OCPA is fully in force for both for-profit and nonprofit controllers as of the current date, with a live statutory text and active DOJ guidance program.
Traffic-light rationale — GreenOCPA is fully in force for both for-profit and nonprofit controllers as of the current date, with a live statutory text and active DOJ guidance program.
Sub-modules (5)
Regulator And AuthorityGreen
The Oregon AG's Civil Enforcement Division, through its Privacy Unit within the Antitrust, False Claims, and Privacy Section, holds exclusive enforcement authority over the OCPA.
Claims (1):
The Oregon Department of Justice enforces the OCPA as the exclusive regulator, with no dedicated standalone privacy agency.
Act And InstrumentsGreen
OCPA (SB 619) is codified at ORS 646A.570-646A.589; the older Oregon Consumer Information Protection Act (OCIPA), ORS 646A.600-646A.628, governs data breach notification separately.
Claims (2):
The Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and took effect on July 1, 2024 for for-profit entities.
The OCPA took effect for nonprofit entities on July 1, 2025.
Material ScopeGreen
OCPA applies based on a controller-processed-consumer-volume threshold rather than a subject-matter test.
Claims (1):
The OCPA applies to entities that during a calendar year control or process personal data of at least 100,000 consumers, or 25,000 or more consumers while deriving over 25% of annual gross revenue from the sale of personal data.
Territorial ScopeGreen
OCPA applies to entities physically in Oregon and those directing products/services to Oregon residents, subject to thresholds.
Claims (2):
The OCPA applies to businesses physically located in Oregon and to businesses outside Oregon that direct products or services to Oregon residents, subject to the statutory thresholds.
As of September 26, 2025, the OCPA's threshold exception was expanded so that all motor vehicle manufacturers and certain affiliates collecting personal data from vehicle use must comply regardless of the general numeric thresholds.
Regulator Registration And FilingAmber
OCPA itself imposes no controller registration/filing regime with DOJ; however, Oregon separately operates a public data broker registry under other Oregon law that the Privacy Unit uses for enforcement targeting.
Claims (1):
Oregon maintains a public data broker registry (separate from OCPA) which the Privacy Unit used to generate a target list of data brokers for OCPA compliance outreach.
Category narrative54 words
Oregon's comprehensive consumer privacy regime is the Oregon Consumer Privacy Act (OCPA), <cite index="1-20">The Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and takes effect on July 1, 2024.</cite> The Oregon Department of Justice (DOJ) is the sole enforcement authority; <cite index="1-3">The Department of Justice enforces the OCPA.</cite>
Sources and claims (7)
ConfirmedOregon DOJ — The Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and took effect on July 1, 2024 for for-profit entities.observed
ConfirmedOregon DOJ — The OCPA took effect for nonprofit entities on July 1, 2025.observed
ConfirmedOregon DOJ — The Oregon Department of Justice enforces the OCPA as the exclusive regulator, with no dedicated standalone privacy agency.observed
ConfirmedOregon DOJ — The OCPA applies to entities that during a calendar year control or process personal data of at least 100,000 consumers, or 25,000 or more consumers while deriving over 25% of annual gross revenue from the sale of personal data.observed
ConfirmedOregon DOJ — The OCPA applies to businesses physically located in Oregon and to businesses outside Oregon that direct products or services to Oregon residents, subject to the statutory thresholds.observed
ConfirmedOregon DOJ — As of September 26, 2025, the OCPA's threshold exception was expanded so that all motor vehicle manufacturers and certain affiliates collecting personal data from vehicle use must comply regardless of the general numeric thresholds.observed
ProbableOregon DOJ — Oregon maintains a public data broker registry (separate from OCPA) which the Privacy Unit used to generate a target list of data brokers for OCPA compliance outreach.observed
No enumerated 'lawful bases' construct exists (amber vs. GDPR-aligned green); sensitive-data consent and de-identification safe harbours are, however, clearly specified.
