Oregon Consumer Privacy Act
Universal Opt-Out and Marketing

Oregon Consumer Privacy Act OREGONCPA-4: Universal Opt-Out, Targeted Advertising, Profiling

Honor universal opt-out + targeted advertising + profiling per Oregon OCPA per ORS 646A.574. Universal Opt Out Mechanism Recognition must (a) recognise opt-out signals communicated by platforms + technologies + or mechanisms that clearly indicate consumer intent to opt out (Global Privacy Control / GPC + similar), (b) treat as valid opt-out request per ORS 646A.574(5), (c) align with multi-state UOOM specifications (Colorado + Connecticut + California + similar). Targeted advertising opt-out must apply to advertising based on personal data obtained from consumer activity across non-affiliated websites or applications. Profiling opt-out applies to (a) profiling in furtherance of decisions that produce legal or similarly significant effects on the consumer + (b) such as financial + lending + housing + insurance + education + criminal justice + employment + healthcare + access to essential goods or services. Maintain (a) automated decision-making documentation + (b) human review capability + (c) explanation of significant decisions affecting consumers + (d) opt-out fulfilment within statutory timeframes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 19 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

APPI · 1 control

  • APPI-A31 Provision of Personally Referable Information

Bahrain PDPL · 1 control

  • BH-PDPL-18 Regular security testing and assessment
  • FFIEC-08 Application security controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)

ISO/IEC 27400:2022 · 1 control

  • 27400-6.3 Secure Update Mechanism
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • IM8-DSS.3 Secure Development Practices

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.