Oregon Privacy Compliance Checklist
Oregon Consumer Privacy Act — Step-by-step guide to compliance
What is the OCPA compliance checklist?
The OCPA compliance checklist is a 11-step plan for meeting the Oregon Consumer Privacy Act (OCPA), Oregon's consumer privacy law, which took effect July 1, 2024. It is enforced by the Oregon Attorney General, with civil penalties up to $7,500 per violation and no cure period. Work through every step below, then confirm your specific obligations with the free applicability calculator.
Compliance Steps
Effective: July 1, 20240
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
Key Enforcement Details
Related Resources
OCPA Compliance Checklist FAQ
What is the OCPA compliance checklist?
It is a 11-step plan organizations use to meet the Oregon Consumer Privacy Act (OCPA), which took effect July 1, 2024. The steps below cover consumer-rights request handling, privacy-notice disclosures, opt-out mechanisms, data-processing agreements, and security safeguards required under Oregon law.
Who has to comply with the Oregon Consumer Privacy Act?
The OCPA generally applies to organizations that handle Oregon residents' personal data above the law's revenue and data-volume thresholds. Whether it applies to you depends on the specifics — check your exact obligations with the free applicability calculator at /calculator rather than assuming.
What is the penalty for OCPA non-compliance?
The Oregon Attorney General can impose civil penalties of up to $7,500 per violation and no cure period. There is no private right of action, so enforcement comes from the state, not individual lawsuits. Figures verified July 28, 2026.
Termly builds and maintains an Oregon-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests OCPA grants.
Does this law apply to you?
Use our free calculator to check if Oregon Consumer Privacy Act applies to your business.
Check Applicability