Privacy Law Library

Oregon Consumer Information Protection Act: breach notification

OCIPA breach notification

Breach notification

Requires any business or other entity holding Oregon residents' personal information to notify affected consumers of a data breach within 45 days, and the Attorney General when more than 250 Oregonians are affected. Vendors must alert the covered entity within 10 days. Notice may be skipped only after a documented determination that harm is unlikely.

Where
Oregon
Citation
ORS 646A.602, 646A.604 (part of ORS 646A.600 to 646A.628)
Status
In force
In force since
2007-10-01
Last amended
2020-01-01
Enforced by
Oregon Attorney General (unlawful practice under ORS 646.607) and the Director of the Department of Consumer and Business Services (ORS 646A.624)
People can sue
No
Penalties
Unlawful trade practice under ORS 646.607, so AG injunctions and civil penalties up to $25,000 per willful violation (ORS 646A.604(11); 646.642(3)). DCBS may also impose up to $1,000 per violation, each day a separate violation, capped at $500,000 per occurrence (ORS 646A.624(4)).
Applies to
  • Covered entities: any person (including nonprofits and public bodies) that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of business, vocation, occupation or volunteer activities (ORS 646A.602(5), (11))
  • Vendors that maintain or process personal information for a covered entity (ORS 646A.602(19); 646A.604(2))
  • Personal information: name plus SSN, driver license/state ID, passport or federal ID, financial account or card number with access code, biometric authentication data, health insurance ID with identifier, or medical/health information; username plus password; or those data elements alone if they would enable identity theft (ORS 646A.602(12))

What a privacy notice must say

  • Notice must describe the breach, its approximate date, the type of information involved, contact information for the entity and national consumer reporting agencies, and advise reporting identity theft to law enforcement, the AG and the FTC.ORS 646A.604(5)

Practices it requires

  • Free credit monitoring or identity theft services offered with a breach notice may not be conditioned on giving a card number or buying another service; paid add-ons must be clearly disclosed.ORS 646A.604(7)

Breach duties

  • Notify affected consumers in the most expeditious manner possible and no later than 45 days after discovering or being notified of the breach; delay only on written law-enforcement request.ORS 646A.604(1)(a), (3)
  • Notify the Attorney General (in writing or electronically) when more than 250 consumers must be notified, and send the AG a copy of any notice sent to consumers or regulators, even if otherwise exempt.ORS 646A.604(1)(b), (10) · Only if: More than 250 Oregon consumers affected
  • Vendors must notify the covered entity within 10 days of discovering a breach, and notify the AG if more than 250 (or an undeterminable number of) consumers are affected and the covered entity has not.ORS 646A.604(2)
  • Notify all nationwide consumer reporting agencies of the timing, distribution and content of the notice (with any police report number) when more than 1,000 consumers are affected.ORS 646A.604(6) · Only if: More than 1,000 consumers affected

Other duties

  • Entities complying with their primary federal regulator's breach rules, GLBA, or HIPAA/HITECH are exempt from the consumer notice rules (but not the AG copy requirement).ORS 646A.604(9)
  • Notice is not required if, after investigation or consultation with law enforcement, the entity reasonably determines harm is unlikely; the determination must be documented in writing and kept 5 years.ORS 646A.604(8)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.