🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-OR · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Oregon

US-OR schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

OCPA is fully in force for both for-profit and nonprofit controllers as of the current date, with a live statutory text and active DOJ guidance program.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589)
Traffic-light rationale — GreenOCPA is fully in force for both for-profit and nonprofit controllers as of the current date, with a live statutory text and active DOJ guidance program.

Sub-modules (5)

Regulator And AuthorityGreen

The Oregon AG's Civil Enforcement Division, through its Privacy Unit within the Antitrust, False Claims, and Privacy Section, holds exclusive enforcement authority over the OCPA.

Claims (1):

  • The Oregon Department of Justice enforces the OCPA as the exclusive regulator, with no dedicated standalone privacy agency.

Act And InstrumentsGreen

OCPA (SB 619) is codified at ORS 646A.570-646A.589; the older Oregon Consumer Information Protection Act (OCIPA), ORS 646A.600-646A.628, governs data breach notification separately.

Claims (2):

  • The Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and took effect on July 1, 2024 for for-profit entities.
  • The OCPA took effect for nonprofit entities on July 1, 2025.

Material ScopeGreen

OCPA applies based on a controller-processed-consumer-volume threshold rather than a subject-matter test.

Claims (1):

  • The OCPA applies to entities that during a calendar year control or process personal data of at least 100,000 consumers, or 25,000 or more consumers while deriving over 25% of annual gross revenue from the sale of personal data.

Territorial ScopeGreen

OCPA applies to entities physically in Oregon and those directing products/services to Oregon residents, subject to thresholds.

Claims (2):

  • The OCPA applies to businesses physically located in Oregon and to businesses outside Oregon that direct products or services to Oregon residents, subject to the statutory thresholds.
  • As of September 26, 2025, the OCPA's threshold exception was expanded so that all motor vehicle manufacturers and certain affiliates collecting personal data from vehicle use must comply regardless of the general numeric thresholds.

Regulator Registration And FilingAmber

OCPA itself imposes no controller registration/filing regime with DOJ; however, Oregon separately operates a public data broker registry under other Oregon law that the Privacy Unit uses for enforcement targeting.

Claims (1):

  • Oregon maintains a public data broker registry (separate from OCPA) which the Privacy Unit used to generate a target list of data brokers for OCPA compliance outreach.
Category narrative54 words

Oregon's comprehensive consumer privacy regime is the Oregon Consumer Privacy Act (OCPA), <cite index="1-20">The Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and takes effect on July 1, 2024.</cite> The Oregon Department of Justice (DOJ) is the sole enforcement authority; <cite index="1-3">The Department of Justice enforces the OCPA.</cite>

Sources and claims (7)
  1. ConfirmedOregon DOJThe Oregon Consumer Privacy Act (OCPA), ORS 646A.570-646A.589, was signed into law by Governor Kotek and took effect on July 1, 2024 for for-profit entities.observed
  2. ConfirmedOregon DOJThe OCPA took effect for nonprofit entities on July 1, 2025.observed
  3. ConfirmedOregon DOJThe Oregon Department of Justice enforces the OCPA as the exclusive regulator, with no dedicated standalone privacy agency.observed
  4. ConfirmedOregon DOJThe OCPA applies to entities that during a calendar year control or process personal data of at least 100,000 consumers, or 25,000 or more consumers while deriving over 25% of annual gross revenue from the sale of personal data.observed
  5. ConfirmedOregon DOJThe OCPA applies to businesses physically located in Oregon and to businesses outside Oregon that direct products or services to Oregon residents, subject to the statutory thresholds.observed
  6. ConfirmedOregon DOJAs of September 26, 2025, the OCPA's threshold exception was expanded so that all motor vehicle manufacturers and certain affiliates collecting personal data from vehicle use must comply regardless of the general numeric thresholds.observed
  7. ProbableOregon DOJOregon maintains a public data broker registry (separate from OCPA) which the Privacy Unit used to generate a target list of data brokers for OCPA compliance outreach.observed

#

No enumerated 'lawful bases' construct exists (amber vs. GDPR-aligned green); sensitive-data consent and de-identification safe harbours are, however, clearly specified.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589)
Traffic-light rationale — AmberNo enumerated 'lawful bases' construct exists (amber vs. GDPR-aligned green); sensitive-data consent and de-identification safe harbours are, however, clearly specified.

