Oregon
What Is the OCPA? Oregon Consumer Privacy Act
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

The Oregon Consumer Privacy Act (OCPA), codified at ORS 646A.570 to 646A.589, took effect July 1, 2024 for most businesses and July 1, 2025 for covered nonprofit organizations. Enacted as Senate Bill 619 and signed by Governor Tina Kotek on July 18, 2023, it gives Oregon residents a full slate of data rights, including one feature few other states match: the right to obtain a list of the specific third parties that received personal data, with the controller electing whether that list covers the consumer's own data or any personal data.
As of 2026, the Oregon Attorney General's Department of Justice holds exclusive enforcement authority and may seek civil penalties of up to $7,500 per violation. The 30-day right to cure that businesses relied on through 2025 sunset on January 1, 2026, so a business can no longer count on a guaranteed grace period before the state acts.
Jurisdiction scope: This covers the Oregon Consumer Privacy Act (ORS 646A.570 to 646A.589). It is general legal information, not legal advice.
What the OCPA is: statute, enactment, and dual effective dates
The Oregon Consumer Privacy Act is Oregon's first comprehensive consumer data privacy law. It is codified at Oregon Revised Statutes Sections 646A.570 through 646A.589 and was enacted during the 2023 regular session as Senate Bill 619, a measure requested by then-Attorney General Ellen Rosenblum. Governor Tina Kotek signed SB 619 into law on July 18, 2023.
The OCPA has two effective dates, a structure that sets Oregon apart from most state privacy laws. For most controllers, the law took effect July 1, 2024. For covered nonprofit organizations, it took effect one year later, on July 1, 2025. That staggered timeline reflects another Oregon distinction: the OCPA reaches many nonprofit organizations at all. Several other state privacy laws exempt nonprofits entirely, so the nonprofit community in those states never has a compliance date.
The delayed nonprofit date gave charities, advocacy groups, and similar organizations extra time to build privacy programs before their obligations began. As of 2026, both effective dates have passed, so every category of covered organization, for-profit and nonprofit alike, is now fully subject to the OCPA.
For the controller and processor obligations, privacy notice content rules, and data protection assessment requirements in full, see the Oregon data privacy laws parent page.
Who the OCPA covers: applicability with no dollar threshold
The OCPA's applicability test lives in ORS 646A.572(1). The law applies to a person that conducts business in Oregon, or that provides products or services to residents of Oregon, and that during a calendar year controls or processes the personal data of either of two groups.
The first trigger, ORS 646A.572(1)(a)(A), is 100,000 or more consumers, counting all consumers except those whose data is controlled or processed "solely for the purpose of completing a payment transaction." The payment-transaction carve-out means a retailer does not count every card swipe toward the threshold if the only data involved is what is needed to process that single purchase.
The second trigger, ORS 646A.572(1)(a)(B), is 25,000 or more consumers, but only "while deriving 25 percent or more of the person's annual gross revenue from selling personal data." This lower headcount applies to data-driven businesses whose model depends on selling personal information.
What is notably absent is any dollar-revenue floor. Many state privacy laws, including Utah's and Virginia's, pair a consumer-count threshold with a revenue threshold, so that a company below a set annual revenue level escapes coverage regardless of how much data it handles. Oregon set no such floor. A company that meets the 100,000-consumer count is covered even if its annual revenue is modest. This makes the OCPA's net broader at the low-revenue end than several of its peer statutes.
The practical consequence is that mid-size and even smaller companies that process large volumes of Oregon resident data can be covered, where the same company might escape coverage under a law that requires both a data count and a revenue minimum.
One industry has no threshold at all. Since September 26, 2025, ORS 646A.572(1)(b), added by HB 3875, applies the OCPA to any motor vehicle manufacturer and its affiliates that control or process personal data obtained from a consumer's use of a vehicle or a vehicle component, regardless of how many Oregon consumers' data the company holds.

Oregon's exemptions: narrower than most states
Many state privacy laws grant sweeping entity-level exemptions: if an organization is a financial institution subject to the Gramm-Leach-Bliley Act, or is a nonprofit, the entire organization falls outside the law. Oregon took a narrower path for nonprofits and for HIPAA-covered entities, and that is one of the OCPA's defining features.
At the data level, ORS 646A.572(2) excludes "protected health information" processed by entities complying with HIPAA, and it excludes various categories of data governed by other federal frameworks. These are data-level carve-outs: the specific regulated data is exempt, not necessarily the whole organization.
