01/09/2026
Navigating Oregon's Tech Confidentiality Laws
Does your Oregon-based business handle employee data, customer information, or health records digitally? Navigating the legal landscape is crucial.
Beyond federal laws like HIPAA or CCPA, Oregon has its own specific statutes governing digital privacy and confidentiality. Ignoring them isn't just a compliance risk—it's a breach of trust.
Here’s a breakdown of key Oregon laws every leader should know:
1. Oregon Consumer Data Protection Act (OCDPA) – Effective July 1, 2024
Applies to: Controllers/processors who handle data of 100,000+ Oregon consumers (or 25,000+ with 25%+ revenue from data sales) and conduct business in Oregon.
Key Duty: Provide clear privacy notices and honor consumer rights (access, correction, deletion, opt-out of targeted ads/profiling).
Action: If you're a tech company or handle significant consumer data, update your privacy policy and data governance now.
2. Oregon Identity Theft Protection Act (OR-IDTPA)
The Core Rule: Requires businesses to notify Oregon residents of a data breach involving their personal information "in the most expeditious time possible."
"Personal Information" Definition: Broadly includes name + SSN, driver's license, passport, or financial account number with access code. It also uniquely includes medical information and health insurance policy numbers.
Action: Have a clear, tested incident response plan that meets Oregon’s "expeditious" standard.
3. Confidentiality of Health Information (Beyond HIPAA)
Oregon Health Information (OR Statute 192.553): Imposes strict confidentiality on all "health information," not just that covered by HIPAA. Applies to a wider range of entities.
Genetic Information Privacy (OR Statute 192.531-192.549): Prohibits the collection, retention, or disclosure of an individual's genetic information without specific written consent, with narrow exceptions. Critical for wellness apps, HR, and tech in the health space.
4. Employee & Workplace Surveillance
While Oregon permits monitoring for legitimate business purposes, two key restrictions exist:
Off-Duty Conduct Law (ORS 659A.330): Prohibits discrimination based on lawful off-duty activities. Overly broad social media monitoring could risk violations.
Audio Recording (ORS 165.540): Oregon is an "all-party consent" state. You cannot record a private conversation (including video with audio) without the consent of all parties. This is a major pitfall for remote employee monitoring tools.
Bottom Line: Oregon law often provides stricter protections than federal standards, especially regarding health data, breach notification speed, and genetic privacy. Compliance is not a "set and forget" task.
Key Steps for Your Business:
Conduct a Data Inventory: What data do you collect, from whom, and where does it flow?
Review & Update Policies: Ensure your privacy policy, breach notification plan, and employee handbook reflect Oregon law.
Audit Vendors: Your data processors must also comply.
Train Your Team: HR, IT, and marketing often handle this data daily.
Is your organization prepared for these obligations? I recommend consulting with a qualified Oregon privacy attorney for a formal review.