{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/oregon",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/oregon.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/oregon",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/oregon/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/oregon/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "oregon",
    "frontmatter": {
      "title": "Oregon Consumer Privacy Law (OCPA)",
      "description": "The Oregon Consumer Privacy Act gives Oregon consumers rights over their personal data and imposes notice, contracting, and consent duties on controllers above defined thresholds — it is enforced exclusively by the Attorney General, carries civil penalties of up to $7,500 per violation, provides no private right of action, and as of January 1, 2026 no longer offers most businesses a mandatory right to cure.",
      "state": "Oregon",
      "lastReviewed": "2026-06-05",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Or. Rev. Stat. §§ 646A.570–646A.589 (Oregon Consumer Privacy Act)",
        "appliesTo": "Persons doing business in Oregon (or targeting residents) that, in a calendar year, control or process the personal data of 100,000+ consumers, or 25,000+ while deriving 25% or more of annual gross revenue from selling personal data — no dollar revenue floor; nonprofits covered; GLBA financial institutions, insurers, and public bodies are exempt at the entity level, while HIPAA-regulated health data is exempt only at the data level (so HIPAA-covered businesses still comply for non-exempt data)",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's",
        "regulator": "Oregon Attorney General (exclusive)",
        "bottomLine": "If you meet the 100,000-consumer (or 25,000 plus 25%-data-sale-revenue) threshold in Oregon, the OCPA requires a privacy notice with prescribed contents, opt-in consent to process sensitive data, recognition of a universal opt-out signal, and processor contracts — enforced by the Attorney General with civil penalties up to $7,500 per violation, no consumer lawsuits, and no general right to cure after January 1, 2026.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "required"
      },
      "about": [
        "Oregon Consumer Privacy Act OCPA",
        "Oregon privacy policy requirements",
        "Oregon privacy notice contents",
        "OCPA applicability thresholds",
        "OCPA sensitive data consent",
        "OCPA processor contract requirements",
        "Oregon Attorney General privacy enforcement",
        "OCPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-ocpa-apply",
        "label": "Does the OCPA apply to your business?",
        "heading": "Does the OCPA apply to your business?",
        "answerText": "It turns on consumer volume, not dollar revenue. The OCPA applies to a person that conducts business in Oregon or provides products or services to its residents and that, during a calendar year, controls or processes the personal data of 100,000 or more consumers, or 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data.",
        "sources": [
          {
            "id": "stat-572-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.572",
            "citation": "Or. Rev. Stat. § 646A.572(1)(a).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The OCPA applies to persons doing business in Oregon or targeting residents that control or process the data of 100,000 or more consumers, or 25,000 or more while deriving 25 percent or more of gross revenue from selling personal data.",
            "verbatimQuote": "ORS 646A.570 to 646A.589 apply to any person that conducts business in this state, or that provides products or services to residents of this state, and that during a calendar year, controls or processes: (A) The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transaction; or (B) The personal data of 25,000 or more consumers, while deriving 25 percent or more of the person’s annual gross revenue from selling personal data.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-572-apply"
          },
          {
            "id": "stat-570-consumer",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.570",
            "citation": "Or. Rev. Stat. § 646A.570(7).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "A consumer is an Oregon resident acting in a capacity other than a commercial or employment context, which excludes workforce and business-to-business data.",
            "verbatimQuote": "“Consumer” means a natural person who resides in this state and acts in any capacity other than in a commercial or employment context.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-570-consumer"
          },
          {
            "id": "stat-572-exempt",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.572",
            "citation": "Or. Rev. Stat. § 646A.572(2)(a), (L), (n), (o).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The OCPA grants entity-level exemptions to a financial institution as defined in Oregon banking law, to insurers, and to insurance producers, in addition to public bodies.",
            "verbatimQuote": "(L) A financial institution, as defined in ORS 706.008, or a financial institution’s affiliate or subsidiary that is only and directly engaged in financial activities, as described in 12 U.S.C. 1843(k), as in effect on January 1, 2024;",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-572-exempt"
          },
          {
            "id": "stat-572-exempt-data",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.572",
            "citation": "Or. Rev. Stat. § 646A.572(2)(b), (j), (k).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The OCPA also grants data-level and activity-level exemptions, including HIPAA protected health information, information processed under the Gramm-Leach-Bliley Act and FERPA, and activity carried out strictly under the Fair Credit Reporting Act.",
            "verbatimQuote": "(b) Protected health information that a covered entity or business associate processes in accordance with, or documents that a covered entity or business associate creates for the purpose of complying with, the Health Insurance Portability and Accountability Act of 1996, P.L. 104-191, and regulations promulgated under the Act, as in effect on January 1, 2024;",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-572-exempt-data"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Oregon privacy policy contain?",
        "heading": "What must your Oregon privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear and meaningful privacy notice that lists the categories of personal data it processes, describes the purposes for processing, explains how a consumer may exercise and appeal rights, lists the categories of personal data shared with third parties, and describes the categories of those third parties.",
