in 47 U.S.C. 397 which receive Corporation for Public Broadcasting funding or are a primary entry point, national primary or state primary as defined in 47 C.F.R. 11.18, and which distribute their journalism content without cost to recipients. Section 6 of the same chapter repealed section 5 on July 1, 2026.
How quickly must an Oregon vendor report a breach to its customer?
Within ten days. Section 646A.604(2)(a) requires a vendor that discovers a breach of security, or has reason to believe one has occurred, to notify the covered entity with which it has a contract as soon as is practicable but not later than ten days after that discovery or belief. Paragraph (b) extends the duty along a chain of vendors, and paragraph (c) requires the vendor to notify the Attorney General itself where the breach involved the personal information of more than 250 consumers or a number of consumers the vendor could not determine, unless the covered entity has already given that notice.
Where does Oregon register its data brokers?
With the Department of Consumer and Business Services rather than the Attorney General. Section 646A.593 requires registration to operate as a data broker, supplies the method of registration and a penalty for failure, and grants rulemaking authority. Subsection (1)(a) defines the “brokered personal data” that brings a business within the section as computerized elements about a resident individual categorized or organized for sale or licensing, listing among them the maiden name of the individual’s mother, biometric information, and date or place of birth.
How long does an Oregon consumer have to revoke consent, and how fast must processing stop?
Section 646A.578(1)(d) requires a controller to provide an effective means by which a consumer may revoke consent given under ORS 646A.570 to 646A.589, and specifies that the means “must be at least as easy as the means by which the consumer provided consent”. Once the consumer revokes, the controller is to cease processing the personal data as soon as is practicable, but not later than fifteen days after receiving the revocation.
Where are OCPA enforcement actions brought, and how long does the state have?
Section 646A.589(4)(a) requires the Attorney General to bring an action in the circuit court for Multnomah County or the circuit court of a county where any part of the violation occurred. Subsection (5) requires the action to be brought within five years after the date of the last act constituting the violation for which relief is sought. Subsection (4)(c) directs the proceeds of any recovery into the Department of Justice Protection and Education Revolving Account as provided in ORS 180.095.
What did Oregon find when it looked at the named-third-party right?
The Department of Justice’s first-year report states that many companies about which the Privacy Unit received complaints fail to comply with the requirement in ORS 646A.574(1)(a)(B) in one way or another more than a year after the Act took effect. It records that consumers are concerned by companies that do not list the right as available at all, and that 19 of the complaints the unit received describe companies which claim to provide the right but do not handle such requests correctly.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.