Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope

The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.

By Rebecca Leung · July 17, 2026 ·
Table of Contents

Two years in, the Oregon Consumer Privacy Act is no longer a future event on a compliance calendar. It’s an active enforcement program without a safety net.

The 30-day cure period expired January 1, 2026. The Oregon AG can now pursue $7,500-per-violation civil penalties without giving advance notice. There were 214 complaints in year one. All 38 enforcement matters were resolved through cure letters — which means there are 38 companies whose OCPA gaps were documented, fixed, and on record. New violations don’t get that second chance.

If you work in financial services and haven’t looked at Oregon specifically, there are two things you need to know: the GLBA exemption probably doesn’t cover everything you think it does, and Oregon has a consumer disclosure requirement that no other state in the country replicates.

TL;DR

  • The Oregon Consumer Privacy Act (ORS 646A.570–646A.589) has been in effect since July 1, 2024 — the 30-day cure period expired January 1, 2026
  • The GLBA entity-level exemption applies only to ORS 706.008 financial institutions (FDIC-insured banks, Oregon credit unions and their qualifying affiliates) — fintechs, mortgage companies, RIAs, and broker-dealers are NOT covered
  • Oregon is the only U.S. state that gives consumers the right to request specific named third parties (not just categories) that received their data — per ORS 646A.574(1)(a)(B)
  • HB 2008 effective January 1, 2026 bans selling precise geolocation data (within 1,750-foot radius) — no consent exception
  • 214 complaints in year one; $7,500/violation with no cure period since January 1, 2026

The GLBA Exemption Is Narrower Than You Think

Most financial services companies encountering a new state privacy law default to the same question: “Are we a GLBA-covered entity?” And if yes, the assumption is that the entity-level exemption removes the problem.

Oregon doesn’t work that way.

The OCPA’s financial institution exemption has two separate tiers that do very different things:

Tier 1 — Entity-level exemption (narrow): Under ORS 646A.572(2), the OCPA exempts financial institutions as defined by ORS 706.008 — the Oregon Bank Act definition. That definition covers FDIC-insured banks, banks organized under foreign law, Oregon-chartered credit unions, out-of-state credit unions, and federal credit unions. It also covers affiliates and subsidiaries of those entities, but only if the affiliate is “only and directly engaged in financial activities” as described in 12 U.S.C. 1843(k).

This is significantly narrower than the federal GLBA definition. GLBA covers any company “significantly engaged in financial activities.” Oregon’s entity-level exemption does not.

The practical implication: fintechs, nonbank mortgage lenders, registered investment advisers, broker-dealers, insurance companies, and payment processors are not covered by Oregon’s entity-level exemption — even if they’re fully GLBA-regulated. A payments fintech that processes transactions for Oregon consumers is subject to the OCPA regardless of its GLBA compliance posture.

Tier 2 — Data-level exemption (broader): Separately, the OCPA exempts personal data that “originates from, or is intermingled so as to be indistinguishable from” GLBA-covered NPI — but only for entities licensed under the Oregon Consumer Finance Act (ORS 725.010), and only for data collected in the manner GLBA requires. This tracks the approach California took under the CCPA.

The data-level exemption is narrower than it sounds in practice. It covers the specific NPI that GLBA requires you to manage — loan application data, account information, payment history. It does not cover:

  • Prospect and lead data collected before a consumer becomes a customer
  • Website analytics and behavioral data collected pre-login
  • Rejected applicants’ data that never became account data
  • Marketing partner data where the consumer relationship is indirect
  • Biometric authentication data that isn’t itself financial NPI
  • Subsidiary business lines whose activities aren’t financial services

For a fintech that collects pre-login browsing behavior for marketing segmentation, runs targeted advertising to prospects who never became customers, or operates a loyalty or rewards program alongside its financial product — significant portions of its data processing fall outside the data-level exemption entirely.

The Mayer Brown analysis of Oregon’s narrow financial institution exemption covers this distinction in detail; Orrick has similarly confirmed the gap across multiple state privacy law comparisons. The consensus: Oregon’s financial services exemption is one of the most narrowly scoped of any U.S. state privacy law.


The Feature No Other State Has: Named Third Parties

Every major state privacy law requires privacy notices that include categories of third parties that receive consumer data. “Advertising partners,” “service providers,” “analytics providers.” That’s the industry standard.

Oregon added something different. ORS 646A.574(1)(a)(B) gives consumers the right to request “a list of specific third parties, other than natural persons,” to whom the controller has disclosed their personal data. Not categories. Specific named entities.

In Oregon’s one-year enforcement report, 19 of the 214 complaints specifically cited denial of this right. That’s the third most common complaint, behind delete requests (77) and data copy requests (20).

