Privacy Law Library

Security requirements for Internet-connected devices

ORS 646A.813 (IoT security)

Data security

Requires makers of consumer internet-connected devices sold in Oregon to build in reasonable security features, such as a unique preset password or forcing the user to set new credentials on first use.

Where
Oregon
Citation
ORS 646A.813; 646.607(13)
Status
In force
In force since
2020-01-01
Enforced by
Oregon Attorney General (unlawful trade practice under ORS 646.607)
People can sue
No
Penalties
Unlawful trade practice: injunction and civil penalties up to $25,000 per willful violation (ORS 646A.813(6); 646.642(3)).
Applies to
  • Manufacturers that make and sell or offer to sell in Oregon connected devices used primarily for personal, family or household purposes
  • Excludes HIPAA-regulated activity and FDA-regulated medical devices (ORS 646A.813(4))

Security duties

  • Equip connected devices with reasonable security features appropriate to the device and data, such as a unique preprogrammed password per device, a requirement to create new authentication before first access, or compliance with applicable federal security requirements.ORS 646A.813(2)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.