Oregon
Oregon Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Under ORS 646A.604, Oregon requires businesses to notify affected consumers of a data breach as soon as practicable and no later than 45 days after discovery. The Oregon Attorney General must also be notified when a breach affects more than 250 residents. Penalties can reach $500,000 for a continuing violation.
If your business handles personal information belonging to Oregon residents, a data breach triggers specific legal obligations under the Oregon Consumer Information Protection Act. ORS 646A.600 through 646A.628 sets out who must be notified, what information triggers the duty, and how quickly you need to act. Originally enacted in 2007, strengthened through Senate Bill 601 (2015), and substantially rewritten by the 2019 amendments (2019 Or Laws ch. 180), Oregon's law stands out for its broad definition of personal information, strict 45-day notification deadline, and separate requirement to maintain reasonable security safeguards.
This guide covers the full scope of Oregon's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, enforcement penalties, exemptions, and how the law connects to the state's broader data privacy framework.

Who Must Comply With Oregon's Breach Notification Law
Oregon's breach notification law applies to a covered entity. Under ORS 646A.602(5), that means a person that owns, licenses, maintains, stores, manages, collects, processes, acquires, or otherwise possesses personal information in the course of the person's business, vocation, occupation, or volunteer activities. This covers a wide range of entities, including for-profit businesses, nonprofits, and volunteer organizations. A person is not a covered entity to the extent that it acts solely as a vendor.
Vendors carry their own separate duties. A vendor is a person a covered entity contracts with to maintain, store, manage, process, or otherwise access personal information on the covered entity's behalf. If a vendor discovers a breach or has reason to believe one occurred, it must notify the covered entity as soon as practicable but no later than 10 days after discovery, under ORS 646A.604(2)(a). The covered entity then carries the primary obligation to notify affected consumers and regulators. Under ORS 646A.604(2)(c), a vendor must notify the Attorney General directly if its breach involved the personal information of more than 250 consumers, or a number of consumers the vendor could not determine, unless the covered entity has already notified the Attorney General.
Oregon's law applies to businesses located outside the state if they hold data belonging to Oregon residents.
What Qualifies as a Breach of Security
Under ORS 646A.602, a breach of security means the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information that a person maintains or possesses.
The "materially compromises" threshold means not every unauthorized access triggers notification. The access must create a meaningful impact on the security or confidentiality of the data.
Inadvertent Acquisition Exception
A breach of security does not include an inadvertent acquisition of personal information by a person or the person's employee or agent, provided the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information.
The 2019 amendments replaced Oregon's older "good faith acquisition" language with this narrower standard. The questions now are whether the acquisition was inadvertent and whether the information was misused or put at actual risk, not whether an employee acquired it for a business purpose.
The Encryption Safe Harbor
Oregon provides a conditional encryption safe harbor. Encrypted or redacted data does not trigger notification, unless the encryption key has also been acquired during the breach. If both the encrypted data and the key are compromised, the safe harbor does not apply and notification is required.
This is a critical distinction from states that provide an unconditional encryption safe harbor. Businesses should not assume encryption alone eliminates notification obligations.

What Personal Information Triggers the Law
Oregon has one of the broadest definitions of personal information among state breach notification laws. Under ORS 646A.602, personal information means a consumer's first name or first initial and last name in combination with any of the following data elements, when not rendered unusable through encryption, redaction, or other methods:
- Social Security number
- Driver license number or state identification card number issued by the Department of Transportation
- Passport number or other identification number issued by the United States
- Financial account number, credit card number, or debit card number, in combination with any required security code, access code, or password that would permit access to the account
- Data from automatic measurements of a consumer's physical characteristics, such as an image of a fingerprint, retina, or iris, that are used to authenticate the consumer's identity in the course of a financial transaction or other transaction
- Health insurance policy number or health insurance subscriber identification number, in combination with any other unique identifier that a health insurer uses to identify the consumer
- Medical information, meaning any information about a consumer's medical history or mental or physical condition, or about a health care professional's medical diagnosis or treatment of the consumer
Note that the biometric element and the health insurance element both carry qualifiers that are easy to miss. Oregon covers physical measurements only where they are used to authenticate identity in a transaction, and it covers a health insurance number only when it is paired with another identifier the health insurer uses for that consumer.