Traffic-light rationale — AmberNo enumerated 'lawful bases' construct exists (amber vs. GDPR-aligned green); sensitive-data consent and de-identification safe harbours are, however, clearly specified.
Sub-modules (4)
Lawful BasesAmber
OCPA does not adopt an Art.6-style enumerated lawful-basis framework; processing is generally permitted subject to consumer opt-out rights and consent requirements for sensitive/children's data. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no GDPR-style lawful-basis taxonomy located.
Consent ThresholdsGreen
Consent under OCPA must not be obtained via dark patterns.
Claims (1):
The OCPA's definition of consent prohibits obtaining consent through dark patterns, even though the statute does not use that term explicitly.
Special CategoriesGreen
OCPA defines an expansive 'sensitive data' category.
Claims (1):
OCPA sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, transgender or nonbinary status, or crime victim status, as well as genetic data and biometric data that could identify an individual.
Pseudonymisation And AnonymisationGreen
De-identified/publicly available data is excluded from 'personal data' subject to specific safe-harbour conditions on controllers.
Claims (1):
Controllers processing deidentified data must take reasonable measures ensuring it cannot be associated with an individual, publicly commit to not re-identifying it, and bind recipients to the same obligations by contract to retain the deidentified-data exemption.
Category narrative37 words
OCPA follows the opt-out/permissive-processing model typical of the 2023-24 wave of US state privacy laws rather than a GDPR-style enumerated lawful-bases test; consent is required specifically for sensitive data processing and for processing children's data under 13.
Sources and claims (4)
ConfirmedOregon DOJ — OCPA sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, transgender or nonbinary status, or crime victim status, as well as genetic data and biometric data that could identify an individual.observed
ConfirmedDataGuidance (OneTrust) — Controllers processing deidentified data must take reasonable measures ensuring it cannot be associated with an individual, publicly commit to not re-identifying it, and bind recipients to the same obligations by contract to retain the deidentified-data exemption.observed
ConfirmedOregon DOJ — Before collecting, using, or otherwise processing personal data about a consumer a business knows to be under 13, the business must obtain consent from that child's parent or legal guardian.observed
ProbableOregon DOJ — The OCPA's definition of consent prohibits obtaining consent through dark patterns, even though the statute does not use that term explicitly.observed
Traffic-light rationale — GreenRights framework is comprehensive, codified, and operative with defined response windows.
Sub-modules (5)
Access RightGreen
Consumers have a right to know/access data collected about them, and a novel right to a list of specific third parties who received it.
Claims (2):
Oregon consumers have the right to access personal data that has been collected about them.
Oregon was the first state to give consumers a right to obtain a list of the specific third parties to whom their data was disclosed, rather than merely categories of third parties.
Rectification And ErasureGreen
Consumers can correct inaccuracies and request deletion of personal and sensitive data.
Claims (1):
Oregon consumers have the right to correct inaccuracies in their personal data and the right to have their personal data deleted.
Restriction And ObjectionGreen
Consumers may opt out of sale, targeted advertising, and certain profiling.
Claims (1):
Oregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.
Data PortabilityGreen
Consumers may obtain a portable copy of their personal and sensitive data.
Claims (1):
Oregon consumers have the right to obtain a copy of their personal data from a controller.
Deadlines And Response WindowsGreen
Statutory 45-day windows apply to appeal responses and deletion fulfillment.
Claims (2):
A business must respond in writing to a consumer's appeal of a denied rights request within 45 days, explaining actions taken or reasons for refusal.
A controller must develop a system to delete personal data within 45 days of receiving a valid consumer deletion request, unless an exemption applies.
Category narrative35 words
OCPA grants Oregon consumers a bundle of rights DOJ summarizes with the mnemonic L.O.C.K.E.D. (List, Opt-out, Copy, Know, Edit, Delete), including a first-in-the-nation right to a list of specific third-party recipients of a consumer's data.
