Oregon Consumer Privacy Act
Enforcement and Compliance

Oregon Consumer Privacy Act OREGONCPA-8: Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

Operate within Oregon OCPA enforcement framework + maintain training + compliance monitoring per ORS 646A.583 + 646A.586. Cure Period and Attorney General Enforcement: (a) Oregon Attorney General has exclusive enforcement authority through ORS 646A.583, (b) initial 30-day cure period available for alleged violations during 1 July 2024 through 1 January 2026 (sunsetting after that date), (c) civil penalty up to USD 7,500 per violation, (d) Attorney General may issue investigative demands + bring civil action. Non Profit Effective Date and Phased Compliance: (a) non-profit organisations have 1 July 2025 effective date allowing additional preparation time, (b) phased compliance approach permits operational readiness build. Compliance monitoring and auditing must (a) implement internal compliance programme covering policy + procedure + training + measurement, (b) conduct periodic audit + assessment + with documented findings + remediation. Training and awareness programs must (a) train personnel handling personal data + (b) maintain training records + (c) refresh on substantive change. Regulatory reporting and cooperation must cooperate with AG investigations + (a) respond to investigative demands + (b) maintain documentation for AG review. Complaints handling and resolution must (a) provide consumer complaint mechanism + (b) respond within statutory timeframes + (c) document resolution + (d) inform consumer of right to contact AG. Enforcement and penalties awareness must train relevant personnel on enforcement framework + civil penalty exposure + cooperation expectations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 125 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • CH-FADP-22 Privacy by design and default
  • CH-FADP-23 Data processing agreements
  • CH-FADP-24 Cross-border transfer safeguards
  • CH-FADP-25 Compliance monitoring and auditing
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

Bahrain PDPL · 5 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

NIST SP 800-190 · 4 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

GDPR · 3 controls

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 3 controls

  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-5 Cross-Border Health Data Flows
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • ASD37-27 Outbound data loss prevention (Very Good)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 125 it maps to, and the evidence behind each claim, over MCP and REST.