How long does a business have to respond to an Oregon privacy request?
Under ORS 646A.576, an Oregon controller must respond to a consumer privacy request within 45 days of receiving it, and may extend that period once by 45 more days if it tells the consumer about the delay and the reason. Appeals get a separate 45-day clock.
Applies to: Controllers subject to the Oregon Consumer Privacy Act that receive a consumer request to confirm, access, correct, delete, obtain a copy of, or opt out of the processing of personal data, and that must run an appeal process.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanOregon looks like every other state privacy law until you get to appeals. The request deadline is the familiar 45 days with one 45-day extension. The appeal deadline is 45 days as well, and that is where Oregon parts company with its neighbors: Texas, Nebraska and Indiana all give a controller 60 days to decide an appeal. Oregon gives you two weeks less.
The 45-day request clock
A controller must respond to a consumer's request no later than 45 days after receipt of the request. The Oregon Department of Justice puts it in exactly those terms in its privacy FAQs for businesses, and the enacted text of SB 619 sets the same period.
The words that matter are "after receipt." The clock does not wait for you to authenticate the consumer, route the ticket, or decide whether the request is one you have to honor. A request that sits in a shared support inbox for three weeks has already spent two thirds of your allowance.
The extension has a condition attached
The controller may extend the response period by an additional 45 days when the extension is reasonably necessary, taking into account the complexity and number of the consumer's requests. The condition is that the controller must tell the consumer that the response will be delayed and explain the reason for the delay.
That makes the extension something you claim, not something you drift into. There is no version of this where a controller answers on day 70 and calls it an extension. Either the notice went out, or the deadline was missed.
Declining is still a response
If the controller declines to act, it has to say so within the same 45 days, explain the justification for not taking action, and include instructions for how the consumer can appeal. A refusal is not a slower track. It is a response with two extra ingredients.
The 45-day appeal clock
The appeal process lives in ORS 646A.576 alongside the request duties. A consumer may appeal a controller's refusal, and the controller has 45 days from the date it received the appeal to notify the consumer in writing of the decision and the reasons for it. If the appeal is denied, the notice has to give the consumer a method of contacting the Oregon Attorney General.
Two practical consequences follow. First, if you built one shared "60-day appeal" timer for your multi-state program, it is wrong for Oregon. Second, appeals usually arrive as a reply to a rejection email rather than through the intake form you instrumented, so the deadline that is easiest to miss is also the shortest one.
What a request costs the consumer
Information has to be provided free of charge for the first request within any 12-month period. For a second or later request in the same window, the controller may charge a reasonable fee to cover administrative costs. The exception is a request that only asks the controller to confirm that it corrected or deleted data in response to an earlier request, which stays free.
Next step
Oregon's 45-day appeal deadline, and its removal of the right to cure at the start of 2026, make it one of the least forgiving state programs to run late. The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR at once and tells you which clocks you are actually on. For the applicability test see the Oregon Consumer Privacy Act overview, for what a missed deadline now costs see Oregon privacy law fines and penalties, and to compare states side by side see privacy request response deadlines by state.
Compliance checklist
- Date-stamp each request when it arrives, because the 45 days runs from receipt and not from the day the request reaches your privacy team.
- Set an internal review at day 30 so there is still time to send the extension notice, which is what makes the extra 45 days available at all.
- Answer refusals inside the same 45 days, with the justification for declining and instructions for how to appeal.
- Run appeals on their own 45-day timer, and put the reasons for the decision in writing rather than in a phone call.
- Include a method for the consumer to contact the Oregon Attorney General in every appeal denial.
- Give the first request in any 12-month period free of charge, and only charge a reasonable administrative fee for later ones.
Sources
- Oregon Laws 2023, chapter 369 (SB 619), the Oregon Consumer Privacy Act as enacted, Oregon State Legislature
- ORS 646A.576, Method for requesting personal data; duties of controller; process for appealing controller's refusal, Oregon Revised Statutes
- Privacy Law FAQs for Businesses, Oregon Department of Justice (response window, extension, and fees)
Last verified: 2026-09-01
Informational, not legal advice.