Sources and claims (7)
ConfirmedOregon DOJ — Oregon consumers have the right to access personal data that has been collected about them.observed
ConfirmedOregon DOJ — Oregon consumers have the right to correct inaccuracies in their personal data and the right to have their personal data deleted.observed
ConfirmedOregon DOJ — Oregon consumers have the right to obtain a copy of their personal data from a controller.observed
ConfirmedOregon DOJ — Oregon was the first state to give consumers a right to obtain a list of the specific third parties to whom their data was disclosed, rather than merely categories of third parties.observed
ConfirmedOregon DOJ — Oregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.observed
ConfirmedOregon DOJ — A business must respond in writing to a consumer's appeal of a denied rights request within 45 days, explaining actions taken or reasons for refusal.observed
ConfirmedOregon DOJ — A controller must develop a system to delete personal data within 45 days of receiving a valid consumer deletion request, unless an exemption applies.observed
Core accountability, processor-contract, security and breach-notification duties are clearly documented in DOJ guidance and statute citations; DPO appointment and formal ROPA obligations are not features of this statute.
Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589); Oregon Consumer Information Protection Act (ORS 646A.600-646A.628) for breach notification
Traffic-light rationale — GreenCore accountability, processor-contract, security and breach-notification duties are clearly documented in DOJ guidance and statute citations; DPO appointment and formal ROPA obligations are not features of this statute.
Sub-modules (7)
Accountability And DpiaGreen
Controllers must conduct Data Protection Assessments (DPAs) before heightened-risk processing (targeted advertising, sale, profiling, sensitive data) and retain them five years.
Claims (2):
Controllers must conduct a Data Protection Assessment before processing personal data in a manner presenting a heightened risk of harm to consumers, including targeted advertising, sale, profiling, and any processing of sensitive data.
Data Protection Assessments must be kept on file by the controller for five years.
Dpo RequirementsRed
No DPO-appointment requirement was located in OCPA text or DOJ guidance. Absent_field_provenance: searched DOJ FAQs, six-month and one-year enforcement reports, and Data Protection Assessment Guidelines; no DPO/independent-officer mandate found.
Ropa RequirementsAmber
OCPA does not impose a freestanding Records-of-Processing-Activities obligation distinct from the Data Protection Assessment/five-year retention duty. Absent_field_provenance: searched DOJ guidance materials; no separate ROPA regime identified.
Joint Controller ArrangementsGreen
Processors must act only on controller instructions under a binding contract; the OCPA does not have a distinct 'joint controller' concept but does regulate controller-processor relationships extensively.
Claims (1):
Processors may only process data at the request and under the direction of a controller pursuant to a binding contract specifying processing instructions, nature, purpose, type of data, and duration, and processors must assist controllers in meeting OCPA obligations.
Security MeasuresGreen
OCPA requires reasonable administrative, technical and physical safeguards; the older OCIPA already imposes baseline data-security duties on any entity holding Oregonians' personal information.
Claims (2):
Entities maintaining personal data under OCPA must implement reasonable safeguards, commonly including risk assessment, access controls, encryption, employee training, and data minimization.
The Oregon Consumer Information Protection Act (ORS 646A.600) already places baseline data-security obligations on all entities holding Oregon residents' personal information, independent of OCPA.
Breach NotificationGreen
Breach notification obligations run through OCIPA: consumer notice within 45 days of discovery, and AG notice (with a sample notice) within 45 days if 250+ Oregon consumers are affected.
Claims (2):
Oregon law requires entities to notify any Oregon consumer whose personal information was subject to a breach of security within 45 days of discovering the breach.
If a breach impacts more than 250 Oregon consumers, the entity must also provide a report and a sample copy of the consumer breach notice to the Oregon DOJ within 45 days.
Retention And DisposalAmber
OCPA's principal retention-related duty found is the five-year retention of Data Protection Assessments; no general data-retention-limitation or disposal mandate distinct from data-minimization principles was located. Absent_field_provenance: searched DOJ FAQs and DPA guidance for retention/disposal schedules; none specified beyond the five-year DPA record rule.