Sub-modules (4)

Lawful BasesAmber

OCPA does not adopt an Art.6-style enumerated lawful-basis framework; processing is generally permitted subject to consumer opt-out rights and consent requirements for sensitive/children's data. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no GDPR-style lawful-basis taxonomy located.

Special CategoriesGreen

OCPA defines an expansive 'sensitive data' category.

Claims (1):

  • OCPA sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, transgender or nonbinary status, or crime victim status, as well as genetic data and biometric data that could identify an individual.

Pseudonymisation And AnonymisationGreen

De-identified/publicly available data is excluded from 'personal data' subject to specific safe-harbour conditions on controllers.

Claims (1):

  • Controllers processing deidentified data must take reasonable measures ensuring it cannot be associated with an individual, publicly commit to not re-identifying it, and bind recipients to the same obligations by contract to retain the deidentified-data exemption.
Category narrative37 words

OCPA follows the opt-out/permissive-processing model typical of the 2023-24 wave of US state privacy laws rather than a GDPR-style enumerated lawful-bases test; consent is required specifically for sensitive data processing and for processing children's data under 13.

Sources and claims (4)
  1. ConfirmedOregon DOJOCPA sensitive data includes data revealing racial or ethnic background, national origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, transgender or nonbinary status, or crime victim status, as well as genetic data and biometric data that could identify an individual.observed
  2. ConfirmedDataGuidance (OneTrust)Controllers processing deidentified data must take reasonable measures ensuring it cannot be associated with an individual, publicly commit to not re-identifying it, and bind recipients to the same obligations by contract to retain the deidentified-data exemption.observed
  3. ConfirmedOregon DOJBefore collecting, using, or otherwise processing personal data about a consumer a business knows to be under 13, the business must obtain consent from that child's parent or legal guardian.observed
  4. ProbableOregon DOJThe OCPA's definition of consent prohibits obtaining consent through dark patterns, even though the statute does not use that term explicitly.observed

#

Rights framework is comprehensive, codified, and operative with defined response windows.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589)
Traffic-light rationale — GreenRights framework is comprehensive, codified, and operative with defined response windows.

Sub-modules (5)

Access RightGreen

Consumers have a right to know/access data collected about them, and a novel right to a list of specific third parties who received it.

Claims (2):

  • Oregon consumers have the right to access personal data that has been collected about them.
  • Oregon was the first state to give consumers a right to obtain a list of the specific third parties to whom their data was disclosed, rather than merely categories of third parties.

Rectification And ErasureGreen

Consumers can correct inaccuracies and request deletion of personal and sensitive data.

Claims (1):

  • Oregon consumers have the right to correct inaccuracies in their personal data and the right to have their personal data deleted.

Restriction And ObjectionGreen

Consumers may opt out of sale, targeted advertising, and certain profiling.

Claims (1):

  • Oregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.

Data PortabilityGreen

Consumers may obtain a portable copy of their personal and sensitive data.

Claims (1):

  • Oregon consumers have the right to obtain a copy of their personal data from a controller.

Deadlines And Response WindowsGreen

Statutory 45-day windows apply to appeal responses and deletion fulfillment.

Claims (2):

  • A business must respond in writing to a consumer's appeal of a denied rights request within 45 days, explaining actions taken or reasons for refusal.
  • A controller must develop a system to delete personal data within 45 days of receiving a valid consumer deletion request, unless an exemption applies.
Category narrative35 words

OCPA grants Oregon consumers a bundle of rights DOJ summarizes with the mnemonic L.O.C.K.E.D. (List, Opt-out, Copy, Know, Edit, Delete), including a first-in-the-nation right to a list of specific third-party recipients of a consumer's data.