        "sources": [
          {
            "id": "stat-578-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.578",
            "citation": "Or. Rev. Stat. § 646A.578(4).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "A controller must provide a reasonably accessible, clear and meaningful privacy notice that lists the categories of personal data processed and describes the purposes for processing, among other required disclosures.",
            "verbatimQuote": "A controller shall provide to consumers a reasonably accessible, clear and meaningful privacy notice that: (a) Lists the categories of personal data, including the categories of sensitive data, that the controller processes; (b) Describes the controller’s purposes for processing the personal data;",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-578-notice"
          },
          {
            "id": "stat-578-notice-detail",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.578",
            "citation": "Or. Rev. Stat. § 646A.578(4).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The privacy notice must also explain how consumers exercise and appeal their rights, disclose third-party sharing, identify the controller, and describe targeted-advertising and profiling opt-out procedures.",
            "verbatimQuote": "(c) Describes how a consumer may exercise the consumer’s rights under ORS 646A.570 to 646A.589, including how a consumer may appeal a controller’s denial of a consumer’s request under ORS 646A.576; (d) Lists all categories of personal data, including the categories of sensitive data, that the controller shares with third parties; (e) Describes all categories of third parties with which the controller shares personal data at a level of detail that enables the consumer to understand what type of entity each third party is and, to the extent possible, how each third party may process personal data;",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-578-notice-detail"
          },
          {
            "id": "stat-578-minimize",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.578",
            "citation": "Or. Rev. Stat. § 646A.578(1)(b).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "A controller must limit its collection of personal data to what is adequate, relevant and reasonably necessary for the purposes specified in the privacy notice.",
            "verbatimQuote": "Limit the controller’s collection of personal data to only the personal data that is adequate, relevant and reasonably necessary to serve the purposes the controller specified in paragraph (a) of this subsection;",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-578-minimize"
          }
        ]
      },
      {
        "slug": "vendor-processor-contracts",
        "label": "What must your contracts with vendors and processors include?",
        "heading": "What must your contracts with vendors and processors include?",
        "answerText": "A processor must enter into a contract with the controller that governs how the processor processes personal data on the controller's behalf — so a data processing agreement is a statutory requirement, not a best practice.",
        "sources": [
          {
            "id": "stat-581-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.581",
            "citation": "Or. Rev. Stat. § 646A.581(2).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "A processor must enter into a contract with the controller that governs how the processor processes personal data on the controller's behalf.",
            "verbatimQuote": "The processor shall enter into a contract with the controller that governs how the processor processes personal data on the controller’s behalf.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-581-contract"
          },
          {
            "id": "stat-581-terms",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.581",
            "citation": "Or. Rev. Stat. § 646A.581(2)(b)-(h).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The controller-processor contract must set forth clear processing instructions and the nature, purpose, type, and duration of processing; specify each party's rights and obligations; impose a duty of confidentiality; require deletion or return of data; require information to verify compliance; require subcontractor flow-down; and allow assessment of the processor's safeguards.",
            "verbatimQuote": "(b) Set forth clear instructions for processing data, the nature and purpose of the processing, the type of data that is subject to processing and the duration of the processing; (c) Specify the rights and obligations of both parties with respect to the subject matter of the contract; (d) Ensure that each person that processes personal data is subject to a duty of confidentiality with respect to the personal data; (e) Require the processor to delete the personal data or return the personal data to the controller at the controller’s direction or at the end of the provision of services, unless a law requires the processor to retain the personal data; (f) Require the processor to make available to the controller, at the controller’s request, all information the controller needs to verify that the processor has complied with all obligations the processor has under ORS 646A.570 to 646A.589; (g) Require the processor to enter into a subcontract with a person the processor engages to assist with processing personal data on the controller’s behalf and in the subcontract require the subcontractor to meet the processor’s obligations under the processor’s contract with the controller; and (h) Allow the controller, the controller’s designee or a qualified and independent person the processor engages, in accordance with an appropriate and accepted control standard, framework or procedure, to assess the processor’s policies and technical and organizational measures for complying with the processor’s obligations under ORS 646A.570 to 646A.589, and require the processor to cooperate with the assessment and, at the controller’s request, report the results of the assessment to the controller.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-581-terms"
          }
        ]
      },
      {
        "slug": "sensitive-data-and-opt-out",
        "label": "When do you need consent, and must you honor a universal opt-out signal?",
        "heading": "When do you need consent, and must you honor a universal opt-out signal?",
