Consumer Data Privacy

Oregon Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines

What Oregon’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed August 2026.

What You Need to Know

Oregon's law is one of the more consumer-friendly privacy laws enacted to date. The law does not have a HIPAA-covered entity exemption, and its GLBA entity-level exemption language is narrower. The law applies to non-profits with a couple of exceptions. The definitions of personal data, biometric data, and sensitive data are unique and are intended to be broader and cover more information than in other states. Oregon was the first state to create a right for consumers to request a list of specific third parties, other than natural persons, to which a controller has disclosed the consumer's personal data or any personal data. The law also does not have a pseudonymous data exemption for the rights to access, correct, delete, and port. Controllers must state the "express purpose" for processing personal data in their privacy notices.

Official law text
Who the law applies to
ThresholdRequirement
Annual gross revenueN/A
Consumers whose data is processed100,000 consumers 2.35% of state's 4.24 million population
Revenue from sale of personal dataDerives 25% or more of annual gross revenue from sale of personal data and controls or processes personal data of 25,000 or more consumers.
Consumer rights under Oregon's law15
RightProvided?
KnowYes
AccessYes
Obtain list of third parties to which personal data was disclosedYes
Data portabilityYes
DeleteYes
Correct inaccuraciesYes
Not be discriminated against for exercising rightsYes
Opt-out of saleYes
Opt-out of targeted advertising/sharingYes
Opt-out of certain types of profilingYes
Opt-out of ADMTNo
Recognize opt-out signalsYes
Revoke consentYes
Not process data in discriminatory mannerNo
AppealYes

Tracking Oregon’s privacy law? We write about it as the law changes.

Categories treated as sensitive data12
  • Racial or ethnic origin
  • National origin
  • Religious beliefs
  • Mental or physical health diagnosis
  • Mental or physical health condition
  • Sexual orientation
  • Status as transgender or nonbinary
  • Citizenship or immigration status
  • Genetic or biometric data
    noteDelaware, Maryland, and Oregon's definitions of sensitive data do not state that biometric data must be used to identify individuals. However, this requirement is found in each law's definition of biometric data.
  • Personal data of known child
  • Precise geolocation
    noteConnecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data.
  • Status as victim of crime
How sensitive data must be treated3
  • Obtain Consent to Process
  • Cannot Sell Precise Geolocation Data
  • Conduct Data Protection or Risk Assessment
Requirements for minors' data2
  • Process personal data of children under 13 in accordance with COPPA or parental/legal guardian consent
  • Cannot sell personal data, process personal data for targeted advertising, or profile for consequential decisions for children under 16
Activities that trigger a risk or impact assessment5
  • Targeted advertising (“sharing”)
  • Sale of personal data
  • Processing of sensitive data
  • Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
  • Any processing activities involving personal data that present a heightened risk of harm to consumers
Other notable provisions9
  • Definition of “Sale” Includes “Other Valuable Consideration”
  • Applies to Nonprofits
  • Data Processing Agreements
  • Privacy Policy
  • Duty of Purpose Specification
  • Implement Reasonable Data Security Measures
  • Duty to Avoid Secondary Use
  • Data Minimization
  • Attorney General Enforcement
Key dates2
DateWhat happens
July 1, 2024Oregon's consumer data privacy law takes effect
July 1, 2025Oregon's law extends to apply to nonprofit organizations

Questions about Oregon’s privacy law?

Stauss PLLC advises companies on state privacy, AI, and data broker compliance.

Contact Stauss PLLC

Follow Oregon’s privacy law

Our analysis, by email, as the law moves.

This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.