Sources and claims (7)
  1. ConfirmedOregon DOJOregon consumers have the right to access personal data that has been collected about them.observed
  2. ConfirmedOregon DOJOregon consumers have the right to correct inaccuracies in their personal data and the right to have their personal data deleted.observed
  3. ConfirmedOregon DOJOregon consumers have the right to obtain a copy of their personal data from a controller.observed
  4. ConfirmedOregon DOJOregon was the first state to give consumers a right to obtain a list of the specific third parties to whom their data was disclosed, rather than merely categories of third parties.observed
  5. ConfirmedOregon DOJOregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.observed
  6. ConfirmedOregon DOJA business must respond in writing to a consumer's appeal of a denied rights request within 45 days, explaining actions taken or reasons for refusal.observed
  7. ConfirmedOregon DOJA controller must develop a system to delete personal data within 45 days of receiving a valid consumer deletion request, unless an exemption applies.observed

#

Core accountability, processor-contract, security and breach-notification duties are clearly documented in DOJ guidance and statute citations; DPO appointment and formal ROPA obligations are not features of this statute.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589); Oregon Consumer Information Protection Act (ORS 646A.600-646A.628) for breach notification
Traffic-light rationale — GreenCore accountability, processor-contract, security and breach-notification duties are clearly documented in DOJ guidance and statute citations; DPO appointment and formal ROPA obligations are not features of this statute.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct Data Protection Assessments (DPAs) before heightened-risk processing (targeted advertising, sale, profiling, sensitive data) and retain them five years.

Claims (2):

  • Controllers must conduct a Data Protection Assessment before processing personal data in a manner presenting a heightened risk of harm to consumers, including targeted advertising, sale, profiling, and any processing of sensitive data.
  • Data Protection Assessments must be kept on file by the controller for five years.

Dpo RequirementsRed

No DPO-appointment requirement was located in OCPA text or DOJ guidance. Absent_field_provenance: searched DOJ FAQs, six-month and one-year enforcement reports, and Data Protection Assessment Guidelines; no DPO/independent-officer mandate found.

Ropa RequirementsAmber

OCPA does not impose a freestanding Records-of-Processing-Activities obligation distinct from the Data Protection Assessment/five-year retention duty. Absent_field_provenance: searched DOJ guidance materials; no separate ROPA regime identified.

Joint Controller ArrangementsGreen

Processors must act only on controller instructions under a binding contract; the OCPA does not have a distinct 'joint controller' concept but does regulate controller-processor relationships extensively.

Claims (1):

  • Processors may only process data at the request and under the direction of a controller pursuant to a binding contract specifying processing instructions, nature, purpose, type of data, and duration, and processors must assist controllers in meeting OCPA obligations.

Security MeasuresGreen

OCPA requires reasonable administrative, technical and physical safeguards; the older OCIPA already imposes baseline data-security duties on any entity holding Oregonians' personal information.

Claims (2):

  • Entities maintaining personal data under OCPA must implement reasonable safeguards, commonly including risk assessment, access controls, encryption, employee training, and data minimization.
  • The Oregon Consumer Information Protection Act (ORS 646A.600) already places baseline data-security obligations on all entities holding Oregon residents' personal information, independent of OCPA.

Breach NotificationGreen

Breach notification obligations run through OCIPA: consumer notice within 45 days of discovery, and AG notice (with a sample notice) within 45 days if 250+ Oregon consumers are affected.

Claims (2):

  • Oregon law requires entities to notify any Oregon consumer whose personal information was subject to a breach of security within 45 days of discovering the breach.
  • If a breach impacts more than 250 Oregon consumers, the entity must also provide a report and a sample copy of the consumer breach notice to the Oregon DOJ within 45 days.

Retention And DisposalAmber

OCPA's principal retention-related duty found is the five-year retention of Data Protection Assessments; no general data-retention-limitation or disposal mandate distinct from data-minimization principles was located. Absent_field_provenance: searched DOJ FAQs and DPA guidance for retention/disposal schedules; none specified beyond the five-year DPA record rule.