On financial institutions, Oregon actually grants the same kind of blanket exemption most states use. ORS 646A.572(2)(L) exempts a financial institution, as defined under ORS 706.008, and any affiliate or subsidiary that is only and directly engaged in financial activities, from the OCPA entirely, regardless of what data it holds. That entity-level exemption sits alongside a separate data-level carve-out in ORS 646A.572(2)(k)(A) for information handled specifically under GLBA. So it is Oregon's treatment of nonprofits and healthcare entities, not financial institutions, that departs from the typical state approach.
On nonprofits, the contrast is sharpest. Most state privacy laws exempt all nonprofit organizations. Oregon does not. It carves out only narrow categories, such as a nonprofit organization that detects and prevents insurance fraud, and noncommercial activity by publishers and broadcasters. The general body of Oregon nonprofit organizations is covered, which is why the legislature gave them a delayed July 1, 2025 effective date. A consumer advocacy group, a museum, or a membership association that meets the applicability thresholds is generally subject to the OCPA.
Public corporations and public bodies, including bodies such as Oregon Health and Science University and the Oregon State Bar, are addressed within the ORS 646A.572(2) exemption list. Businesses should map each data set and entity against the exemption list rather than assuming a single regulatory status removes the whole organization from the law.
The broad sensitive-data definition
Sensitive data sits at the center of the OCPA because processing it requires opt-in consent. The definition in ORS 646A.570(18) is notably broad compared to peer states.
Under ORS 646A.570(18)(a)(A), sensitive data includes personal data that "reveals a consumer's racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a victim of crime or citizenship or immigration status." Two of those categories stand out. The express inclusion of "status as transgender or nonbinary" is rare in state privacy law, and the inclusion of "status as a victim of crime" is also uncommon. Many states cover sexual orientation and immigration status, but Oregon's explicit naming of transgender or nonbinary status and crime-victim status broadens the protected set.
The definition continues. ORS 646A.570(18)(a)(B) covers "a child's personal data." ORS 646A.570(18)(a)(C) covers precise location data, specifically data that "accurately identifies within a radius of 1,750 feet a consumer's present or past location." ORS 646A.570(18)(a)(D) covers data that "is genetic or biometric data."
Because sensitive data triggers an opt-in consent requirement, the breadth of Oregon's definition has real operational weight. A controller that processes data revealing a consumer's immigration status or transgender status, or that processes precise geolocation, must obtain affirmative consent first. A broader definition means more data categories fall inside the consent gate.
Two of these categories carry a stricter rule than consent for one specific use. Since January 1, 2026, ORS 646A.578(2)(d) bans the sale of personal data outright when the controller knows, or willfully disregards, that the consumer is under 16, and bans the sale of precise geolocation data within 1,750 feet. Consent does not permit these sales; unlike the rest of the sensitive-data list, this is a flat prohibition, not a consent gate.

The specific third-party list right: Oregon's signature feature
The OCPA's most distinctive consumer right is the ability to learn exactly which third parties received a consumer's data. Under ORS 646A.574(1)(a)(B), a consumer may request "a list of specific third parties, other than natural persons," to which the controller has disclosed the consumer's personal data, or, at the controller's option, any personal data.
This is meaningfully different from the disclosure most state privacy laws require. Under the more common model, a consumer can learn only the categories of third parties, such as "advertising partners" or "data analytics vendors." Oregon goes further and lets the consumer ask for the named, specific entities. Oregon was a leader in adding this right, and as of 2026 it remains uncommon nationally.
For businesses, the specific-third-party list right is one of the harder OCPA obligations to engineer, because it requires tracking disclosures at the level of named recipients rather than broad categories. For consumers, it offers far more transparency about where their data actually traveled. The Oregon consumer rights guide covers this right and the response procedure in depth.
OCPA vs. CCPA: the key differences
Oregon's OCPA and California's CCPA are often compared by companies that operate nationally. The state data privacy law comparison page covers the broader multistate picture, but several differences between the OCPA and California's CCPA stand out.
| Feature | Oregon OCPA | California CCPA/CPRA |
|---|---|---|
| Coverage threshold | 100,000 consumers, or 25,000 plus 25% of revenue from data sales; no dollar floor | $25M revenue, 100,000 consumers, or 50% revenue from data sales |
| Nonprofits | Generally covered (effective July 1, 2025) | Generally exempt |
| Third-party disclosure right | Specific named third parties (ORS 646A.574(1)(a)(B)) | Categories of third parties |
| Sensitive data | Opt-in consent required; broad definition | Right to limit use; opt-out model |
| Private right of action | None | Limited, for certain data breaches |
The most consequential differences are the coverage net and the third-party list right. Oregon's lack of a dollar-revenue floor pulls in companies that the CCPA's $25 million revenue threshold would leave out, and Oregon's specific-third-party list right gives consumers a level of transparency the CCPA's category-level disclosure does not.
The two laws also differ on sensitive data. California uses a "right to limit" the use of sensitive personal information, an opt-out model. Oregon requires opt-in consent before sensitive data may be processed at all, a stricter default for that data.
Related guides
- Oregon data privacy laws parent hub
- OCPA consumer rights
- OCPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Oregon Laws
Frequently Asked Questions
What is the OCPA?
The OCPA, or Oregon Consumer Privacy Act, is Oregon's comprehensive consumer data privacy law codified at ORS 646A.570 to 646A.589. It was enacted as Senate Bill 619, signed by Governor Tina Kotek on July 18, 2023, and took effect July 1, 2024 for most controllers and July 1, 2025 for covered nonprofit organizations. It gives Oregon residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and disclose it.
When did the OCPA take effect?
The OCPA has two effective dates. For most controllers, it took effect July 1, 2024. For covered nonprofit organizations, it took effect one year later, on July 1, 2025. As of 2026, both dates have passed, so every category of covered organization is fully subject to the law. A separate requirement to recognize a universal opt-out signal took effect January 1, 2026.
Does the OCPA have a revenue threshold?
No. Under ORS 646A.572(1), the OCPA covers any person doing business in Oregon or serving Oregon residents that controls or processes the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data. Unlike Utah and Virginia, Oregon sets no dollar-revenue floor, so a company can be covered based on data volume alone. One industry has no threshold at all: since September 26, 2025, motor vehicle manufacturers and their affiliates must comply regardless of consumer count, under ORS 646A.572(1)(b), added by HB 3875.
Does the OCPA apply to nonprofits?
Yes, generally. Oregon is unusual in covering many nonprofit organizations, where several other states exempt nonprofits entirely. ORS 646A.572(2) carves out only narrow categories, such as a nonprofit that detects and prevents insurance fraud and certain noncommercial media activity. Most nonprofits that meet the applicability thresholds are covered, which is why the legislature gave them a delayed effective date of July 1, 2025.
What counts as sensitive data under the OCPA?
Under ORS 646A.570(18), sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a victim of crime, and citizenship or immigration status. It also includes a child's personal data, genetic or biometric data, and precise geolocation within 1,750 feet. Processing sensitive data generally requires opt-in consent, but two categories go further: since January 1, 2026, ORS 646A.578(2)(d) bans the sale of a consumer's precise geolocation data and the sale of personal data belonging to a consumer known to be under 16 outright, regardless of consent.
What is Oregon's specific third-party list right?
Under ORS 646A.574(1)(a)(B), an Oregon consumer may request a list of the specific third parties, other than natural persons, to which the controller disclosed the consumer's personal data, or at the controller's option any personal data. This is broader than the category-level disclosure most state laws require, because it identifies named recipients rather than broad groups. Oregon led on this right, and it remains uncommon as of 2026.
How is the OCPA different from the CCPA?
Key differences: Oregon has no dollar-revenue threshold while California's CCPA uses a $25 million revenue floor among its triggers; Oregon generally covers nonprofits while California generally exempts them; Oregon lets consumers request specific named third parties while California discloses categories; Oregon requires opt-in consent for sensitive data while California uses an opt-out right to limit; and California has a limited private right of action for certain breaches while Oregon has none.
Who enforces the OCPA?
The Oregon Attorney General, through the Oregon Department of Justice, has exclusive enforcement authority under ORS 646A.589(7). There is no private right of action. Civil penalties run up to $7,500 per violation under ORS 646A.589(4)(a). The 30-day right to cure that controllers relied on through 2025 sunset January 1, 2026, so a guaranteed cure window no longer exists.
Updates
Clarified that Oregon's specific third-party list right under ORS 646A.574(1)(a)(B) is provided at the controller's option, which may cover the consumer's own data or any personal data.
