Oregon
OCPA Compliance Checklist for Oregon Businesses
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 8, 2026. · 3 primary sources cited on this page. How we verify our legal content

Businesses subject to the Oregon Consumer Privacy Act (OCPA), codified at ORS 646A.570 to 646A.589, must run an applicability test, publish a compliant privacy notice, obtain opt-in consent before processing sensitive data, recognize a universal opt-out signal as of January 1, 2026, complete data protection assessments for high-risk processing, sign processor contracts, and build a way to disclose the specific third parties that received a consumer's data. This checklist walks through each step as of 2026.
The enforcement stakes rose in 2026. The 30-day right to cure that controllers relied on through 2025 ended on January 1, 2026 for every controller except one narrow class of public broadcaster, so the Oregon Attorney General may now bring an action against an ordinary business without first offering a guaranteed window to fix the problem. Civil penalties run up to $7,500 per violation under ORS 646A.589.
Jurisdiction scope: This covers the Oregon Consumer Privacy Act (ORS 646A.570 to 646A.589). It is general legal information, not legal advice.
Step 1: Run the applicability test
The first task is to determine whether the OCPA applies at all. Under ORS 646A.572(1), the law covers a person that conducts business in Oregon, or that provides products or services to residents of Oregon, and that during a calendar year controls or processes the personal data of either 100,000 or more consumers, or 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data.
The defining feature of this test is that it uses no dollar-revenue floor. Unlike Utah and Virginia, Oregon does not require a business to cross a minimum revenue threshold before the law applies. A company that meets the 100,000-consumer count is covered regardless of how large or small its revenue is. One industry is covered without regard to those counts, but only on a specific trigger. Under ORS 646A.572(1)(b), added by HB 3875 (2025) and effective on the 91st day after the 2025 regular session adjourned sine die, the OCPA applies notwithstanding the threshold numbers to a motor vehicle manufacturer, and to any affiliate of a motor vehicle manufacturer, that controls or processes any personal data obtained from a consumer's use of a motor vehicle or any component of a motor vehicle. That coverage remains subject to the exemptions in ORS 646A.572(2) and (3), and it attaches to vehicle-derived data rather than to any Oregon data an automaker happens to hold. The Oregon OCPA overview explains why this broad net pulls in companies that escape coverage under several peer state laws.
When counting consumers toward the 100,000 threshold, exclude data controlled or processed "solely for the purpose of completing a payment transaction" under ORS 646A.572(1)(a). A business should also check the exemption list in ORS 646A.572(2), but should not assume a single regulatory status removes the whole organization. Oregon's exemptions are narrower than most states in some respects: HIPAA-covered protected health information is exempt only at the data level under ORS 646A.572(2)(b), with no blanket exemption for healthcare entities, and most nonprofits are covered rather than exempt, which is why nonprofits got a delayed July 1, 2025 effective date. GLBA is different. ORS 646A.572(2) exempts GLBA-compliant data at the data level and separately grants a full entity-level exemption to financial institutions and their financial-activity affiliates and subsidiaries.
Step 2: Publish a compliant privacy notice
Under ORS 646A.578, a covered controller must provide consumers with a reasonably accessible, clear, and meaningful privacy notice. The notice must describe the categories of personal data the controller processes, the purposes for processing, how a consumer may exercise their rights and appeal a decision, the categories of personal data the controller shares with third parties, and the categories of those third parties.
The notice must also identify whether the controller sells personal data or processes it for targeted advertising, and it must explain how a consumer may opt out of those activities. As of January 1, 2026, the notice should reflect that the controller recognizes a universal opt-out mechanism. Keep the notice current: when processing practices change materially, the notice must be updated to match.
Step 3: Obtain opt-in consent for sensitive data
Oregon requires affirmative, opt-in consent before a controller may process sensitive data. Under ORS 646A.578, a controller may not process sensitive data about a consumer without first obtaining the consumer's consent, and for the data of a known child, it must process that data consistent with the federal Children's Online Privacy Protection Act.
The reason this step demands attention is the breadth of Oregon's sensitive-data definition. Under ORS 646A.570(18), sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a victim of crime, and citizenship or immigration status. It also covers a child's personal data, genetic or biometric data, and precise geolocation within 1,750 feet. The express inclusion of transgender or nonbinary status, crime-victim status, and immigration status makes Oregon's gate wider than many states. Consent must be a clear affirmative act; pre-checked boxes and inferred agreement do not qualify.