Claims (1):
Data Protection Assessments must be kept on file by the controller for five years.
Category narrative30 words
OCPA imposes Data Protection Assessment obligations for heightened-risk processing, mandates processor contracts, and requires reasonable security safeguards; breach notification runs through the separate, older Oregon Consumer Information Protection Act (OCIPA).
Sources and claims (7)
ConfirmedOregon DOJ — Controllers must conduct a Data Protection Assessment before processing personal data in a manner presenting a heightened risk of harm to consumers, including targeted advertising, sale, profiling, and any processing of sensitive data.observed
ConfirmedOregon DOJ — Data Protection Assessments must be kept on file by the controller for five years.observed
ConfirmedDataGuidance (OneTrust) — Processors may only process data at the request and under the direction of a controller pursuant to a binding contract specifying processing instructions, nature, purpose, type of data, and duration, and processors must assist controllers in meeting OCPA obligations.observed
ConfirmedOregon DOJ — Entities maintaining personal data under OCPA must implement reasonable safeguards, commonly including risk assessment, access controls, encryption, employee training, and data minimization.observed
ConfirmedOregon DOJ — The Oregon Consumer Information Protection Act (ORS 646A.600) already places baseline data-security obligations on all entities holding Oregon residents' personal information, independent of OCPA.observed
ConfirmedOregon DOJ — Oregon law requires entities to notify any Oregon consumer whose personal information was subject to a breach of security within 45 days of discovering the breach.observed
ConfirmedOregon DOJ — If a breach impacts more than 250 Oregon consumers, the entity must also provide a report and a sample copy of the consumer breach notice to the Oregon DOJ within 45 days.observed
Traffic-light rationale — RedUnregulated area within this jurisdiction's chosen statutory model — this is a legitimate finding of absence rather than a research gap.
Sub-modules (6)
Transfer MechanismsRed
No OCPA transfer-mechanism regime identified.
Adequacy ReceivedRed
Not applicable; Oregon does not operate an adequacy-recognition framework.
Adequacy GrantedRed
Not applicable.
Sccs And BcrsRed
No SCC/BCR concept exists under OCPA.
Transfer Impact AssessmentRed
No TIA requirement identified; heightened-risk Data Protection Assessments address in-state processing risk, not cross-border transfer risk specifically.
Data LocalisationRed
No data-localisation mandate identified in Oregon law.
Category narrative65 words
No cross-border transfer mechanism, adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime was located within the OCPA or associated Oregon DOJ guidance; unlike GDPR, US state comprehensive privacy statutes of this generation do not regulate international personal-data transfers as a distinct compliance obligation. Absent_field_provenance: searched OCPA text summaries, DOJ FAQs (business, consumer, nonprofit), six-month and one-year enforcement reports, and DataGuidance overview notes for transfer/adequacy/localisation provisions; none found.
Sectoral exemptions are clearly documented for financial (GLBA), health (HIPAA), credit (FCRA), employment, and insurance; telecoms/eprivacy and education-specific carve-outs were not separately confirmed.
Traffic-light rationale — AmberSectoral exemptions are clearly documented for financial (GLBA), health (HIPAA), credit (FCRA), employment, and insurance; telecoms/eprivacy and education-specific carve-outs were not separately confirmed.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA-covered financial data/entities are exempted from OCPA.
Claims (1):
OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.
Health Sector OverlayGreen
HIPAA-covered protected health information is exempted from OCPA.
Claims (1):
OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.
Telecoms And EprivacyRed
No telecoms-specific or ePrivacy-style overlay was identified for Oregon under OCPA. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no telecoms-sector carve-out or overlay found.
Employment DataGreen
OCPA expressly excludes data maintained for employment-record purposes and defines 'consumer' to exclude individuals acting as employees or job applicants.
Claims (1):
OCPA does not apply to data maintained for employment-record purposes, and 'consumer' under the statute excludes an individual acting as an employee or job applicant.
Credit And ScoringGreen
FCRA-covered credit reporting data/entities are exempted from OCPA.
