Oregon Consumer Privacy Act (OCPA)
The Oregon Consumer Privacy Act (OCPA) was signed into law on July 18, 2023, and takes effect on July 1, 2024. Oregon joins the growing number of US states enacting comprehensive consumer data privacy legislation.
What Is the OCPA?
The OCPA grants Oregon residents rights over their personal data and places obligations on businesses that collect or process that data. Oregon's law is notably broader than most other state privacy laws, applying to a wider range of organizations including nonprofits, and providing an expansive definition of sensitive data.
Who Does the OCPA Apply To?
The OCPA applies to businesses that conduct business in Oregon or produce products or services targeted to Oregon residents, and during the prior calendar year either:
- Controlled or processed the personal data of at least 100,000 consumers; or
- Controlled or processed the personal data of at least 25,000 consumers and derived more than 25% of gross revenue from the sale of personal data.
Unlike most other state privacy laws, the OCPA applies to nonprofits beginning July 1, 2025.
Consumer Rights Under the OCPA
Oregon residents are entitled to:
- Right to access: confirm whether a business processes their personal data and request a copy
- Right to correction: request correction of inaccurate personal data
- Right to deletion: request deletion of their personal data
- Right to data portability: obtain a portable copy of their personal data
- Right to opt out: opt out of targeted advertising, sale of personal data, and profiling for significant decisions
- Right to obtain a list of third parties: request a list of specific third parties to whom the controller has disclosed personal data
- Right to appeal: appeal a business's denial of a rights request
Businesses must respond to verified consumer requests within 45 days, extendable by an additional 45 days when reasonably necessary.
Sensitive Data
Processing sensitive data requires opt-in consent from consumers. The OCPA has one of the broadest sensitive data definitions among US state privacy laws, including racial or ethnic origin, national origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, status as transgender or nonbinary, citizenship or immigration status, genetic or biometric data, precise geolocation data, and personal data of known children.
Enforcement
The Oregon Attorney General enforces the OCPA. There is no private right of action. Businesses have a 30-day cure period through January 1, 2026; after that date, granting an opportunity to cure is at the Attorney General's discretion. Civil penalties of up to $7,500 per violation may be imposed.
How UniConsent Supports OCPA Compliance
UniConsent provides the tools businesses need to meet OCPA requirements:
- Opt-out and opt-in consent banners configurable by state
- Global Privacy Control (GPC) signal recognition
- Consumer rights request management
- Sensitive data consent workflows
- Integration with websites, mobile apps, and tag managers
Get started with UniConsent or explore our features.
Other US State Privacy Laws
- CCPA: California Consumer Privacy Act, learn more at CCPA
- CPRA: California Privacy Rights Act, learn more at CPRA
- CPA: Colorado Privacy Act, learn more at CPA
- VCDPA: Virginia Consumer Data Protection Act, learn more at VCDPA
- UCPA: Utah Consumer Privacy Act, learn more at UCPA
- CTDPA: Connecticut Data Protection Act, learn more at CTDPA
- TDPSA: Texas Data Privacy and Security Act, learn more at TDPSA
- DPDPA: Delaware Personal Data Privacy Act, learn more at DPDPA
- NHPA: New Hampshire Privacy Act, learn more at NHPA
- MTCDPA: Montana Consumer Data Privacy Act, learn more at MTCDPA
- FDBR: Florida Digital Bill of Rights, learn more at FDBR
- NJDPA: New Jersey Data Protection Act, learn more at NJDPA
- INCDPA: Indiana Consumer Data Protection Act, learn more at INCDPA
- ICDPA: Iowa Consumer Data Protection Act, learn more at ICDPA
- MODPA: Maryland Online Data Privacy Act, learn more at MODPA
- MNCDPA: Minnesota Consumer Data Privacy Act, learn more at MNCDPA
- NDPA: Nebraska Data Privacy Act, learn more at NDPA
Compare different US State Privacy Laws