Oregon Consumer Privacy Act (ORS 646A.570 et seq.)
Below is what the official text of Oregon Consumer Privacy Act (ORS 646A.570 et seq.) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Oregon and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Oregon: Not triggered by these answers.
- A US business with no users in Oregon: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | A comprehensive consumer privacy law giving Oregon consumers rights over the collection, retention, use and sale of their personal and sensitive information, binding controllers and processors that meet its thresholds.Official wordingThe Oregon Consumer Privacy Act (OCPA) is a comprehensive consumer privacy law. The law gives Oregon consumers specific privacy rights which allows them to manage the collection, retention, and use or sale of their personal and sensitive information. | www.doj.state.or.us read 2026-10-06 |
| When it applies to a business | Generally applies to any individual or entity that conducts business in Oregon or provides products or services to Oregon residents and, during a calendar year, controls or processes personal data of at least 100,000 consumers, or of 25,000 or more consumers while deriving over 25% of annual gross revenue from the sale of personal data. Conditions to check: Source is the Oregon DOJ's business FAQ, not the statute text (the legislature's site could not be reached); the FAQ says the statute controls. Per the FAQ the OCPA applies to nonprofits too since July 1, 2025 (same thresholds), so we do not test the organisation type. Excluded entities per the FAQ: state, local and tribal governments; financial institutions as defined in ORS 706.008; certain insurers, insurance producers and consultants. Data maintained for employment records and data covered by HIPAA, GLBA or FCRA is not covered (list at ORS 646A.572(2)). The threshold has a stated exception: motor vehicle manufacturers and affiliates that process data from consumers' use of a motor vehicle are covered regardless of the number of Oregonians. 'Consumer' means an Oregon resident acting in an individual or household context. Related entities' consumer counts may be added together, per the FAQ. Official wordingGenerally, the law applies to any individual or entity that conducts business in Oregon or that provides products or services to Oregon residents if, during a calendar year, that individual or entity controls or processes the personal data of: at least 100,000 consumers; or 25,000 or more consumers and derives over 25% of annual gross revenue from the sale of personal data. | www.doj.state.or.us read 2026-10-06 |
| In force from | 2024-07-01 Oregon DOJ: signed into law and takes effect on July 1, 2024 (nonprofits July 1, 2025, per the nonprofit FAQ); the FAQ also dates later changes (Sept 2025 motor vehicle manufacturers; Jan 1, 2026 universal opt-out mechanism, ban on selling precise geolocation and under-16 data, no cure period). Official wordingwas signed into law by Governor Kotek and takes effect on July 1, 2024. | www.doj.state.or.us read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text read does not say whether a data protection officer or privacy officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Not stated on the official pages we read. the statute text (ORS 646A.578(4)) was not read; the DOJ FAQ only summarises the notice contents | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here