Claims (1):
OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.
EducationAmber
No education-sector-specific overlay (e.g., FERPA carve-out) was expressly confirmed in DOJ guidance reviewed. Absent_field_provenance: searched DOJ FAQs and enforcement reports; education-sector-specific treatment not separately documented.
InsuranceGreen
Certain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA even if they meet the general thresholds.
Claims (1):
Certain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA compliance even if they otherwise meet the statutory thresholds.
Category narrative25 words
OCPA carves out several sectoral overlaps rather than displacing them: GLBA, HIPAA, and FCRA-covered data/entities are exempted, as are employment records and certain insurance entities.
Sources and claims (3)
ConfirmedOregon DOJ — OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.observed
ConfirmedOregon DOJ — OCPA does not apply to data maintained for employment-record purposes, and 'consumer' under the statute excludes an individual acting as an employee or job applicant.observed
ConfirmedOregon DOJ — Certain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA compliance even if they otherwise meet the statutory thresholds.observed
Opt-out-signal and cross-context-advertising opt-out rights are clearly in force; cookie-specific and clean-room/data-collaboration rules are not separately addressed by the statute.
Traffic-light rationale — AmberOpt-out-signal and cross-context-advertising opt-out rights are clearly in force; cookie-specific and clean-room/data-collaboration rules are not separately addressed by the statute.
Sub-modules (6)
Cookies And TrackersAmber
No dedicated cookie-consent regime (ePrivacy-style) was found; cookie-based tracking is addressed generally under the personal-data/opt-out framework. Absent_field_provenance: searched DOJ FAQs and OCPA summaries for a cookie-specific banner/consent mandate; none found distinct from general opt-out rights.
Dark PatternsAmber
Dark-pattern design is not named in the statute but is addressed via OCPA's consent and accessibility requirements.
Claims (1):
Dark-pattern design practices that impair a consumer's ability to give freely-given, informed consent may violate OCPA's accessibility and consent-definition requirements, and may separately implicate Oregon's Unlawful Trade Practices Act, even though OCPA does not use the term 'dark patterns.'
Opt Out SignalsGreen
As of January 1, 2026, controllers meeting OCPA thresholds must honor technically-compliant universal opt-out preference signals, such as Global Privacy Control, as valid opt-out requests.
Claims (1):
As of January 1, 2026, businesses and nonprofits meeting OCPA thresholds must honor opt-out preference signals meeting technical requirements, such as the Global Privacy Control, as a valid consumer opt-out request.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room-specific rules were identified in Oregon law. Absent_field_provenance: searched DOJ guidance and enforcement reports; no clean-room provisions found.
Cross Context AdvertisingGreen
Consumers may opt out of a controller's use of their data for targeted advertising and of sale to third parties, functionally analogous to CPRA's 'sale'/'share' opt-outs.
Claims (1):
Oregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.
Direct MarketingAmber
No distinct direct-marketing consent/suppression regime separate from the general targeted-advertising opt-out was identified. Absent_field_provenance: searched DOJ FAQs; direct marketing is treated as a subset of targeted advertising/sale opt-out rights rather than a standalone regime.
Category narrative41 words
OCPA requires recognition of universal opt-out mechanisms (e.g., Global Privacy Control) from January 1, 2026, prohibits dark-pattern consent practices implicitly, and gives consumers opt-out rights over sale, targeted advertising, and certain profiling; a dedicated cookie-consent or clean-room regime was not identified.
Sources and claims (2)
ConfirmedOregon DOJ — As of January 1, 2026, businesses and nonprofits meeting OCPA thresholds must honor opt-out preference signals meeting technical requirements, such as the Global Privacy Control, as a valid consumer opt-out request.observed
ProbableOregon DOJ — Dark-pattern design practices that impair a consumer's ability to give freely-given, informed consent may violate OCPA's accessibility and consent-definition requirements, and may separately implicate Oregon's Unlawful Trade Practices Act, even though OCPA does not use the term 'dark patterns.'observed
Profiling opt-out and biometric/genetic sensitive-data classification are confirmed; there is no EU AI Act-style dedicated AI risk-assessment regime distinct from the general Data Protection Assessment duty, and ADM 'explanation rights' beyond opt-out were not located.
