EnglishEspañol
Oregon flag

Oregon

Oregon Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Oregon Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Oregon residents of a data breach?

Oregon requires notification in the most expeditious manner possible, without unreasonable delay, and no later than 45 days after discovering or receiving notice of the breach under ORS 646A.604. The clock starts on the date of discovery, not the date the breach occurred. Notice may be delayed only if a law enforcement agency determines it would impede a criminal investigation and requests the delay in writing.

When must the Oregon Attorney General be notified of a data breach?

The Oregon Department of Justice must be notified when a breach affects more than 250 Oregon consumers. A sample copy of the consumer notice and the number of affected individuals must be provided. That copy is still required under ORS 646A.604(10) even when an exemption applies. Consumer reporting agencies must also be notified when a breach affects more than 1,000 consumers.

Does Oregon require businesses to maintain security safeguards before a breach occurs?

Yes. Under ORS 646A.622, a covered entity and a vendor must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of personal information. This is a standalone obligation, separate from breach notification, and failure to comply is itself an unlawful trade practice.

Can a business skip notifying consumers after an Oregon data breach?

Sometimes. Under ORS 646A.604(8), a covered entity does not need to notify consumers if, after an appropriate investigation or after consulting relevant law enforcement agencies, it reasonably determines that affected consumers are unlikely to suffer harm. The determination must be documented in writing and kept for at least five years, and a copy of any notice still goes to the Attorney General when a breach affects more than 250 consumers.

Does Oregon's breach notification law cover biometric data and health information?

Yes, with limits. Oregon covers data from automatic measurements of physical characteristics, such as an image of a fingerprint, retina, or iris, but only where those measurements are used to authenticate identity in the course of a financial or other transaction. It covers a health insurance policy or subscriber number only in combination with another unique identifier the health insurer uses for that consumer. It also covers medical information, passport numbers, and username and password combinations that enable account access.

What penalties does Oregon impose for failing to provide breach notification?

Violations can result in civil penalties of up to $1,000 per violation, with a cap of $500,000 for a continuing violation, which the Director of the Department of Consumer and Business Services may impose under ORS 646A.624. Separately, the Attorney General may enforce the law as an unlawful trade practice under Oregon's Unlawful Trade Practices Act.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Updated Oregon's breach notification page to the current ORS 646A text: the inadvertent-acquisition exception replaces the repealed good faith language, the law enforcement delay now requires a written request and carries no national security ground, and the ORS 646A.604(8) risk-of-harm exemption and ORS 646A.604(10) Attorney General copy requirement have been added.

Corrected the Attorney General and credit-bureau notification thresholds (they trigger above 250 and 1,000 affected Oregon consumers, not at those numbers), clarified that the $1,000-per-violation/$500,000 civil penalty is imposed by the DCBS Director rather than the Attorney General, and added the statute's username/password PII category, vendor 10-day notice deadline, credit-monitoring-offer conditions, and required consumer-reporting-agency contact information.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. ORS 646A.600-628 - Oregon Consumer Information Protection Act(oregonlegislature.gov).gov
  2. Oregon SB 601 (2015) - Breach Notification Amendments(oregonlegislature.gov).gov
  3. Oregon DOJ - Data Security Breaches Portal(justice.oregon.gov).gov
  4. Oregon DFR - Consumer Information Protection Act Guide(dfr.oregon.gov).gov
Share: