Law / United States / Oregon

Notice of breach of security

ORS 646A.604

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A breach notification rule binding public and private bodies.

As of 27 August 2026.

What it requires

  • Notify each affected Oregon consumer of a breach of security, including one you learn of through a vendor, and notify the Oregon Attorney General as well once more than 250 Oregon consumers are notified.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A covered entity subject to a breach of security, or that receives notice of one from a vendor, must give notice of the breach to each affected Oregon consumer, and must also notify the Attorney General once the number of Oregon consumers notified exceeds 250. This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official Oregon statute text, ORS 646A.604, Oregon Consumer Identity Theft Protection Act

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app