Oregon

Browse data breach notification laws in the United States by states or territories. This database currently includes breach statutes for a business that collects personal information. This database is for informational purposes only and may not be up-to-date. Please review our Terms of Service. Report any errors or issues to: webmaster@amp.legal.

Last Updated Oregon breach law summary was last updated on 07/02/2017
Statute Oregon Rev. Stat. §§ 646A.600 to .628   [View Source]   [Download PDF]
Covered Entities"Person" means an individual, private or public corporation, partnership, cooperative, association, estate, limited liability company, organization or other entity, whether or not organized to operate at a profit, or a public body as defined in ORS 174.109.
Covered Information"Personal Information" includes a consumer's First Name (or First Initial) and Last Name PLUS one of the following:
  • Social security number
  • Driver's License number or state identification card number issued by the Department of Transportation
  • A consumer's passport number or other identification number issued by the United States
  • A consumer's financial account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to a consumer's financial account
  • Data from automatic measurements of a consumer's physical characteristics, such as an image of a fingerprint, retina or iris, that are used to authenticate the consumer's identity in the course of a financial transaction or other transaction
  • A consumer's health insurance policy number or health insurance subscriber identification number in combination with any other unique identifier that a health insurer uses to identify the consumer
  • Any information about a consumer's medical history or mental or physical condition or about a health care professional's medical diagnosis or treatment of the consumer
OR
  • Any information about a consumer's medical history or mental or physical condition or about a health care professional's medical diagnosis or treatment of the consumer
  • Any of the data elements or any combination of the data elements described in paragraph (a) of this subsection without the consumer's first name or first initial and last name if: (i) Encryption, redaction or other methods have not rendered the data element or combination of data elements unusable; and (ii) The data element or combination of data elements would enable a person to commit identity theft against a consumer
Form of InformationElectronic
Breach TriggerUnauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information that a person maintains.
Encryption Safe HarborNo. A consumer's first name or first initial and last name in combination with any one or more of the following data elements, if encryption, redaction or other methods have not rendered the data elements unusable or if the data elements are encrypted and the encryption key has been acquired.
Risk of Harm AnalysisYes. A person does not need to notify consumers of a breach of security if, after an appropriate investigation or after consultation with relevant federal, state or local law enforcement agencies, the person reasonably determines that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. The person must document the determination in writing and maintain the documentation for at least five years.
Consumer NoticeA person that owns or licenses personal information that the person uses in the course of the person's business, vocation, occupation or volunteer activities and that was subject to a breach of security shall give notice of the breach of security to: The consumer to whom the personal information pertains after the person discovers the breach of security or after the person receives notice of a breach of security.
Government Agency NoticeYes, more than 250. Notify the Attorney General, either in writing or electronically, if the number of consumers to whom the person must send the notice described in paragraph (a) of this subsection exceeds 250.
Credit Agency NoticeYes, more than 1,000 consumers. If a person discovers a breach of security that affects more than 1,000 consumers, the person shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain reports on consumers on a nationwide basis of the timing, distribution and content of the notice the person gave to affected consumers and shall include in the notice any police report number assigned to the breach of security.
PenaltiesYes. A person's violation of a provision of ORS 646A.600 to 646A.628 is an unlawful practice under ORS 646.607.
Private Cause of ActionYes. 646A.624(3): If the director has reason to believe that any person has engaged or is engaging in any violation of ORS 646A.600 to 646A.628, the director may issue an order, subject to ORS chapter 183, directed to the person to cease and desist from the violation, or require the person to pay compensation to consumers injured by the violation. The director may order compensation to consumers only upon a finding that enforcement of the rights of the consumers by private civil action would be so burdensome or expensive as to be impractical.