Home
Oregon OCPA and Cookies: All You Need to Know

Oregon OCPA and Cookies: All You Need to Know

2 years ago
João Bruno Soares
13 minutes

Oregon passed a privacy law with at least three characteristics you will probably not find in any other US state legislation.

The Oregon Consumer Privacy Act (OCPA), ORS 646A.570 to 646A.589, took effect on July 1, 2024. Developed by the Attorney General's Consumer Privacy Task Force with more than 150 experts involved, and signed by Governor Tina Kotek.

In the first year of enforcement: 214 complaints received, 38 investigations opened. Enforcement is real.

What is the OCPA?

The OCPA is Oregon's state personal data protection law. It grants rights to state residents and creates obligations for businesses that process their data.

Enforcement is the exclusive responsibility of the Oregon Attorney General. There is no private right of action.

When did the OCPA take effect?

On July 1, 2024.

Two important changes came into force on January 1, 2026: the obligation to honor universal opt-out signals such as the Global Privacy Control (GPC), and the elimination of the 30-day cure period. From that date, the Attorney General can act without prior notice.

Who needs to comply with the OCPA?

Under Section 2(1) of the law, it applies to persons that conduct business in Oregon or produce products or services targeted to state residents and that, during a calendar year:

Control or process personal data of at least 100,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction.

Or control or process personal data of at least 25,000 consumers while deriving 25% or more of annual gross revenue from selling personal data.

Three points that distinguish the OCPA from virtually all other state laws:

The payment transaction exclusion from the 100K threshold: data processed exclusively to complete payments does not count toward the 100K threshold. This is different from other laws that do not make this exclusion.

The 25% revenue threshold: most state laws use 50% of revenue from data sales. The OCPA uses 25%, making the second criterion easier to reach.

The inclusion of derived data in the definition of personal data: profiles created from the consumer's data are also personal data under the OCPA. This directly impacts the scope of access and deletion requests.

Understanding the distinction between controller and processor is fundamental to defining responsibilities in the processing chain.

OCPA Exemptions

Under Section 2(2), the following are exempt:

Government entities and public corporations of Oregon, including Oregon Health and Science University and the Oregon State Bar.

Protected health information processed by covered entities or business associates under HIPAA.

Information used solely for public health purposes.

Clinical research data regulated by federal standards.

Data processed solely in the context of employment, contractual relationships with business entities, or employer benefits.

Data regulated by the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, FERPA, and Airline Deregulation Act (within each law's limits).

Financial institutions and their affiliates engaged solely in financial activities.

Insurers, insurance producers, and insurance consultants.

Non-profit organizations established to detect and prevent insurance fraud.

Non-commercial activities of press outlets and licensed radio and TV broadcasters.

Two recent additions

As of July 1, 2025, non-profit organizations under section 501(c)(3) of the Internal Revenue Code became subject to the OCPA.

As of September 26, 2025, all auto manufacturers that collect personal data from Oregon consumers are subject to the law regardless of thresholds.

What is personal data under the OCPA?

Under Section 1(13), personal data means data, derived data, or any unique identifier linked to or reasonably linkable to a consumer or to a device that identifies, is linked to, or is reasonably linkable to one or more consumers in a household.

De-identified data and data lawfully available through government records or widely distributed media are excluded.

The explicit inclusion of derived data is a key differentiator of the OCPA. Marketing profiles, behavioral scores, and audience segment classifications created from consumer data are personal data under the law.

What is sensitive data under the OCPA?

Under Section 1(18), sensitive data includes:

Data revealing racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a crime victim, or citizenship or immigration status.

Personal data of children under 13.

Precise geolocation data within a radius of 1,750 feet (approximately 533 meters).

Genetic or biometric data.

Sensitive data cannot be processed without explicit consumer consent, per Section 5(2)(b) of the OCPA.

What are consumer rights under the OCPA?

The Oregon Department of Justice created the L.O.C.K.E.D. acronym to summarize the rights guaranteed by Section 3(1) of the OCPA:

L (List): obtain a list of the specific entities to which the controller disclosed their personal data, or a list of any personal data disclosed.

O (Opt-out): refuse processing of data for targeted advertising, sale of personal data, and profiling for decisions with legal effects or effects of similar significance.

C (Copy): obtain a copy of all personal data the controller has processed, in a portable and readily usable format where technically feasible.

K (Know): confirm whether the controller processes or has processed their data and which categories are involved.

E (Edit): correct inaccuracies in personal data, taking into account the nature and purpose of processing.

D (Delete): request deletion of personal data, including data provided by the consumer, obtained from other sources, and derived data.

The controller has 45 days to respond (Section 4(5)(a)). The deadline may be extended by an additional 45 days when reasonably necessary, with notification within the initial period.