Two categories carry a stricter rule than consent. Since January 1, 2026, ORS 646A.578(2)(d), added by HB 2008 (2025), bans the sale of personal data outright when the controller knows, or willfully disregards, that the consumer is under 16, prohibits processing an under-16 consumer's data for targeted advertising or profiling under ORS 646A.578(2)(c), and bans the sale of precise geolocation data (accurate within a 1,750-foot radius). Consent does not permit these sales; they are flat prohibitions, not consent gates like the rest of this step.

Step 4: Recognize the universal opt-out mechanism by January 1, 2026
A controller that processes personal data for targeted advertising or that sells personal data must let consumers opt out through a universal opt-out mechanism as of January 1, 2026, under ORS 646A.578. This is a browser-level or device-level signal that communicates the consumer's choice without the consumer visiting each controller individually.
The Global Privacy Control (GPC) is the leading example, and the Oregon DOJ has identified it as a qualifying signal. The mechanism must reflect the consumer's affirmative, voluntary choice rather than a default setting. To comply, a controller must build the technical capability to detect a qualifying signal and to treat it as a valid opt-out from targeted advertising and sale. The OCPA consumer rights guide covers how this signal interacts with individual opt-out requests.
Step 5: Complete data protection assessments
Under ORS 646A.586, a controller must conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm to a consumer. The statute names the high-risk categories: processing for targeted advertising, the sale of personal data, processing sensitive data, and certain profiling, specifically profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury; intrusion upon a consumer's solitude, seclusion, or private affairs that would be offensive to a reasonable person; or other substantial injury.
The assessment must weigh the benefits of the processing against the risks to the consumer, as mitigated by safeguards the controller can use. The controller must keep the assessment and make it available to the Oregon Attorney General upon request in connection with an investigation. Assessments apply to processing activities conducted on or after the law's effective date and are not retroactive. Because the Attorney General may demand them during an investigation, assessments function both as a compliance obligation and as potential enforcement evidence.
Step 6: Execute processor contracts
Under ORS 646A.581, a controller that engages a processor to handle personal data on its behalf must do so under a binding contract. The contract must set out the processing instructions, the nature and purpose of the processing, the type of data subject to processing, the duration of the processing, and the rights and obligations of both parties.
The contract must also require the processor to ensure that each person processing the data is subject to a duty of confidentiality, to delete or return personal data at the end of the engagement, to make available information necessary to demonstrate compliance, to allow and cooperate with reasonable assessments, and to engage subcontractors only under a written contract that imposes the same obligations. A controller that shares data with vendors without these contractual terms in place has a compliance gap that the Attorney General can act on.

Step 7: Build the specific third-party list mechanism
Oregon's signature obligation is the duty to disclose specific third parties. Under ORS 646A.574(1)(a)(B), a consumer may request a list of the specific third parties, other than natural persons, to which the controller disclosed the consumer's personal data, or at the controller's option any personal data. This is named-entity disclosure, not the category-level disclosure most state laws require.
To satisfy it, a controller must maintain records of disclosures at the level of identifiable recipients, not just broad groups such as "advertising partners." This is one of the harder OCPA capabilities to engineer, because it requires tracking which specific organizations received personal data. Building this capability early, including a data map of recipients and a workflow to generate the list on request, is the practical core of OCPA readiness on this point. The OCPA overview explains why Oregon led on this right and why it remains rare.
Enforcement now that the cure period has sunset
Enforcement of the OCPA belongs exclusively to the Oregon Attorney General, acting through the Oregon Department of Justice. Under ORS 646A.589(7), the Attorney General "has exclusive authority to enforce" the OCPA, and the statute does not create a private right of action. No consumer may sue a covered business directly under the OCPA, no matter how clear the violation.
The biggest 2026 change is the end of the guaranteed cure period. Through 2025, ORS 646A.589 required the Attorney General, before bringing an action, to notify the controller and allow 30 days to cure, but only when the Attorney General first determined the violation was curable at all. It was not an automatic grace period for every violation. That cure provision sunset on January 1, 2026. As of 2026, the Attorney General may still choose to allow a controller to fix a problem, but is no longer required to offer a 30-day window. A controller can no longer assume it will get a grace period before enforcement.
