State Guide
Oregon Privacy & Data Security Laws
Every statute below can apply to a business handling Oregon residents' data, depending on your revenue, the number of Oregon consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies at 100,000+ Oregon consumers, or 25,000+ if you derive revenue from selling personal data (nonprofits get a delayed effective date of Jul 1, 2025 but most are otherwise covered — only insurance-fraud-detection nonprofits and certain noncommercial publisher/broadcaster activity are exempt). Oregon's HIPAA exemption is data-level only (covers PHI processed per HIPAA, not covered entities/business associates as a whole). Its GLBA exemption is also data-level for GLBA-regulated data generally; a separate, much narrower entity-level carve-out exists only for FDIC-insured banks and Oregon/federally chartered credit unions (not GLBA-regulated financial institutions generally). No general higher-education exemption — only Oregon Health & Science University is separately named as an exempt public corporation.
Data Security & Breach Notification · 1
Consumer Identity Theft Protection Act requires reasonable safeguards for personal information. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Data Broker Registration & Duties · 1
Brokers must register with the Oregon Department of Consumer and Business Services before collecting, selling, or licensing brokered personal data, and renew each year. "Brokered personal data" is defined broadly and expressly includes biometric information and government identifiers when organized for sale or licensing. Oregon separately bans the sale of precise geolocation data under its comprehensive privacy act.