Law / United States / Oregon
Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information
ORS 646A.622 (2007 c.759 sec. 12; amended 2015 c.357 sec. 3; 2018 c.10 sec. 6; 2019 c.180 sec. 4)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A security baseline statutes rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds a covered entity, any person, including a public body, that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses an Oregon consumer's personal information in the course of business, vocation, occupation or volunteer activity, and a vendor the covered entity contracts with to hold that information on its behalf; a person who acts solely as a vendor is not itself a covered entity.
- Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including its secure disposal.
- Satisfy this duty either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, HIPAA and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with a designated coordinator, a periodic risk assessment, employee training, vetted service-provider contracts, network and software risk assessment and patch management, attack detection and testing, and secure destruction of records when the information is no longer needed.
- A small business may scale its program's administrative, technical and physical safeguards to its own size, complexity and the sensitivity of the personal information it collects.
- The Director of the Department of Consumer and Business Services enforces this duty by investigation, subpoena and a cease-and-desist order, with a civil penalty of up to $1,000 per violation and up to $500,000 for any one occurrence; the sections name no private right of action of their own.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Every violation is a separate offense and each day of a continuing violation is a separate violation, but the total penalty for any one occurrence may not exceed the $500,000 aggregate cap; paid to the state General Fund and recoverable only by the Director of the Department of Consumer and Business Services, not by a private plaintiff.
- Rule
- Per violation only
- As of
- 12 September 2026
- Currency
- USD
- Fixed cap
- 500,000
- Per violation unit
- Violation
- Per violation amount
- 1,000
Who enforces it
Enforcement body
The Director of the Department of Consumer and Business Services, who may investigate, subpoena records and witnesses, issue a cease-and-desist order, and, only where enforcement by private civil action would be so burdensome or expensive as to be impractical, order compensation to injured consumers.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A covered entity and a vendor must develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including safeguards for its disposal.
A covered entity is any person, defined to include a public body, that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person's business, vocation, occupation or volunteer activities. A vendor is a person a covered entity contracts with to maintain, store, manage, process or otherwise access personal information on the covered entity's behalf.
A covered entity or vendor complies either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, HIPAA and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with the administrative safeguards (a designated coordinator, periodic risk assessment, employee training, vetted service-provider contracts), technical safeguards (network and software risk assessment, security patch management, attack detection and testing) and physical safeguards (collection and disposal risk assessment, intrusion monitoring, and secure destruction of records) the statute lists.
A small business may instead scale its program to its own size, complexity and the sensitivity of the personal information it collects. The Director of the Department of Consumer and Business Services enforces the duty by investigation, subpoena, and a cease-and-desist order or, only where enforcement by private civil action would be impractical, an order that the violator compensate injured consumers, with a civil penalty of up to $1,000 per violation and up to $500,000 for any one occurrence.
The sections name no private right of action of their own. The safeguards duty was first enacted in 2007 (2007 c.759 sec. 12) and has since been amended three times, most recently in 2019 (2019 c.180 sec. 4), each amendment carrying only a session and chapter citation rather than a stated calendar date, so no day-precise date is recorded here for when the duty as it now reads began to operate.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Oregon Revised Statutes, ORS chapter 646A