Oregon also treats a username or other account identifier, together with any password or other method needed to authenticate it, as personal information on its own under ORS 646A.602(12)(a)(B). Unlike the elements above, this category does not require combination with the consumer's name.
Additionally, Oregon provides a standalone trigger: any of the above data elements, even without a name or username, qualifies as personal information if it has not been rendered unusable and would enable a person to commit identity theft.
Personal information does not include information in federal, state, or local government records (other than Social Security numbers) that is lawfully made available to the public.
Notification Timeline
Oregon imposes a firm 45-day deadline. Under ORS 646A.604, notification must be provided to affected consumers in the most expeditious manner possible, without unreasonable delay, and no later than 45 days after discovering or receiving notification of the breach.
The 45-day clock starts from the date of discovery, not the date the breach occurred. There is no general extension of that deadline for investigation purposes, although the risk-of-harm exemption described below can remove the duty to notify consumers altogether.
Law Enforcement Delay
Under ORS 646A.604(3)(c), a covered entity may delay notification only if a law enforcement agency determines that notification will impede a criminal investigation and the agency requests in writing that the covered entity delay the notification. Both conditions must be met, so an oral or informal request from an investigator does not authorize a delay, and there is no national security ground for delay in the Oregon statute. Keep the written request on file, because it is the record of why the 45-day deadline in ORS 646A.604(3)(a) was extended.
Who Must Be Notified
Affected Individuals
Unless the risk-of-harm exemption below applies, every Oregon consumer whose personal information was subject to a breach of security must receive notification. The notice must include:
- A description of the incident in general terms
- The approximate date of the breach
- The type of personal information subject to the breach
- Contact information for the covered entity
- Contact information for national consumer reporting agencies
- Advice to the consumer to report suspected identity theft to law enforcement, including the Federal Trade Commission and the Oregon Attorney General
Attorney General
The Oregon Department of Justice Consumer Protection Division must be notified when a breach affects more than 250 Oregon consumers. The AG notification must include a copy of the notice sent to consumers and the number of affected individuals.
Oregon's 250-person AG notification threshold is among the lowest in the country, ensuring the Attorney General has visibility into relatively small breaches.
Consumer Reporting Agencies
When a breach affects more than 1,000 Oregon consumers, the entity must also notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. The CRA notification must include the timing, distribution, and content of the consumer notice, along with any police report number assigned to the breach.
Credit Monitoring Offers
If a business chooses to offer free credit monitoring or identity theft prevention services in connection with a breach notice, ORS 646A.604(7) bars conditioning that offer on the consumer providing a credit or debit card number or accepting a separate paid service. Any additional service offered for a fee must be clearly and conspicuously disclosed as carrying a charge. Oregon law does not require businesses to offer credit monitoring after a breach; it only regulates the terms of an offer a business chooses to make.
Methods of Notification
Businesses can provide notification through:
- Written notice sent to the consumer's postal address in the most current records of the person
- Electronic notice, if the covered entity customarily communicates with the consumer electronically or the notice is consistent with the federal E-SIGN Act
- Telephone notice directly to the affected consumer
Substitute Notice
Substitute notice is available if the person demonstrates that:
- The cost of providing direct notice would exceed $250,000, or
- The affected class exceeds 350,000 consumers, or
- The person does not have sufficient contact information
Note that Oregon's substitute notice threshold for affected class size (350,000) is lower than the 500,000 threshold used in many states.
Substitute notice must include: conspicuous posting of the notice or a link to it on the covered entity's website, and notification to major statewide television and newspaper media.

