Skip to content

Cyber Liability by state

Oregon data breach notification law and cyber insurance

Direct answer

What is Oregon's data breach notification law?

Oregon's breach notification law (Or. Rev. Stat. sect. 646A.600 et seq.) requires businesses to notify affected residents in the most expeditious manner possible and without unreasonable delay, but not later than 45 days after discovering the breach after a breach of personal information.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Oregon requires businesses to notify affected residents within 45 days of discovering a breach, with Attorney General notice when more than 250 residents are affected. Cyber liability insurance typically covers the forensics, notification, and legal review this deadline demands.

Consumer notification deadline
In the most expeditious manner possible and without unreasonable delay, but not later than 45 days after discovering the breach
Regulator notice
Notify the Oregon Attorney General when a breach affects more than 250 residents.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 1,000 residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key was not acquired, or where an investigation finds no reasonable likelihood of harm.
Enforcement
Violations are unlawful practices under the state's consumer protection law, enforceable by the Attorney General.

Statutes and sources

  • Oregon Consumer Information Protection Act

    Or. Rev. Stat. sect. 646A.600 et seq.

Regulator: Oregon Department of Justice . Last verified 2026-07-29 from the official source .

Get Oregon coverage handled

Share a few details and an agent will respond within one business day.