Law / United States / Oregon

Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information

ORS 646A.622 (2007 c.759 sec. 12; amended 2015 c.357 sec. 3; 2018 c.10 sec. 6; 2019 c.180 sec. 4)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A security baseline statutes rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds a covered entity, any person, including a public body, that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses an Oregon consumer's personal information in the course of business, vocation, occupation or volunteer activity, and a vendor the covered entity contracts with to hold that information on its behalf; a person who acts solely as a vendor is not itself a covered entity.
  • Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including its secure disposal.
  • Satisfy this duty either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, HIPAA and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with a designated coordinator, a periodic risk assessment, employee training, vetted service-provider contracts, network and software risk assessment and patch management, attack detection and testing, and secure destruction of records when the information is no longer needed.
  • A small business may scale its program's administrative, technical and physical safeguards to its own size, complexity and the sensitivity of the personal information it collects.
  • The Director of the Department of Consumer and Business Services enforces this duty by investigation, subpoena and a cease-and-desist order, with a civil penalty of up to $1,000 per violation and up to $500,000 for any one occurrence; the sections name no private right of action of their own.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Every violation is a separate offense and each day of a continuing violation is a separate violation, but the total penalty for any one occurrence may not exceed the $500,000 aggregate cap; paid to the state General Fund and recoverable only by the Director of the Department of Consumer and Business Services, not by a private plaintiff.

Rule
Per violation only
As of
12 September 2026
Currency
USD
Fixed cap
500,000
Per violation unit
Violation
Per violation amount
1,000

Who enforces it

Enforcement body

The Director of the Department of Consumer and Business Services, who may investigate, subpoena records and witnesses, issue a cease-and-desist order, and, only where enforcement by private civil action would be so burdensome or expensive as to be impractical, order compensation to injured consumers.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A covered entity and a vendor must develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including safeguards for its disposal.

A covered entity is any person, defined to include a public body, that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person's business, vocation, occupation or volunteer activities. A vendor is a person a covered entity contracts with to maintain, store, manage, process or otherwise access personal information on the covered entity's behalf.

A covered entity or vendor complies either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, HIPAA and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with the administrative safeguards (a designated coordinator, periodic risk assessment, employee training, vetted service-provider contracts), technical safeguards (network and software risk assessment, security patch management, attack detection and testing) and physical safeguards (collection and disposal risk assessment, intrusion monitoring, and secure destruction of records) the statute lists.

A small business may instead scale its program to its own size, complexity and the sensitivity of the personal information it collects. The Director of the Department of Consumer and Business Services enforces the duty by investigation, subpoena, and a cease-and-desist order or, only where enforcement by private civil action would be impractical, an order that the violator compensate injured consumers, with a civil penalty of up to $1,000 per violation and up to $500,000 for any one occurrence.

The sections name no private right of action of their own. The safeguards duty was first enacted in 2007 (2007 c.759 sec. 12) and has since been amended three times, most recently in 2019 (2019 c.180 sec. 4), each amendment carrying only a session and chapter citation rather than a stated calendar date, so no day-precise date is recorded here for when the duty as it now reads began to operate.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Oregon Revised Statutes, ORS chapter 646A

Back to the example  ·  Lint your app