EnglishEspañol
Oregon flag

Oregon

Oregon Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

Oregon Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Oregon have a standalone biometric privacy law like Illinois?

No. Oregon does not have a dedicated biometric privacy statute. Instead, the Oregon Consumer Privacy Act (OCPA), effective July 1, 2024, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The OCPA requires businesses to obtain opt-in consent before processing biometric data. Portland separately bans facial recognition technology in places of public accommodation through City Code Chapter 34.10.

Can I find out exactly which companies received my biometric data in Oregon?

Yes. Under ORS 646A.574, you can ask any covered business for a list of specific third parties that received personal data. At the controller's option, the response may name the third parties that received your data specifically or the third parties to which it disclosed any consumer's data. This goes beyond most other states, which require disclosure only of categories of recipients like analytics companies or data brokers. Minnesota adopted the same right effective July 31, 2025, so Oregon is one of a small number of states offering it rather than the only one.

Does Portland's facial recognition ban apply to all businesses?

Portland's ban applies to private entities using facial recognition technology in places of public accommodation, which includes restaurants, retail stores, hotels, entertainment venues, and similar public-facing locations. It does not apply to private clubs, religious organizations, or private residences. Exemptions exist for legal compliance, personal device unlock features, and social media auto-detection. The ban carries penalties of $1,000 per day or actual damages, whichever is greater.

Does the OCPA protect my biometric data at work?

The OCPA exempts data collected in an employment context. If your employer collects fingerprints for timekeeping or uses biometric scanners for building access, the OCPA does not regulate that activity. However, Oregon's breach notification law (ORS 646A.600-628) still applies if employer-held biometric data is compromised in a data breach, requiring notification within 45 days.

What penalties can businesses face for mishandling biometric data in Oregon?

Under the OCPA, the Oregon Attorney General can impose civil penalties of up to $7,500 per violation. The 30-day cure notice requirement narrowed on January 1, 2026 to a small class of noncommercial educational broadcast stations and was repealed on July 1, 2026, so the AG can now act against any controller without first issuing a cure notice. In Portland, the facial recognition ban allows individuals to sue for $1,000 per day of violation or actual damages, whichever is greater, plus attorney fees. Oregon's breach notification law also requires businesses to notify affected consumers within 45 days if biometric data is exposed in a breach.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the claim that Oregon is the only state giving consumers a right to a list of specific third parties (Minnesota adopted the same right effective July 31, 2025), and clarified that the OCPA cure notice requirement narrowed on January 1, 2026 to certain noncommercial educational broadcast stations before being repealed outright on July 1, 2026.

Corrected the citation for the biometric opt-in consent requirement (ORS 646A.578, not 646A.572), fixed the breach-law Attorney General reporting threshold to 'more than 250' Oregon consumers, added coverage of HB 2008 (2025)'s January 1, 2026 ban on selling precise geolocation data and new under-16 data protections, and restored the statutory qualifier that breach-law biometric data must be used for identity authentication in a transaction.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Oregon Consumer Privacy Act (OCPA)(oregonlegislature.gov).gov
  2. Oregon DOJ Privacy Law FAQs for Businesses(doj.state.or.us).gov
  3. Portland City Code Chapter 34.10 - Facial Recognition Ban(portland.gov).gov
  4. Portland Facial Recognition Ban Purpose (Section 34.10.010)(portland.gov).gov
  5. Portland Facial Recognition Ban Definitions (Section 34.10.020)(portland.gov).gov
  6. Portland Facial Recognition Ban Exceptions (Section 34.10.040)(portland.gov).gov
  7. Portland City Council Approves Facial Recognition Ban(portland.gov).gov
  8. Oregon DOJ Data Breaches - Breach Notification Requirements(doj.state.or.us).gov
  9. Oregon DOJ OCPA One-Year Enforcement Report(doj.state.or.us).gov
  10. Oregon DOJ Universal Opt-Out Mechanism Announcement(doj.state.or.us).gov
  11. Oregon DOJ Data Breach Reporting Portal(justice.oregon.gov).gov
  12. Minn. Stat. 325M.14 - Minnesota Consumer Data Privacy Act, consumer rights (specific third-party disclosure list, subd. 1(h))(revisor.mn.gov)
Share: