Feature Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Table of Contents
Two years in, the Oregon Consumer Privacy Act is no longer a future event on a compliance calendar. It’s an active enforcement program without a safety net.
The 30-day cure period expired January 1, 2026. The Oregon AG can now pursue $7,500-per-violation civil penalties without giving advance notice. There were 214 complaints in year one. All 38 enforcement matters were resolved through cure letters — which means there are 38 companies whose OCPA gaps were documented, fixed, and on record. New violations don’t get that second chance.
If you work in financial services and haven’t looked at Oregon specifically, there are two things you need to know: the GLBA exemption probably doesn’t cover everything you think it does, and Oregon has a consumer disclosure requirement that no other state in the country replicates.
TL;DR
- The Oregon Consumer Privacy Act (ORS 646A.570–646A.589) has been in effect since July 1, 2024 — the 30-day cure period expired January 1, 2026
- The GLBA entity-level exemption applies only to ORS 706.008 financial institutions (FDIC-insured banks, Oregon credit unions and their qualifying affiliates) — fintechs, mortgage companies, RIAs, and broker-dealers are NOT covered
- Oregon is the only U.S. state that gives consumers the right to request specific named third parties (not just categories) that received their data — per ORS 646A.574(1)(a)(B)
- HB 2008 effective January 1, 2026 bans selling precise geolocation data (within 1,750-foot radius) — no consent exception
- 214 complaints in year one; $7,500/violation with no cure period since January 1, 2026
The GLBA Exemption Is Narrower Than You Think
Most financial services companies encountering a new state privacy law default to the same question: “Are we a GLBA-covered entity?” And if yes, the assumption is that the entity-level exemption removes the problem.
Oregon doesn’t work that way.
The OCPA’s financial institution exemption has two separate tiers that do very different things:
Tier 1 — Entity-level exemption (narrow): Under ORS 646A.572(2), the OCPA exempts financial institutions as defined by ORS 706.008 — the Oregon Bank Act definition. That definition covers FDIC-insured banks, banks organized under foreign law, Oregon-chartered credit unions, out-of-state credit unions, and federal credit unions. It also covers affiliates and subsidiaries of those entities, but only if the affiliate is “only and directly engaged in financial activities” as described in 12 U.S.C. 1843(k).
This is significantly narrower than the federal GLBA definition. GLBA covers any company “significantly engaged in financial activities.” Oregon’s entity-level exemption does not.
The practical implication: fintechs, nonbank mortgage lenders, registered investment advisers, broker-dealers, insurance companies, and payment processors are not covered by Oregon’s entity-level exemption — even if they’re fully GLBA-regulated. A payments fintech that processes transactions for Oregon consumers is subject to the OCPA regardless of its GLBA compliance posture.
Tier 2 — Data-level exemption (broader): Separately, the OCPA exempts personal data that “originates from, or is intermingled so as to be indistinguishable from” GLBA-covered NPI — but only for entities licensed under the Oregon Consumer Finance Act (ORS 725.010), and only for data collected in the manner GLBA requires. This tracks the approach California took under the CCPA.
The data-level exemption is narrower than it sounds in practice. It covers the specific NPI that GLBA requires you to manage — loan application data, account information, payment history. It does not cover:
- Prospect and lead data collected before a consumer becomes a customer
- Website analytics and behavioral data collected pre-login
- Rejected applicants’ data that never became account data
- Marketing partner data where the consumer relationship is indirect
- Biometric authentication data that isn’t itself financial NPI
- Subsidiary business lines whose activities aren’t financial services
For a fintech that collects pre-login browsing behavior for marketing segmentation, runs targeted advertising to prospects who never became customers, or operates a loyalty or rewards program alongside its financial product — significant portions of its data processing fall outside the data-level exemption entirely.
The Mayer Brown analysis of Oregon’s narrow financial institution exemption covers this distinction in detail; Orrick has similarly confirmed the gap across multiple state privacy law comparisons. The consensus: Oregon’s financial services exemption is one of the most narrowly scoped of any U.S. state privacy law.