Claims (1):

  • Data Protection Assessments must be kept on file by the controller for five years.
Category narrative30 words

OCPA imposes Data Protection Assessment obligations for heightened-risk processing, mandates processor contracts, and requires reasonable security safeguards; breach notification runs through the separate, older Oregon Consumer Information Protection Act (OCIPA).

Sources and claims (7)
  1. ConfirmedOregon DOJControllers must conduct a Data Protection Assessment before processing personal data in a manner presenting a heightened risk of harm to consumers, including targeted advertising, sale, profiling, and any processing of sensitive data.observed
  2. ConfirmedOregon DOJData Protection Assessments must be kept on file by the controller for five years.observed
  3. ConfirmedDataGuidance (OneTrust)Processors may only process data at the request and under the direction of a controller pursuant to a binding contract specifying processing instructions, nature, purpose, type of data, and duration, and processors must assist controllers in meeting OCPA obligations.observed
  4. ConfirmedOregon DOJEntities maintaining personal data under OCPA must implement reasonable safeguards, commonly including risk assessment, access controls, encryption, employee training, and data minimization.observed
  5. ConfirmedOregon DOJThe Oregon Consumer Information Protection Act (ORS 646A.600) already places baseline data-security obligations on all entities holding Oregon residents' personal information, independent of OCPA.observed
  6. ConfirmedOregon DOJOregon law requires entities to notify any Oregon consumer whose personal information was subject to a breach of security within 45 days of discovering the breach.observed
  7. ConfirmedOregon DOJIf a breach impacts more than 250 Oregon consumers, the entity must also provide a report and a sample copy of the consumer breach notice to the Oregon DOJ within 45 days.observed

#

Unregulated area within this jurisdiction's chosen statutory model — this is a legitimate finding of absence rather than a research gap.

Supervisory authorityOregon Department of Justice
Traffic-light rationale — RedUnregulated area within this jurisdiction's chosen statutory model — this is a legitimate finding of absence rather than a research gap.

Sub-modules (6)

Transfer MechanismsRed

No OCPA transfer-mechanism regime identified.

Adequacy ReceivedRed

Not applicable; Oregon does not operate an adequacy-recognition framework.

Adequacy GrantedRed

Not applicable.

Sccs And BcrsRed

No SCC/BCR concept exists under OCPA.

Transfer Impact AssessmentRed

No TIA requirement identified; heightened-risk Data Protection Assessments address in-state processing risk, not cross-border transfer risk specifically.

Data LocalisationRed

No data-localisation mandate identified in Oregon law.

Category narrative65 words

No cross-border transfer mechanism, adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime was located within the OCPA or associated Oregon DOJ guidance; unlike GDPR, US state comprehensive privacy statutes of this generation do not regulate international personal-data transfers as a distinct compliance obligation. Absent_field_provenance: searched OCPA text summaries, DOJ FAQs (business, consumer, nonprofit), six-month and one-year enforcement reports, and DataGuidance overview notes for transfer/adequacy/localisation provisions; none found.

#

Sectoral exemptions are clearly documented for financial (GLBA), health (HIPAA), credit (FCRA), employment, and insurance; telecoms/eprivacy and education-specific carve-outs were not separately confirmed.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589), exemption provisions at ORS 646A.572
Traffic-light rationale — AmberSectoral exemptions are clearly documented for financial (GLBA), health (HIPAA), credit (FCRA), employment, and insurance; telecoms/eprivacy and education-specific carve-outs were not separately confirmed.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA-covered financial data/entities are exempted from OCPA.

Claims (1):

  • OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.

Health Sector OverlayGreen

HIPAA-covered protected health information is exempted from OCPA.

Claims (1):

  • OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.

Telecoms And EprivacyRed

No telecoms-specific or ePrivacy-style overlay was identified for Oregon under OCPA. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no telecoms-sector carve-out or overlay found.

Employment DataGreen

OCPA expressly excludes data maintained for employment-record purposes and defines 'consumer' to exclude individuals acting as employees or job applicants.

Claims (1):

  • OCPA does not apply to data maintained for employment-record purposes, and 'consumer' under the statute excludes an individual acting as an employee or job applicant.

Credit And ScoringGreen

FCRA-covered credit reporting data/entities are exempted from OCPA.

Claims (1):

  • OCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.

EducationAmber

No education-sector-specific overlay (e.g., FERPA carve-out) was expressly confirmed in DOJ guidance reviewed. Absent_field_provenance: searched DOJ FAQs and enforcement reports; education-sector-specific treatment not separately documented.

InsuranceGreen

Certain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA even if they meet the general thresholds.

Claims (1):

  • Certain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA compliance even if they otherwise meet the statutory thresholds.
Category narrative25 words

OCPA carves out several sectoral overlaps rather than displacing them: GLBA, HIPAA, and FCRA-covered data/entities are exempted, as are employment records and certain insurance entities.

Sources and claims (3)
  1. ConfirmedOregon DOJOCPA does not apply to certain personal data maintained in compliance with specific federal privacy laws, including HIPAA, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act.observed
  2. ConfirmedOregon DOJOCPA does not apply to data maintained for employment-record purposes, and 'consumer' under the statute excludes an individual acting as an employee or job applicant.observed
  3. ConfirmedOregon DOJCertain insurers, insurance producers, and insurance consultants defined under Oregon law are excluded from OCPA compliance even if they otherwise meet the statutory thresholds.observed

#

Opt-out-signal and cross-context-advertising opt-out rights are clearly in force; cookie-specific and clean-room/data-collaboration rules are not separately addressed by the statute.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589)
Traffic-light rationale — AmberOpt-out-signal and cross-context-advertising opt-out rights are clearly in force; cookie-specific and clean-room/data-collaboration rules are not separately addressed by the statute.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie-consent regime (ePrivacy-style) was found; cookie-based tracking is addressed generally under the personal-data/opt-out framework. Absent_field_provenance: searched DOJ FAQs and OCPA summaries for a cookie-specific banner/consent mandate; none found distinct from general opt-out rights.

Dark PatternsAmber

Dark-pattern design is not named in the statute but is addressed via OCPA's consent and accessibility requirements.

Claims (1):

  • Dark-pattern design practices that impair a consumer's ability to give freely-given, informed consent may violate OCPA's accessibility and consent-definition requirements, and may separately implicate Oregon's Unlawful Trade Practices Act, even though OCPA does not use the term 'dark patterns.'

Opt Out SignalsGreen

As of January 1, 2026, controllers meeting OCPA thresholds must honor technically-compliant universal opt-out preference signals, such as Global Privacy Control, as valid opt-out requests.

Claims (1):

  • As of January 1, 2026, businesses and nonprofits meeting OCPA thresholds must honor opt-out preference signals meeting technical requirements, such as the Global Privacy Control, as a valid consumer opt-out request.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rules were identified in Oregon law. Absent_field_provenance: searched DOJ guidance and enforcement reports; no clean-room provisions found.

Cross Context AdvertisingGreen

Consumers may opt out of a controller's use of their data for targeted advertising and of sale to third parties, functionally analogous to CPRA's 'sale'/'share' opt-outs.

Claims (1):

  • Oregon consumers have the right to opt out of a controller selling their data, profiling them, or using their data for targeted advertising, exercisable manually or via a universal opt-out signal.

Direct MarketingAmber

No distinct direct-marketing consent/suppression regime separate from the general targeted-advertising opt-out was identified. Absent_field_provenance: searched DOJ FAQs; direct marketing is treated as a subset of targeted advertising/sale opt-out rights rather than a standalone regime.

Category narrative41 words

OCPA requires recognition of universal opt-out mechanisms (e.g., Global Privacy Control) from January 1, 2026, prohibits dark-pattern consent practices implicitly, and gives consumers opt-out rights over sale, targeted advertising, and certain profiling; a dedicated cookie-consent or clean-room regime was not identified.

