Back to Frameworks

Oregon OCPA

United States
15 domains
31 controls

Oregon Consumer Privacy Act (Or. Rev. Stat. § 646A.570 et seq., effective 1 Jul 2024).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (15)

Accountability

2 controls
Controls in the Accountability domain of Oregon OCPA2 controls
CodeTitle
OR-OCPA-578-DPAData Protection Assessments (DPAs)
OR-OCPA-578-RECORDKEEPINGRecordkeeping for Compliance Demonstration

Advertising

1 controls
Controls in the Advertising domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-CROSS-CONTEXTTargeted Advertising Restrictions

Consent

1 controls
Controls in the Consent domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-580-CONSENT-DEFINITIONDefinition of Consent

Consumer rights

12 controls
Controls in the Consumer rights domain of Oregon OCPA12 controls
CodeTitle
OR-OCPA-574-CORRECTIONRight to Correction
OR-OCPA-574-DELETIONRight to Deletion
OR-OCPA-574-OPTOUTRight to Opt Out of Targeted Advertising, Sale, and Profiling
OR-OCPA-574-PORTABILITYRight to Data Portability
OR-OCPA-574-RIGHT-THIRDPARTY-LISTRight to List of Specific Third Parties (Distinctive Provision)
OR-OCPA-574-UOOMUniversal Opt-Out Mechanism (UOOM) Recognition
OR-OCPA-577-RIGHT-ACCESSRight to Know and Confirm Processing
OR-OCPA-578-APPEALRight to Appeal Denial of Request
OR-OCPA-578-FREE-AUTHENTICATIONFree Response and Authentication
OR-OCPA-578-LOYALTYBona Fide Loyalty Programs
OR-OCPA-578-NON-DISCRIMINATIONNon-Discrimination for Exercising Rights
OR-OCPA-578-RESPONSE-TIMEResponse Timing for Consumer Requests

Data classification

1 controls
Controls in the Data classification domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-DEIDENTIFIEDDeidentified and Pseudonymous Data

Definitions

1 controls
Controls in the Definitions domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-570-DEFINITIONSKey Definitions: Controller, Processor, Consumer, Personal Data

Enforcement

2 controls
Controls in the Enforcement domain of Oregon OCPA2 controls
CodeTitle
OR-OCPA-583-CURE30-Day Right to Cure (Sunsets 2026-01-01)
OR-OCPA-583-ENFORCEMENTEnforcement by Oregon Attorney General

Principles

1 controls
Controls in the Principles domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-DATA-MINData Minimization and Purpose Limitation

Processor management

1 controls
Controls in the Processor management domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-PROCESSOR-CONTRACTSProcessor Contract Requirements

Profiling

1 controls
Controls in the Profiling domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-PROFILING-DECISIONSProfiling in Furtherance of Significant Decisions

Sale

1 controls
Controls in the Sale domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-SALESale of Personal Data Definition

Scope

3 controls
Controls in the Scope domain of Oregon OCPA3 controls
CodeTitle
OR-OCPA-570-APPLICABILITYApplicability Thresholds
OR-OCPA-570-EXEMPTIONSEntity and Data Level Exemptions
OR-OCPA-NONPROFIT-DELAYNonprofit Effective Date (Distinctive)

Security

1 controls
Controls in the Security domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-SECURITYReasonable Data Security

Sensitive data

2 controls
Controls in the Sensitive data domain of Oregon OCPA2 controls
CodeTitle
OR-OCPA-578-CHILD-DATAChildren's Personal Data
OR-OCPA-578-SENSITIVE-DATASensitive Data Opt-In Consent

Transparency

1 controls
Controls in the Transparency domain of Oregon OCPA1 controls
CodeTitle
OR-OCPA-578-PRIVACY-NOTICEPrivacy Notice Content Requirements

Frequently Asked Questions

What is Oregon OCPA?

Oregon OCPA is a compliance framework from United States with 15 domains and 31 controls. Oregon Consumer Privacy Act (Or. Rev. Stat. § 646A.570 et seq., effective 1 Jul 2024). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Oregon OCPA have?

Oregon OCPA has 31 controls organised across 15 domains. The largest domains are Consumer rights (12 controls), Scope (3 controls), Accountability (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Oregon OCPA map to?

Oregon OCPA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Oregon OCPA compliance?

Start your Oregon OCPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Oregon OCPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required