Oregon passed a privacy law with at least three characteristics you will probably not find in any other US state legislation.
The Oregon Consumer Privacy Act (OCPA), ORS 646A.570 to 646A.589, took effect on July 1, 2024. Developed by the Attorney General's Consumer Privacy Task Force with more than 150 experts involved, and signed by Governor Tina Kotek.
In the first year of enforcement: 214 complaints received, 38 investigations opened. Enforcement is real.
The OCPA is Oregon's state personal data protection law. It grants rights to state residents and creates obligations for businesses that process their data.
Enforcement is the exclusive responsibility of the Oregon Attorney General. There is no private right of action.
On July 1, 2024.
Two important changes came into force on January 1, 2026: the obligation to honor universal opt-out signals such as the Global Privacy Control (GPC), and the elimination of the 30-day cure period. From that date, the Attorney General can act without prior notice.
Under Section 2(1) of the law, it applies to persons that conduct business in Oregon or produce products or services targeted to state residents and that, during a calendar year:
Control or process personal data of at least 100,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction.
Or control or process personal data of at least 25,000 consumers while deriving 25% or more of annual gross revenue from selling personal data.
Three points that distinguish the OCPA from virtually all other state laws:
The payment transaction exclusion from the 100K threshold: data processed exclusively to complete payments does not count toward the 100K threshold. This is different from other laws that do not make this exclusion.
The 25% revenue threshold: most state laws use 50% of revenue from data sales. The OCPA uses 25%, making the second criterion easier to reach.
The inclusion of derived data in the definition of personal data: profiles created from the consumer's data are also personal data under the OCPA. This directly impacts the scope of access and deletion requests.
Understanding the distinction between controller and processor is fundamental to defining responsibilities in the processing chain.
Under Section 2(2), the following are exempt:
Government entities and public corporations of Oregon, including Oregon Health and Science University and the Oregon State Bar.
Protected health information processed by covered entities or business associates under HIPAA.
Information used solely for public health purposes.
Clinical research data regulated by federal standards.
Data processed solely in the context of employment, contractual relationships with business entities, or employer benefits.
Data regulated by the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, FERPA, and Airline Deregulation Act (within each law's limits).
Financial institutions and their affiliates engaged solely in financial activities.
Insurers, insurance producers, and insurance consultants.
Non-profit organizations established to detect and prevent insurance fraud.
Non-commercial activities of press outlets and licensed radio and TV broadcasters.
As of July 1, 2025, non-profit organizations under section 501(c)(3) of the Internal Revenue Code became subject to the OCPA.
As of September 26, 2025, all auto manufacturers that collect personal data from Oregon consumers are subject to the law regardless of thresholds.
Under Section 1(13), personal data means data, derived data, or any unique identifier linked to or reasonably linkable to a consumer or to a device that identifies, is linked to, or is reasonably linkable to one or more consumers in a household.
De-identified data and data lawfully available through government records or widely distributed media are excluded.
The explicit inclusion of derived data is a key differentiator of the OCPA. Marketing profiles, behavioral scores, and audience segment classifications created from consumer data are personal data under the law.
Under Section 1(18), sensitive data includes:
Data revealing racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a crime victim, or citizenship or immigration status.
Personal data of children under 13.
Precise geolocation data within a radius of 1,750 feet (approximately 533 meters).
Genetic or biometric data.
Sensitive data cannot be processed without explicit consumer consent, per Section 5(2)(b) of the OCPA.
The Oregon Department of Justice created the L.O.C.K.E.D. acronym to summarize the rights guaranteed by Section 3(1) of the OCPA:
L (List): obtain a list of the specific entities to which the controller disclosed their personal data, or a list of any personal data disclosed.
O (Opt-out): refuse processing of data for targeted advertising, sale of personal data, and profiling for decisions with legal effects or effects of similar significance.
C (Copy): obtain a copy of all personal data the controller has processed, in a portable and readily usable format where technically feasible.
K (Know): confirm whether the controller processes or has processed their data and which categories are involved.
E (Edit): correct inaccuracies in personal data, taking into account the nature and purpose of processing.
D (Delete): request deletion of personal data, including data provided by the consumer, obtained from other sources, and derived data.
The controller has 45 days to respond (Section 4(5)(a)). The deadline may be extended by an additional 45 days when reasonably necessary, with notification within the initial period.