Sources and claims (2)
  1. ConfirmedOregon DOJAs of January 1, 2026, businesses and nonprofits meeting OCPA thresholds must honor opt-out preference signals meeting technical requirements, such as the Global Privacy Control, as a valid consumer opt-out request.observed
  2. ProbableOregon DOJDark-pattern design practices that impair a consumer's ability to give freely-given, informed consent may violate OCPA's accessibility and consent-definition requirements, and may separately implicate Oregon's Unlawful Trade Practices Act, even though OCPA does not use the term 'dark patterns.'observed

#

Profiling opt-out and biometric/genetic sensitive-data classification are confirmed; there is no EU AI Act-style dedicated AI risk-assessment regime distinct from the general Data Protection Assessment duty, and ADM 'explanation rights' beyond opt-out were not located.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589)
Traffic-light rationale — AmberProfiling opt-out and biometric/genetic sensitive-data classification are confirmed; there is no EU AI Act-style dedicated AI risk-assessment regime distinct from the general Data Protection Assessment duty, and ADM 'explanation rights' beyond opt-out were not located.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling used to make decisions producing legal or similarly significant effects (e.g., financial services, housing, employment, healthcare).

Claims (1):

  • Oregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.

Automated Decision Making TransparencyAmber

Profiling is defined as automated processing to evaluate, analyze, or predict consumer attributes; the OCPA gives an opt-out right rather than a standalone explanation/transparency right akin to GDPR Art.22.

Claims (1):

  • Oregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.

Ai Risk AssessmentsAmber

No AI-specific risk-assessment regime distinct from the general heightened-risk Data Protection Assessment (which covers profiling) was identified. Absent_field_provenance: searched DOJ guidance and enforcement reports for AI-specific assessment obligations; none found beyond the general DPA duty covering profiling activities.

Biometric RegimeGreen

Biometric data is classified as sensitive data under OCPA and separately as personal information under the OCIPA breach-notification statute.

Claims (2):

  • Biometric data that could be used to identify an individual is classified as sensitive data under the OCPA.
  • Under the separate OCIPA breach-notification statute, 'personal information' includes biometric data from automatic measurements of a consumer's physical characteristics, such as fingerprint, retina, or iris images.

Genetic DataGreen

Genetic data is classified as sensitive data under OCPA, triggering heightened-risk consent and Data Protection Assessment obligations.

Claims (1):

  • Genetic data is classified as sensitive data under the OCPA, subject to consent and heightened-risk processing requirements.

State Surveillance CarveoutsAmber

OCPA does not apply to federal, state, or local governments.

Claims (1):

  • The Oregon privacy law does not apply to federal, state, or local governments.
Category narrative39 words

OCPA classifies biometric and genetic data as sensitive data requiring consent-based heightened protection, grants consumers an opt-out right against profiling used for legally or similarly significant decisions, and expressly excludes federal, state and local government bodies from its scope.

Sources and claims (5)
  1. ConfirmedOregon DOJOregon's privacy law gives consumers the right to opt out of profiling used to make decisions that may result in the consumer being given or denied financial, housing, insurance, educational, employment, healthcare, or other legally or similarly significant outcomes.observed
  2. ConfirmedOregon DOJBiometric data that could be used to identify an individual is classified as sensitive data under the OCPA.observed
  3. ConfirmedOregon DOJGenetic data is classified as sensitive data under the OCPA, subject to consent and heightened-risk processing requirements.observed
  4. ConfirmedOregon DOJThe Oregon privacy law does not apply to federal, state, or local governments.observed
  5. ConfirmedOregon DOJUnder the separate OCIPA breach-notification statute, 'personal information' includes biometric data from automatic measurements of a consumer's physical characteristics, such as fingerprint, retina, or iris images.observed

#

Core children's-data protections (parental consent, under-16 sale/targeted-ad/profiling ban) are clearly in force; age-verification, education-specific, and dependent-adult sub-modules are unaddressed in the statute.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589), as amended by HB 2008 (2025)
Traffic-light rationale — AmberCore children's-data protections (parental consent, under-16 sale/targeted-ad/profiling ban) are clearly in force; age-verification, education-specific, and dependent-adult sub-modules are unaddressed in the statute.

