United States: Tag you're it—Oregon is number 11 in the game of state consumer privacy

In brief

On 18 July 2023, Oregon Governor Tina Kotek signed SB 619 into law as the Oregon Consumer Privacy Act, making Oregon the eleventh US state to enact consumer privacy legislation and the seventh in 2023 alone. The compliance deadline for for-profit entities is 1 July 2024.

The Oregon Consumer Privacy Act has no revenue threshold and applies to any person that conducts business in Oregon or provides products or services to Oregon residents and who, during a calendar year, controls or processes either:

  • The personal data of at least 100,000 consumers
  • The personal data of at least 25,000 consumers, if they derive more than 25% of their annual gross revenue from the sale of personal data

Contents

In depth

Exemptions/Exceptions: The law does not apply to public corporations (defined under existing Oregon law as entities created by the state to carry out public missions and services), public bodies (state government bodies, local government bodies and special government bodies) or insurers. Activities subject to the Fair Credit Reporting Act's privacy requirements are also exempt, as well as organizations who process data compliant with the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA) and the Family Educational Rights and Privacy Act (FERPA). Further, the Act exempts noncommercial activities of newspapers, magazines, periodicals, radio and television stations, press association and wire services, as well as nonprofit organizations that provide programming to radio or television networks.

Nonprofits, exempt under many other state privacy laws, don't benefit from a blanket exemption, although they will have an extra year (until 1 July 2025) to comply.

Personal Data is defined as that which "is linked to or is reasonably linkable to a consumer or to a device that identifies, is linked to or is reasonably linkable to one or more consumers in a household," and excludes de-identified data, and data that is lawfully available through governmental records or widely distributed media. The Act also doesn't apply to consumers insofar as they are acting in a commercial or employment context.

Sensitive Date is defined as data that "reveals a consumer's racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, status as transgender or nonbinary, status as a victim of crime, or citizenship or immigration status." Sensitive data additionally includes precise geolocation data, children's data and biometric data.

Data subject requests: A controller must respond to data subject requests without undue delay and, in any case within 45 days of receiving the request, though this period may be extended by an additional 45 days if such extension is reasonably necessary, including:

  • Confirm whether a controller is processing a consumer's personal data
  • Obtain a list of third-parties to whom the controller discloses personal data
  • Obtain a copy, in a portable and readily usable format, of the consumer's personal data that the controller has processed
  • Correct inaccuracies in their personal data
  • Request the deletion of their personal data
  • Opt out of processing for the purpose of targeted advertising, sale of the personal data (sale includes exchange for any valuable consideration), or profiling that produces legal or other similarly significant effects.

Controller Obligations: Controller organizations must provide consumers with a reasonably accessible, clear and meaningful privacy notice as well as obtaining a consumer's affirmative consent to process a consumer's Sensitive Data (or, if the consumer is known to be a child, processing their sensitive data in accordance with the Children's Online Privacy Protection Act) or process personal data for the purpose of targeted advertising or profiling if the controller knows that the consumer is at least 13 years old but not older than 16.

Further, the Act also requires controllers to perform data protection assessments under certain circumstances and to enter into valid contracts with processors that set forth instructions for the processing of personal data that give the controller wide rights to audit and enforce confidentiality obligations on processors.

Controllers must limit collection of personal data to that which is adequate, relevant and reasonably necessary for the stated purpose as well as maintaining information security safeguards to protect the confidentiality, integrity and accessibility of personal data to the extent appropriate based on the volume and nature of the personal data. Controllers that process de-identified data must take reasonable measures to prevent the de-identified data from being linked to an individual and respond to universal browser opt-out signals.

Enforcement: The attorney general may bring an action seeking up USD 7,500 per violation, as well as injunctive and other equitable relief.

Before bringing an action under the Oregon Consumer Privacy Act, the attorney general must notify the controller of the alleged violation and provide the controller with 30 days to rectify the alleged violation. If the controller fails to cure the violation after the 30 day period, the attorney general may proceed with the action without further notice. This cure period provision will expire on 1 January 2026.

Key takeaways

With less than a year before the Oregon Consumer Privacy Act becomes operative, businesses should review their privacy programs to ensure compliance with the requirements of the new law. Although the Oregon law largely tracks existing consumer privacy legislation, it does contain some notable and unique features—including narrow exceptions that may mean that it will apply to some organizations not caught by other privacy laws. Businesses should continue to work with counsel to assess their obligations and monitor new legislative developments.

Contact Information
Cynthia Cole
Partner at BakerMcKenzie
Palo Alto
Read my Bio
cynthia.cole@bakermckenzie.com
Rachel Ehlers
Partner at BakerMcKenzie
Houston
Read my Bio
rachel.ehlers@bakermckenzie.com
Helena Engfeldt
Partner at BakerMcKenzie
San Francisco
Read my Bio
helena.engfeldt@bakermckenzie.com

Copyright © 2024 Baker & McKenzie. All rights reserved. Ownership: This documentation and content (Content) is a proprietary resource owned exclusively by Baker McKenzie (meaning Baker & McKenzie International and its member firms). The Content is protected under international copyright conventions. Use of this Content does not of itself create a contractual relationship, nor any attorney/client relationship, between Baker McKenzie and any person. Non-reliance and exclusion: All Content is for informational purposes only and may not reflect the most current legal and regulatory developments. All summaries of the laws, regulations and practice are subject to change. The Content is not offered as legal or professional advice for any specific matter. It is not intended to be a substitute for reference to (and compliance with) the detailed provisions of applicable laws, rules, regulations or forms. Legal advice should always be sought before taking any action or refraining from taking any action based on any Content. Baker McKenzie and the editors and the contributing authors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The Content may contain links to external websites and external websites may link to the Content. Baker McKenzie is not responsible for the content or operation of any such external sites and disclaims all liability, howsoever occurring, in respect of the content or operation of any such external websites. Attorney Advertising: This Content may qualify as “Attorney Advertising” requiring notice in some jurisdictions. To the extent that this Content may qualify as Attorney Advertising, PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME. Reproduction: Reproduction of reasonable portions of the Content is permitted provided that (i) such reproductions are made available free of charge and for non-commercial purposes, (ii) such reproductions are properly attributed to Baker McKenzie, (iii) the portion of the Content being reproduced is not altered or made available in a manner that modifies the Content or presents the Content being reproduced in a false light and (iv) notice is made to the disclaimers included on the Content. The permission to re-copy does not allow for incorporation of any substantial portion of the Content in any work or publication, whether in hard copy, electronic or any other form or for commercial purposes.