Response is free once per 12-month period per consumer. For subsequent requests within the same period, the business may charge a reasonable fee, except when the request verifies compliance with a prior correction or deletion (Section 4(5)(c)).
Section 4(6) requires the controller to establish an appeal process. It must be conspicuously available, similar to the original submission method, and result in a written response within 45 days with the decision and reasoning.
If the appeal is denied, the notice must provide information enabling the consumer to contact the Attorney General.
Under Section 1(6), consent is an affirmative act by which the consumer clearly and conspicuously communicates freely given, specific, informed, and unambiguous agreement. The interface may not have any mechanism with the purpose or substantial effect of obtaining consent by obscuring, subverting, or impairing the consumer's autonomy and decision-making. And inaction does not constitute consent.
The correct standard for cookies: non-essential technologies off by default. The user chooses what to enable, not what to disable.
Under Section 5, the controller must:
Specify in the privacy notice the express purposes for collecting and processing personal data.
Limit collection to what is adequate, relevant, and reasonably necessary for the declared purposes.
Implement reasonable technical, administrative, and physical safeguards to protect the data.
Provide a consent revocation mechanism at least as easy as the consent mechanism. After revocation, cease processing within 15 days (Section 5(1)(d)).
Not process data for purposes incompatible with those declared, unless the consumer consents.
Not process sensitive data without prior consumer consent.
Not process data of consumers aged 13 to 15 for targeted advertising, profiling, or data sales without explicit consent.
Not discriminate against consumers who exercise their rights.
Provide an accessible, clear, and meaningful privacy notice with an actively monitored contact channel.
Establish a DSAR channel without requiring creation of a new account.
Conduct and document Data Protection Assessments for high-risk activities.
Section 5(2)(c) prohibits processing data of consumers aged 13 to 15 for targeted advertising, profiling for decisions with legal effects, or data sales without those consumers' consent, when the controller has actual knowledge or willfully disregards that age range.
As of January 1, 2026, protection was expanded: prohibition on selling data of minors under 16 and on using data of minors under 16 for targeted advertising and certain types of profiling.
Section 5(1)(d) requires the controller to provide an effective consent revocation mechanism at least as easy as the consent mechanism. After revocation, the controller must cease processing as soon as practicable, but not later than 15 days.
Cookies that collect personal data or allow user identification fall directly within the OCPA's scope.
The controller must display a clear cookie notice, provide an opt-out mechanism for targeted advertising, block non-necessary trackers before they fire, and honor consumer preferences.
Correct tag categorization is what makes it possible to identify which cookies constitute targeted advertising or data sales.
Section 1(19) defines targeted advertising as ads selected based on data collected from the consumer's activities over time and across one or more non-affiliated websites or online applications.
As of January 1, 2026, Section 5(5)(c) requires controllers to honor opt-out signals sent with the consumer's consent by platforms, technologies, or mechanisms such as the Global Privacy Control (GPC). A visitor with the GPC enabled is equivalent to a visitor who clicked the opt-out button.
Under Section 8, the controller must conduct and document Data Protection Assessments for:
Processing data for targeted advertising.
Processing sensitive data.
Selling personal data.
Profiling that presents a reasonably foreseeable risk of unfair treatment, financial, physical, or reputational harm, intrusion into privacy, or other substantial harm.
Assessments must be retained for at least five years (Section 8(6)) and are confidential. The Attorney General may request access during investigations without that constituting a waiver of attorney-client privilege.
Under Section 9, the Oregon Attorney General has exclusive enforcement authority. There is no private right of action.
Through December 31, 2025: the AG was required to notify the controller and grant 30 days to cure violations before initiating formal action.
As of January 1, 2026: the cure period was eliminated by Section 11. The AG may initiate action directly.
If violations are identified, the AG may seek:
Injunction to stop the violations.
Civil penalties of up to US$ 7,500 per violation (Section 9(4)(a)).
Recovery of attorney fees and investigation costs.
The AG has five years from the last act constituting the violation to bring an action.
Understand what you collect, including derived data, where it is, how it is used, and who it is shared with. Data mapping is the foundation of any compliance program.
The document must cover all requirements of Section 5(4), including an actively monitored contact channel and a detailed description of third-party categories.
