The Letter About Your Information
ORS 646A.604 — notice of a data breach within 45 days, and the Attorney General told when over 250 people
45 days. A business or other covered entity that suffers a breach of security involving personal information notifies the consumers concerned in the most expeditious manner possible, without unreasonable delay, and not later than 45 days after discovering or being told of the breach. A delay is allowed only if a law enforcement agency asks in writing because notice would impede a criminal investigation.
- A description of the breach in general terms, and its approximate date.
- The type of personal information involved.
- Contact information for the covered entity and for the national consumer reporting agencies.
- Advice to report suspected identity theft to law enforcement, including the Attorney General and the Federal Trade Commission.
That is what the notice includes at a minimum. The Attorney General is notified too when more than 250 consumers are involved, and nationwide consumer reporting agencies when more than 1,000 are. A vendor that discovers a breach tells the covered entity within 10 days.
Free credit monitoring offered with the notice may not be conditioned on giving a credit or debit card number or buying another service, and any paid add-on has to be disclosed clearly. Notice may be skipped only if, after investigation, the entity reasonably determines in writing that harm is unlikely, and keeps that record for five years.
A violation is an unlawful practice under the state's unfair trade practices law. Entities that follow a federal regulator's breach rules, or comparable state or federal laws, are exempt. Whether a particular incident triggered the duty is a question for a licensed Oregon attorney.
Sources for this section (1)
- ORS 646A.604 — Notice of breach of security
Legal information, not legal advice. Verified as of October 2026. Applying it to a particular situation is the work of a licensed Oregon attorney.