OCPA Compliance Checklist 2026 — 10 Steps + Oregon Privacy Law Calculator
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
Quick answer
The Oregon Consumer Privacy Act (OCPA) applies if you process data of 100,000+ Oregon consumers, or 25,000+ while earning 25%+ of gross revenue from data sales — and unlike most states it also covers nonprofits and all motor vehicle manufacturers. The core 2026 compliance duties are:
- Honor Global Privacy Control — mandatory since January 1, 2026 (detect the
Sec-GPC: 1header andnavigator.globalPrivacyControl). - Post a Do Not Sell or Share link and disclose universal-opt-out handling in your privacy notice by July 1, 2026.
- Run the eight consumer-rights workflows on a 45-day clock and obtain opt-in consent for sensitive data.
- There is no cure period — the Oregon AG can enforce immediately, with penalties up to $7,500 per violation.
Oregon Consumer Privacy Act (OCPA) at a Glance
- Statutory citation: ORS 646A.570 to 646A.589 (Senate Bill 619, 2023 Regular Session)
- Effective date: July 1, 2024 for for-profit controllers; July 1, 2025 for nonprofit organizations
- Universal opt-out / GPC: Required since January 1, 2026 — controllers must honor browser-level signals such as Global Privacy Control
- Cure period: None — the original 30-day cure sunset on January 1, 2026; the Oregon AG can enforce immediately
- Penalty: Up to $7,500 per violation (no cap on aggregate violations)
- Enforcement: Exclusive authority of the Oregon Attorney General — no private right of action
- Applicability: 100,000+ Oregon consumers OR 25,000+ consumers AND 25%+ annual gross revenue from data sales (motor vehicle manufacturers covered regardless of thresholds under HB 3875)
- Unique coverage: Nonprofits are not exempt — Oregon is one of very few states where its privacy law applies to nonprofit organizations
Sources: ORS Chapter 646A and the Oregon DOJ Privacy Law FAQs for Businesses (retrieved May 21, 2026).
OCPA Compliance Checklist — Printable Quick Version
Below is the quick visual version of the OCPA compliance checklist you can print, copy, or paste into your project tracker. The full 10-step deep-dive (with implementation guidance and links to free tools) is further down this page.
- ☐ 1. Confirm OCPA applies. 100,000+ Oregon consumers OR 25,000+ AND 25%+ annual gross revenue from data sales. Nonprofits covered. Motor vehicle manufacturers covered regardless of thresholds.
- ☐ 2. Honor Global Privacy Control (GPC). Required since January 1, 2026. Detect
Sec-GPC: 1header andnavigator.globalPrivacyControl. Suppress sale and ad-targeting tags. Persist opt-out across sessions. - ☐ 3. Add a Do Not Sell or Share link. Visible on every page that collects personal data. No login required. No dark patterns.
- ☐ 4. Update your privacy notice. Universal-opt-out signal disclosure required by July 1, 2026.
- ☐ 5. Build the eight consumer-rights workflows. Access, correction, deletion, portability, opt-out (sale), opt-out (targeted ads), opt-out (profiling), appeal. 45-day response window with one 45-day extension.
- ☐ 6. Document data protection assessments (DPAs). Required before targeted advertising, sale, profiling, or sensitive-data processing.
- ☐ 7. Tighten processor contracts. Confidentiality, processing scope, deletion or return on termination.
- ☐ 8. Audit minor and geolocation practices. No selling personal data of consumers under 16 (HB 2008). No selling precise geolocation within 1,750 ft (HB 2008).
- ☐ 9. Get sensitive-data opt-in consent. Race, ethnicity, religion, health, sexual orientation, citizenship, biometric ID data — opt-in only.
- ☐ 10. Track enforcement risk. No cure period — AG can act immediately. Penalty up to $7,500 per violation, no aggregate cap.
