Oregon runs its own comprehensive privacy statute, the Oregon Consumer Privacy Act, with a personal-data definition that reaches further than most of its peers and a distinctive consumer right to a list of specific third-party recipients. This page walks through what the OCPA actually covers, why it draws a sharp B2B/individual line that matters for a firmographic tool like lead.box, and what an Oregon procurement or legal review typically wants to see before signing off.
At a glance
- Framework
- Oregon Consumer Privacy Act (OCPA), Or. Rev. Stat. §646A.570 et seq. (SB 619), effective 1 July 2024 (1 July 2025 for non-profits)
- Supervision
- Oregon Department of Justice / Attorney General exclusively; 30-day cure period, sunsetting 1 January 2026
- Usual legal basis
- Legitimate business purpose; identification resolves the organisation, not a consumer acting in an individual or household context
- Processing location
- ISO-certified EU data centres
The Oregon Consumer Privacy Act
Regulation at a glance
- FrameworkOregon Consumer Privacy Act (OCPA), Or. Rev. Stat. §646A.570 et seq. (SB 619), effective 1 July 2024 (1 July 2025 for non-profits)
- SupervisionOregon Department of Justice / Attorney General exclusively; 30-day cure period, sunsetting 1 January 2026
- Usual legal basisLegitimate business purpose; identification resolves the organisation, not a consumer acting in an individual or household context
- Processing locationISO-certified EU data centres
The Oregon Consumer Privacy Act, codified at Or. Rev. Stat. §646A.570 et seq. and originally enacted as SB 619, took effect on 1 July 2024, with a one-year delayed start for non-profit organisations on 1 July 2025. It applies to a controller or processor that conducts business in Oregon, or that produces products or services targeted at Oregon residents, and that during a calendar year controls or processes the personal data of 100,000 or more Oregon consumers — excluding data processed solely to complete a payment transaction — or of 25,000 or more consumers while deriving 25% or more of annual gross revenue from selling personal data. There is no separate revenue-only threshold that pulls in a small site purely because of its size.
Enforcement sits exclusively with the Oregon Department of Justice, acting through the Attorney General; unlike some peer states, the OCPA gives no consumer a private right of action. Controllers currently benefit from a 30-day cure period during which the Attorney General must notify a suspected violation and allow it to be fixed before formal action proceeds, but that cure period is written to expire on 1 January 2026, after which the Attorney General can pursue enforcement without a mandatory notice-and-fix window.
Two features of the OCPA stand out among comparable state laws. First, its definition of personal data is unusually broad: data that is linked or reasonably linkable to a consumer, or to a device that is linked or reasonably linkable to a consumer, which pulls device-level signals into scope more readily than statutes anchored strictly to an identified natural person. Second, Oregon consumers gain a right most peer states do not grant — obtaining, on request, a list of the specific third parties to which a controller has disclosed their personal data, rather than only a description of categories of recipients.
Why the OCPA's B2B line matters here
The OCPA defines a covered 'consumer' as a natural person who resides in Oregon and is acting only in an individual or household context; the statute explicitly excludes a natural person acting in a commercial or employment context, including as an employee, owner, director, officer or contractor of a company communicating in that capacity. That is a deliberate design choice, and it is the same structural exclusion used by most comprehensive US state privacy laws outside California. Purely business-to-business contact data — a work email tied to a job function, a vendor's outreach to a corporate buyer — sits outside the OCPA's consumer-rights machinery as a result.
That stands in direct contrast to California, where the CCPA/CPRA's temporary B2B and employee exemptions expired on 1 January 2023, meaning California's statute now reaches business contact data that Oregon's does not. An Oregon-based company selling nationally still has to track California's broader scope for its California visitors even while its own state law draws the B2B line more narrowly, which is exactly the kind of state-by-state variation a legal team has to hold in its head rather than treat as one national rule.
The third distinction sits alongside both of those: lead.box identifies the organisation behind a website visit — a company name, industry and size band inferred from network-level signals — not a named individual and not a business contact's personal details. That places company-level identification in a different analytical bucket from either the OCPA's individual-context consumer or California's now-covered B2B contact, and it is a distinction worth stating plainly to your own counsel rather than assuming it resolves the question for you.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
What this means for Oregon sales and marketing teams
Portland's software and services buyers, along with procurement teams at Oregon's manufacturing and timber-adjacent industrial base, increasingly ask a vendor review committee to confirm two things before adding a new site tool: does it touch personal data as the OCPA defines it, and does it fall under any of the growing state or federal universal opt-out signal requirements. From 1 January 2026, the OCPA requires controllers to recognise a universal opt-out mechanism for opt-out preference signals sent by a consumer's browser or device, which is a compliance item Oregon buyers will start asking vendors about well before that date arrives.
Because the OCPA's third-party disclosure list right is broader than most peer statutes, an Oregon-based controller adopting a new vendor tends to want a precise answer about who receives what data and why, rather than a generic category description that might satisfy a lighter-touch state law. A vendor that can hand over a clear sub-processor list and a plain description of what is and is not shared makes that specific Oregon ask easier to close.
