Enhance your TRUST relationship with PRIVACY and SECURITY. Privacy Made Simple!

   +1 866 267 0049   830 NE Pop Tilton Place, Jensen Beach, FL 34957

Oregon
Privacy Laws

Overview

BREACH NOTIFICATION – Mandated Timeframe
Within 45 days

FINES & PENALTIES – Violations
$1,000 – $500,000 per violation

Legal

Regulation Levels

  • Breach Reporting

    Breach Reporting

  • Consumer Notification

    Consumer Notification

  • Vendor Management

    Vendor Management

  • Vendor Contract Required

    Vendor Contract Required

PRIVACY AND SECURITY LAWS

Laws related to personal information and privacy and security.

QUICK FACTS

Oregon Privacy Law Information

PRIVACY PROGRAM

Vendors must have the same level of security and protection for personal information as Organizations, including a program for protection and security with administrative, technical and physical safeguards. The information security program includes requirements for the secure disposal of personal information when it is no longer needed for business purposes or as required by law. An organization contracted with a record destruction vendor is considered in compliance with the requirement if the vendor provides the same level of data protection and security. Organizations must contract with Vendors to require that Vendors maintain appropriate safeguards to protect the personal information of the Organization. Organizations and their contracted vendors must develop, implement and maintain an information security program to protect personal information it possesses and accesses. Documentation must be maintained for at least 5 years if it is reasonably determined that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. Vendors must have the same safeguards in place during data disposal. Data disposal vendors must be contracted. Organizations may be fined or penalized for Vendor violations.

BREACH REPORTING

Breach reporting must be made to all consumer reporting agencies that compile and maintain reports on consumers on a nationwide basis if the breach affects more than 1,000 Oregon residents. Notification to the Attorney General is required when 250 or more residents are affected. Breach notifications to any affected Oregon residents must be made within 45 days of discovery of a breach.

CONSUMER NOTIFICATION

If a breach affects residents of other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.

VENDOR/THIRD PARTIES

If a contracted Vendor who experiences a breach of security affecting more than 250 Oregon residents (or if the Vendor cannot determine the number affected) finds that the Organization has not provided breach notification to the Attorney General, the Vendor must complete the breach notification. If a contracted vendor experiences a breach or suspected breach of security, they must notify the data owner within 10 days of discovering the breach.

FINES & PENALTIES

Organizations may be fined or penalized for Vendor violations. Documentation must be maintained for at least 5 years if it is reasonably determined that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. The State Attorney General may publish the name of the breached entity and corresponding information.

Oregon Statutes and Laws

OAR §§ 581-021-0220 – 581-021-0440

Student education records

OAR § 581-021-0270

Right of inspection and review of education records

ORS §§ 646A.600 – 646A.628

Oregon consumer information protection act

ORS § 646A.604

Notice of breach of security

ORS § 646A.622

Requirement to develop safeguards for personal information

ORS § 646A.624

Powers of director, penalties

OAR § 847-012-0000

Patient’s access to medical records

DISCLAIMER

The information provided is not legal guidance or recommendations and are for informational purposes only.