Free Oregon Consumer Privacy Act Calculator · Free GPC Compliance Checker · Free Do Not Sell Link Generator
Oregon’s Unique Approach to Data Privacy
The Oregon Consumer Privacy Act (OCPA) took effect on July 1, 2024, after being signed into law in 2023 as Senate Bill 619 (2023 Regular Session). Oregon’s privacy law stands out for two key reasons: it is one of the few states that applies its privacy law to nonprofit organizations, and it underwent significant amendments in 2025 that eliminated the cure period, banned the sale of minors’ data, and expanded coverage to all motor vehicle manufacturers.
If your business or nonprofit operates in Oregon or serves Oregon consumers, you may be subject to the OCPA. Use our Privacy Law Calculator to check your compliance obligations across all states, or jump straight to the 10-step OCPA compliance checklist below.
Who Must Comply with the OCPA?
The OCPA applies to entities that conduct business in Oregon or deliver commercial products or services targeted to Oregon consumers, AND meet either of these thresholds during a calendar year:
- Control or process personal data of 100,000 or more Oregon consumers, OR
- Control or process personal data of 25,000 or more Oregon consumers AND derive 25% or more of annual gross revenue from the sale of personal data
Critical distinction: Unlike most state privacy laws, the OCPA applies to both for-profit businesses and nonprofit organizations. If your nonprofit processes data of 100,000+ Oregon consumers, you are subject to the full requirements of the law.
Motor Vehicle Manufacturers
Under HB 3875 (effective September 26, 2025), all motor vehicle manufacturers that process consumer vehicle data in Oregon are now covered by the OCPA regardless of whether they meet the standard consumer count thresholds. This was a direct response to growing concerns about connected-car data collection.
Exemptions
The OCPA exempts several categories of entities and data types:
- Entity exemptions: Government bodies, financial institutions subject to GLBA, entities covered by HIPAA (entity-level exemption), and institutions of higher education
- Data exemptions: Data governed by HIPAA, GLBA, FCRA, FERPA, DPPA, and certain employment and B2B contact data
- Not exempt: Nonprofit organizations (Oregon is unique in this regard)
Consumer Rights Under the OCPA
Oregon provides its consumers with a comprehensive set of privacy rights, placing it among the more consumer-friendly state laws:
- Right to access — Confirm whether a controller is processing their personal data, access that data, and — uniquely under Oregon law — request a list of the specific third parties that received it
- Right to correction — Request correction of inaccurate personal data
- Right to deletion — Request deletion of personal data
- Right to data portability — Obtain a copy of personal data in a portable, readily usable format
- Right to opt out of sale — Opt out of the sale of personal data
- Right to opt out of targeted advertising — Opt out of processing for targeted advertising
- Right to opt out of profiling — Opt out of profiling in furtherance of decisions with legal or similarly significant effects
- Right to appeal — Appeal a controller’s denial of a consumer rights request
Controllers must respond to consumer requests within 45 days, with one 45-day extension if reasonably necessary.
Oregon’s Unique Right: A List of Specific Third Parties
Oregon was the first US state to write into a comprehensive privacy law a consumer right to learn the specific, named third parties — not just the broad categories of recipients — that received personal data. Under ORS 646A.574, a consumer’s access request may include, “at the controller’s option, a list of specific third parties, other than natural persons, to which the controller has disclosed: (i) the consumer’s personal data; or (ii) any personal data.”
Two practical points most OCPA checklists miss:
- How you answer is the controller’s choice. The statute lets you satisfy the request with either the named-third-party list or the categories of recipients — you are not forced to publish every vendor by name. But you must be able to produce one of the two on demand, which in practice means maintaining an accurate, queryable data map of who receives Oregon consumers’ data.
- The specific-party list can reach “any personal data,” not only the requester’s. Where you opt for the named-third-party route, the statute lets a consumer ask for the third parties that received any personal data — broader than California’s CCPA, which discloses only categories of recipients.
This is what makes the OCPA distinctive among the 20-plus comprehensive state laws: CCPA stops at categories, whereas Oregon reaches the specific-entity level, an approach later echoed by Minnesota’s MCDPA. Even if you ultimately respond with categories, build your DSAR tooling and vendor data map so it can answer at named-vendor granularity. Source: ORS 646A.574 (date_retrieved: 2026-06-05).
