Last updated
Who this affects: This page tracks Oregon’s OCPA, which governs controllers and processors.
Who it applies to: Entities that do business in Oregon or serve its residents, and meet: 100,000+ consumers, or 25,000+ consumers and 25%+ of gross revenue from selling data, or other thresholds (see below).
Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.The law, in plain English
OCPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.
These are the highlights we judge most important, not everything OCPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.
The comprehensive law
OCPA (SB 619) is Oregon’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.
Corroborated by Privacy-law tracker
Corroborated by Regulator guidance
Corroborated by Privacy-law tracker Regulator guidance
What the law gives consumers
Who the law governs
Exemptions
Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.
Timeline
Drag the handle or use ← → to step through the milestones. The marker shows where today falls.
Applies to organizations described in section 501(c)(3) of the Internal Revenue Code.
Source: primary citation
Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.