Law / United States /
Oregon
Notice of breach of security
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A breach notification rule binding public and private bodies.
As of 27 August 2026.
What it requires
- Notify each affected Oregon consumer of a breach of security, including one you learn of through a vendor, and notify the Oregon Attorney General as well once more than 250 Oregon consumers are notified.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A covered entity subject to a breach of security, or that receives notice of one from a vendor, must give notice of the breach to each affected Oregon consumer, and must also notify the Attorney General once the number of Oregon consumers notified exceeds 250. This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
official Oregon statute text, ORS 646A.604, Oregon Consumer Identity Theft Protection Act
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.