The Feature No Other State Has: Named Third Parties
Every major state privacy law requires privacy notices that include categories of third parties that receive consumer data. “Advertising partners,” “service providers,” “analytics providers.” That’s the industry standard.
Oregon added something different. ORS 646A.574(1)(a)(B) gives consumers the right to request “a list of specific third parties, other than natural persons,” to whom the controller has disclosed their personal data. Not categories. Specific named entities.
In Oregon’s one-year enforcement report, 19 of the 214 complaints specifically cited denial of this right. That’s the third most common complaint, behind delete requests (77) and data copy requests (20).
Complying with this right is operationally different from complying with categorical third-party disclosure requirements. You can’t point to your privacy policy and call it done. You need:
- An auditable record of which named entities received each consumer’s data. Not aggregated at the company level — attributable to specific consumers.
- A system that can produce that list on request within the 45-day response window Oregon requires.
- Data mapping that tracks third-party disclosures at the individual record level — not just categories of recipients.
For financial services companies that share data with affiliate marketing networks, lead generation platforms, credit reporting agencies, or analytics vendors, the list of named third parties for a single consumer can be substantial. And unlike California or Colorado, Oregon requires the actual company names.
If your data mapping only documents “third-party analytics vendors” and “credit bureau partners,” your OCPA compliance for this right is incomplete.
Cure Period Gone, Enforcement Clock Running
In year one, the Oregon AG’s office received 214 complaints and resolved all 38 enforcement matters through the cure process. Companies got notified, fixed the issue, and avoided penalties.
That era ended January 1, 2026.
Under ORS 646A.589, the AG can now pursue $7,500-per-violation civil penalties — with each affected consumer potentially counting as a separate violation — from the first complaint. There’s no mandatory notice. There’s no correction window.
The year-one enforcement data reveals where the risk concentrates:
| Most Common Complaints (Year One) | Count |
|---|---|
| Right to delete not honored | 77 |
| Right to data copy not fulfilled | 20 |
| Named specific third-party list not provided | 19 |
| Other OCPA rights | 14 |
Data brokers and background check sites were the single largest complaint category. But financial services companies appeared across multiple complaint types — particularly for failing to recognize that offline data and back-end systems are subject to consumer rights requests, not just app or website data.
The AG’s office noted explicitly in year one: companies often didn’t recognize that their obligations extend to all personal data they control, regardless of how it was collected. Loan files, call center records, historical transaction databases, and physical records — if they contain personal data of Oregon consumers, consumer rights apply.
January 2026: Two Laws Tightened at Once
Oregon’s privacy exposure for financial services companies intensified at the start of 2026 from two directions simultaneously.
The cure period sunset. As discussed: no more 30-day correction window before penalties apply.
Oregon HB 2008’s geolocation ban. Signed by Governor Tina Kotek on June 3, 2025 and effective January 1, 2026, HB 2008 added an outright ban on selling precise geolocation data — defined as data capable of identifying an individual or device’s location within a 1,750-foot radius.
The ban has no consent exception. Consumers cannot opt in to allow their precise geolocation data to be sold. The only exceptions are narrow operational carve-outs for communications providers and public utilities. Everyone else is prohibited from selling precise geolocation data regardless of what the privacy policy says or what consents exist.
As Davis Wright Tremaine’s analysis of HB 2008 explains, the 1,750-foot definition captures data from mobile devices, GPS coordinates, IP-address-based location, and location data embedded in photos or other content.
Financial services companies using location data for fraud risk modeling, marketing segmentation, or personalization need to assess whether any of that data is sold (or licensed in ways that constitute a “sale” under Oregon’s definition) to third parties. If yes, those activities are prohibited in Oregon since January 1, 2026.
HB 2008 also eliminated the remaining cure period carve-out for nonprofits — what had previously applied broadly now applies only to noncommercial educational broadcast stations. There’s no meaningful nonprofit exception remaining.
What In-Scope Financial Services Companies Need to Do
The OCPA’s official business FAQ page from the Oregon DOJ is the clearest starting point for confirming whether your organization is in scope.
For financial services companies that clear the OCPA threshold (100,000 Oregon consumers or 25,000 consumers with 25% revenue from data sales):
Map your GLBA boundary accurately. Identify which data processing activities fall within the GLBA data-level exemption and which don’t. Prospect data, marketing analytics, rejected applicant data, and behavioral data collected before account opening are likely outside the exemption. Don’t assume GLBA covers your full data footprint.
Build the named third-party tracking. If you share personal data with any named entities — advertising platforms, analytics vendors, affiliates, credit reporting agencies, data brokers — build the record-level tracking that lets you respond to a specific-named-third-party request for an individual consumer. Category disclosure in a privacy policy isn’t enough.
Audit geolocation data practices. If your product, analytics, or marketing operations involve location data precise enough to identify an individual within 1,750 feet, confirm whether that data is being sold or licensed in ways that constitute a sale. If yes, that stopped being permissible in Oregon on January 1, 2026.
Update your consumer rights response process. Oregon’s 45-day response window applies to all rights requests. With no cure period, a failed response means immediate enforcement exposure.
Check whether existing privacy notices are OCPA-compliant. Oregon has specific required disclosures that may differ from your CCPA/CPRA-compliant notices. Oregon’s specific-named-third-party right needs to be addressed — and your response process needs to actually produce the named list, not a category-level summary.
The State Enforcement Environment Makes Oregon Matter More
As our analysis of state AG enforcement priorities for 2026 covers, the retreat of federal consumer financial enforcement activity hasn’t reduced compliance risk — it’s shifted enforcement activity to state levels.
The CFPB’s 2026 regulatory agenda reflects a Bureau that’s cut nonbank examination by 64% in two years. Oregon’s AG isn’t pulling back. The combination of active state privacy enforcement, a cure period that has expired, and consumer rights requirements that many financial services companies have underinvested in creates a real exposure profile that federal examination reduction doesn’t offset.
State privacy enforcement is the enforcement environment now for many companies. Oregon’s unique features — the narrow GLBA exemption, the named-third-party right, the geolocation ban — make it one of the most demanding state privacy regimes for financial services companies to navigate correctly.
So What?
Oregon is a manageable compliance obligation, but only if companies understand what they’re actually subject to. The GLBA exemption is narrower than GLBA-regulated companies typically assume. The named third-party right is unlike anything in other state privacy laws and requires infrastructure most companies’ current data mapping doesn’t support. The cure period is gone.
The year-one enforcement data shows the AG’s office is actively working through complaints and resolved every matter it took up. The resolution mechanism through January 2026 was cure letters. The resolution mechanism now is civil penalties.
If you’re building out your state privacy compliance program or need documentation templates for consumer rights request processes, data mapping frameworks, and third-party disclosure inventories, the Data Privacy Compliance Kit gives you the frameworks to operationalize OCPA compliance alongside parallel obligations in California, Colorado, and other active state regimes.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the GLBA exemption protect fintechs and financial services companies under Oregon's privacy law?
What is Oregon's right to a specific named third-party list, and how is it different from other state privacy laws?
When did the Oregon Consumer Privacy Act's cure period end, and what does that mean for enforcement?
What does Oregon's geolocation ban effective January 1, 2026 require?
What are Oregon's consumer volume thresholds for OCPA applicability?
What did Oregon's year-one enforcement report reveal about common compliance failures?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026
Data Privacy
California's ADMT Rules Are Live: What Banks and Fintechs Get Wrong About the GLBA Exemption
The CPPA finalized ADMT regulations effective January 1, 2026 — and California's GLBA exemption is narrower than you think. Here's what financial institutions and fintechs actually need to do about automated decision-making, opt-out rights, and risk assessments.
Jul 13, 2026