Response is free once per 12-month period per consumer. For subsequent requests within the same period, the business may charge a reasonable fee, except when the request verifies compliance with a prior correction or deletion (Section 4(5)(c)).

Right to appeal

Section 4(6) requires the controller to establish an appeal process. It must be conspicuously available, similar to the original submission method, and result in a written response within 45 days with the decision and reasoning.

If the appeal is denied, the notice must provide information enabling the consumer to contact the Attorney General.

Consent: what the OCPA requires

Under Section 1(6), consent is an affirmative act by which the consumer clearly and conspicuously communicates freely given, specific, informed, and unambiguous agreement. The interface may not have any mechanism with the purpose or substantial effect of obtaining consent by obscuring, subverting, or impairing the consumer's autonomy and decision-making. And inaction does not constitute consent.

The correct standard for cookies: non-essential technologies off by default. The user chooses what to enable, not what to disable.

Controller obligations under the OCPA

Under Section 5, the controller must:

Specify in the privacy notice the express purposes for collecting and processing personal data.

Limit collection to what is adequate, relevant, and reasonably necessary for the declared purposes.

Implement reasonable technical, administrative, and physical safeguards to protect the data.

Provide a consent revocation mechanism at least as easy as the consent mechanism. After revocation, cease processing within 15 days (Section 5(1)(d)).

Not process data for purposes incompatible with those declared, unless the consumer consents.

Not process sensitive data without prior consumer consent.

Not process data of consumers aged 13 to 15 for targeted advertising, profiling, or data sales without explicit consent.

Not discriminate against consumers who exercise their rights.

Provide an accessible, clear, and meaningful privacy notice with an actively monitored contact channel.

Establish a DSAR channel without requiring creation of a new account.

Conduct and document Data Protection Assessments for high-risk activities.

Special protection for teens aged 13 to 15

Section 5(2)(c) prohibits processing data of consumers aged 13 to 15 for targeted advertising, profiling for decisions with legal effects, or data sales without those consumers' consent, when the controller has actual knowledge or willfully disregards that age range.

As of January 1, 2026, protection was expanded: prohibition on selling data of minors under 16 and on using data of minors under 16 for targeted advertising and certain types of profiling.

The 15-day consent revocation deadline

Section 5(1)(d) requires the controller to provide an effective consent revocation mechanism at least as easy as the consent mechanism. After revocation, the controller must cease processing as soon as practicable, but not later than 15 days.

Cookies and the OCPA

Cookies that collect personal data or allow user identification fall directly within the OCPA's scope.

The controller must display a clear cookie notice, provide an opt-out mechanism for targeted advertising, block non-necessary trackers before they fire, and honor consumer preferences.

Correct tag categorization is what makes it possible to identify which cookies constitute targeted advertising or data sales.

Section 1(19) defines targeted advertising as ads selected based on data collected from the consumer's activities over time and across one or more non-affiliated websites or online applications.

As of January 1, 2026, Section 5(5)(c) requires controllers to honor opt-out signals sent with the consumer's consent by platforms, technologies, or mechanisms such as the Global Privacy Control (GPC). A visitor with the GPC enabled is equivalent to a visitor who clicked the opt-out button.

Data Protection Assessments

Under Section 8, the controller must conduct and document Data Protection Assessments for:

Processing data for targeted advertising.

Processing sensitive data.

Selling personal data.

Profiling that presents a reasonably foreseeable risk of unfair treatment, financial, physical, or reputational harm, intrusion into privacy, or other substantial harm.

Assessments must be retained for at least five years (Section 8(6)) and are confidential. The Attorney General may request access during investigations without that constituting a waiver of attorney-client privilege.

Enforcement and penalties

Under Section 9, the Oregon Attorney General has exclusive enforcement authority. There is no private right of action.

Through December 31, 2025: the AG was required to notify the controller and grant 30 days to cure violations before initiating formal action.

As of January 1, 2026: the cure period was eliminated by Section 11. The AG may initiate action directly.

If violations are identified, the AG may seek:

Injunction to stop the violations.

Civil penalties of up to US$ 7,500 per violation (Section 9(4)(a)).

Recovery of attorney fees and investigation costs.

The AG has five years from the last act constituting the violation to bring an action.

How to comply with the OCPA in practice

1. Data mapping

Understand what you collect, including derived data, where it is, how it is used, and who it is shared with. Data mapping is the foundation of any compliance program.

2. Update your privacy policy

The document must cover all requirements of Section 5(4), including an actively monitored contact channel and a detailed description of third-party categories.

3. Implement a functional cookie notice

A cookie banner that blocks non-necessary trackers before acceptance, records preferences, offers opt-out from targeted advertising, and honors the GPC from January 2026.

4. Create a DSAR channel

At least one secure and reliable mechanism for receiving requests, without requiring creation of a new account.