Sub-modules (5)

Age VerificationAmber

No dedicated age-verification mandate was identified in OCPA or DOJ guidance; obligations trigger on actual or constructive knowledge of a consumer's age. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no age-verification-technology mandate found.

Minor Profiling BansGreen

As of January 1, 2026, it is unlawful to sell the personal data of, or use for targeted advertising or certain profiling of, any consumer under 16.

Claims (2):

  • As of January 1, 2026, it is unlawful for businesses to sell the personal data of any consumer under 16 years of age or to use their personal data for targeted advertising or profiling.
  • The 2025 legislative amendment (HB 2008) bans controllers from selling or sharing for value the personal or sensitive data of a child or teen the controller knows or should have known is under 16.

Education SettingsRed

No education-setting-specific children's-data rule was identified beyond the general under-13/under-16 protections. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no education-specific minors' provision found.

Dependent AdultsRed

No dependent-adult/elderly-specific protection provision was identified in OCPA. Absent_field_provenance: searched DOJ FAQs, enforcement reports, and DataGuidance overview; no dependent-adult-specific rule found.

Category narrative35 words

OCPA and its 2025 amendment (HB 2008) impose parental-consent requirements for under-13 processing and expanded sale/targeted-advertising/profiling bans for consumers under 16, effective January 1, 2026; no age-verification mandate, education-setting-specific rule, or dependent-adult provision was identified.

Sources and claims (4)
  1. ConfirmedOregon DOJBusinesses must obtain consent from a parent or legal guardian before collecting, using, or otherwise processing personal data about a consumer the business knows to be under 13 years old.observed
  2. ConfirmedOregon DOJAs of January 1, 2026, it is unlawful for businesses to sell the personal data of any consumer under 16 years of age or to use their personal data for targeted advertising or profiling.observed
  3. ConfirmedOregon DOJThe 2025 legislative amendment (HB 2008) bans controllers from selling or sharing for value the personal or sensitive data of a child or teen the controller knows or should have known is under 16.observed
  4. ConfirmedOregon DOJHB 2008 clarifies that processing the data of children under 13 must still comply with the federal Children's Online Privacy Protection Act as recently updated and strengthened.observed

#

Enforcement powers, penalty caps, and two years of published enforcement-activity reports provide strong evidentiary grounding; the absence of a private right of action or collective-redress mechanism is a clearly documented structural feature rather than a gap.

Primary frameworkOregon Consumer Privacy Act (ORS 646A.570-646A.589)
Traffic-light rationale — GreenEnforcement powers, penalty caps, and two years of published enforcement-activity reports provide strong evidentiary grounding; the absence of a private right of action or collective-redress mechanism is a clearly documented structural feature rather than a gap.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AG may seek civil penalties up to $7,500 per violation plus injunctive relief, restitution, and disgorgement.

Claims (1):

  • Entities that violate the OCPA may face civil penalties up to $7,500 per violation, and the Attorney General may also seek injunctive relief, restitution, and/or disgorgement.

Enforcement Activity IndexGreen

DOJ has published six-month and one-year enforcement reports quantifying complaints and cure-notice matters.

Claims (2):

  • In the first year of OCPA enforcement, the Privacy Unit received 214 complaints and initiated and closed 38 cure-notice/inquiry matters.
  • In the first six months of OCPA enforcement, the Privacy Unit had received 110 complaints and initiated and closed 21 cure-notice matters.

Regulator Funding And CapacityAmber

The Legislature authorized dedicated Privacy Unit staffing given the lack of a private right of action.

Claims (1):

  • Given the lack of a private right of action and increased enforcement workload, the Oregon Legislature authorized three attorney and two specialized staff positions to enforce the OCPA, with the Privacy Unit expanding significantly within its first six months.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to OCPA was identified; enforcement is centralized in the AG. Absent_field_provenance: searched DOJ FAQs and enforcement reports; no class-action provision found within OCPA itself.

Claims (1):

  • The OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.

Private Right Of ActionRed

OCPA does not include a private right of action; only the Oregon Attorney General may enforce the law.

Claims (1):

  • The OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.