Traffic-light rationale — AmberProfiling opt-out and biometric/genetic sensitive-data classification are confirmed; there is no EU AI Act-style dedicated AI risk-assessment regime distinct from the general Data Protection Assessment duty, and ADM 'explanation rights' beyond opt-out were not located.
Sub-modules (6)
Profiling RestrictionsGreen
Consumers may opt out of profiling used to make decisions producing legal or similarly significant effects (e.g., financial services, housing, employment, healthcare).
Claims (1):
Oregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.
Automated Decision Making TransparencyAmber
Profiling is defined as automated processing to evaluate, analyze, or predict consumer attributes; the OCPA gives an opt-out right rather than a standalone explanation/transparency right akin to GDPR Art.22.
Claims (1):
Oregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.
Ai Risk AssessmentsAmber
No AI-specific risk-assessment regime distinct from the general heightened-risk Data Protection Assessment (which covers profiling) was identified. Absent_field_provenance: searched DOJ guidance and enforcement reports for AI-specific assessment obligations; none found beyond the general DPA duty covering profiling activities.
Biometric RegimeGreen
Biometric data is classified as sensitive data under OCPA and separately as personal information under the OCIPA breach-notification statute.
Claims (2):
Biometric data that could be used to identify an individual is classified as sensitive data under the OCPA.
Under the separate OCIPA breach-notification statute, 'personal information' includes biometric data from automatic measurements of a consumer's physical characteristics, such as fingerprint, retina, or iris images.
Genetic DataGreen
Genetic data is classified as sensitive data under OCPA, triggering heightened-risk consent and Data Protection Assessment obligations.
Claims (1):
Genetic data is classified as sensitive data under the OCPA, subject to consent and heightened-risk processing requirements.
State Surveillance CarveoutsAmber
OCPA does not apply to federal, state, or local governments.
Claims (1):
The Oregon privacy law does not apply to federal, state, or local governments.
Category narrative39 words
OCPA classifies biometric and genetic data as sensitive data requiring consent-based heightened protection, grants consumers an opt-out right against profiling used for legally or similarly significant decisions, and expressly excludes federal, state and local government bodies from its scope.
Sources and claims (5)
ConfirmedOregon DOJ — Oregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.observed
ConfirmedOregon DOJ — Biometric data that could be used to identify an individual is classified as sensitive data under the OCPA.observed
ConfirmedOregon DOJ — Genetic data is classified as sensitive data under the OCPA, subject to consent and heightened-risk processing requirements.observed
ConfirmedOregon DOJ — The Oregon privacy law does not apply to federal, state, or local governments.observed
ConfirmedOregon DOJ — Under the separate OCIPA breach-notification statute, 'personal information' includes biometric data from automatic measurements of a consumer's physical characteristics, such as fingerprint, retina, or iris images.observed
Core children's-data protections (parental consent, under-16 sale/targeted-ad/profiling ban) are clearly in force; age-verification, education-specific, and dependent-adult sub-modules are unaddressed in the statute.
Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589), as amended by HB 2008 (2025)
Traffic-light rationale — AmberCore children's-data protections (parental consent, under-16 sale/targeted-ad/profiling ban) are clearly in force; age-verification, education-specific, and dependent-adult sub-modules are unaddressed in the statute.
Sub-modules (5)
Age VerificationAmber
No dedicated age-verification mandate was identified in OCPA or DOJ guidance; obligations trigger on actual or constructive knowledge of a consumer's age. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no age-verification-technology mandate found.
Parental ConsentGreen
Parental/guardian consent is required before processing personal data of a consumer known to be under 13; all data about children under 13 is treated as sensitive.
