Back to the hub

Does Oregon's Consumer Privacy Act apply to your business?

Oregon's Consumer Privacy Act applies to any business operating in Oregon or serving Oregon residents that, in a calendar year, controls or processes personal data of 100,000 or more consumers, or 25,000 or more consumers while deriving 25 percent or more of gross revenue from selling data. Effective July 1, 2024.

Applies to: Businesses that operate in Oregon or provide products or services to Oregon residents and, in a calendar year, control or process personal data of 100,000+ consumers, or 25,000+ consumers while deriving at least 25% of annual gross revenue from selling personal data.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Oregon's law looks familiar at first: the same 100,000 and 25,000 consumer counts you see in Colorado and Connecticut. Two details set it apart. There is no revenue floor, and the data-sale branch triggers at a lower share of revenue than almost anywhere else, which pulls in businesses that would clear the line in other states.

Who the OCPA covers

The Oregon Consumer Privacy Act applies to a person that conducts business in Oregon, or that provides products or services to Oregon residents, and that in a calendar year controls or processes personal data above one of two thresholds. As in the other states, where your company is based does not decide it. Serving enough Oregon residents does. Employee data and business-to-business contacts are outside the consumer counts, so the relevant number is the personal data of Oregon residents acting for themselves.

What are the thresholds?

You are covered if, in a calendar year, you control or process the personal data of 100,000 or more consumers, or the personal data of 25,000 or more consumers while deriving 25 percent or more of your annual gross revenue from selling personal data. There is a useful wrinkle on the first branch: personal data you handle solely to complete a payment transaction does not count toward the 100,000 figure, so a high volume of one-off checkouts alone will not necessarily pull you in.

What makes Oregon different?

The 25 percent revenue trigger is the headline. Most states, including Virginia and Colorado, set their data-sale branch at 50 percent of revenue, so Oregon reaches businesses that make a smaller, but still meaningful, share of their money from selling data. Oregon also has no revenue floor of the kind Utah uses, so a small company that clears the consumer counts is covered. The exemptions are broadly familiar: public bodies, GLBA financial institutions, HIPAA covered entities, insurers, and specific federally regulated data are carved out.

How Oregon compares

Because the consumer counts match, the Colorado Privacy Act and the Connecticut Data Privacy Act are the closest relatives, but Oregon's 25 percent data-sale branch is stricter than either. It is a world away from the Texas TDPSA and its small-business test. The US state privacy laws hub sets the counts and triggers next to each other so you can see where you land.

Next step

Oregon rewards careful counting: separating true consumer data from payment-only and employee records, then checking the 25 percent revenue branch. The free 2-minute Obligation Scan runs Oregon's thresholds against your data and tells you whether the OCPA applies, then lists the notice, opt-out, and assessment duties that follow, so you spend your time on obligations rather than on the arithmetic.

Compliance checklist

  • Count how many Oregon residents' personal data you control or process in a calendar year.
  • Exclude data you process solely to complete a payment transaction, which does not count toward the 100,000 threshold.
  • Check whether at least 25 percent of your annual gross revenue comes from selling personal data, which pairs with the 25,000-consumer branch.
  • Leave out employee and business-to-business records, which are not consumer data under the Act.
  • Confirm you are not exempt, for example as a GLBA financial institution, HIPAA covered entity, insurer, or public body.

Sources

Last verified: 2026-07-21

Informational, not legal advice.