{
 "jurisdiction_id": "US-OR",
 "jurisdiction": "United States – Oregon",
 "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 46,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "OCPA is fully in force for both for-profit and nonprofit controllers as of the current date, with a live statutory text and active DOJ guidance program.",
   "claims": [
    {
     "statement": "The Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and took effect on July 1, 2024 for for-profit entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The OCPA took effect for nonprofit entities on July 1, 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-nonprofits/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Oregon Department of Justice enforces the OCPA as the exclusive regulator, with no dedicated standalone privacy agency.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The OCPA applies to entities that during a calendar year control or process personal data of at least 100,000 consumers, or 25,000 or more consumers while deriving over 25% of annual gross revenue from the sale of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/03/OCPA-Six-Month-Enforcement-Report.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The OCPA applies to businesses physically located in Oregon and to businesses outside Oregon that direct products or services to Oregon residents, subject to the statutory thresholds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "As of September 26, 2025, the OCPA's threshold exception was expanded so that all motor vehicle manufacturers and certain affiliates collecting personal data from vehicle use must comply regardless of the general numeric thresholds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/08/OCPA-One-Year-Enforcement-Report-2025.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oregon maintains a public data broker registry (separate from OCPA) which the Privacy Unit used to generate a target list of data brokers for OCPA compliance outreach.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/03/OCPA-Six-Month-Enforcement-Report.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No enumerated 'lawful bases' construct exists (amber vs. GDPR-aligned green); sensitive-data consent and de-identification safe harbours are, however, clearly specified.",
   "claims": [
    {
     "statement": "OCPA sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, transgender or nonbinary status, or crime victim status, as well as genetic data and biometric data that could identify an individual.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Controllers processing deidentified data must take reasonable measures ensuring it cannot be associated with an individual, publicly commit to not re-identifying it, and bind recipients to the same obligations by contract to retain the deidentified-data exemption.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://legacy.dataguidance.com/opinion/oregon-consumer-privacy-act-comprehensive-consumer",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Before collecting, using, or otherwise processing personal data about a consumer a business knows to be under 13, the business must obtain consent from that child's parent or legal guardian.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The OCPA's definition of consent prohibits obtaining consent through dark patterns, even though the statute does not use that term explicitly.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is comprehensive, codified, and operative with defined response windows.",
   "claims": [
    {
     "statement": "Oregon consumers have the right to access personal data that has been collected about them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oregon consumers have the right to correct inaccuracies in their personal data and the right to have their personal data deleted.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oregon consumers have the right to obtain a copy of their personal data from a controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oregon was the first state to give consumers a right to obtain a list of the specific third parties to whom their data was disclosed, rather than merely categories of third parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/03/OCPA-Six-Month-Enforcement-Report.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A business must respond in writing to a consumer's appeal of a denied rights request within 45 days, explaining actions taken or reasons for refusal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A controller must develop a system to delete personal data within 45 days of receiving a valid consumer deletion request, unless an exemption applies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-nonprofits/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability, processor-contract, security and breach-notification duties are clearly documented in DOJ guidance and statute citations; DPO appointment and formal ROPA obligations are not features of this statute.",
   "claims": [
    {
     "statement": "Controllers must conduct a Data Protection Assessment before processing personal data in a manner presenting a heightened risk of harm to consumers, including targeted advertising, sale, profiling, and any processing of sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2024/06/Data-Protection-Assessment-Guidelines.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Data Protection Assessments must be kept on file by the controller for five years.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2024/06/Data-Protection-Assessment-Guidelines.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Processors may only process data at the request and under the direction of a controller pursuant to a binding contract specifying processing instructions, nature, purpose, type of data, and duration, and processors must assist controllers in meeting OCPA obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://legacy.dataguidance.com/opinion/oregon-consumer-privacy-act-comprehensive-consumer",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Entities maintaining personal data under OCPA must implement reasonable safeguards, commonly including risk assessment, access controls, encryption, employee training, and data minimization.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Oregon Consumer Information Protection Act (ORS 646A.600) already places baseline data-security obligations on all entities holding Oregon residents' personal information, independent of OCPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Oregon law requires entities to notify any Oregon consumer whose personal information was subject to a breach of security within 45 days of discovering the breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "If a breach impacts more than 250 Oregon consumers, the entity must also provide a report and a sample copy of the consumer breach notice to the Oregon DOJ within 45 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Unregulated area within this jurisdiction's chosen statutory model — this is a legitimate finding of absence rather than a research gap.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral exemptions are clearly documented for financial (GLBA), health (HIPAA), credit (FCRA), employment, and insurance; telecoms/eprivacy and education-specific carve-outs were not separately confirmed.",
