Consumer Data Privacy
Oregon Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines
What Oregon’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed August 2026.
What You Need to Know
Oregon's law is one of the more consumer-friendly privacy laws enacted to date. The law does not have a HIPAA-covered entity exemption, and its GLBA entity-level exemption language is narrower. The law applies to non-profits with a couple of exceptions. The definitions of personal data, biometric data, and sensitive data are unique and are intended to be broader and cover more information than in other states. Oregon was the first state to create a right for consumers to request a list of specific third parties, other than natural persons, to which a controller has disclosed the consumer's personal data or any personal data. The law also does not have a pseudonymous data exemption for the rights to access, correct, delete, and port. Controllers must state the "express purpose" for processing personal data in their privacy notices.
Official law text
Who the law applies to
| Threshold | Requirement |
|---|---|
| Annual gross revenue | N/A |
| Consumers whose data is processed | 100,000 consumers 2.35% of state's 4.24 million population |
| Revenue from sale of personal data | Derives 25% or more of annual gross revenue from sale of personal data and controls or processes personal data of 25,000 or more consumers. |
Consumer rights under Oregon's law15
| Right | Provided? |
|---|---|
| Know | Yes |
| Access | Yes |
| Obtain list of third parties to which personal data was disclosed | Yes |
| Data portability | Yes |
| Delete | Yes |
| Correct inaccuracies | Yes |
| Not be discriminated against for exercising rights | Yes |
| Opt-out of sale | Yes |
| Opt-out of targeted advertising/sharing | Yes |
| Opt-out of certain types of profiling | Yes |
| Opt-out of ADMT | No |
| Recognize opt-out signals | Yes |
| Revoke consent | Yes |
| Not process data in discriminatory manner | No |
| Appeal | Yes |
Categories treated as sensitive data12
- Racial or ethnic origin
- National origin
- Religious beliefs
- Mental or physical health diagnosis
- Mental or physical health condition
- Sexual orientation
- Status as transgender or nonbinary
- Citizenship or immigration status
- Genetic or biometric data
note
Delaware, Maryland, and Oregon's definitions of sensitive data do not state that biometric data must be used to identify individuals. However, this requirement is found in each law's definition of biometric data. - Personal data of known child
- Precise geolocation
note
Connecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data. - Status as victim of crime
How sensitive data must be treated3
- Obtain Consent to Process
- Cannot Sell Precise Geolocation Data
- Conduct Data Protection or Risk Assessment
Requirements for minors' data2
- Process personal data of children under 13 in accordance with COPPA or parental/legal guardian consent
- Cannot sell personal data, process personal data for targeted advertising, or profile for consequential decisions for children under 16
Activities that trigger a risk or impact assessment5
- Targeted advertising (“sharing”)
- Sale of personal data
- Processing of sensitive data
- Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
- Any processing activities involving personal data that present a heightened risk of harm to consumers
Other notable provisions9
- Definition of “Sale” Includes “Other Valuable Consideration”
- Applies to Nonprofits
- Data Processing Agreements
- Privacy Policy
- Duty of Purpose Specification
- Implement Reasonable Data Security Measures
- Duty to Avoid Secondary Use
- Data Minimization
- Attorney General Enforcement
Key dates2
| Date | What happens |
|---|---|
| July 1, 2024 | Oregon's consumer data privacy law takes effect |
| July 1, 2025 | Oregon's law extends to apply to nonprofit organizations |
One link, every dated item SPARC tracks — Consumer Privacy, Data Broker, and AI Laws, not just this table.
Subscribe now (opens your default calendar app)
https://staussfirm.com/sparc/calendar.ics
Google Calendar: Settings → Add calendar → From URL → paste the link above.
Outlook: Add calendar → Subscribe from web → paste the link above.
Questions about Oregon’s privacy law?
Stauss PLLC advises companies on state privacy, AI, and data broker compliance.
Contact Stauss PLLCFollow Oregon’s privacy law
Our analysis, by email, as the law moves.
This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.