Recent Developments 180DGreen

Within the 180 days preceding this run, the OCPA's mandatory 30-day cure period sunset (January 1, 2026), universal opt-out signal recognition became mandatory, and the under-16 sale/targeted-advertising ban and geolocation-sale ban took effect.

Claims (2):

  • As of January 1, 2026, the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the OCPA violation, and may proceed directly to a Civil Investigative Demand or lawsuit.
  • As of January 1, 2026, Oregon's privacy law bans the sale of precise geolocation data of all Oregon consumers, defined as a radius of 1,750 feet covering present and past location data.
Category narrative48 words

The Oregon AG holds exclusive OCPA enforcement authority, with civil penalties up to $7,500 per violation plus injunctive relief, restitution and disgorgement; there is no private right of action. The Privacy Unit's cure-notice/30-day-cure requirement sunset on January 1, 2026, after which DOJ can proceed directly to enforcement action.

Sources and claims (7)
  1. ConfirmedOregon DOJThe OCPA does not include a private right of action; the Oregon Attorney General has sole enforcement power, and private individuals cannot file lawsuits against companies for violating the law.observed
  2. ConfirmedOregon DOJEntities that violate the OCPA may face civil penalties up to $7,500 per violation, and the Attorney General may also seek injunctive relief, restitution, and/or disgorgement.observed
  3. ConfirmedOregon DOJGiven the lack of a private right of action and increased enforcement workload, the Oregon Legislature authorized three attorney and two specialized staff positions to enforce the OCPA, with the Privacy Unit expanding significantly within its first six months.observed
  4. ConfirmedOregon DOJIn the first year of OCPA enforcement, the Privacy Unit received 214 complaints and initiated and closed 38 cure-notice/inquiry matters.observed
  5. ConfirmedOregon DOJIn the first six months of OCPA enforcement, the Privacy Unit had received 110 complaints and initiated and closed 21 cure-notice matters.observed
  6. ConfirmedOregon DOJAs of January 1, 2026, the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the OCPA violation, and may proceed directly to a Civil Investigative Demand or lawsuit.observed
  7. ConfirmedOregon DOJAs of January 1, 2026, Oregon's privacy law bans the sale of precise geolocation data of all Oregon consumers, defined as a radius of 1,750 feet covering present and past location data.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Oregon
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, controller_processor_duties (security/breach/DPA), children_and_vulnerable_groups, and enforcement_and_redress are grounded predominantly in T1 primary DOJ sources (OCPA FAQs, Data Protection Assessment Guidelines, data-breach page) supplemented by T2 DOJ enforcement reports for activity metrics and recent developments. sectoral_watch and adtech_and_commercial_privacy sub-modules on exemptions and opt-out signals rest on T1 DOJ FAQ sources; processor-contract detail in controller_processor_duties.joint_controller_arrangements and lawful_processing_and_special_data.pseudonymisation_and_anonymisation relied on a T3 DataGuidance legacy opinion piece cross-referencing statutory citations, as the underlying statute text (ORS 646A.570-646A.589) itself was not directly fetched. cross_border_and_adequacy carries zero claims with an explicit absent_field_provenance rationale, reflecting a genuine regulatory gap in this statutory model rather than a research shortfall. DPO requirements, ROPA, cookie-specific rules, clean-room rules, age-verification, education-settings, and dependent-adult sub-modules similarly carry absent_field_provenance rather than fabricated obligations.

Unresolved questions (4):

  • Has the Oregon DOJ issued any binding implementing rules/regulations beyond FAQs and guidance documents, and would these change any in_force claims?
  • Are there OCPA-adjacent 2026 legislative session amendments (post one-year report, dated August 2025) not yet reflected in DOJ FAQ pages as retrieved?
  • Does Oregon's separate data broker registration statute (outside ORS 646A.570-646A.589) impose filing obligations that should be more fully scoped under regulator_registration_and_filing?
  • Is there any education-sector-specific (FERPA-interface) or dependent-adult-specific provision in the full statutory text (ORS 646A.570-646A.589) not captured in DOJ's plain-language FAQ summaries?

Escalate to primary-source review: yes