Oregon Privacy Compliance in 2026: What Businesses Need to Know
Abstract
Oregon's privacy compliance regime has entered a new phase. With the Oregon Consumer Privacy Act (OCPA) now fully in effect, new consumer rights and opt-out requirements in place, and the Attorney General actively enforcing the law without a statutory cure period, businesses should take a fresh look at their privacy programs. This overview explores how Oregon's privacy, breach notification, and data broker laws fit together and highlights the practical compliance considerations organizations should evaluate as enforcement activity continues to mature.
Oregon has long been a familiar place for us, and its privacy developments are worth watching closely. We first visited Oregon in the early 2000s and 2010s. One of us was a law-school student in Portland, and the other had recently joined the in-house legal department of a technology company with operations outside of Portland. Back then, the focus was on breach notification and reasonable security. The GDPR in Europe—which just about everyone is familiar with today—was not yet law. Today, joining others, Oregon has one of the first general state consumer privacy laws—the Oregon Consumer Privacy Act, or OCPA—plus a separate data broker registration regime. For businesses that collect, use, sell, license, or disclose personal data about Oregon residents, the takeaway is simple: Oregon privacy compliance is now wide-ranging and comprehensive.
What Oregon Businesses Should Know About Privacy Compliance Now
The OCPA, codified at ORS 646A.570 to 646A.589, took effect for most covered businesses on July 1, 2024, and for qualifying nonprofits on July 1, 2025. Together with the Oregon Consumer Information Protection Act, which addresses breach notification and reasonable security, the OCPA pushes companies to manage privacy across the data lifecycle: collection, use, disclosure, retention, security, and vendor management.
Does the OCPA Apply?
The OCPA applies to entities that conduct business in Oregon or provide products or services to Oregon residents and, in a calendar year, control or process personal data of at least 100,000 consumers, or process personal data of at least 25,000 consumers while deriving at least 25 percent of annual gross revenue from selling personal data. Motor vehicle manufacturers and affiliates are covered regardless of consumer count. The law generally excludes employee and business-to-business data and includes exemptions for government bodies, financial institutions, certain insurers, and data regulated by HIPAA, GLBA, or FCRA. Covered controllers should ensure their privacy notices explain what data is processed, why, how it is shared, who receives it, and how Oregon consumers can exercise their rights.
Oregon Gives Consumers a Broad Set of Rights
Oregon consumers can confirm processing of and access, correct, delete, and obtain a portable copy of personal data, and opt out of the sale of personal data, targeted advertising, and certain profiling. One Oregon-specific feature is especially noteworthy: consumers may request a list of the specific third parties to whom a controller disclosed their data. Controllers must authenticate requests, respond within 45 days, and provide an appeal process. Sensitive-data processing requires consent, and Oregon defines sensitive data broadly, including race or ethnicity, religious beliefs, health condition, sexual orientation, transgender or nonbinary status, crime-victim status, citizenship or immigration status, genetic or biometric data, precise geolocation, and children’s data. As of January 1, 2026, controllers must honor universal opt-out mechanisms and may not sell precise geolocation data or under-16 personal data, or use under-16 data for targeted advertising or certain profiling.
Do Not Forget Vendors and Assessments
The OCPA also reaches behind the scenes. Processors have direct duties, and controller-processor contracts must address processing instructions, purpose, data types, duration, confidentiality, sub-processors, audit rights, deletion or return of data, and assistance with consumer requests and security obligations. Controllers also need data protection assessments for higher-risk processing, including targeted advertising, sale of personal data, certain profiling, and sensitive-data processing. These assessments should evaluate necessity, proportionality, benefits, risks, and safeguards, and may be requested by the Oregon Attorney General during an investigation.
Enforcement Is Happening
The Oregon Attorney General has exclusive enforcement authority under the OCPA, including authority to investigate, issue civil investigative demands, seek injunctive relief, and pursue civil penalties of up to $7,500 per violation. The OCPA does not create a private right of action, but the law still has teeth. The 30-day cure period ended on January 1, 2026, so the Attorney General may now proceed directly to enforcement without first offering an opportunity to cure. Relative to other general state privacy laws, the OCPA has been generally stable, and the Oregon Attorney General has now had more than two years to enforce it. General state privacy laws are becoming more stringent and do not be surprised if there are additional changes when the Oregon legislature reconvenes in January 2027.
To date, the Oregon DOJ’s Privacy Unit primarily has focused on practical gaps: incomplete notices, broken request forms, missing Oregon rights workflows, failure to offer the specific third-party-list right, and failure to apply access or deletion requests to back-end data such as marketing profiles and internally generated records. As one can imagine, many investigations are consumer-complaint driven. As such, appropriate training of personnel on OCPA requirements is a good way to mitigate risk. More recently, the Oregon DOJ also has taken up civil investigations on its own, whether as a result of independent research, sometimes using automated scanning tools, and mainstream news reports, or based on other widely available information regarding new data privacy trends or issues. Regardless of how the investigation comes about, investigators will want to see adequate and appropriate documentation. The Oregon Attorney General is also a member of the Consortium of Privacy Regulators, which includes the California Privacy Protection Agency and state Attorneys General from California, Colorado, Connecticut, Delaware, Indiana, New Hampshire, New Jersey, Maryland, Minnesota, and Vermont. Put otherwise, if there is a data privacy issue or trend in, e.g., California, it is quickly making its way up I-5 to Oregon.
Breach Notification and Data Brokers Are Part of the Story Too
Separate from the OCPA, the Oregon Consumer Information Protection Act requires entities that own, maintain, or possess personal information to notify affected Oregon consumers of a security breach without unreasonable delay and no later than 45 days after discovery. Read literally, the clock starts ticking once the breach is discovered, not when the business determines that a specific individual may have been impacted and will need to be notified. Notice to the Oregon DOJ is required if a breach affects more than 250 Oregon consumers. Investigations may follow notice. In practice, a breach may require notification to multiple regulators, depending on the status of the entity and the specific mix of data elements at issue. Vendors must notify covered entities promptly, and Oregon law also requires reasonable safeguards for personal information.
Oregon’s data broker law is another piece of the compliance puzzle. A data broker generally is a business entity that collects and sells or licenses brokered personal data about Oregon residents. Registration has been required since January 1, 2024, through the Oregon Division of Financial Regulation. Applicants must maintain an active Oregon Secretary of State business registration, apply through the state’s eGov system, pay a $600 fee, and submit a public-facing narrative describing how consumers may opt out. Registrations expire annually, and failure to register can result in civil penalties and may bar operation in Oregon.
So What Should Companies Do?
For organizations subject to Oregon privacy law, the best starting point is a practical compliance check. Confirm whether the OCPA applies. Refresh the data inventory. Identify sensitive data and opt-out triggers. Test rights-request intake, authentication, response, and appeal workflows. Update privacy notices for Oregon-specific rights and be sure to specifically call out rights available to Oregon consumers. A website with a last updated date of, e.g., January 1, 2020 is an easy giveaway. Implement universal opt-out controls. Review processor contracts. Update data protection assessment templates. Confirm breach-response procedures. And if the business collects and sells or licenses brokered personal data about Oregon residents, evaluate whether data broker registration is required.
Related Professionals
- Partner
- Partner