Law / United States / Oregon

Oregon

United States law applies in Oregon Oregon is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Oregon, described on this page below, applies here too.
Oregon has 1 local jurisdiction That local jurisdiction has law of its own, on a page of its own, listed below.

14 of 15 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 2 enacted but not yet in force. As of 12 September 2026.

  1. AI law 4
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law4 instruments, 3 in force, 1 enacted but not yet in force

Research summary (289 words)

Oregon adds four sector-specific AI disclosure and prohibition duties on top of the federal baseline, and has no general-purpose AI risk-management statute. A 2024 election-law amendment requires a disclosure whenever a campaign communication uses synthetic media to create a realistic but false depiction of a candidate (ORS 260.268, created by SB 1571).

A 2025 amendment extends the state's nonconsensual intimate-image crime to a digitally created, manipulated or altered depiction that is reasonably realistic, reaching an AI-generated or deepfake image on the same terms as an authentic one (ORS 163.472, amended by HB 2299). A separate 2025 act bars any nonhuman entity, including an agent powered by artificial intelligence, from using a protected nursing title (ORS 678.027, created by HB 2748).

A 2026 act requires an operator of an AI companion chatbot to disclose that a user is interacting with artificially generated output, run a suicide and self-harm detection protocol, and observe additional safeguards where a user is a minor, backed by a private right of action (Or. Laws 2026, ch. 85, SB 1546).

The Oregon Department of Justice issued guidance in December 2024 stating that the state's existing unlawful-trade-practices, consumer-privacy, breach-notification and civil-rights statutes already reach AI conduct, but that is guidance rather than a binding duty and is not catalogued as an instrument here.

A bill that would create a permanent Commission on Artificial Intelligence and a Chief Artificial Intelligence Officer within the Department of Justice (HB 3592) reaches only the state's own use of AI and is likewise not catalogued. No Oregon statute or reported decision was found addressing an AI-generated depiction of child sexual abuse beyond the federal baseline; ORS 163.684 to 163.689 (encouraging child sexual abuse) carry no 2025 or 2026 amendment on the point.

AI prohibited practices

Unlawful dissemination of an intimate image extended to AI-generated depictions (HB 2299)

ORS 163.472 (amended by 2025 Or. Laws ch. 116 (HB 2299))Oregon State Legislature, current Oregon Revised Statutes chapter 163

In force. Binds public and private bodies.

What this law does

Oregon's crime of unlawfully disseminating an intimate image, previously limited to a photograph, film or other visual reproduction, now also reaches a digitally created, manipulated or altered depiction that is reasonably realistic, so a deepfake or AI-generated nude or sexual image of a real, identifiable person falls within the same crime as an authentic one.

The person must have caused the disclosure with intent to harass, humiliate or injure someone who did not consent, and a reasonable person must be harassed, humiliated or injured by it. A first offense is a Class A misdemeanor; a second or later offense is a Class C felony.

Law enforcement activity, legitimate medical, scientific or educational activity, legal proceedings, reporting to law enforcement, and images the depicted person voluntarily displayed publicly or that were created commercially with consent are excluded.

What it requires

AI sector rules

Use of nursing titles by a nonhuman entity (HB 2748)

ORS 678.027Oregon State Legislature, current Oregon Revised Statutes chapter 678

In force. Binds public and private bodies.

What this law does

A nonhuman entity, including but not limited to an agent powered by artificial intelligence, may not use the title or abbreviation of Advanced Practice Registered Nurse, certified registered nurse anesthetist, clinical nurse specialist, licensed practical nurse, registered nurse, nurse practitioner, certified medication aide or certified nursing assistant.

The chapter carrying this section exempts only the employment of nurses in institutions or agencies of the federal government; a state or local government entity is otherwise bound the same as a private one, so an AI system interacting with patients in a state, local or private health care setting may not present itself under any of these titles.

What it requires

AI transparency

AI Companion Chatbot Safety Act (SB 1546)

Or. Senate Bill 1546, 2026 Regular SessionOregon Legislative Information System, enrolled Senate Bill 1546 (2026 Regular Session)

Commencement not set. Binds private bodies.