Enforcement and Penalties
Attorney General Enforcement
A violation of ORS 646A.604 (breach notification) or ORS 646A.622 (reasonable safeguards) is an unlawful trade practice under ORS 646.607, which the Oregon Attorney General enforces through the state's Unlawful Trade Practices Act.
DCBS Director Enforcement and Civil Penalties
Separately, ORS 646A.624 gives the Director of the Department of Consumer and Business Services (DCBS) independent authority to investigate violations, subpoena witnesses, and issue cease-and-desist orders. Under this authority, the penalty structure is:
- Up to $1,000 per violation
- Up to $500,000 for a continuing violation
These civil penalties are imposed by the DCBS Director, not the Attorney General. The $500,000 cap for continuing violations makes Oregon's penalty structure among the more significant in the country, particularly for businesses that knowingly delay notification or fail to maintain required safeguards.
No Express Private Right of Action
Oregon's breach notification statute does not create an express private right of action. However, because violations are classified as unlawful trade practices, consumers may have remedies under Oregon's general Unlawful Trade Practices Act, which does provide for private enforcement in certain circumstances.
Reasonable Safeguards Requirement
Unlike many states that focus solely on breach notification, Oregon imposes a separate obligation to maintain reasonable safeguards. Under ORS 646A.622, a covered entity and a vendor must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of personal information, including safeguards that protect the information at disposal.
This means Oregon businesses face compliance obligations before any breach occurs. Failure to maintain reasonable safeguards is itself a violation, regardless of whether a breach has happened.
The statute also sets out ways to comply, including running an information security program with administrative, technical, and physical safeguards scaled to the volume and nature of the personal information held. That gives businesses flexibility but also sets a minimum standard that scales with the sensitivity and amount of data.
Exemptions
Risk-of-Harm Exemption
Under ORS 646A.604(8), a covered entity does not need to notify consumers of a breach of security if, after an appropriate investigation or after consultation with relevant federal, state, or local law enforcement agencies, it reasonably determines that the consumers whose personal information was subject to the breach are unlikely to suffer harm. The covered entity must document that determination in writing and maintain the documentation for at least five years.
This is a determination the business makes itself rather than one a regulator approves in advance, so the written record is what supports the decision if it is questioned later.
HIPAA Compliance Exemption
Entities subject to and in compliance with HIPAA's breach notification requirements are deemed in compliance with Oregon's law.
Financial Institution Exemption
Financial institutions subject to and in compliance with the Gramm-Leach-Bliley Act's breach notification guidelines are also exempt.
Compliance With Other Notification Rules
An entity that already provides breach notice under rules that another law, regulation, or its primary functional regulator imposes, with protections at least as rigorous as Oregon's, is deemed in compliance with the state's notification requirements under ORS 646A.604(9). Oregon law does not offer a safe harbor merely for following an internal notification policy.
The Attorney General Copy Is Still Required
The exemptions in ORS 646A.604(9) do not switch off the Attorney General. Under ORS 646A.604(10), a person, covered entity, or vendor must still provide the Attorney General, within a reasonable time, at least one copy of any notice it sends to consumers or to its primary or functional regulator as a consequence of a breach, whenever the breach affects more than 250 consumers.
This article provides general legal information about Oregon data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Oregon for guidance specific to your situation.
More Oregon Laws
Frequently Asked Questions
How quickly must a business notify Oregon residents of a data breach?
Oregon requires notification in the most expeditious manner possible, without unreasonable delay, and no later than 45 days after discovering or receiving notice of the breach under ORS 646A.604. The clock starts on the date of discovery, not the date the breach occurred. Notice may be delayed only if a law enforcement agency determines it would impede a criminal investigation and requests the delay in writing.
When must the Oregon Attorney General be notified of a data breach?
The Oregon Department of Justice must be notified when a breach affects more than 250 Oregon consumers. A sample copy of the consumer notice and the number of affected individuals must be provided. That copy is still required under ORS 646A.604(10) even when an exemption applies. Consumer reporting agencies must also be notified when a breach affects more than 1,000 consumers.