Complying with this right is operationally different from complying with categorical third-party disclosure requirements. You can’t point to your privacy policy and call it done. You need:

  1. An auditable record of which named entities received each consumer’s data. Not aggregated at the company level — attributable to specific consumers.
  2. A system that can produce that list on request within the 45-day response window Oregon requires.
  3. Data mapping that tracks third-party disclosures at the individual record level — not just categories of recipients.

For financial services companies that share data with affiliate marketing networks, lead generation platforms, credit reporting agencies, or analytics vendors, the list of named third parties for a single consumer can be substantial. And unlike California or Colorado, Oregon requires the actual company names.

If your data mapping only documents “third-party analytics vendors” and “credit bureau partners,” your OCPA compliance for this right is incomplete.


Cure Period Gone, Enforcement Clock Running

In year one, the Oregon AG’s office received 214 complaints and resolved all 38 enforcement matters through the cure process. Companies got notified, fixed the issue, and avoided penalties.

That era ended January 1, 2026.

Under ORS 646A.589, the AG can now pursue $7,500-per-violation civil penalties — with each affected consumer potentially counting as a separate violation — from the first complaint. There’s no mandatory notice. There’s no correction window.

The year-one enforcement data reveals where the risk concentrates:

Most Common Complaints (Year One)Count
Right to delete not honored77
Right to data copy not fulfilled20
Named specific third-party list not provided19
Other OCPA rights14

Data brokers and background check sites were the single largest complaint category. But financial services companies appeared across multiple complaint types — particularly for failing to recognize that offline data and back-end systems are subject to consumer rights requests, not just app or website data.

The AG’s office noted explicitly in year one: companies often didn’t recognize that their obligations extend to all personal data they control, regardless of how it was collected. Loan files, call center records, historical transaction databases, and physical records — if they contain personal data of Oregon consumers, consumer rights apply.


January 2026: Two Laws Tightened at Once

Oregon’s privacy exposure for financial services companies intensified at the start of 2026 from two directions simultaneously.

The cure period sunset. As discussed: no more 30-day correction window before penalties apply.

Oregon HB 2008’s geolocation ban. Signed by Governor Tina Kotek on June 3, 2025 and effective January 1, 2026, HB 2008 added an outright ban on selling precise geolocation data — defined as data capable of identifying an individual or device’s location within a 1,750-foot radius.

The ban has no consent exception. Consumers cannot opt in to allow their precise geolocation data to be sold. The only exceptions are narrow operational carve-outs for communications providers and public utilities. Everyone else is prohibited from selling precise geolocation data regardless of what the privacy policy says or what consents exist.

As Davis Wright Tremaine’s analysis of HB 2008 explains, the 1,750-foot definition captures data from mobile devices, GPS coordinates, IP-address-based location, and location data embedded in photos or other content.

Financial services companies using location data for fraud risk modeling, marketing segmentation, or personalization need to assess whether any of that data is sold (or licensed in ways that constitute a “sale” under Oregon’s definition) to third parties. If yes, those activities are prohibited in Oregon since January 1, 2026.

HB 2008 also eliminated the remaining cure period carve-out for nonprofits — what had previously applied broadly now applies only to noncommercial educational broadcast stations. There’s no meaningful nonprofit exception remaining.


What In-Scope Financial Services Companies Need to Do

The OCPA’s official business FAQ page from the Oregon DOJ is the clearest starting point for confirming whether your organization is in scope.

For financial services companies that clear the OCPA threshold (100,000 Oregon consumers or 25,000 consumers with 25% revenue from data sales):

Map your GLBA boundary accurately. Identify which data processing activities fall within the GLBA data-level exemption and which don’t. Prospect data, marketing analytics, rejected applicant data, and behavioral data collected before account opening are likely outside the exemption. Don’t assume GLBA covers your full data footprint.

Build the named third-party tracking. If you share personal data with any named entities — advertising platforms, analytics vendors, affiliates, credit reporting agencies, data brokers — build the record-level tracking that lets you respond to a specific-named-third-party request for an individual consumer. Category disclosure in a privacy policy isn’t enough.

Audit geolocation data practices. If your product, analytics, or marketing operations involve location data precise enough to identify an individual within 1,750 feet, confirm whether that data is being sold or licensed in ways that constitute a sale. If yes, that stopped being permissible in Oregon on January 1, 2026.

Update your consumer rights response process. Oregon’s 45-day response window applies to all rights requests. With no cure period, a failed response means immediate enforcement exposure.

Check whether existing privacy notices are OCPA-compliant. Oregon has specific required disclosures that may differ from your CCPA/CPRA-compliant notices. Oregon’s specific-named-third-party right needs to be addressed — and your response process needs to actually produce the named list, not a category-level summary.


The State Enforcement Environment Makes Oregon Matter More

As our analysis of state AG enforcement priorities for 2026 covers, the retreat of federal consumer financial enforcement activity hasn’t reduced compliance risk — it’s shifted enforcement activity to state levels.