What this law does

An operator of an artificial intelligence companion or companion platform, software designed to simulate a sustained human-like platonic, intimate or romantic relationship by retaining information across sessions, asking unprompted emotional questions and sustaining personal dialogue, must give users a clear and conspicuous notice that they are interacting with artificially generated output whenever a reasonable person could otherwise believe they were talking to a natural person.

An operator must maintain an evidence-based protocol for detecting suicidal or self-harm ideation that refers a user to the 988 crisis lifeline, or to a youth-specific lifeline where the operator identifies the user as under 25, and must publish its protocol and an annual incident report.

Where an operator knows or has reason to believe a user is a minor, it must prevent the companion from claiming to be sentient or human, simulating emotional dependence or romantic interest, role-playing a romantic relationship with a minor, or producing sexually explicit content, and must add periodic reminders that the output is artificially generated.

An individual who suffers an ascertainable loss because of a violation may sue for the greater of actual or statutory damages of $1,000 per violation, plus an injunction and, if they prevail, attorney fees. Customer-service, productivity, video-game and voice-assistant software are excluded, as are stand-alone voice-command devices. Passed by the Legislative Assembly in the 2026 regular session and assigned chapter 85; no commencement date has been located in the sources reviewed.

What it requires

Campaign communication disclosure of synthetic media (SB 1571)

ORS 260.268 (created by 2024 Or. Laws ch. 62 (SB 1571))Oregon State Legislature, current Oregon Revised Statutes chapter 260

In force since 27 March 2024. Binds public and private bodies.

What this law does

A campaign communication that includes synthetic media, an image, audio or video recording of a candidate's appearance, speech or conduct intentionally manipulated with artificial intelligence or similar digital technology to create a realistic but false depiction, must include a disclosure that the recording has been manipulated.

The Secretary of State, and in specified cases the Attorney General, may sue to enjoin a violation, and a court may impose a civil penalty of up to $10,000, which the statute makes the exclusive remedy. Interactive computer services, bona fide news coverage, paid broadcasters, periodicals that carry a corrective statement, and satire or parody are excluded.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (232 words)

The Oregon Consumer Privacy Act (OCPA), ORS 646A.570 to 646A.589, is Oregon's comprehensive consumer-privacy regime, enacted as S.B. 619 (2023), effective July 1, 2024 for most controllers, with nonprofits exempt until January 1, 2026. Every citation here rests on the official Oregon State Legislature site (oregonlegislature.gov) rather than on a private republisher.

'Oregon Consumer Privacy Act' is the popular name for S.B. 619; the codified sections carry no short-title or caption naming the Act, so the regime is named here in prose rather than quoted from a short title that does not exist. Two 2025 amendments (H.B. 2008, H.B. 3875), effective January 1, 2026, added a precise-geolocation sale ban, a strict under-16 processing prohibition, and removed motor-vehicle manufacturers from the small-controller exemption.

Genetic or biometric data is one of OCPA's enumerated sensitive-data categories, unqualified by an identification-purpose clause. Oregon's biometric-data definition also carries the most explicit clawback in this batch: it separately and by name brings facial mapping or facial geometry back into 'biometric data' whenever generated or used to identify a specific consumer, in addition to the general photo, audio, or video-derived-data clawback.

A separate chapter, ORS 646A.604, governs breach notification, requiring notice to the Attorney General only once the number of affected consumers exceeds 250. The Attorney General has exclusive enforcement authority, with a discretionary cure option from the outset of the Act; there is no private right of action.

Breach notification

Notice of breach of security

ORS 646A.604official Oregon statute text, ORS 646A.604, Oregon Consumer Identity Theft Protection Act

Commencement not set. Binds public and private bodies.

What this law does

A covered entity subject to a breach of security, or that receives notice of one from a vendor, must give notice of the breach to each affected Oregon consumer, and must also notify the Attorney General once the number of Oregon consumers notified exceeds 250. This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Comprehensive regime

Oregon Consumer Privacy Act (OCPA), general applicability and controller duties

ORS 646A.570, 646A.578official Oregon statute text, ORS 646A.570 to 646A.589, Oregon Revised Statutes

In force since 1 July 2024. Binds private bodies.

What this law does

OCPA governs private-sector processing of Oregon consumers' personal data. Enacted as S.B. 619 (2023 Regular Session), Or. Laws 2023, ch. 369, effective July 1, 2024 for most controllers; nonprofits were exempt from OCPA duties until January 1, 2026.

Two 2025 amendments, both effective January 1, 2026, are already reflected in the current codified text: H.B. 2008 added a precise-geolocation sale ban and a strict under-16 processing prohibition for targeted advertising, sale, and profiling; H.B. 3875 removed motor-vehicle manufacturers from the small-controller exemption.

What it requires

Data subject rights

Oregon Consumer Privacy Act, consumer rights

ORS 646A.574, 646A.576, 646A.578official Oregon statute text, ORS 646A.570 to 646A.589, Oregon Revised Statutes

In force since 1 July 2024. Binds private bodies.

What this law does

OCPA gives an Oregon consumer the right to confirm processing, obtain a categories disclosure, receive a portable copy, correct, delete, and opt out of targeted advertising, sale, and profiling for decisions with legal or similarly significant effects.

A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available; an appeal of a refusal must be decided within 45 days; and consent revocation must be honored no later than 15 days after receipt.

What it requires

Enforcement supervision

Oregon Consumer Privacy Act, Attorney General enforcement

ORS 646A.589official Oregon statute text, ORS 646A.570 to 646A.589, Oregon Revised Statutes

In force since 1 July 2024. Binds private bodies.

What this law does

The Oregon Attorney General has exclusive authority to enforce OCPA; no other Oregon law creates a private right of action for a violation. Civil penalties run up to $7,500 per violation, and the statute of limitations is five years from the last violative act.

The cure opportunity was discretionary from the outset: the Attorney General may notify a controller of a violation only if the Attorney General determines the violation can be cured, and, per secondary reporting, that discretionary practice tightened further as of January 1, 2026.

What it requires

Sensitive categories

Oregon Consumer Privacy Act, sensitive data and biometric data definitions

ORS 646A.570(3), (18)official Oregon statute text, ORS 646A.570 to 646A.589, Oregon Revised Statutes

In force since 1 July 2024. Binds private bodies.

What this law does

OCPA lists genetic or biometric data independently as sensitive data, not qualified by a for-the-purpose-of-uniquely-identifying clause the way several peer states phrase it, alongside data revealing racial or ethnic background, national origin, religious beliefs, mental or physical condition, sexual orientation, transgender or nonbinary status, victim-of-crime status, citizenship or immigration status, a child's data, and precise geolocation data.

'Biometric data' means data from automatic measurement of biological characteristics used to identify a consumer, and Oregon's clawback is the most explicit of any state in this batch: it separately and by name brings facial mapping or facial geometry back into biometric data whenever generated or used to identify a specific consumer, in addition to the general photo, audio, or video-derived-data clawback.

What it requires

Scraping law2 instruments, 2 in force

Research summary (248 words)

Oregon diverges from federal scraping law in the computer_misuse and personal_data families.

Its computer crime statute, ORS 164.377, tracks the Computer Fraud and Abuse Act (CFAA)'s own without-authorization language closely enough that a court would likely import the federal circuit split (Van Buren v. United States; hiQ Labs v. LinkedIn) as the operative framework, but no Oregon case addresses an unauthenticated, no-login scraping fact pattern directly; the two reported cases construing without authorization, State v. Nascimento (2016) and State v. Schwartz (2001), are both insider-misuse cases.

The Oregon Consumer Privacy Act reaches scraped public personal data more explicitly than most peer statutes on two points: sensitive data is defined to include a consumer's precise geolocation (accurate within a 1,750-foot radius) and genetic or biometric data, and a controller may not process sensitive data without first obtaining the consumer's consent, reaching scraped public personal data that falls in a sensitive category regardless of its public source.

A 2025 amendment (HB 2008) is reported to flatly ban selling a consumer's precise geolocation data effective January 1, 2026, but this is not independently confirmed against primary bill text and is reported here as secondary-sourced only. Copyright, text-and-data-mining, and database rights add nothing beyond the federal position.

ToS enforceability rests on ordinary Oregon contract law with no Oregon-specific statute or case; Oregon's Unlawful Trade Practices Act and common-law trespass to chattels are available in principle for unfair competition and misappropriation but are untested against scraping in Oregon case law. robots.txt carries no independent legal weight in Oregon.

Computer misuse

Oregon Computer Crime, without-authorization access and alteration

Or. Rev. Stat. § 164.377official text, Oregon State Legislature (oregonlegislature.gov)

In force. Binds public and private bodies.

What this law does

Subsections (3) and (4) make it a crime to knowingly and without authorization alter, damage, destroy, use, access, or attempt to access any computer, computer system, computer network, or the software, program, documentation, or data it contains.

This tracks the Computer Fraud and Abuse Act (CFAA)'s own without-authorization language closely enough that a court applying it would likely import the federal circuit split, Van Buren v. United States (593 U.S. 374, 2021) and hiQ Labs v. LinkedIn (31 F.4th 1180, 9th Cir. 2022), as the operative framework, though no Oregon court has adopted or rejected the Ninth Circuit's reading that a computer presumptively open to all comers erects no authorization gate at all.

Oregon's own case law construing without authorization comes from the insider-misuse context rather than outside scraping: State v. Nascimento, 360 Or 28, 379 P3d 484 (2016), held that an employee using access already granted for an improper personal purpose does not thereby act without authorization absent technical circumvention, and State v. Schwartz, 173 Or App 301, 21 P3d 1128 (2001), rejected a vagueness challenge to the phrase.

Neither reaches the hiQ fact pattern of unauthenticated, no-login access, so open-web crawling of an Oregon-connected public page is unsettled leaning toward permitted rather than settled by direct authority. Oregon has no ToS-specific statute or case (ordinary contract law governs browsewrap and clickwrap alike), no state text-and-data-mining exception or database right beyond the federal position, and no statute giving robots.txt independent legal weight.

Oregon's Unlawful Trade Practices Act, ORS 646.605 et seq., and common-law trespass to chattels are available in principle for unfair competition and misappropriation claims but remain untested against scraping specifically in Oregon case law.

What it requires

Personal data

Oregon Consumer Privacy Act (OCPA), sensitive-data consent and geolocation

Or. Rev. Stat. §§ 646A.570 to 646A.589official text, Oregon State Legislature (oregonlegislature.gov)

In force since 1 July 2024. Binds private bodies.

What this law does

OCPA applies to a person conducting business in Oregon, or providing products or services to Oregon residents, that during a calendar year controls or processes the personal data of 100,000 or more consumers, other than data processed solely to complete a payment transaction, or of 25,000 or more consumers while deriving 25 percent or more of gross revenue from selling personal data, with no separate dollar-revenue threshold of its own.

Sensitive data is defined to include a consumer's precise present or past location, accurate within a 1,750-foot radius, and genetic or biometric data, and a controller may not process sensitive data about a consumer without first obtaining the consumer's consent.

OCPA's own 'personal data' definition does carry a publicly-available-information exemption, and 'sensitive data' is itself defined as a subset of personal data, so the same exemption applies upstream to it: personal data does not include data that is lawfully available through federal, state, or local government records or through widely distributed media, or that a controller reasonably has understood to have been lawfully made available to the public by the consumer (ORS 646A.570(13)(b)).

This is narrower than a blanket public-availability exemption, since it does not cover data merely observable online that a scraper, rather than the consumer or a distributed-media outlet, is the one making public; scraped sensitive or personal data of unclear provenance should still be treated as covered unless one of those two specific showings applies.

Oregon amended OCPA in 2025 (HB 2008, reported signed by Governor Kotek June 3, 2025) to flatly ban selling a consumer's precise geolocation data effective January 1, 2026, a stricter rule than most peer states' consent-based approach; this amendment is reported by contemporaneous legal commentary and is not independently confirmed against HB 2008's own enrolled text, so its effective date and exact mechanism should be treated as reported rather than machine-verified.

Enforcement is by the Attorney General only, with a civil penalty of up to $7,500 per violation and a cure period through 2026; OCPA carries no private right of action.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (562 words)

Oregon binds a private-sector manufacturer of an Internet-connected consumer device to a market-entry security duty at ORS 646A.813 (2019 c.193, House Bill 2395-A), which requires a manufacturer that sells or offers to sell a connected device, a physical object connected directly or indirectly to the Internet and used primarily for personal, family or household purposes, in the state to equip it with reasonable security features: a unique preprogrammed authentication credential or a requirement that the user set new credentials before first use, or compliance with an applicable federal security requirement.

The section reaches only the manufacturer of the physical device itself, expressly disclaiming any duty over software, firmware or peripheral devices that another manufacturer makes and a consumer later adds, so it does not by itself reach a developer who ships only an app or other software with no connected device of its own, and it exempts a device already regulated under Health Insurance Portability and Accountability Act (HIPAA) or under the Food and Drug Administration's medical-device rules.

A violation is declared an unlawful trade practice under ORS 646.607, enforceable by the Attorney General or a district attorney by injunction under ORS 646.632 and by a civil penalty of up to $25,000 per willful violation under ORS 646.642(3); Oregon's general private right of action for unlawful trade practices, ORS 646.638, reaches only a practice declared unlawful under the separate ORS 646.608, so the connected-device duty carries no private remedy of its own.

Separately, the Oregon Consumer Information Protection Act's safeguards provision, ORS 646A.622 (originally 2007 c.759, most recently amended 2019 c.180), requires a covered entity, a person who owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses an Oregon consumer's personal information in the course of business, vocation, occupation or volunteer activity, including a public body, and a vendor that holds that information on a covered entity's behalf, to develop, implement and maintain reasonable administrative, technical and physical safeguards; a covered entity or vendor complies either by already being regulated under Gramm-Leach-Bliley Act Title V, HIPAA and HITECH, or another law providing greater protection, or by running an information security program with the administrative, technical and physical elements the statute lists, and a small business may scale its program to its own size and the sensitivity of the information it holds.

The Director of the Department of Consumer and Business Services enforces the safeguards duty by investigation, subpoena and a cease-and-desist or consumer-compensation order, with a civil penalty of up to $1,000 per violation capped at $500,000 for any one occurrence; the sections name no private right of action of their own.

No Oregon statute requiring a private business to report an exploited vulnerability or a security incident to an authority, a CSIRT or users is described here; none was located in the sources checked.

No state-specific sector cyber-resilience regime, a financial-services or insurance information-security regulation binding a class of regulated entity, is described here either; Oregon's insurance trade-practices chapter, ORS 746, returned no match for an information-security or cybersecurity program duty on a compliant and two browser-rendered reads, but the rest of Oregon's insurance and financial-services statutes were not read, so their silence or content on the point is not established here.

Oregon's breach-of-security notice duty, ORS 646A.604, is part of the same Oregon Consumer Information Protection Act as the safeguards provision above but is already this jurisdiction's privacy row and is not repeated here.

Product security requirements

Security requirements for Internet-connected devices

ORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607)Official statute text, Oregon Revised Statutes, ORS chapter 646A

In force. Binds private bodies.

What this law does

A manufacturer, a person that makes a connected device and sells or offers to sell it in Oregon, must equip the device with reasonable security features: a preprogrammed authentication credential unique to each unit, or a requirement that the user generate new credentials before first use, or compliance with an applicable federal security requirement for connected devices.

A connected device is limited, under the section's own definition, to a physical object used primarily for personal, family or household purposes that connects to the Internet or is assigned an address for a short-range wireless connection.

