Oregon Consumer Privacy Act

US StatePrivacy2024
ByDecipherU Editorial

The Oregon Consumer Privacy Act is a cybersecurity privacy law effective July 2024 that applies to both for-profit and nonprofit organizations. Oregon is the first state to include nonprofit entities in its privacy law. It requires honoring universal opt-out signals and provides standard consumer privacy rights including access, deletion, and correction.

Quick Reference

EnactedJuly 1, 2024
Enforcement BodyOregon Attorney General (exclusive enforcement)
PenaltiesUp to $7,500 per violation; 30-day cure period (sunsets January 2026)
Applicable ToBusinesses and nonprofits processing data of 100,000+ Oregon consumers, or 25,000+ consumers with 25%+ revenue from data sales

Key Requirements

ORS § 646A.576

Consumers have the right to confirm processing, access, correct, delete, and obtain a copy of personal data

ORS § 646A.578

Controllers must recognize universal opt-out mechanisms

ORS § 646A.582

Controllers must conduct data protection assessments for targeted advertising, profiling, and processing sensitive data

How Does OCPA Affect Cybersecurity Careers?

The inclusion of nonprofits expands the cybersecurity compliance landscape. Security professionals at nonprofit organizations (hospitals, universities, NGOs) in Oregon now face formal privacy obligations. GRC analysts must update compliance matrices to include nonprofit clients.

Cybersecurity Roles That Work With OCPA

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of OCPA at the official source: https://olis.oregonlegislature.gov/liz/2023R1/Measures/Overview/SB619

Frequently Asked Questions

What is OCPA in cybersecurity?

The Oregon Consumer Privacy Act is a cybersecurity privacy law effective July 2024 that applies to both for-profit and nonprofit organizations. Oregon is the first state to include nonprofit entities in its privacy law. It requires honoring universal opt-out signals and provides standard consumer privacy rights including access, deletion, and correction.

How does OCPA affect cybersecurity careers?

The inclusion of nonprofits expands the cybersecurity compliance landscape. Security professionals at nonprofit organizations (hospitals, universities, NGOs) in Oregon now face formal privacy obligations. GRC analysts must update compliance matrices to include nonprofit clients.

What are the penalties for OCPA non-compliance?

Up to $7,500 per violation; 30-day cure period (sunsets January 2026)

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?