Key 2026 Changes — What’s New
The OCPA underwent major changes that took effect in late 2025 and early 2026. Businesses must be aware of all of these:
Universal Opt-Out (GPC) Requirement — Effective January 1, 2026
Starting January 1, 2026, businesses must recognize and honor universal opt-out mechanisms such as Global Privacy Control (GPC) for opt-out of data sales and targeted advertising. On Data Privacy Day 2026, Oregon AG Dan Rayfield publicly highlighted the launch of the universal opt-out tool, signaling that GPC enforcement is an active priority for the Oregon DOJ (Oregon DOJ press release, January 28, 2026, retrieved April 27, 2026). From July 1, 2026, controllers must also include information about universal opt-out signal methods in their privacy notices.
How to implement OCPA Do Not Sell or Share + GPC compliance
Concretely, OCPA-covered controllers should:
- Detect the GPC header server-side (HTTP request header
Sec-GPC: 1) and thenavigator.globalPrivacyControlJavaScript property client-side. Treat either signal as a valid opt-out from sale of personal data and from processing for targeted advertising for that consumer. - Suppress sale and ad-targeting tags when the signal is present — no behavioural advertising pixels, no audience-segmentation cookies, no transmission of personal data to ad-tech vendors classified as “sales” under the OCPA.
- Persist the opt-out against the user’s account or device identifier so the preference survives subsequent visits (a per-session opt-out is not compliant).
- Surface a visible “Do Not Sell or Share My Personal Information” mechanism on every page where personal data is collected, even if the GPC signal is also honoured. Plain-language link, no dark patterns, no requirement to log in.
- Update the privacy notice by July 1, 2026 to disclose which universal opt-out signals are recognised and how consumers can use them.
- Test with our free GPC Compliance Checker — it sends a GPC signal against your domain and reports whether sale tags fire after opt-out.
For broader background on universal opt-out mechanisms and how OCPA aligns with the seven other states (California, Colorado, Connecticut, Texas, Montana, Delaware, Maryland) that require recognition, see our universal opt-out mechanism compliance guide. Oregon and Colorado share the strictest enforcement posture among UOOM states: both eliminated their cure periods and both treat precise geolocation as sensitive data requiring opt-in consent.
Cure Period Eliminated — Effective January 1, 2026
The OCPA’s original 30-day cure period expired on January 1, 2026. The Oregon Attorney General now has full enforcement discretion and can proceed directly to enforcement action without offering businesses an opportunity to cure alleged violations.
Minor Data Protections — Effective September 2025
HB 2008 (effective September 26, 2025) added two important protections:
- Ban on selling minor data: Controllers cannot sell personal data when they have actual knowledge the consumer is under 16 years of age
- Precise geolocation data ban: Controllers cannot sell precise geolocation data (within a 1,750-foot radius) of any consumer
Motor Vehicle Data Expansion — Effective September 2025
HB 3875 extended the OCPA’s coverage to all motor vehicle manufacturers that process consumer vehicle data, regardless of whether they meet the standard applicability thresholds. Read more about connected car data privacy.
Key Business Obligations
Privacy Notices
Controllers must provide a reasonably accessible, clear privacy notice covering: categories of personal data processed, purposes of processing, how consumers can exercise their rights (including universal opt-out signal methods as of July 1, 2026), categories of data shared with third parties, and categories of third parties.
Sensitive Data Consent
Processing sensitive data requires opt-in consent. Sensitive data under the OCPA includes: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, and biometric data used for identification.
Data Protection Assessments
Controllers must conduct and document data protection assessments (DPAs) before engaging in processing that presents a heightened risk of harm to consumers. This includes processing for targeted advertising, sale of personal data, profiling, and sensitive data processing.
Processor Contracts
Controllers engaging processors must establish written contracts governing: the nature and purpose of processing, the type of data processed, duration, rights and obligations, confidentiality requirements, and deletion or return of data upon contract termination.
Enforcement and Penalties
The Oregon Attorney General has exclusive enforcement authority. There is no private right of action.
