Law note · Oregon
Notice of breach of security
A covered entity subject to a breach of security, or that receives notice of one from a vendor, must give notice of the breach to each affected Oregon consumer, and must also notify the Attorney General once the number of Oregon consumers notified exceeds 250. This provision is in force under the current codified text; the underlying research did not establish a dated original commencement, so no effective_date is recorded here.
What it asks of an app
- Notify each affected Oregon consumer of a breach of security, including one you learn of through a vendor, and notify the Oregon Attorney General as well once more than 250 Oregon consumers are notified.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Oregon statute text, ORS 646A.604, Oregon Consumer Identity Theft Protection Act