Does Oregon require businesses to maintain security safeguards before a breach occurs?
Yes. Under ORS 646A.622, a covered entity and a vendor must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of personal information. This is a standalone obligation, separate from breach notification, and failure to comply is itself an unlawful trade practice.
Can a business skip notifying consumers after an Oregon data breach?
Sometimes. Under ORS 646A.604(8), a covered entity does not need to notify consumers if, after an appropriate investigation or after consulting relevant law enforcement agencies, it reasonably determines that affected consumers are unlikely to suffer harm. The determination must be documented in writing and kept for at least five years, and a copy of any notice still goes to the Attorney General when a breach affects more than 250 consumers.
Does Oregon's breach notification law cover biometric data and health information?
Yes, with limits. Oregon covers data from automatic measurements of physical characteristics, such as an image of a fingerprint, retina, or iris, but only where those measurements are used to authenticate identity in the course of a financial or other transaction. It covers a health insurance policy or subscriber number only in combination with another unique identifier the health insurer uses for that consumer. It also covers medical information, passport numbers, and username and password combinations that enable account access.
What penalties does Oregon impose for failing to provide breach notification?
Violations can result in civil penalties of up to $1,000 per violation, with a cap of $500,000 for a continuing violation, which the Director of the Department of Consumer and Business Services may impose under ORS 646A.624. Separately, the Attorney General may enforce the law as an unlawful trade practice under Oregon's Unlawful Trade Practices Act.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Updated Oregon's breach notification page to the current ORS 646A text: the inadvertent-acquisition exception replaces the repealed good faith language, the law enforcement delay now requires a written request and carries no national security ground, and the ORS 646A.604(8) risk-of-harm exemption and ORS 646A.604(10) Attorney General copy requirement have been added.
Corrected the Attorney General and credit-bureau notification thresholds (they trigger above 250 and 1,000 affected Oregon consumers, not at those numbers), clarified that the $1,000-per-violation/$500,000 civil penalty is imposed by the DCBS Director rather than the Attorney General, and added the statute's username/password PII category, vendor 10-day notice deadline, credit-monitoring-offer conditions, and required consumer-reporting-agency contact information.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Oregon Revised Statutes, Chapter 646A: Trade Regulation
§ 646A.604Notice of breach of security; delay; methods of notification; contents of notice; application of notice requirementIn forcecited in 2 of our articles
(1) If a covered entity is subject to a breach of security or receives notice of a breach of security from a vendor, the covered entity shall give notice of the breach of security to: (a) The consumer to whom the personal information pertains. (b) The Attorney General, either in writing or electronically, if the number of consumers to whom the covered entity must send the notice described in paragraph (a) of this subsection exceeds 250. (2)(a) A vendor that discovers a breach of security or has reason to believe that a breach of security has occurred shall notify a covered entity with which the vendor has a contract as soon as is practicable but not later than 10 days after discovering the breach of security or having a reason to believe that the breach of security occurred. (b) If a vendor has a contract with another vendor that, in turn, has a contract with a covered entity, the vendor shall notify the other vendor of a breach of security as provided in paragraph (a) of this subsection.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Eldred v. Oregon Anesthesiology Group (Court of Appeals of Oregon 2026, 347 Or. App. 169)“…that expose consumers’ personal information. ORS 646A.602; ORS 646A.604; ORS 646A.620; ORS 646A.622. Section 5…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Oregon Identity Theft Laws: ORS 165.800 and 165.803 Explained
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- ORS 646A.600-628 - Oregon Consumer Information Protection Act(oregonlegislature.gov).gov
- Oregon SB 601 (2015) - Breach Notification Amendments(oregonlegislature.gov).gov
- Oregon DOJ - Data Security Breaches Portal(justice.oregon.gov).gov
- Oregon DFR - Consumer Information Protection Act Guide(dfr.oregon.gov).gov