- Penalties: Up to $7,500 per violation
- Cure period: None (expired January 1, 2026) — AG can enforce immediately
The Oregon DOJ published consumer opt-out guidance on Data Privacy Day in January 2026, signaling an active enforcement posture. View enforcement trends on our Enforcement Tracker.
OCPA vs HIPAA: Are You Actually Exempt?
One of the most common OCPA compliance mistakes is assuming a HIPAA-related business is fully exempt. The OCPA exempts covered entities and business associates as defined under HIPAA, plus protected health information (PHI) processed under HIPAA — but the exemption is narrower than most teams expect.
| Scenario | OCPA applies? | Why |
|---|---|---|
| Hospital processing PHI under HIPAA | No — entity-level exemption | HIPAA covered entity |
| Health-tech startup that is not a HIPAA covered entity (e.g. wellness app) | Yes | Not a covered entity; data is not PHI under HIPAA |
| Hospital’s marketing site collecting visitor analytics + cookies | Yes for that data | Visitor analytics & ad cookies are not PHI; entity exemption is for the HIPAA-regulated activity |
| HIPAA business associate processing only PHI | No — PHI is HIPAA-regulated | Data-level exemption for PHI |
| Pharmacy chain’s loyalty program collecting non-PHI purchase data | Yes for the loyalty data | Loyalty/marketing data is not PHI |
| Financial institution covered by GLBA | No — GLBA exemption applies | GLBA-regulated entities are exempt at the entity level |
The practical takeaway: a HIPAA hospital is exempt for clinical data, but its marketing website, advertising tags, and visitor cookies often fall outside the exemption. Run those parts of the business through the OCPA applicability calculator separately. Source: ORS 646A.572 exemptions; Oregon DOJ Privacy Law FAQs.
OCPA Cookie Consent Requirements
The OCPA does not impose a GDPR-style universal cookie consent banner, but cookies do trigger OCPA obligations in three specific ways:
- Sale of personal data via cookies. Third-party advertising cookies, ID-graph syncs, and audience-segmentation pixels that send personal data to ad-tech vendors for monetary or other valuable consideration generally qualify as a “sale” under the OCPA. A user with a GPC signal must have those cookies suppressed before any data is transmitted.
- Targeted advertising via cookies. Even when no money changes hands, cross-context behavioural advertising cookies are an opt-out activity under the OCPA. GPC must suppress them.
- Sensitive data via cookies. Cookies that carry sensitive data (biometric IDs, geolocation precise to 1,750 ft, health data) require opt-in consent, not opt-out — full stop.
What this means in practice for an Oregon-targeting website:
- You do not need a GDPR-style consent wall before any cookies fire.
- You do need to detect GPC, suppress all sale and targeted-ad tags when present, and persist that suppression.
- You do need a visible “Do Not Sell or Share My Personal Information” link as a fallback for users without GPC.
- You do need an opt-in flow for any sensitive-data cookies before they are set.
Validate your implementation end-to-end with the free Cookie Consent Compliance Checker and the GPC Compliance Checker.
How to File a Complaint Under the Oregon Consumer Privacy Act
Oregon consumers (and businesses reporting non-compliance by competitors) can submit OCPA complaints directly to the Oregon Department of Justice. There is no private right of action — complaints route through the Oregon Attorney General.
- Where: Oregon DOJ Consumer Protection Section — doj.state.or.us privacy complaints page
- Form: Oregon DOJ online consumer complaint form (free; no login required)
- What to include: the controller’s name and website, the consumer right you exercised, the date and method of the request, the controller’s response (or absence of one), and any supporting screenshots
- Hotline: (877) 877-9392 (Oregon DOJ consumer line)
- Timeline: Oregon DOJ does not commit to a complaint-response SLA. The 2025 one-year report from AG Rayfield indicates active triage of OCPA complaints in the law’s second year.