   "claims": [
    {
     "statement": "OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "OCPA does not apply to data maintained for employment-record purposes, and 'consumer' under the statute excludes an individual acting as an employee or job applicant.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Certain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA compliance even if they otherwise meet the statutory thresholds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Opt-out-signal and cross-context-advertising opt-out rights are clearly in force; cookie-specific and clean-room/data-collaboration rules are not separately addressed by the statute.",
   "claims": [
    {
     "statement": "As of January 1, 2026, businesses and nonprofits meeting OCPA thresholds must honor opt-out preference signals meeting technical requirements, such as the Global Privacy Control, as a valid consumer opt-out request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Dark-pattern design practices that impair a consumer's ability to give freely-given, informed consent may violate OCPA's accessibility and consent-definition requirements, and may separately implicate Oregon's Unlawful Trade Practices Act, even though OCPA does not use the term 'dark patterns.'",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling opt-out and biometric/genetic sensitive-data classification are confirmed; there is no EU AI Act-style dedicated AI risk-assessment regime distinct from the general Data Protection Assessment duty, and ADM 'explanation rights' beyond opt-out were not located.",
   "claims": [
    {
     "statement": "Oregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Biometric data that could be used to identify an individual is classified as sensitive data under the OCPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Genetic data is classified as sensitive data under the OCPA, subject to consent and heightened-risk processing requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Oregon privacy law does not apply to federal, state, or local governments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Under the separate OCIPA breach-notification statute, 'personal information' includes biometric data from automatic measurements of a consumer's physical characteristics, such as fingerprint, retina, or iris images.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core children's-data protections (parental consent, under-16 sale/targeted-ad/profiling ban) are clearly in force; age-verification, education-specific, and dependent-adult sub-modules are unaddressed in the statute.",
   "claims": [
    {
     "statement": "Businesses must obtain consent from a parent or legal guardian before collecting, using, or otherwise processing personal data about a consumer the business knows to be under 13 years old.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "As of January 1, 2026, it is unlawful for businesses to sell the personal data of any consumer under 16 years of age or to use their personal data for targeted advertising or profiling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The 2025 legislative amendment (HB 2008) bans controllers from selling or sharing for value the personal or sensitive data of a child or teen the controller knows or should have known is under 16.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/08/OCPA-One-Year-Enforcement-Report-2025.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "HB 2008 clarifies that processing the data of children under 13 must still comply with the federal Children's Online Privacy Protection Act as recently updated and strengthened.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/08/OCPA-One-Year-Enforcement-Report-2025.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-oregon/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers, penalty caps, and two years of published enforcement-activity reports provide strong evidentiary grounding; the absence of a private right of action or collective-redress mechanism is a clearly documented structural feature rather than a gap.",
   "claims": [
    {
     "statement": "The OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Entities that violate the OCPA may face civil penalties up to $7,500 per violation, and the Attorney General may also seek injunctive relief, restitution, and/or disgorgement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Given the lack of a private right of action and increased enforcement workload, the Oregon Legislature authorized three attorney and two specialized staff positions to enforce the OCPA, with the Privacy Unit expanding significantly within its first six months.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/wp-content/uploads/2025/03/OCPA-Six-Month-Enforcement-Report.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "In the first year of OCPA enforcement, the Privacy Unit received 214 complaints and initiated and closed 38 cure-notice/inquiry matters.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/media-home/news-media-releases/attorney-general-rayfield-releases-one-year-report-on-oregon-consumer-privacy-act/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "In the first six months of OCPA enforcement, the Privacy Unit had received 110 complaints and initiated and closed 21 cure-notice matters.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/media-home/news-media-releases/attorney-general-rayfield-releases-6-month-report-on-oregon-consumer-privacy-act/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "As of January 1, 2026, the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the OCPA violation, and may proceed directly to a Civil Investigative Demand or lawsuit.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "As of January 1, 2026, Oregon's privacy law bans the sale of precise geolocation data of all Oregon consumers, defined as a radius of 1,750 feet covering present and past location data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Oregon DOJ",
     "source_url": "https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}