---
title: Data Breach Notifications Laws for Oregon State
description: Oregon’s data breach notification law requires businesses to notify Oregon consumers whose personal information was subject to a breach of security.
---

[IT, Cybersecurity and Compliance Solutions in Washington and Oregon ](https://blog.teknologize.com)

# [Data Breach Notifications Laws for Oregon State](https://blog.teknologize.com/data-breach-notifications-laws-for-oregon-state)

 Written by [Byron Martin](https://blog.teknologize.com/author/byron-martin) | Feb 2, 2021

What does Oregon law require you to do, and who are you required to notify? What happens if you don’t notify anyone?

 

# **Data Breach Notification Laws**

Enacted in 2007, Oregon’s data breach notification law requires businesses and state agencies to notify any Oregon consumer whose personal information was subject to a breach of security. If a breach effected more than 250 Oregon consumers, the law also requires that a sample copy of a breach notice sent must also be provided to the Oregon Attorney General.

 

## **Breach of Security**

The [Oregon Department of Justice](https://www.doj.state.or.us/consumer-protection/) defines breach of security as an unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information that a person maintains or possesses.

 

Requirements:

1. If your company has experienced a data breach of an Oregonian’s personal information, you must notify the affected person within 45 days of discovering the breach.
2. If your company has experienced a data breach of 250 or more Oregonians’ personal information, you must report the breach to the Attorney General within 45 days of discovering the breach. Report a data breach online at: [https://justice.oregon.gov/consumer/DataBreach/Home/Submit](https://justice.oregon.gov/consumer/DataBreach/Home/Submit)

1. If more than 1,000 individuals must be notified, breached entities must also notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis.

1. If you fail to have reasonable security or provide proper notification of a data breach, you could be liable for civil penalties of up to $25,000 per violation.

 

### **Personal Information (PI)**

Personal information (PI) includes an Oregonian’s first name or first initial and last name in combination with any one or more of the following data elements:

- Social Security Number.
- Driver license number or state identification card number issued by the department of transportation.
- Passport number or other identification number issued by the United States.
- Account number or credit card number or debit card number in combination with any required security code, access code, or password that would permit access to a financial account.
- Biometric data such as an image of a fingerprint, retina or iris, or other unique characteristics used to authenticate the consumer’s identity.
- Health insurance policy number or health insurance subscriber identification number in combination with any other unique identifier that a health insurer uses to identify the consumer.
- Medical information, including medical history, mental or physical condition, diagnosis, or treatment.

#### **Data Security Breach Notification Laws by State**

Businesses must invest in security and be ready to respond if a breach occurs. Part of your preparedness program should be staying current on data breach legislation at the state level. [Mintz](https://www.mintz.com/mintz-matrix) is a useful online resource to review Data Breach Notification Laws by state.

<https://www.mintz.com/mintz-matrix>

*Image Courtesy of *[*Mintz*](https://www.mintz.com/mintz-matrix)

 

##### **List of Data Breach Notifications in Oregon **

Data security breach notifications sent to the Oregon Attorney General’s Office are [available for review here](https://justice.oregon.gov/consumer/DataBreach/). 

** **

###### **Oregon State Data Breach Resources**

- [Oregon Revised Statutes 646A.604: Notice of Breach of Security](https://www.oregonlaws.org/ors/646A.604)
- [Oregon Data Breach Reporting](https://www.doj.state.or.us/wp-content/uploads/2017/10/oregon_data_breach_reporting.pdf) *(PDF)*
- [Oregon Department of Justice Consumer Protection](https://www.doj.state.or.us/consumer-protection/)

###### **Additional Data Breach Resources**

- [Data Breach Response: A Guide for Business](https://www.ftc.gov/tips-advice/business-center/guidance/data-breach-response-guide-business) *(FTC Link)*
- [Data Breach Response: A Guide for Business](https://www.ftc.gov/system/files/documents/plain-language/pdf-0154_data-breach-response-guide-for-business-042519-508.pdf) *(PDF)*

Teknologize has clients throughout the Pacific Northwest with offices located in the Tri-Cities and Yakima, Washington 509.396.6640 and Bend, Oregon 541.848.6072.

[View full post](https://blog.teknologize.com/data-breach-notifications-laws-for-oregon-state)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Byron Martin"
  },
  "dateModified" : "2021-04-20T18:09:16.885Z",
  "datePublished" : "2021-02-02T18:35:54Z",
  "headline" : "Data Breach Notifications Laws for Oregon State",
  "image" : {
    "@type" : "ImageObject",
    "height" : 377,
    "url" : "https://f.hubspotusercontent20.net/hubfs/7748222/image-png-Feb-02-2021-05-00-00-18-PM.png",
    "width" : 624
  },
  "mainEntityOfPage" : "https://blog.teknologize.com/data-breach-notifications-laws-for-oregon-state",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "IT, Cloud, Cybersecurity and Compliance Solutions in the Washington Tri Cities Area"
  }
}
```