OCPA Full Text and Official Sources
- Oregon Consumer Privacy Act, full text: ORS Chapter 646A §§ 646A.570 to 646A.589 (codified version)
- Original enrolled bill: SB 619 (2023 Regular Session)
- Minor & geolocation amendment: HB 2008 (2025) — effective September 26, 2025
- Motor vehicle manufacturer expansion: HB 3875 (2025) — effective September 26, 2025
- Oregon DOJ Privacy Law FAQs for Businesses: doj.state.or.us
- Oregon DOJ Universal Opt-Out announcement (Data Privacy Day 2026): Press release, January 28, 2026
How Oregon Compares to Other State Privacy Laws
The OCPA occupies a unique position in the US state privacy law landscape:
- Nonprofit applicability: Oregon is one of very few states whose privacy law covers nonprofits — most states exempt them entirely
- GPC required: Oregon joins California, Colorado, Connecticut, Texas, Montana, and Delaware in requiring universal opt-out recognition
- No cure period: Joining California and Colorado in eliminating the cure period — unlike Iowa (permanent 90 days) or Tennessee (60 days)
- Motor vehicle expansion: Oregon and Utah have specific provisions bringing auto manufacturers under their privacy laws
- Minor data protections: The ban on selling data of consumers under 16 places Oregon among the stricter states for children’s privacy
- Precise geolocation ban: The prohibition on selling precise geolocation data mirrors an emerging trend also seen in Virginia’s SB 338
Use our State Comparison Tool for a detailed side-by-side analysis.
OCPA Compliance Checklist — 10 Steps
- Assess applicability — Determine if your organization (including nonprofits) processes data of 100,000+ Oregon consumers, or 25,000+ while deriving 25%+ annual gross revenue from data sales. Motor vehicle manufacturers: you are covered regardless of thresholds. Use the Privacy Law Calculator.
- Implement GPC recognition — Ensure your website and apps recognize and honor Global Privacy Control and other universal opt-out signals. This has been required since January 1, 2026. See the implementation steps above and verify with our GPC Compliance Checker.
- Add a Do Not Sell or Share mechanism — Provide a clear, conspicuous opt-out link or button for sale and targeted-advertising opt-outs. Do not require login, account creation, or unnecessary identity collection.
- Update privacy notices — Include all OCPA-required disclosures. By July 1, 2026, you must also include information about universal opt-out signal methods. Generate a state-aware draft with our Privacy Policy Generator.
- Build consumer rights workflows — Support access, correction, deletion, portability, opt-out, and appeal requests. Include back-end data such as marketing profiles and shopping patterns, not only account-profile fields. Oregon access requests can also seek the list of specific third parties that received personal data, so keep a current data map of recipients.
- Conduct data protection assessments — Document DPAs before targeted advertising, sale, profiling, sensitive-data processing, or other heightened-risk processing.
- Review processor contracts — Ensure all data processor agreements include OCPA-mandated provisions for processing scope, confidentiality, assistance with rights requests, and data return or deletion.
- Review minor data practices — Do not sell personal data of known consumers under 16. Do not sell precise geolocation data (within 1,750-foot radius) of any consumer. Use the Geolocation Compliance Checker if you process location data.
- Get opt-in consent for sensitive data — The OCPA treats data revealing racial or ethnic background, national origin, religion, health, sexual orientation, citizenship or immigration status, transgender or nonbinary status, crime-victim status, genetic data, biometric identifiers, children’s data, and precise location as sensitive.
- Set the 45-day DSAR clock — Respond within 45 days, with one 45-day extension when reasonably necessary. Track multi-state DSARs with our DSAR Request Manager.
- Track no-cure enforcement risk — As of January 1, 2026, Oregon DOJ no longer has to give notice and a cure opportunity before serving a Civil Investigative Demand or filing suit.
For a detailed walkthrough, visit our Oregon Compliance Checklist.
Frequently Asked Questions
When did the Oregon Consumer Privacy Act take effect?
The OCPA took effect on July 1, 2024 for for-profit controllers and on July 1, 2025 for nonprofit organizations — Oregon is one of the few US states whose comprehensive privacy law applies to nonprofits. The law was enacted as Senate Bill 619 in the 2023 Regular Session and is codified at ORS 646A.570 to 646A.589. Two later amendments (HB 2008 and HB 3875, both effective September 26, 2025) added a ban on selling minors’ data, a ban on selling precise geolocation, and broader coverage for motor vehicle manufacturers. Source: Oregon DOJ Privacy Law FAQs for Businesses (retrieved April 27, 2026).
Who must comply with the Oregon privacy law?
The OCPA applies to any controller that conducts business in Oregon or targets Oregon consumers and meets one of two thresholds in a calendar year: (a) processes personal data of 100,000 or more Oregon consumers, or (b) processes personal data of 25,000 or more Oregon consumers and derives 25% or more of annual gross revenue from selling personal data. Unlike most state laws, the OCPA covers nonprofits. Under HB 3875, all motor vehicle manufacturers that process consumer vehicle data in Oregon are covered regardless of consumer-count thresholds. Use our Privacy Law Calculator to confirm exposure across all 21 state laws.
Does the OCPA require honoring Global Privacy Control (GPC)?
Yes. Since January 1, 2026, OCPA-covered controllers must recognize and honor universal opt-out signals such as GPC as a valid request to opt out of sale of personal data and processing for targeted advertising. By July 1, 2026, controllers must additionally disclose in their privacy notices which universal opt-out methods they recognize. Oregon AG Dan Rayfield publicly highlighted the universal opt-out launch on Data Privacy Day 2026, signaling active enforcement intent (Oregon DOJ press release, January 28, 2026). Verify your implementation with our GPC Compliance Checker.
How do I implement Do Not Sell or Share under the OCPA?
OCPA “Do Not Sell or Share” implementation has two layers. (1) A user-facing opt-out mechanism — a prominent “Do Not Sell or Share My Personal Information” link or button on every page that collects personal data, with a frictionless workflow (no account required, no dark patterns). (2) Server- and client-side GPC signal honoring: detect the Sec-GPC: 1 HTTP header and the navigator.globalPrivacyControl property, suppress all sale tags and targeted-advertising vendors when present, and persist the opt-out across sessions tied to the user’s account or device identifier. Use our free Opt-Out Link Generator for a state-aware HTML snippet, and validate end-to-end with the GPC Compliance Checker.
What’s the OCPA compliance checklist for businesses?
The full 10-step OCPA compliance checklist is above. In short: (1) assess applicability with the Privacy Law Calculator; (2) implement GPC recognition (live since Jan 1, 2026); (3) add a Do Not Sell or Share mechanism; (4) update privacy notices (universal-opt-out disclosure mandatory by July 1, 2026); (5) build consumer rights workflows; (6) conduct documented data protection assessments; (7) tighten processor contracts; (8) review minor and geolocation data practices; (9) get opt-in consent for sensitive data; and (10) track no-cure enforcement risk. For a state-specific deep-dive, see the Oregon Compliance Checklist.
What are the penalties for violating the OCPA?
The Oregon Attorney General can seek civil penalties of up to $7,500 per violation, and there is no cap on aggregate violations. There is no private right of action — only the AG can enforce. The original 30-day cure period sunset on January 1, 2026, so the AG can now proceed directly to enforcement without first offering businesses an opportunity to fix the violation. The Oregon DOJ’s one-year report on the OCPA (released by AG Rayfield in 2025) confirmed an active enforcement posture in the law’s second year (Oregon DOJ press release, retrieved April 27, 2026). Track enforcement trends across all states on our Enforcement Tracker.
Can Oregon consumers find out which specific companies received their data?
Yes — this is one of the OCPA’s most distinctive features. Under ORS 646A.574, an Oregon consumer’s access request may include a request for a list of the specific third parties (other than natural persons) to which the controller has disclosed their personal data, or to which it has disclosed any personal data. Oregon was the first state to put this named-third-party right into a comprehensive privacy law; California’s CCPA, by contrast, discloses only the categories of recipients. The statute provides the named list “at the controller’s option,” so a business may instead respond with categories of recipients — but it must be able to produce one or the other, which requires an accurate vendor data map. Full detail above. Source: ORS 646A.574 (date_retrieved: 2026-06-05).
This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 29, 2026. Last verified: June 5, 2026.
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.