EnglishEspañol
Oregon flag

Oregon

OCPA Compliance Checklist for Oregon Businesses

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 8, 2026. · 3 primary sources cited on this page. How we verify our legal content

OCPA Compliance Checklist for Oregon Businesses

Frequently Asked Questions

How do I know if my business is subject to the OCPA?

Apply the test in ORS 646A.572(1). The OCPA covers any person doing business in Oregon or serving Oregon residents that, in a calendar year, controls or processes the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data. Oregon uses no dollar-revenue floor, so a business can be covered on data volume alone. Exclude data used solely to complete a payment transaction when counting toward the 100,000 threshold. One rule applies regardless of these thresholds. Under ORS 646A.572(1)(b), added by HB 3875 (2025), the OCPA applies to a motor vehicle manufacturer, and to any affiliate of a motor vehicle manufacturer, that controls or processes any personal data obtained from a consumer's use of a motor vehicle or any component of a motor vehicle, subject to the exemptions in ORS 646A.572(2) and (3). The trigger is vehicle-derived data, not simply being an automaker.

Does the OCPA exempt financial institutions and nonprofits?

Not as broadly as most states for HIPAA. Under ORS 646A.572(2), Oregon exempts HIPAA-covered protected health information only at the data level, with no blanket exemption for healthcare entities, and it covers most nonprofit organizations rather than exempting them. GLBA is treated more broadly: Oregon exempts GLBA-compliant data at the data level and also grants a full entity-level exemption to financial institutions and their financial-activity affiliates and subsidiaries. Only narrow nonprofit categories, such as a nonprofit that detects insurance fraud, are carved out. Because most nonprofits are covered, the legislature gave them a delayed effective date of July 1, 2025. Map each data set and entity against the exemption list rather than assuming one status removes the whole organization.

When must my business honor a universal opt-out signal?

As of January 1, 2026. Under ORS 646A.578, a controller that processes personal data for targeted advertising or that sells personal data must let consumers opt out through a universal opt-out mechanism. The Oregon DOJ has identified Global Privacy Control as a qualifying signal. To comply, build the technical capability to detect the signal and treat it as a valid opt-out from targeted advertising and sale. The signal must reflect the consumer's affirmative choice, not a browser default.

What does the specific third-party list right require me to build?

Under ORS 646A.574(1)(a)(B), a consumer can request a list of the specific named third parties, other than natural persons, to which you disclosed their personal data, or at your option any personal data. Unlike the category-level disclosure most states require, this demands tracking disclosures at the level of identifiable recipients. To satisfy it, maintain a data map of which specific organizations received personal data and build a workflow that can generate the list when a consumer asks. This is one of the harder OCPA capabilities to engineer.

When are data protection assessments required under the OCPA?

Under ORS 646A.586, a controller must conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm. The named high-risk categories are processing for targeted advertising, the sale of personal data, processing sensitive data, and certain profiling that risks unfair or deceptive treatment or unlawful disparate impact, financial, physical, or reputational injury, or intrusion on a consumer's solitude, seclusion, or private affairs. The assessment must weigh benefits against risks, and the Attorney General may request it during an investigation. Assessments are not retroactive.

What changed about OCPA enforcement in 2026?

The 30-day right to cure sunset on January 1, 2026. Through 2025, the Oregon Attorney General had to notify a controller and allow 30 days to fix a violation before bringing an action, but only when the Attorney General first determined the violation was curable. It was not an automatic grace period for every violation. As of 2026, that guaranteed window is gone for ordinary businesses. The Attorney General may still choose to allow a cure but is no longer required to offer one, so a business can no longer count on a grace period before enforcement. One narrow exception survives: under sections 4 to 6, chapter 417, Oregon Laws 2025, a notice-and-30-day-cure requirement still applies to a controller that is a qualifying noncommercial educational broadcast station under 47 U.S.C. 397, and that carve-out is itself repealed on July 1, 2026. Civil penalties run up to $7,500 per violation under ORS 646A.589(4)(a).

What are the penalties for violating the OCPA?

Under ORS 646A.589(4)(a), the Oregon Attorney General may seek a civil penalty of up to $7,500 for each violation. The per-violation structure means a systemic failure affecting many consumers can accumulate quickly. Enforcement is exclusive to the Attorney General under ORS 646A.589(7); there is no private right of action, so consumers cannot sue businesses directly but may submit complaints to the Oregon Department of Justice, which can investigate and seek penalties.

Do I need a contract with my data processors?

Yes. Under ORS 646A.581, a controller that uses a processor must have a binding contract that sets out the processing instructions, nature, purpose, data types, and duration, and that imposes duties such as confidentiality, deletion or return of data at the end of the engagement, cooperation with assessments, and flow-down terms to any subcontractor. Sharing personal data with a vendor without these contractual terms in place is a compliance gap the Attorney General can act on.

Updates

Corrected the OCPA motor vehicle manufacturer rule to state its codified cite, its vehicle-data trigger, its extension to affiliates and its exemptions, and noted the narrow noncommercial educational broadcast station cure period that runs until July 1, 2026.

Added coverage of two enacted 2025 amendments to the OCPA that are now current law: HB 2008's outright ban on selling precise geolocation data and the personal data of consumers known to be under 16 (effective January 1, 2026), and HB 3875's extension of OCPA coverage to all automobile manufacturers regardless of the consumer-count thresholds (effective September 26, 2025). Corrected the description of Oregon's GLBA exemption, which includes a genuine entity-level exemption for financial institutions, not just a data-level carve-out. Completed the statutory list of risk factors for data protection assessments, and clarified that the pre-2026 30-day cure right applied only when the Attorney General determined a violation was curable.

Independently fact-checked against the cited primary sources

Fixed the Attorney General exclusive-enforcement citation from ORS 646A.589(8) to the correct subsection (7).

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. ORS 646A.572: Applicability and Exemptions(oregon.public.law)
  2. ORS 646A.578: Controller Duties, Privacy Notice, Sensitive-Data Consent, and Universal Opt-Out(oregon.public.law)
  3. ORS 646A.581: Processor Duties and Controller-Processor Contracts(oregon.public.law)
  4. ORS 646A.586: Data Protection Assessments(oregon.public.law)
  5. ORS 646A.589: Attorney General Enforcement and Civil Penalties(oregon.public.law)
  6. ORS 646A.574: Consumer Rights, Including Specific Third-Party List(oregon.public.law)
  7. ORS 646A.570 to 646A.589: Oregon Consumer Privacy Act (Full Chapter)(oregonlegislature.gov).gov
  8. Oregon DOJ: Consumer Privacy (Oregon Consumer Privacy Act)(doj.state.or.us).gov
  9. Oregon DOJ: OCPA One-Year Enforcement Report (2025)(doj.state.or.us).gov
  10. Enrolled HB 3875 (2025), amending ORS 646A.572: motor vehicle manufacturers and affiliates(olis.oregonlegislature.gov)
Share: