Law status
Verified comprehensive law
Yes - Oregon Consumer Privacy Act
- Official name / citation
- ORS 646A.570-646A.589
- Status / effective date
- In force; effective July 1, 2024 per the state agency page
- Principal enforcer
- Oregon Department of Justice / Attorney General
Direct attached-library attribution
0 cases · $0
These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.
The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.
Official law sources
Other generally applicable PII law
n.a.
Public enforcement context
Tier 1*
EyeMed Vision Care
$2.5 million total (four states) · May 16, 2023
Oregon joined New Jersey, Florida and Pennsylvania in settling claims over a June 2020 breach exposing patients' personal information.
Legal basis: State consumer protection laws, state personal-information protection laws and HIPAA
Mapped control outcomes
1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence
Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.
Educational information, not legal advice. The supplied snapshot is dated August 25, 2026; confirm current law, applicability, exceptions, official status, and reporting decisions with qualified counsel and the relevant authority.