The CFPB’s 2026 regulatory agenda reflects a Bureau that’s cut nonbank examination by 64% in two years. Oregon’s AG isn’t pulling back. The combination of active state privacy enforcement, a cure period that has expired, and consumer rights requirements that many financial services companies have underinvested in creates a real exposure profile that federal examination reduction doesn’t offset.

State privacy enforcement is the enforcement environment now for many companies. Oregon’s unique features — the narrow GLBA exemption, the named-third-party right, the geolocation ban — make it one of the most demanding state privacy regimes for financial services companies to navigate correctly.


So What?

Oregon is a manageable compliance obligation, but only if companies understand what they’re actually subject to. The GLBA exemption is narrower than GLBA-regulated companies typically assume. The named third-party right is unlike anything in other state privacy laws and requires infrastructure most companies’ current data mapping doesn’t support. The cure period is gone.

The year-one enforcement data shows the AG’s office is actively working through complaints and resolved every matter it took up. The resolution mechanism through January 2026 was cure letters. The resolution mechanism now is civil penalties.

If you’re building out your state privacy compliance program or need documentation templates for consumer rights request processes, data mapping frameworks, and third-party disclosure inventories, the Data Privacy Compliance Kit gives you the frameworks to operationalize OCPA compliance alongside parallel obligations in California, Colorado, and other active state regimes.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the GLBA exemption protect fintechs and financial services companies under Oregon's privacy law?
The Oregon Consumer Privacy Act (OCPA) has two separate GLBA-related exemptions, and the entity-level exemption is narrower than most financial services companies assume. The entity-level exemption — which covers the entire company — applies only to 'financial institutions' as defined by ORS 706.008: FDIC-insured banks, Oregon-chartered credit unions, and their direct affiliates and subsidiaries that are 'only and directly engaged in financial activities.' Fintechs, mortgage companies, registered investment advisers, broker-dealers, insurance companies, and other non-bank financial services firms generally do not qualify for the entity-level exemption. They may qualify for a data-level exemption on personal data that is covered GLBA NPI — but their broader data practices (marketing profiles, behavioral data, prospect data, website analytics) are fully subject to the OCPA.
What is Oregon's right to a specific named third-party list, and how is it different from other state privacy laws?
ORS 646A.574(1)(a)(B) gives Oregon consumers the right to request 'a list of specific third parties, other than natural persons,' to whom the controller has disclosed the consumer's personal data. No other U.S. state privacy law currently requires this level of specificity — other state privacy laws require disclosure by category ('advertising partners,' 'service providers') but not specific company names. In Oregon's first year of enforcement, 19 complaints directly cited denial of this specific-third-party list right. Compliance requires maintaining an accurate, auditable list of every named entity that received consumer personal data — not just categories.
When did the Oregon Consumer Privacy Act's cure period end, and what does that mean for enforcement?
The 30-day cure period for OCPA violations expired January 1, 2026, as provided in ORS 646A.589. Before that date, the Oregon AG was required to provide notice and give companies 30 days to fix a violation before pursuing enforcement. Since January 1, 2026, there is no mandatory cure period — the AG can pursue civil penalties of up to $7,500 per violation immediately upon finding a violation. In the year-one enforcement report (July 2024–June 2025), all 38 enforcement matters were resolved through the cure process; those remediation opportunities no longer exist for new violations.
What does Oregon's geolocation ban effective January 1, 2026 require?
Oregon HB 2008, signed June 3, 2025 and effective January 1, 2026, prohibits any company subject to the OCPA from selling 'precise geolocation data' — defined as data capable of identifying the location of an individual or device within a 1,750-foot radius. The ban applies regardless of consent — consumers cannot opt in to allow their precise geolocation data to be sold. Narrow exceptions exist for communications providers and public utilities. Companies that sell location data, location-based advertising data, or any data that could identify someone's location within a 1,750-foot radius need to assess whether that activity is now prohibited in Oregon.
What are Oregon's consumer volume thresholds for OCPA applicability?
The OCPA applies under ORS 646A.572(1) to controllers that conduct business in Oregon or target products or services to Oregon residents and that, during a calendar year: (1) control or process personal data of 100,000 or more consumers, excluding data processed solely for payment transactions; or (2) control or process personal data of 25,000 or more consumers and derive 25% or more of annual gross revenue from selling personal data. 'Consumer' means natural persons acting in an individual or household capacity — it excludes employees and B2B contacts.
What did Oregon's year-one enforcement report reveal about common compliance failures?
The Oregon AG's one-year enforcement report (published August 2025) showed 214 total OCPA complaints in year one, with 130 being OCPA-specific. The most common complaint category involved data brokers (background check sites). The three most-complained-about rights were: right to delete (77 complaints), right to a data copy (20 complaints), and the right to a list of specific named third parties (19 complaints). The AG noted that common compliance failures included controllers not recognizing that their OCPA obligations extend to offline data, marketing profiles, and back-end data systems — not just data collected on an app or website.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.