06/18/2026
Ever read a headline about Oregon's privacy laws and quietly wondered if you were breaking one?
Here is some reassurance. Oregon has two data laws, and the one with the big penalties only applies to businesses handling data for 100,000-plus residents. Most Portland small businesses are not in that group.
The law that does apply to nearly everyone is far more down to earth: keep customer data reasonably safe, and report a breach within 45 days. Think multi-factor logins, limiting who can see what, and encrypting your laptops and backups.
We put together a plain-English guide that walks through which law applies to you and the simple steps that keep you on the right side of it.
→ [Link]