Oregon’s privacy compliance regime has entered a new phase. With the Oregon Consumer Privacy Act (OCPA) now fully in effect, new consumer rights and opt-out requirements in place, and the Attorney General actively enforcing the law without a statutory cure period, businesses should take a fresh look at their privacy programs and compliance processes.

Oregon’s privacy framework now extends well beyond breach notification and security obligations. The OCPA, together with Oregon’s breach notification law and data broker registration requirements, imposes obligations across the data lifecycle, including transparency, consumer rights, sensitive-data processing, vendor management, data protection assessments, and incident response. At the same time, regulators are increasingly scrutinizing practical compliance issues such as privacy notices, consumer request workflows, and documentation supporting privacy practices.

As enforcement activity matures and privacy regulators continue to coordinate across jurisdictions, organizations should assess whether their policies, procedures, contracts, and technical controls align with Oregon’s evolving requirements. Businesses that have not recently reviewed their privacy compliance programs may want to take this opportunity to identify potential gaps before they become the subject of regulatory scrutiny.

Continue reading for a deeper discussion of Oregon’s privacy landscape, emerging enforcement trends, and practical steps organizations can take to strengthen compliance.

Photo of John Pavolotsky John Pavolotsky

John Pavolotsky focuses his practice on data privacy, security matters, complex technology transactions. On privacy and security matters, John advises a broad range of clients on general compliance, use of new(er) technologies such as artificial intelligence (AI), data incidents, and breach response. On…

John Pavolotsky focuses his practice on data privacy, security matters, complex technology transactions. On privacy and security matters, John advises a broad range of clients on general compliance, use of new(er) technologies such as artificial intelligence (AI), data incidents, and breach response. On technology transactions matters, John assists clients with technology licensing, collaboration and joint development agreements, and cloud (XaaS) services agreements, among others. In addition, John advises clients in privacy, cybersecurity, and intellectual property matters in mergers and acquisitions (M&A) transactions. Click here for John Pavolotsky’s full bio.

Photo of Nathan Morales Nathan Morales

Nathan Morales is an experienced trial and appellate attorney. As a member of both the Stoel Rives’ global Privacy and Data Security practice and Litigation group, Nathan counsels and advises a wide range of clients on an array of privacy-related matters, including compliance…

Nathan Morales is an experienced trial and appellate attorney. As a member of both the Stoel Rives’ global Privacy and Data Security practice and Litigation group, Nathan counsels and advises a wide range of clients on an array of privacy-related matters, including compliance with GDPR, CalCPA, and other federal and state regulatory regimes, assessment and management of third-party risk, and development of internal programs, policies, and procedures.

Nathan regularly advises and represents clients in connection with data breach and security incident planning; preparation and response, including internal investigations, notifications and public announcements; and regulatory reporting. And he represents businesses and individuals in privacy and data security disputes and litigation, particularly in putative class actions.

Click here for Nathan Morales’ full bio.