Oregon Consumer Privacy Act
Consumer Rights

Oregon Consumer Privacy Act OREGONCPA-2: Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out

Honor consumer rights per Oregon OCPA per ORS 646A.574. Rights include (a) right of access including obtaining list of specific third parties to which the controller has disclosed personal data per the consumer or any consumer (Oregon-unique provision distinguishing OCPA from other state laws), (b) right to correction of inaccurate personal data, (c) right to deletion of personal data, (d) right to portability of personal data in a readily usable format, (e) right to opt out of sale of personal data + targeted advertising + profiling in furtherance of decisions producing legal or similarly significant effects on the consumer. Authorised agent requests must be honored where consumer authorises agent in writing or via permitted technical means. Rights handling must (a) verify consumer identity using commercially reasonable methods + (b) respond within 45 days extendable + (c) provide twice yearly free of charge + (d) provide accessible methods for submission. Appeal of rights decision must (a) allow consumer to appeal denied request + (b) respond within 45 days + (c) provide reasoning + (d) inform of right to contact Attorney General.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 30 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CH-FADP-09 Notification of data files to the FDPIC
  • FADP-13 Right to Data Portability (Article 28)

APPI · 1 control

  • APPI-A27 Restriction on Provision to Third Parties
  • DS-2 Ensure software supply chain security

Bahrain PDPL · 1 control

  • BB-DPA-14 Section 15 - Right to Data Portability
  • DIQ-1 Data Integration and Interoperability
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

GDPR · 1 control

  • ISO8000-MDG-01 Master Data Quality
  • LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NORWAY-2 Data Subject Rights and Automated Decision-Making
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-3 IPP 6-8 Access, Correction, Accuracy
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • IM8-DAT.3 Data Sharing and Transfer

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37

Turkey KVKK · 1 control

  • TURKEYKVKK-1 VERBIS Registration and Lawful Basis
  • OB-API.2 Open Data API Specification
  • CPSC-STD.4 Interoperability Safety
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.