Claims (2):
Businesses must obtain consent from a parent or legal guardian before collecting, using, or otherwise processing personal data about a consumer the business knows to be under 13 years old.
HB 2008 clarifies that processing the data of children under 13 must still comply with the federal Children's Online Privacy Protection Act as recently updated and strengthened.
Minor Profiling BansGreen
As of January 1, 2026, it is unlawful to sell the personal data of, or use for targeted advertising or certain profiling of, any consumer under 16.
Claims (2):
As of January 1, 2026, it is unlawful for businesses to sell the personal data of any consumer under 16 years of age or to use their personal data for targeted advertising or profiling.
The 2025 legislative amendment (HB 2008) bans controllers from selling or sharing for value the personal or sensitive data of a child or teen the controller knows or should have known is under 16.
Education SettingsRed
No education-setting-specific children's-data rule was identified beyond the general under-13/under-16 protections. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no education-specific minors' provision found.
Dependent AdultsRed
No dependent-adult/elderly-specific protection provision was identified in OCPA. Absent_field_provenance: searched DOJ FAQs, enforcement reports, and DataGuidance overview; no dependent-adult-specific rule found.
Category narrative35 words
OCPA and its 2025 amendment (HB 2008) impose parental-consent requirements for under-13 processing and expanded sale/targeted-advertising/profiling bans for consumers under 16, effective January 1, 2026; no age-verification mandate, education-setting-specific rule, or dependent-adult provision was identified.
Sources and claims (4)
ConfirmedOregon DOJ — Businesses must obtain consent from a parent or legal guardian before collecting, using, or otherwise processing personal data about a consumer the business knows to be under 13 years old.observed
ConfirmedOregon DOJ — As of January 1, 2026, it is unlawful for businesses to sell the personal data of any consumer under 16 years of age or to use their personal data for targeted advertising or profiling.observed
ConfirmedOregon DOJ — The 2025 legislative amendment (HB 2008) bans controllers from selling or sharing for value the personal or sensitive data of a child or teen the controller knows or should have known is under 16.observed
ConfirmedOregon DOJ — HB 2008 clarifies that processing the data of children under 13 must still comply with the federal Children's Online Privacy Protection Act as recently updated and strengthened.observed
Enforcement powers, penalty caps, and two years of published enforcement-activity reports provide strong evidentiary grounding; the absence of a private right of action or collective-redress mechanism is a clearly documented structural feature rather than a gap.
Traffic-light rationale — GreenEnforcement powers, penalty caps, and two years of published enforcement-activity reports provide strong evidentiary grounding; the absence of a private right of action or collective-redress mechanism is a clearly documented structural feature rather than a gap.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
AG may seek civil penalties up to $7,500 per violation plus injunctive relief, restitution, and disgorgement.
Claims (1):
Entities that violate the OCPA may face civil penalties up to $7,500 per violation, and the Attorney General may also seek injunctive relief, restitution, and/or disgorgement.
Enforcement Activity IndexGreen
DOJ has published six-month and one-year enforcement reports quantifying complaints and cure-notice matters.
Claims (2):
In the first year of OCPA enforcement, the Privacy Unit received 214 complaints and initiated and closed 38 cure-notice/inquiry matters.
In the first six months of OCPA enforcement, the Privacy Unit had received 110 complaints and initiated and closed 21 cure-notice matters.
Regulator Funding And CapacityAmber
The Legislature authorized dedicated Privacy Unit staffing given the lack of a private right of action.
Claims (1):
Given the lack of a private right of action and increased enforcement workload, the Oregon Legislature authorized three attorney and two specialized staff positions to enforce the OCPA, with the Privacy Unit expanding significantly within its first six months.
Collective Redress And Class ActionsRed
No collective-redress or class-action mechanism specific to OCPA was identified; enforcement is centralized in the AG. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no class-action provision found within OCPA itself.
Claims (1):
The OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.
Private Right Of ActionRed
OCPA does not include a private right of action; only the Oregon Attorney General may enforce the law.