One narrow exception outlasts that date. Sections 4 to 6, chapter 417, Oregon Laws 2025, printed as a note to ORS 646A.589, keep a notice-and-30-day-cure requirement in force past January 1, 2026 for a controller that is a noncommercial educational broadcast station, as defined in 47 U.S.C. 397, that receives funding from the Corporation for Public Broadcasting or is a primary entry point, national primary or state primary under 47 C.F.R. 11.18, and that distributes its journalism content without cost to recipients. Section 6 repeals that carve-out on July 1, 2026, after which no controller has a guaranteed cure period.
Civil penalties run up to $7,500 for each violation under ORS 646A.589(4)(a). The per-violation structure means that a systemic failure affecting many consumers, such as ignoring deletion requests at scale or selling sensitive data without consent, can accumulate quickly. The Oregon DOJ also publishes enforcement reports describing the most common compliance gaps it sees, which businesses can use to prioritize their own programs.
OCPA compliance checklist at a glance
| Step | ORS cite | Key deadline or note |
|---|---|---|
| Applicability test | 646A.572(1) | No dollar floor; 100,000 or 25,000-plus consumers; 646A.572(1)(b) covers motor vehicle manufacturers and their affiliates that process vehicle-derived data regardless of thresholds |
| Privacy notice | 646A.578 | Disclose data, purposes, rights, appeals |
| Sensitive-data opt-in | 646A.578, 646A.570(18) | Affirmative consent before processing |
| Geolocation and under-16 sale ban | 646A.578(2)(d) | Sale banned outright since January 1, 2026 (HB 2008) |
| Universal opt-out | 646A.578 | Recognize signal by January 1, 2026 |
| Data protection assessments | 646A.586 | High-risk processing; available to AG |
| Processor contracts | 646A.581 | Required terms with every vendor |
| Specific third-party list | 646A.574(1)(a)(B) | Track named recipients |
| Enforcement | 646A.589 | General cure requirement ended January 1, 2026, with a narrow broadcast-station carve-out until July 1, 2026; up to $7,500 per violation |
Related guides
- Oregon data privacy laws parent hub
- What is the OCPA?
- OCPA consumer rights
- State data privacy law comparison
- What is the CCPA?
More Oregon Laws
Frequently Asked Questions
How do I know if my business is subject to the OCPA?
Apply the test in ORS 646A.572(1). The OCPA covers any person doing business in Oregon or serving Oregon residents that, in a calendar year, controls or processes the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data. Oregon uses no dollar-revenue floor, so a business can be covered on data volume alone. Exclude data used solely to complete a payment transaction when counting toward the 100,000 threshold. One rule applies regardless of these thresholds. Under ORS 646A.572(1)(b), added by HB 3875 (2025), the OCPA applies to a motor vehicle manufacturer, and to any affiliate of a motor vehicle manufacturer, that controls or processes any personal data obtained from a consumer's use of a motor vehicle or any component of a motor vehicle, subject to the exemptions in ORS 646A.572(2) and (3). The trigger is vehicle-derived data, not simply being an automaker.
Does the OCPA exempt financial institutions and nonprofits?
Not as broadly as most states for HIPAA. Under ORS 646A.572(2), Oregon exempts HIPAA-covered protected health information only at the data level, with no blanket exemption for healthcare entities, and it covers most nonprofit organizations rather than exempting them. GLBA is treated more broadly: Oregon exempts GLBA-compliant data at the data level and also grants a full entity-level exemption to financial institutions and their financial-activity affiliates and subsidiaries. Only narrow nonprofit categories, such as a nonprofit that detects insurance fraud, are carved out. Because most nonprofits are covered, the legislature gave them a delayed effective date of July 1, 2025. Map each data set and entity against the exemption list rather than assuming one status removes the whole organization.
When must my business honor a universal opt-out signal?
As of January 1, 2026. Under ORS 646A.578, a controller that processes personal data for targeted advertising or that sells personal data must let consumers opt out through a universal opt-out mechanism. The Oregon DOJ has identified Global Privacy Control as a qualifying signal. To comply, build the technical capability to detect the signal and treat it as a valid opt-out from targeted advertising and sale. The signal must reflect the consumer's affirmative choice, not a browser default.
What does the specific third-party list right require me to build?
Under ORS 646A.574(1)(a)(B), a consumer can request a list of the specific named third parties, other than natural persons, to which you disclosed their personal data, or at your option any personal data. Unlike the category-level disclosure most states require, this demands tracking disclosures at the level of identifiable recipients. To satisfy it, maintain a data map of which specific organizations received personal data and build a workflow that can generate the list when a consumer asks. This is one of the harder OCPA capabilities to engineer.
When are data protection assessments required under the OCPA?
Under ORS 646A.586, a controller must conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm. The named high-risk categories are processing for targeted advertising, the sale of personal data, processing sensitive data, and certain profiling that risks unfair or deceptive treatment or unlawful disparate impact, financial, physical, or reputational injury, or intrusion on a consumer's solitude, seclusion, or private affairs. The assessment must weigh benefits against risks, and the Attorney General may request it during an investigation. Assessments are not retroactive.
What changed about OCPA enforcement in 2026?
The 30-day right to cure sunset on January 1, 2026. Through 2025, the Oregon Attorney General had to notify a controller and allow 30 days to fix a violation before bringing an action, but only when the Attorney General first determined the violation was curable. It was not an automatic grace period for every violation. As of 2026, that guaranteed window is gone for ordinary businesses. The Attorney General may still choose to allow a cure but is no longer required to offer one, so a business can no longer count on a grace period before enforcement. One narrow exception survives: under sections 4 to 6, chapter 417, Oregon Laws 2025, a notice-and-30-day-cure requirement still applies to a controller that is a qualifying noncommercial educational broadcast station under 47 U.S.C. 397, and that carve-out is itself repealed on July 1, 2026. Civil penalties run up to $7,500 per violation under ORS 646A.589(4)(a).
What are the penalties for violating the OCPA?
Under ORS 646A.589(4)(a), the Oregon Attorney General may seek a civil penalty of up to $7,500 for each violation. The per-violation structure means a systemic failure affecting many consumers can accumulate quickly. Enforcement is exclusive to the Attorney General under ORS 646A.589(7); there is no private right of action, so consumers cannot sue businesses directly but may submit complaints to the Oregon Department of Justice, which can investigate and seek penalties.
Do I need a contract with my data processors?
Yes. Under ORS 646A.581, a controller that uses a processor must have a binding contract that sets out the processing instructions, nature, purpose, data types, and duration, and that imposes duties such as confidentiality, deletion or return of data at the end of the engagement, cooperation with assessments, and flow-down terms to any subcontractor. Sharing personal data with a vendor without these contractual terms in place is a compliance gap the Attorney General can act on.
Updates
Corrected the OCPA motor vehicle manufacturer rule to state its codified cite, its vehicle-data trigger, its extension to affiliates and its exemptions, and noted the narrow noncommercial educational broadcast station cure period that runs until July 1, 2026.
Added coverage of two enacted 2025 amendments to the OCPA that are now current law: HB 2008's outright ban on selling precise geolocation data and the personal data of consumers known to be under 16 (effective January 1, 2026), and HB 3875's extension of OCPA coverage to all automobile manufacturers regardless of the consumer-count thresholds (effective September 26, 2025). Corrected the description of Oregon's GLBA exemption, which includes a genuine entity-level exemption for financial institutions, not just a data-level carve-out. Completed the statutory list of risk factors for data protection assessments, and clarified that the pre-2026 30-day cure right applied only when the Attorney General determined a violation was curable.