        "answerText": "You need consent for sensitive data, and you must honor a universal opt-out signal. A controller may not process a consumer's sensitive data without first obtaining consent, and if it knows the consumer is a child it must instead follow the federal Children's Online Privacy Protection Act. Sensitive data includes data revealing race or ethnicity, religious beliefs, a mental or physical condition or diagnosis, sexual orientation, transgender or nonbinary status, crime-victim status, or citizenship or immigration status; a child's personal data; precise geolocation; and genetic or biometric data.",
        "sources": [
          {
            "id": "stat-578-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.578",
            "citation": "Or. Rev. Stat. § 646A.578(2)(b).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "A controller may not process sensitive data without first obtaining consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "Process sensitive data about a consumer without first obtaining the consumer’s consent or, if the controller knows the consumer is a child, without processing the sensitive data in accordance with the Children’s Online Privacy Protection Act of 1998, 15 U.S.C. 6501 et seq.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-578-consent"
          },
          {
            "id": "stat-570-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.570",
            "citation": "Or. Rev. Stat. § 646A.570(18)(a).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "Sensitive data includes data revealing protected characteristics, a child's personal data, precise geolocation within 1,750 feet, and genetic or biometric data.",
            "verbatimQuote": "“Sensitive data” means personal data that: (A) Reveals a consumer’s racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a victim of crime or citizenship or immigration status; (B) Is a child’s personal data;",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-570-sensitive"
          },
          {
            "id": "stat-578-signal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.578",
            "citation": "Or. Rev. Stat. § 646A.578(5)(c).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "A controller's request methods must let a consumer or authorized agent send an opt-out preference signal that requires an affirmative choice rather than a default setting.",
            "verbatimQuote": "Allow a consumer or authorized agent to send a signal to the controller that indicates the consumer’s preference to opt out of the sale of personal data or targeted advertising under ORS 646A.574 (1)(d) by means of a platform, technology or mechanism that: (A) Does not unfairly disadvantage another controller; (B) Does not use a default setting but instead requires the consumer or authorized agent to make an affirmative, voluntary and unambiguous choice to opt out;",
            "date": "2025-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-578-signal"
          }
        ]
      },
      {
        "slug": "enforcement-and-lawsuits",
        "label": "Who enforces the OCPA, and can consumers sue?",
        "heading": "Who enforces the OCPA, and can consumers sue?",
        "answerText": "The Attorney General enforces it, and consumers cannot sue. The Attorney General has exclusive authority to enforce the OCPA, and the statute provides no private right of action. The Attorney General may bring an action for a civil penalty of up to $7,500 for each violation, plus injunctive or other equitable relief.",
        "sources": [
          {
            "id": "stat-589-exclusive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.589",
            "citation": "Or. Rev. Stat. § 646A.589(7).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The Attorney General has exclusive authority to enforce the OCPA, and the statute creates no private right of action.",
            "verbatimQuote": "The Attorney General has exclusive authority to enforce the provisions of ORS 646A.570 to 646A.589. ORS 646A.570 to 646A.589, or any other laws of this state, do not create a private right of action to enforce a violation of ORS 646A.570 to 646A.589.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-589-exclusive"
          },
          {
            "id": "stat-589-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.589",
            "citation": "Or. Rev. Stat. § 646A.589(4)(a).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The Attorney General may bring an action for a civil penalty of up to $7,500 for each violation, or to enjoin a violation or obtain other equitable relief.",
            "verbatimQuote": "The Attorney General may bring an action to seek a civil penalty of not more than $7,500 for each violation of ORS 646A.570 to 646A.589 or to enjoin a violation or obtain other equitable relief.",
            "date": "2023-07-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-589-penalty"
          },
          {
            "id": "stat-589-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Rev. Stat. § 646A.589",
            "citation": "Or. Laws 2025, ch. 417, § 5(2).",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "Beginning January 1, 2026, the pre-suit 30-day cure requirement applies only to a controller that is a noncommercial educational broadcast station that receives CPB funding or is a designated emergency-alert primary entry point and distributes its journalism content without cost, so other businesses no longer have a mandatory cure period.",
            "verbatimQuote": "(a) Receives funding from the Corporation for Public Broadcasting or is a primary entry point, national primary or state primary, as defined in 47 C.F.R. 11.18, as in effect on the effective date of this 2025 Act; and (b) Distributes the noncommercial educational broadcast station’s journalism content without cost to recipients.",
            "date": "2025-06-24",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-589-cure"
          },
          {
            "id": "stat-589-cure-repeal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Or. Laws 2025, ch. 417, § 6",
            "citation": "Or. Laws 2025, ch. 417, § 6.",
            "url": "https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html",
            "proposition": "The legislature repealed the cure-period section in full effective July 1, 2026, after which no controller has a statutory right to cure.",
            "verbatimQuote": "Section 5 of this 2025 Act is repealed on July 1, 2026.",
            "date": "2025-06-24",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/oregon#src-stat-589-cure-repeal"
          }
        ]
      }
    ]
  }
}