None of this is a substitute for legal advice: whether a given deployment falls inside or outside OCPA scope, and how the approaching 2026 opt-out-signal requirement applies to a specific stack, depends on facts about your own data flows that only your own counsel can assess against the current statutory text and forthcoming guidance.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
The OCPA defines a 'consumer' as an Oregon resident acting only in an individual or household context, and it explicitly excludes a person acting in a commercial or employment capacity — as an employee, owner, director, officer or contractor communicating on behalf of a business. That means data collected in a purely business-to-business context, such as a work email address tied to a job function, generally sits outside the consumer-rights provisions the OCPA creates. This is the same structural approach most US state privacy laws outside California take, and it differs sharply from California, where the CCPA/CPRA's temporary B2B and employee exemptions expired on 1 January 2023, pulling business contact data into scope there. Whether a specific data element your site collects falls inside or outside that B2B carve-out under Oregon's current statutory language and guidance is a determination your own counsel should make, since the facts of each data flow matter.
The OCPA defines personal data unusually broadly as data linked or reasonably linkable to a consumer, or to a device linked or reasonably linkable to a consumer, which is wider than statutes tied strictly to an identified natural person. lead.box resolves a visiting organisation from network-level signals — primarily IP ranges associated with companies — into a company name, industry and size band, without identifying a named individual, without setting advertising identifiers, and without building a cross-site profile of a person. Whether that specific activity falls inside or outside the OCPA's broad personal-data definition, and inside or outside its individual-context consumer definition, depends on exactly what your deployment stores and how it's configured, which is a legal question for your own counsel rather than something lead.box can certify on your behalf. lead.box operates as a processor under a data processing agreement and documents its data flows to support that review.
The OCPA gives Oregon consumers a right, on request, to obtain a list of the specific third parties to which a controller has disclosed their personal data — a broader disclosure right than most comparable state laws, which typically only require a description of categories of recipients. That obligation applies to controllers handling covered consumer personal data, and it is one reason Oregon-based buyers tend to ask vendors for a precise, named sub-processor list rather than a vague category description during procurement. lead.box publishes its sub-processor list and can support a controller's own response to that kind of request, but whether a given website's use of lead.box triggers the obligation at all depends on whether the underlying data is covered personal data about a consumer as the OCPA defines that term — again a determination for your counsel, not a default assumption.
The OCPA applies to a controller that conducts business in Oregon or targets Oregon residents and that, during a calendar year, controls or processes the personal data of 100,000 or more Oregon consumers, excluding data processed solely to complete a payment transaction, or of 25,000 or more consumers while deriving 25% or more of annual gross revenue from selling personal data. There is no separate revenue-only trigger independent of those consumer-count thresholds, so a small site with modest Oregon traffic and no data-sale revenue stream may sit below both thresholds entirely, regardless of overall company size. Counting consumers correctly — including whether visitor identification data even counts toward that number given the B2B exclusion — is a fact-specific exercise, and your own counsel should confirm where your organisation lands before you rely on being under or over the line.
Starting 1 January 2026, the OCPA requires controllers to recognise a universal opt-out mechanism — an opt-out preference signal sent by a consumer's browser, extension or device — as a valid method of exercising certain consumer rights, similar to signals used under some other state laws. That requirement is directed at consumer-facing data uses covered by the statute, such as targeted advertising or sale of personal data about individuals in their personal capacity; it is a separate question from company-level identification of a business visitor, which does not target an individual consumer or rely on advertising identifiers. Oregon buyers are increasingly asking vendors how they'll handle universal opt-out signals well ahead of the 2026 date, and it's worth having a documented, current answer ready even where your own legal analysis concludes the underlying activity falls outside OCPA's consumer scope.
Enforcement authority for the OCPA sits exclusively with the Oregon Department of Justice, acting through the Attorney General; the statute does not give individual Oregon consumers a private right of action to sue directly. Controllers currently have the benefit of a 30-day cure period, during which the Attorney General must give notice of a suspected violation and allow it to be corrected before pursuing further action, but that cure period is set to sunset on 1 January 2026, after which the Attorney General can act without that mandatory notice-and-fix window. That approaching deadline is a reasonable prompt to get documentation and vendor review in order sooner rather than later, but the specific compliance steps that matter for your organisation depend on your own data practices and should be confirmed with counsel.
Oregon's OCPA excludes a person acting in a commercial or employment context from its definition of a protected consumer, so purely business-to-business contact data collected by an Oregon company largely sits outside the statute's individual-rights machinery. California draws that line very differently: the CCPA/CPRA's temporary B2B and employee-data exemptions expired on 1 January 2023, so California's law now covers business contact data in a way Oregon's does not. A Portland-based company selling nationally has to track both frameworks separately for its own compliance posture — narrower B2B treatment at home, broader coverage for California visitors and customers — rather than assuming one state's rule applies everywhere its site is viewed. This kind of state-by-state variation is exactly why a written legal review specific to each state you do business in matters more than a single blanket policy.
Yes, in the sense that OCPA applicability is only one part of a normal vendor review, and it's worth treating them as separate questions rather than assuming a favourable OCPA analysis closes the file. lead.box identifies the visiting organisation, not a named person, processes data as a processor under a written data processing agreement, keeps processing in ISO-certified EU data centres, and publishes its sub-processor list for exactly this kind of review. None of that constitutes legal advice or a compliance certification, and it doesn't substitute for your own counsel confirming how the OCPA's consumer definition, personal-data scope, and upcoming universal opt-out requirement apply to your specific website and data flows. Treating this page as background context for that review, rather than as the review itself, is the right way to use it.
See which companies are researching you from Oregon
Install a first-party snippet, watch the first companies appear, and hand your legal team the same documentation an Oregon procurement review would ask for.