Claims (1):
The OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.
Recent Developments 180DGreen
Within the 180 days preceding this run, the OCPA's mandatory 30-day cure period sunset (January 1, 2026), universal opt-out signal recognition became mandatory, and the under-16 sale/targeted-advertising ban and geolocation-sale ban took effect.
Claims (2):
As of January 1, 2026, the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the OCPA violation, and may proceed directly to a Civil Investigative Demand or lawsuit.
As of January 1, 2026, Oregon's privacy law bans the sale of precise geolocation data of all Oregon consumers, defined as a radius of 1,750 feet covering present and past location data.
Category narrative48 words
The Oregon AG holds exclusive OCPA enforcement authority, with civil penalties up to $7,500 per violation plus injunctive relief, restitution and disgorgement; there is no private right of action. The Privacy Unit's cure-notice/30-day-cure requirement sunset on January 1, 2026, after which DOJ can proceed directly to enforcement action.
Sources and claims (7)
ConfirmedOregon DOJ — The OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.observed
ConfirmedOregon DOJ — Entities that violate the OCPA may face civil penalties up to $7,500 per violation, and the Attorney General may also seek injunctive relief, restitution, and/or disgorgement.observed
ConfirmedOregon DOJ — Given the lack of a private right of action and increased enforcement workload, the Oregon Legislature authorized three attorney and two specialized staff positions to enforce the OCPA, with the Privacy Unit expanding significantly within its first six months.observed
ConfirmedOregon DOJ — In the first year of OCPA enforcement, the Privacy Unit received 214 complaints and initiated and closed 38 cure-notice/inquiry matters.observed
ConfirmedOregon DOJ — In the first six months of OCPA enforcement, the Privacy Unit had received 110 complaints and initiated and closed 21 cure-notice matters.observed
ConfirmedOregon DOJ — As of January 1, 2026, the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the OCPA violation, and may proceed directly to a Civil Investigative Demand or lawsuit.observed
ConfirmedOregon DOJ — As of January 1, 2026, Oregon's privacy law bans the sale of precise geolocation data of all Oregon consumers, defined as a radius of 1,750 feet covering present and past location data.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Oregon
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 13 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
regulator_and_framework, data_subject_rights, controller_processor_duties (security/breach/DPA), children_and_vulnerable_groups, and enforcement_and_redress are grounded predominantly in T1 primary DOJ sources (OCPA FAQs, Data Protection Assessment Guidelines, data-breach page) supplemented by T2 DOJ enforcement reports for activity metrics and recent developments. sectoral_watch and adtech_and_commercial_privacy sub-modules on exemptions and opt-out signals rest on T1 DOJ FAQ sources; processor-contract detail in controller_processor_duties.joint_controller_arrangements and lawful_processing_and_special_data.pseudonymisation_and_anonymisation relied on a T3 DataGuidance legacy opinion piece cross-referencing statutory citations, as the underlying statute text (ORS 646A.570-646A.589) itself was not directly fetched. cross_border_and_adequacy carries zero claims with an explicit absent_field_provenance rationale, reflecting a genuine regulatory gap in this statutory model rather than a research shortfall. DPO requirements, ROPA, cookie-specific rules, clean-room rules, age-verification, education-settings, and dependent-adult sub-modules similarly carry absent_field_provenance rather than fabricated obligations.
Unresolved questions (4):
Has the Oregon DOJ issued any binding implementing rules/regulations beyond FAQs and guidance documents, and would these change any in_force claims?
Are there OCPA-adjacent 2026 legislative session amendments (post one-year report, dated August 2025) not yet reflected in DOJ FAQ pages as retrieved?
Does Oregon's separate data broker registration statute (outside ORS 646A.570-646A.589) impose filing obligations that should be more fully scoped under regulator_registration_and_filing?
Is there any education-sector-specific (FERPA-interface) or dependent-adult-specific provision in the full statutory text (ORS 646A.570-646A.589) not captured in DOJ's plain-language FAQ summaries?