State Guide
Oregon Privacy & Data Security Laws
Every statute below can apply to a business handling Oregon residents' data, depending on your revenue, the number of Oregon consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies at 100,000+ Oregon consumers, or 25,000+ if you derive revenue from selling personal data (nonprofits get a delayed effective date of Jul 1, 2025 but most are otherwise covered — only insurance-fraud-detection nonprofits and certain noncommercial publisher/broadcaster activity are exempt). Notably, Oregon's HIPAA and GLBA exemptions are data-level only, not entity-level — a departure from most peer states.
Data Security & Breach Notification · 1
Consumer Identity Theft Protection Act requires reasonable safeguards for personal information. Applies regardless of company size whenever you hold covered personal information about a resident of this state.