Independently fact-checked against the cited primary sources
Fixed the Attorney General exclusive-enforcement citation from ORS 646A.589(8) to the correct subsection (7).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Oregon Revised Statutes, Chapter 646A: Trade Regulation
§ 646A.578Duties of controller; prohibitions; privacy notice to consumerIn forcecited in 7 of our articles
(1) A controller shall: (a) Specify in the privacy notice described in subsection (4) of this section the express purposes for which the controller is collecting and processing personal data; (b) Limit the controller’s collection of personal data to only the personal data that is adequate, relevant and reasonably necessary to serve the purposes the controller specified in paragraph (a) of this subsection; (c) Establish, implement and maintain for personal data the same safeguards described in ORS 646A.622 that are required for protecting personal information, as defined in ORS 646A.602, such that the controller’s safeguards protect the confidentiality, integrity and accessibility of the personal data to the extent appropriate for the volume and nature of the personal data; and (d) Provide an effective means by which a consumer may revoke consent a consumer gave under ORS 646A.570 to 646A.589 to the controller’s processing of the consumer’s personal data. The means must be at least as easy as the means by which the consumer provided consent.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
Also relied on in: OCPA Consumer Rights: Oregon Data Privacy Act, What Is the OCPA? Oregon Consumer Privacy Act, How to Request Your Personal Data: US Privacy Rights by State
§ 646A.574Consumer requests for personal data; requirement to correct inaccuracies; requirement to delete personal data; conditions under which consumer may opt out of personal data processing; format for providing copy of personal data to consumerIn forcecited in 5 of our articles
(1) Subject to ORS 646A.576, a consumer may: (a) Obtain from a controller: (A) Confirmation as to whether the controller is processing or has processed the consumer’s personal data and the categories of personal data the controller is processing or has processed; (B) At the controller’s option, a list of specific third parties, other than natural persons, to which the controller has disclosed: (i) The consumer’s personal data; or (ii) Any personal data; and (C) A copy of all of the consumer’s personal data that the controller has processed or is processing; (b) Require a controller to correct inaccuracies in personal data about the consumer, taking into account the nature of the personal data and the controller’s purpose for processing the personal data; (c) Require a controller to delete personal data about the consumer, including personal data the consumer provided to the controller, personal data the controller obtained from another source and derived data; or (d) Opt out from a controller’s processing of personal data of the consumer that the controller processes for any of the following purposes: (A) Targeted advertising; (B) Selling…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
§ 646A.581Duties of processor of personal data; contract between controller and processor; liabilities of controller and processorIn force
(1) A processor shall adhere to a controller’s instructions and shall assist the controller in meeting the controller’s obligations under ORS 646A.570 to 646A.589. In assisting the controller, the processor must: (a) Enable the controller to respond to requests from consumers under ORS 646A.576 by means that take into account how the processor processes personal data and the information available to the processor and that use appropriate technical and organizational measures to the extent reasonably practicable; (b) Adopt administrative, technical and physical safeguards that are reasonably designed to protect the security and confidentiality of the personal data the processor processes, taking into account how the processor processes the personal data and the information available to the processor; and (c) Provide information reasonably necessary for the controller to conduct and document data protection assessments. (2) The processor shall enter into a contract with the controller that governs how the processor processes personal data on the controller’s behalf.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at oregonlegislature.gov
§ 646A.589Investigative demand by Attorney General; representation by counsel; confidentiality of proceedings and materials; action to impose civil penalty or obtain injunction; amount of civil penalty; notice of violation; time limit on action; Attorney General’s exclusive authorityIn forcecited in 3 of our articles
(1)(a) The Attorney General may serve an investigative demand upon any person that possesses, controls or has custody of any information, document or other material that the Attorney General determines is relevant to an investigation of a violation of ORS 646A.570 to 646A.589 or that could lead to a discovery of relevant information. An investigative demand may require the person to: (A) Appear and testify under oath at the time and place specified in the investigative demand; (B) Answer written interrogatories; or (C) Produce relevant documents or physical evidence for examination at the time and place specified in the investigative demand. (b) The Attorney General shall serve an investigative demand under this section in the manner provided in ORS 646.622. The Attorney General may enforce the investigative demand as provided in ORS 646.626. (2)(a) An attorney may accompany, represent and advise in confidence a person that appears in response to a demand under subsection (1)(a)(A) of this section.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at oregonlegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- ORS 646A.572: Applicability and Exemptions(oregon.public.law)
- ORS 646A.578: Controller Duties, Privacy Notice, Sensitive-Data Consent, and Universal Opt-Out(oregon.public.law)
- ORS 646A.581: Processor Duties and Controller-Processor Contracts(oregon.public.law)
- ORS 646A.586: Data Protection Assessments(oregon.public.law)
- ORS 646A.589: Attorney General Enforcement and Civil Penalties(oregon.public.law)
- ORS 646A.574: Consumer Rights, Including Specific Third-Party List(oregon.public.law)
- ORS 646A.570 to 646A.589: Oregon Consumer Privacy Act (Full Chapter)(oregonlegislature.gov).gov
- Oregon DOJ: Consumer Privacy (Oregon Consumer Privacy Act)(doj.state.or.us).gov
- Oregon DOJ: OCPA One-Year Enforcement Report (2025)(doj.state.or.us).gov
- Enrolled HB 3875 (2025), amending ORS 646A.572: motor vehicle manufacturers and affiliates(olis.oregonlegislature.gov)