5. Document Data Protection Assessments

For each high-risk processing activity, conduct and document the assessment per Section 8. Retain for at least 5 years.

6. Update contracts with processors

Contracts with service providers that process data on your behalf must meet the requirements of Section 6 of the OCPA.

Applying privacy by design from the start of product development is what makes compliance sustainable over time.

How AdOpt helps with the OCPA

AdOpt records every consent interaction, blocks trackers before acceptance, honors the GPC from January 2026, processes consent revocations within 15 days, and generates the auditable log needed in an Oregon Attorney General investigation.

The automatic scan identifies all active trackers on the site, feeding the data inventory. And when the law changes, the platform updates automatically.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Ready to bring your website into compliance with the Oregon OCPA? Talk to our team.

Comparing OCPA with other privacy laws

LawStateThresholdRevenue %Cure PeriodGPC/Opt-out SignalEffective Date
OCPAOregon100K (excl. payment tx.) or 25K + 25%25%Eliminated (Jan 2026)Jan 2026Jul 2024
CTDPAConnecticut100K (excl. payment tx.) or 25K + 25%25%Discretionary (Jan 2025)Jan 2025Jul 2023
VCDPAVirginia100K or 25K + 50%50%30 days guaranteedNot requiredJan 2023
CPAColorado100K or 25K + 50%50%Discretionary (Jul 2025)Jul 2024Jul 2023
CCPA/CPRACaliforniaUS$ 25M or 100K50%DiscretionaryGPC requiredJan 2020/2023

To understand how these privacy laws compare in depth, our comparative guide goes further.

The OCPA in practice: the three documents

Compliance with the OCPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.

FAQ: Oregon OCPA

1. What is the OCPA and when did it take effect?
The Oregon Consumer Privacy Act (ORS 646A.570–646A.589) is Oregon's state personal data protection law. It took effect on July 1, 2024. It has specific differentiators from other state laws: the payment transaction exclusion from the 100K threshold, the 25% revenue threshold from data sales, the inclusion of derived data in the personal data definition, and the express 15-day deadline for cessation after consent revocation. As of January 2026, it added the GPC requirement and eliminated the 30-day cure period.

2. What makes the OCPA threshold different from other state laws?
The OCPA has two particularities in the threshold: it explicitly excludes data processed solely for payment transactions from the 100K consumer count, and uses 25% of revenue from data sales as the second criterion (vs. 50% in laws like the VCDPA and Colorado CPA). The 25% threshold is shared with Connecticut's CTDPA, but the payment transaction exclusion makes both laws the most specific on this point among all US state privacy laws.

3. What is the 15-day consent revocation deadline in the OCPA?
Section 5(1)(d) requires that after receiving a consumer's consent revocation, the controller cease processing as soon as practicable, but not later than 15 days. This express deadline is unique to the OCPA (shared with Connecticut's CTDPA) and distinguishes both from other US state laws that require cessation "without undue delay" without a specific timeframe.

4. What is the Global Privacy Control and why does the OCPA require honoring it?
The Global Privacy Control (GPC) is a technical signal that consumers activate in their browsers to automatically request opt-out from data sales and targeted advertising on all sites they visit. As of January 1, 2026, Section 5(5)(c) of the OCPA requires controllers to honor this signal as a valid opt-out request. A visitor with GPC enabled is equivalent to a visitor who clicked the opt-out button.

5. What is the penalty for non-compliance with the OCPA?
The Attorney General may seek civil penalties of up to US$ 7,500 per violation, plus injunctive relief and recovery of attorney fees and investigation costs. As of January 2026, there is no longer a 30-day cure period before formal action. The AG may act directly without prior notice. There is no private right of action (Section 9).

Ready to bring your website into compliance with the Oregon OCPA? Talk to our team.

Tags

Cookie Banner
CMP
Data Mapping
Privacy Policy

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

Axeptio Strengthens its International Expansion with the Acquisition of AdOpt

Axeptio acquires Brazil's AdOpt, expanding global reach in consent management and LGPD compliance.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

Texas TDPSA: Privacy Policy

The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Data Mapping or Data Inventory - a life jacket for the DPO!

With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

What is a CMP (Consent Management Platform)?

A CMP is a tool/platform used to manage the consent of up to millions of users so that a company can use the data of these users for its previously stated purposes.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

IOWA ICDPA: Cookies Policy

What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

California CPRA: Cookies Policy

What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.

AdOpt post

How to Choose a CMP (Consent Management Platform)?

Using a CMP (Consent Management Platform) is a great way to make efforts to adapt to new privacy regulations like GDPR, LGPD, DPDPA, CCPA and more...

AdOpt post

How to choose a Cookie Banner for your website

What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!

AdOpt post

New Hampshire NHDPA: Cookies Policy

Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