The section expressly imposes no duty on the manufacturer for software, firmware or peripheral devices that another manufacturer makes and a consumer later installs or adds, so it does not by itself reach a developer who ships only software or an app with no connected device of its own. It also exempts a device already regulated as to the relevant activity under Health Insurance Portability and Accountability Act (HIPAA), or already subject to Food and Drug Administration medical-device requirements.

It imposes no verification duty on an app store or marketplace. A violation is declared an unlawful trade practice under ORS 646.607, enforceable only by the Attorney General or a district attorney by injunction and a civil penalty of up to $25,000 per willful violation. Oregon's general private right of action for unlawful trade practices, ORS 646.638, reaches only a practice declared unlawful under the separate ORS 646.608, so a violation of this section carries no private remedy of its own.

The enacted bill carries no operative-date or emergency clause of its own, so the section took effect under Oregon's constitutional default rule, ninety-one days after the 2019 regular session adjourned; no source located states that calendar day, so no day-precise effective date is recorded here.

What it requires

Security baseline statutes

Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information

ORS 646A.622 (2007 c.759 sec. 12; amended 2015 c.357 sec. 3; 2018 c.10 sec. 6; 2019 c.180 sec. 4)Official statute text, Oregon Revised Statutes, ORS chapter 646A

In force. Binds public and private bodies.

What this law does

A covered entity and a vendor must develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including safeguards for its disposal.

A covered entity is any person, defined to include a public body, that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person's business, vocation, occupation or volunteer activities. A vendor is a person a covered entity contracts with to maintain, store, manage, process or otherwise access personal information on the covered entity's behalf.

A covered entity or vendor complies either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, Health Insurance Portability and Accountability Act (HIPAA) and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with the administrative safeguards (a designated coordinator, periodic risk assessment, employee training, vetted service-provider contracts), technical safeguards (network and software risk assessment, security patch management, attack detection and testing) and physical safeguards (collection and disposal risk assessment, intrusion monitoring, and secure destruction of records) the statute lists.

A small business may instead scale its program to its own size, complexity and the sensitivity of the personal information it collects. The Director of the Department of Consumer and Business Services enforces the duty by investigation, subpoena, and a cease-and-desist order or, only where enforcement by private civil action would be impractical, an order that the violator compensate injured consumers, with a civil penalty of up to $1,000 per violation and up to $500,000 for any one occurrence.

The sections name no private right of action of their own. The safeguards duty was first enacted in 2007 (2007 c.759 sec. 12) and has since been amended three times, most recently in 2019 (2019 c.180 sec. 4), each amendment carrying only a session and chapter citation rather than a stated calendar date, so no day-precise date is recorded here for when the duty as it now reads began to operate.

What it requires

Age gating law1 instrument, 1 in force

Research summary (135 words)

Oregon has no adult content age verification law. A bill that would have required age verification for websites where a substantial share of content is sexual material harmful to minors (HB 2032) died when the 2025 session adjourned on June 27, 2025, and an app store age verification bill (HB 3696) died in House committee at the same adjournment; the short 2026 session, which adjourned March 6, 2026, enacted nothing in the four tracked families.

Oregon has no social media specific minor access law. Its age gating protection instead runs through its comprehensive privacy law: a 2025 amendment to the Oregon Consumer Privacy Act (HB 2008) bars selling the personal data of, serving targeted advertising to, or profiling a consumer the controller knows or willfully disregards is under 16, in effect since January 1, 2026.

Age-appropriate design code

HB 2008, Oregon Consumer Privacy Act minors and geolocation amendments

Or. Rev. Stat. section 646A.578 (2025 Or. Laws ch. 251)official Oregon Legislative Information System enrolled bill and session law chapter

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Bars a controller that has actual knowledge that, or willfully disregards whether, a consumer is under 16 from selling that consumer's personal data, using it for targeted advertising, or profiling in furtherance of decisions with legal or similarly significant effects, with no consent exception, and separately bars selling personal data that identifies a consumer's location within a 1,750 foot radius. Signed by Governor Kotek on June 3, 2025.

Note and primary source

Law in local jurisdictions1 with a page

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.