A cookie banner that blocks non-necessary trackers before acceptance, records preferences, offers opt-out from targeted advertising, and honors the GPC from January 2026.
At least one secure and reliable mechanism for receiving requests, without requiring creation of a new account.
For each high-risk processing activity, conduct and document the assessment per Section 8. Retain for at least 5 years.
Contracts with service providers that process data on your behalf must meet the requirements of Section 6 of the OCPA.
Applying privacy by design from the start of product development is what makes compliance sustainable over time.
AdOpt records every consent interaction, blocks trackers before acceptance, honors the GPC from January 2026, processes consent revocations within 15 days, and generates the auditable log needed in an Oregon Attorney General investigation.
The automatic scan identifies all active trackers on the site, feeding the data inventory. And when the law changes, the platform updates automatically.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Ready to bring your website into compliance with the Oregon OCPA? Talk to our team.
| Law | State | Threshold | Revenue % | Cure Period | GPC/Opt-out Signal | Effective Date |
|---|---|---|---|---|---|---|
| OCPA | Oregon | 100K (excl. payment tx.) or 25K + 25% | 25% | Eliminated (Jan 2026) | Jan 2026 | Jul 2024 |
| CTDPA | Connecticut | 100K (excl. payment tx.) or 25K + 25% | 25% | Discretionary (Jan 2025) | Jan 2025 | Jul 2023 |
| VCDPA | Virginia | 100K or 25K + 50% | 50% | 30 days guaranteed | Not required | Jan 2023 |
| CPA | Colorado | 100K or 25K + 50% | 50% | Discretionary (Jul 2025) | Jul 2024 | Jul 2023 |
| CCPA/CPRA | California | US$ 25M or 100K | 50% | Discretionary | GPC required | Jan 2020/2023 |
To understand how these privacy laws compare in depth, our comparative guide goes further.
Compliance with the OCPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.
1. What is the OCPA and when did it take effect?
The Oregon Consumer Privacy Act (ORS 646A.570–646A.589) is Oregon's state personal data protection law. It took effect on July 1, 2024. It has specific differentiators from other state laws: the payment transaction exclusion from the 100K threshold, the 25% revenue threshold from data sales, the inclusion of derived data in the personal data definition, and the express 15-day deadline for cessation after consent revocation. As of January 2026, it added the GPC requirement and eliminated the 30-day cure period.
2. What makes the OCPA threshold different from other state laws?
The OCPA has two particularities in the threshold: it explicitly excludes data processed solely for payment transactions from the 100K consumer count, and uses 25% of revenue from data sales as the second criterion (vs. 50% in laws like the VCDPA and Colorado CPA). The 25% threshold is shared with Connecticut's CTDPA, but the payment transaction exclusion makes both laws the most specific on this point among all US state privacy laws.
3. What is the 15-day consent revocation deadline in the OCPA?
Section 5(1)(d) requires that after receiving a consumer's consent revocation, the controller cease processing as soon as practicable, but not later than 15 days. This express deadline is unique to the OCPA (shared with Connecticut's CTDPA) and distinguishes both from other US state laws that require cessation "without undue delay" without a specific timeframe.
4. What is the Global Privacy Control and why does the OCPA require honoring it?
The Global Privacy Control (GPC) is a technical signal that consumers activate in their browsers to automatically request opt-out from data sales and targeted advertising on all sites they visit. As of January 1, 2026, Section 5(5)(c) of the OCPA requires controllers to honor this signal as a valid opt-out request. A visitor with GPC enabled is equivalent to a visitor who clicked the opt-out button.
5. What is the penalty for non-compliance with the OCPA?
The Attorney General may seek civil penalties of up to US$ 7,500 per violation, plus injunctive relief and recovery of attorney fees and investigation costs. As of January 2026, there is no longer a 30-day cure period before formal action. The AG may act directly without prior notice. There is no private right of action (Section 9).
Ready to bring your website into compliance with the Oregon OCPA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Axeptio acquires Brazil's AdOpt, expanding global reach in consent management and LGPD compliance.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
A CMP is a tool/platform used to manage the consent of up to millions of users so that a company can use the data of these users for its previously stated purposes.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
Using a CMP (Consent Management Platform) is a great way to make efforts to adapt to new privacy regulations like GDPR, LGPD, DPDPA, CCPA and more...
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
13 Jun 2024
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications