US Privacy Law Oregon, USA

Oregon OCDPA: Consumer Privacy Act Requirements

Oregon's OCDPA: the right to a list of specific third parties, no entity-level GLBA exemption, nonprofit coverage, sensitive-data consent, and AG enforcement.

Regulation

Oregon Consumer Privacy Act (SB 619), ORS 646A.570 et seq., effective July 1, 2024

Max Penalty

Up to $7,500 per violation, plus injunctive relief

Enforcing Authority

Oregon Attorney General

Official Source

www.doj.state.or.us

Executive Summary

  • The OCDPA (effective July 1, 2024; nonprofits July 1, 2025) covers businesses processing personal data of 100,000+ Oregon consumers annually, or 25,000+ with over 25% of revenue from selling personal data.
  • Its signature feature: consumers may demand a list of the specific third parties to whom the controller disclosed their personal data (or any personal data), not just categories, the only state law with this right at launch.
  • Oregon narrows the usual exemptions: no entity-level GLBA carve-out (only data-level), no blanket HIPAA entity exemption, and nonprofits are covered after a one-year delay.
  • Sensitive data, including a distinctive category for status as a victim of crime and transgender or nonbinary status, requires opt-in consent; universal opt-out signal recognition became mandatory January 1, 2026.
  • The AG's Privacy Unit publishes enforcement reports: its first-six-months report logged over 100 complaints and cure notices focused on missing rights mechanisms and confusing disclosures; the 30-day cure period sunsets January 1, 2026.

Oregon took Virginia’s template and closed its escape hatches. Banks are covered for their non-GLBA data, hospitals for their non-HIPAA data, nonprofits after a year’s grace, and every controller faces the law’s genuinely novel demand: name the specific third parties you gave data to, not the comfortable categories. That one right converts vendor management from internal hygiene into consumer-visible fact.

LawOCDPA, ORS 646A.570 et seq.
EffectiveJuly 1, 2024 (nonprofits 2025; UOOM + cure sunset Jan 1, 2026)
Max penalty$7,500 per violation
RegulatorOregon DOJ Privacy Unit
StatuteSB 619 (2023)

Building for Oregon’s distinctives

The disclosure register. Maintain a live mapping of third-party recipients (names, data categories, dates) exportable per consumer request. If your CCPA service-provider inventory is current, this is a reporting layer on top; if it is not, Oregon makes the gap a consumer-visible violation. Expect the list to be read by journalists and plaintiffs’ firms.

Exemption re-analysis. Financial institutions, healthcare organizations, and nonprofits that scoped themselves out of state privacy programs need an Oregon-specific pass: which data is actually GLBA/HIPAA-regulated (exempt) versus everything else (covered). Marketing data at a hospital is the canonical covered remainder.

Consent breadth. The added sensitive categories mean segments like “crime victims” (insurance, legal marketing) and gender-identity data (healthcare, community platforms) need opt-in consent here even where other states are silent. Fold them into your state sensitive-data matrix.

Standard machinery. 45-day DSARs with appeals, processor contracts, data protection assessments for heightened-risk processing, GPC honoring from 2026, and the broker registry under HB 2052 if you sell third-party data, all shareable with your Colorado/Texas builds. The state comparison places Oregon among the strictest tier.

Start with what Oregon’s Privacy Unit checks first, visible opt-outs and notices matching reality: run a free scan.

Frequently Asked Questions

What is the specific-third-parties right?

Under ORS 646A.574, a consumer may obtain, at the controller's option, a list of the specific third parties (names, not categories) to which the controller has disclosed either that consumer's personal data or any personal data. Every other early state law stops at categories. Operationally this requires a maintained third-party disclosure register per data category, exportable on request, your vendor list becomes consumer-facing.

Which usual exemptions does Oregon refuse?

Three that matter: financial institutions get only a data-level GLBA exemption (the institution itself is covered for non-GLBA data), there is no entity-level HIPAA exemption (only protected health information itself is exempt), and nonprofits are covered from July 1, 2025, with narrow exceptions. Banks, insurers, hospitals, and charities that ignore state privacy laws elsewhere cannot ignore Oregon.

What counts as sensitive data in Oregon?

The Virginia list plus Oregon additions: racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a victim of crime, citizenship or immigration status, genetic or biometric data, precise geolocation (1,750 feet), and known-child data. All require prior opt-in consent. The crime-victim and gender-identity categories are unique and matter for media, advocacy, health, and insurance datasets.

When did universal opt-out signals become mandatory?

January 1, 2026: controllers must honor recognized opt-out preference signals (GPC in practice) as valid opt-outs of targeted advertising and sale, aligning Oregon with Colorado, Texas, and Connecticut. Controllers running a national GPC pipeline were compliant on arrival; Oregon-only businesses had an eighteen-month runway from the law's effective date.

How is Oregon enforcing?

Through the DOJ's dedicated Privacy Unit, with a taste for transparency: it publishes periodic enforcement reports describing complaint volumes and cure-notice themes. Early reports flagged failures to offer the specific-third-party list, buried or missing opt-outs, and privacy notices contradicting actual practices. Cure rights (30 days) expire January 1, 2026, after which the AG can seek up to $7,500 per violation immediately. There is no private right of action.

Regulatory Crosswalk

Colorado CPAVirginia VCDPAOregon HB 2052 (broker registry)

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.