Oregon Consumer Privacy Act (OCPA) Compliance: Answer Data Subject Requests on the 45-Day Clock
The Oregon Consumer Privacy Act gives Oregon residents the right to access, correct, delete, and port their personal data, to learn which specific third parties received it, and to opt out of its sale. A verified request starts a 45-day clock, and since January 1, 2026 the right to cure a violation is gone. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Oregon Consumer Privacy Act (OCPA) took effect on July 1, 2024 for most businesses and on July 1, 2025 for nonprofits. It applies to a controller that conducts business in Oregon or targets Oregon residents and, in a calendar year, either controls or processes the personal data of 100,000 or more consumers, or controls or processes the data of 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data. Oregon consumers can confirm whether you process their personal data and access it, correct inaccuracies, delete it, and obtain a portable copy, and they can opt out of the sale of their data, targeted advertising, and profiling. Oregon adds a right no other state law grants in the same form: on request, a consumer can require you to name the specific third parties to which you disclosed their personal data, not just the categories. You generally must respond within 45 days, extendable once by another 45 days with notice. Since January 1, 2026, controllers must honor universal opt-out signals such as Global Privacy Control, and the 30-day right to cure sunset on the same date, so the Oregon Department of Justice can act without first giving you a chance to fix the problem. Civil penalties reach $7,500 per violation, and there is no private right of action. Obtainer handles the operational side of an OCPA request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock. Nothing is disclosed automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.
Why it fits
Oregon businesses and nonprofits, plus out-of-state SaaS, ecommerce, adtech, and B2B firms that target Oregon residents at the OCPA thresholds, that want discovery, third-party disclosure lookups, drafting, and 45-day deadline tracking in one place.
Oregon asks you to name names
Most state laws let you answer a disclosure question with categories of recipients. Oregon lets the consumer demand the specific third parties that received their personal data. That turns an easy paragraph into a real lookup across your vendor and integration surface, which is exactly the work Obtainer does when it builds the manifest for a request.
No cure period since January 2026
The OCPA had a 30-day right to cure through the end of 2025. It sunset on January 1, 2026, so the Oregon Department of Justice no longer has to warn you before enforcing, and penalties run to $7,500 per violation. A missed 45-day deadline is no longer something you can quietly fix after a notice arrives.
Discovery across your stack, priced for you
A single consumer's data sits in your production database, warehouse, Stripe, help desk, and email. Obtainer surfaces where it lives, compiles one manifest with source badges, and captures universal opt-out signals in the intake so honoring Global Privacy Control is part of the workflow. Self-serve from $49/mo, with no five-figure floor before your first request.
More use cases
Related features
Questions
Common questions about this
Who must comply with the Oregon Consumer Privacy Act?
A controller that conducts business in Oregon or targets Oregon residents and, in a calendar year, either processes the personal data of 100,000 or more consumers, or processes the data of 25,000 or more consumers while deriving 25 percent or more of annual gross revenue from selling personal data. There is no flat revenue threshold. Nonprofits came into scope on July 1, 2025, and HIPAA and GLBA regulated data carry exemptions.
What makes the Oregon Consumer Privacy Act different from other state laws?
Oregon gives consumers the right to obtain a list of the specific third parties that received their personal data, not just the categories of recipients. That is broader than Virginia, Texas, or Colorado. Oregon also covers many nonprofits, which most state privacy laws exempt outright, and it defines personal data to include derived data.
What are the penalties for violating the OCPA?
The Oregon Department of Justice has exclusive enforcement authority and can seek civil penalties of up to $7,500 per violation, and each affected consumer can count as a separate violation. The 30-day right to cure sunset on January 1, 2026, so the agency can now issue a civil investigative demand or sue without offering notice and a chance to fix the issue first. There is no private right of action.
Does Oregon require honoring Global Privacy Control?
Yes. Since January 1, 2026, controllers must recognize a universal opt-out mechanism such as Global Privacy Control as a valid opt-out of the sale of personal data and targeted advertising. A browser-level signal is binding on its own, so your intake process has to detect and act on it rather than wait for a consumer to fill in a form.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.