← All jurisdictions
OR · data breach notification

Oregon

med

Or. Rev. Stat. §§646A.600–628

Individual deadline
45 days
Trigger standard
Risk of harm
AG / regulator
Required
Notice to individuals45 calendar days from discovery
Risk-of-harm standardno notice if, after investigation/law-enforcement consultation, no reasonable likelihood of harm
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeOregon Attorney General, required at 250+ residents; within 45 days
Credit reporting agenciesNo CRA-notice requirement.
Substitute noticeTypically available above $250,000 cost / 500,000 affected (verify).
Private right of actionNo, enforcement by the state.
Notable PI definitionsIncludes biometric, credentials, medical, health insurance.

Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Oregon breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →