USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Oregon Privacy & Data Security Laws

Every statute below can apply to a business handling Oregon residents' data, depending on your revenue, the number of Oregon consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Applies at 100,000+ Oregon consumers, or 25,000+ if you derive revenue from selling personal data (nonprofits get a delayed effective date of Jul 1, 2025 but most are otherwise covered — only insurance-fraud-detection nonprofits and certain noncommercial publisher/broadcaster activity are exempt). Notably, Oregon's HIPAA and GLBA exemptions are data-level only, not entity-level — a departure from most peer states.

Or. Rev. Stat. § 646A.570 et seq.Read statute →

Data Security & Breach Notification · 1

Varies by state
Oregon data breach notification law
OR Breach Notification

Consumer Identity Theft Protection Act requires reasonable safeguards for personal information. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Or. Rev. Stat. § 646A.600 et seq.Read statute →