Corrected the description of Oregon's financial-institution exemption, which is a full entity-level exemption under ORS 646A.572(2)(L), not merely a data-level carve-out. Added two enacted 2025 amendments that are now current law: HB 2008's outright ban on selling precise geolocation data and the personal data of consumers known to be under 16 (effective January 1, 2026), and HB 3875's extension of OCPA coverage to all motor vehicle manufacturers regardless of consumer-count thresholds (effective September 26, 2025), and corrected the statutory subpart citations for the two consumer-count triggers to match the current lettering.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Fixed the Attorney General exclusive-enforcement citation from ORS 646A.589(8) to the correct subsection (7).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Oregon Revised Statutes, Chapter 646A: Trade Regulation
§ 646A.578Duties of controller; prohibitions; privacy notice to consumerIn forcecited in 7 of our articles
(1) A controller shall: (a) Specify in the privacy notice described in subsection (4) of this section the express purposes for which the controller is collecting and processing personal data; (b) Limit the controller’s collection of personal data to only the personal data that is adequate, relevant and reasonably necessary to serve the purposes the controller specified in paragraph (a) of this subsection; (c) Establish, implement and maintain for personal data the same safeguards described in ORS 646A.622 that are required for protecting personal information, as defined in ORS 646A.602, such that the controller’s safeguards protect the confidentiality, integrity and accessibility of the personal data to the extent appropriate for the volume and nature of the personal data; and (d) Provide an effective means by which a consumer may revoke consent a consumer gave under ORS 646A.570 to 646A.589 to the controller’s processing of the consumer’s personal data. The means must be at least as easy as the means by which the consumer provided consent.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
Also relied on in: OCPA Compliance Checklist for Oregon Businesses, OCPA Consumer Rights: Oregon Data Privacy Act, How to Request Your Personal Data: US Privacy Rights by State
§ 646A.574Consumer requests for personal data; requirement to correct inaccuracies; requirement to delete personal data; conditions under which consumer may opt out of personal data processing; format for providing copy of personal data to consumerIn forcecited in 5 of our articles
(1) Subject to ORS 646A.576, a consumer may: (a) Obtain from a controller: (A) Confirmation as to whether the controller is processing or has processed the consumer’s personal data and the categories of personal data the controller is processing or has processed; (B) At the controller’s option, a list of specific third parties, other than natural persons, to which the controller has disclosed: (i) The consumer’s personal data; or (ii) Any personal data; and (C) A copy of all of the consumer’s personal data that the controller has processed or is processing; (b) Require a controller to correct inaccuracies in personal data about the consumer, taking into account the nature of the personal data and the controller’s purpose for processing the personal data; (c) Require a controller to delete personal data about the consumer, including personal data the consumer provided to the controller, personal data the controller obtained from another source and derived data; or (d) Opt out from a controller’s processing of personal data of the consumer that the controller processes for any of the following purposes: (A) Targeted advertising; (B) Selling…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
§ 646A.589Investigative demand by Attorney General; representation by counsel; confidentiality of proceedings and materials; action to impose civil penalty or obtain injunction; amount of civil penalty; notice of violation; time limit on action; Attorney General’s exclusive authorityIn forcecited in 3 of our articles
(1)(a) The Attorney General may serve an investigative demand upon any person that possesses, controls or has custody of any information, document or other material that the Attorney General determines is relevant to an investigation of a violation of ORS 646A.570 to 646A.589 or that could lead to a discovery of relevant information. An investigative demand may require the person to: (A) Appear and testify under oath at the time and place specified in the investigative demand; (B) Answer written interrogatories; or (C) Produce relevant documents or physical evidence for examination at the time and place specified in the investigative demand. (b) The Attorney General shall serve an investigative demand under this section in the manner provided in ORS 646.622. The Attorney General may enforce the investigative demand as provided in ORS 646.626. (2)(a) An attorney may accompany, represent and advise in confidence a person that appears in response to a demand under subsection (1)(a)(A) of this section.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at oregonlegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- ORS 646A.570 to 646A.589: Oregon Consumer Privacy Act (Full Chapter)(oregonlegislature.gov).gov
- Oregon SB 619 (2023 Regular Session): Measure Overview(olis.oregonlegislature.gov).gov
- Oregon DOJ: Consumer Privacy (Oregon Consumer Privacy Act)(doj.state.or.us).gov
- ORS 646A.570: Definitions (Sensitive Data and Sale)(oregon.public.law)
- ORS 646A.572: Applicability and Exemptions(oregon.public.law)
- ORS 646A.574: Consumer Rights, Including Specific Third-Party List(oregon.public.law)
- ORS 646A.578: Controller Duties and Privacy Notice(oregon.public.law)
- ORS 646A.589: Attorney General Enforcement and Civil Penalties(oregon.public.law)
- Oregon DOJ: OCPA One-Year Enforcement Report (2025)(doj.state.or.us).gov