What makes Oregon different
The Oregon Consumer Privacy Act (Oregon SB 619, 2023) is codified at ORS 646A.570 through ORS 646A.589. Commercial controllers became subject to it on 1 July 2024. That effective date is unremarkable. What is remarkable is that three structural features of OCPA set it apart from every other US state privacy law - and all three matter operationally for fingerprinting deployments.
First, Oregon explicitly extends its reach to qualifying nonprofits from 1 July 2025. No other comprehensive US state privacy law does this. A nonprofit that processes fingerprint data from 100,000 Oregon consumers in a calendar year, or 25,000 Oregon consumers while deriving more than 25% of its gross revenue from selling personal data, is a 'controller' under ORS 646A.570 with the same obligations as a commercial entity. Nonprofit fingerprinting deployments - common in ticketing, event management, donor analytics, and membership platforms - are inside OCPA.
Second, Oregon's sensitive-data definition is the broadest enacted by any US state. ORS 646A.575 lists the categories that require opt-in consent before processing. Beyond the categories shared with Colorado, Connecticut, and Virginia (precise geolocation, racial or ethnic origin, religious beliefs, mental or physical health, sex life or sexual orientation, citizenship or immigration status, biometric and genetic data), Oregon adds 'transgender or nonbinary status' and 'status as a victim of a crime'. A fingerprint hash used as a join key to derive inferences in either of those categories crosses into the opt-in regime, regardless of whether any of the other sensitive-data categories are involved.
Third, OCPA's cure period sunsets on 1 January 2026. Before that date, the Oregon AG must give a controller 30 days' notice and an opportunity to cure before initiating enforcement. After 1 January 2026, the AG can proceed immediately. For any fingerprinting deployment that has not yet addressed targeted-advertising opt-outs, UOOM handling, or DPA documentation, the correction window is closing.
When OCPA applies to your fingerprinting deployment
ORS 646A.572 sets the applicability thresholds. A controller falls inside OCPA if it conducts business in Oregon or produces products or services targeted to Oregon residents, AND it either (a) controls or processes the personal data of at least 100,000 Oregon consumers in a calendar year, or (b) controls or processes the personal data of at least 25,000 Oregon consumers AND derives more than 25% of its gross revenue from the sale of personal data.
The second leg's 25%-of-revenue test is more restrictive than Colorado's 'any revenue from sale' trigger, but more permissive than Virginia's 50% threshold. An ad-tech vendor that earns 30% of its revenue from selling fingerprint-derived audience segments and processes 30,000 Oregon consumers is inside OCPA. One that earns only 10% from selling personal data is not, even if it processes the same number of consumers.
Consumer under OCPA means a natural person who is an Oregon resident acting in an individual or household capacity. Employees, contractors, and individuals acting in a commercial or business context are excluded. A fingerprint captured on an internal operations tool used only by Oregon employees does not trigger OCPA obligations.
The nonprofit coverage that began on 1 July 2025 applies the same thresholds. A nonprofit that runs an event-ticketing or streaming platform processing 100,000 Oregon consumers, and uses fingerprinting for fraud prevention or analytics, is a controller under OCPA regardless of its tax status.
The opt-out rights that touch fingerprinting
ORS 646A.576 grants Oregon consumers five rights: access, correction, deletion, portability, and opt-out. The opt-out right divides into three independent categories of processing that intersect with fingerprinting.
Targeted advertising under OCPA means displaying advertisements selected based on personal data obtained from a consumer's activities across non-affiliated websites, applications, or online services. Identifying a returning Oregon visitor by their browser fingerprint and serving ads selected from cross-site behaviour is the canonical targeted-advertising case. First-party retargeting on a single domain, contextual advertising, and frequency capping within a single session are excluded.
Sale of personal data under ORS 646A.570 means the exchange of personal data for monetary or other valuable consideration by a controller to a third party. The 'or other valuable consideration' clause aligns Oregon with Colorado and Connecticut, and contrasts with Virginia's monetary-only definition. Sharing fingerprint hashes with an ad-tech partner in exchange for audience matching, attribution lift, or other non-monetary value is more likely to count as a sale in Oregon than it would in Virginia.
Profiling under OCPA covers automated processing of personal data to evaluate, analyse, or predict personal aspects related to an Oregon consumer. The opt-out right applies only when profiling produces 'legal or similarly significant effects' on the consumer - credit decisions, employment, insurance pricing, housing, healthcare access, or education. Profiling a fingerprint hash to refine a marketing dashboard does not trigger the opt-out; profiling it as one input to an insurance pricing model does.
Common fingerprinting purposes under OCPA
| Purpose | Personal data under OCPA? | DPA required? | Opt-out right applies? | Oregon-specific note |
|---|---|---|---|---|
| Anti-fraud at login or payment | Yes | No (not 'reasonably foreseeable risk' processing) | No | Applies equally to commercial controllers and qualifying nonprofits from July 2025 |
| Account-takeover detection | Yes | No | No | No change from Virginia cluster baseline |
| Bot mitigation on a public form | Yes | No | No | No change from Virginia cluster baseline |
| Cross-site targeted advertising | Yes | Yes | Yes (targeted advertising opt-out) | UOOM/GPC mandatory from 1 January 2026; cure no longer available after that date |
| Sharing fingerprint hashes with ad-tech partner for non-monetary value | Yes | Yes | Yes (likely sale under Oregon's broad 'other valuable consideration' definition) | Broader than VCDPA; aligns with Colorado and Connecticut |
| Selling fingerprint-derived audience segments for money | Yes | Yes | Yes (sale) | Applies to nonprofits that derive more than 25% of gross revenue from such sales |
| Profiling for credit, insurance, or employment decisions | Yes | Yes | Yes (profiling with legal or similarly significant effects) | No change from Virginia cluster baseline |
| Fingerprint joined to derive transgender or victim-of-crime status inferences | Yes | Yes | Opt-in consent required (sensitive data) | Unique to Oregon - no other US state includes these categories in sensitive data |
| Fingerprint joined to derive precise geolocation | Yes | Yes | Opt-in consent required (sensitive data) | Within approximately 1,750 feet; consistent with Virginia cluster |
| Product analytics on your own service | Yes | No | No | No change from Virginia cluster baseline |
| Nonprofit ticketing or event-management analytics | Yes (from 1 July 2025) | Depends on purpose | Depends on purpose | Oregon is the only US state that covers qualifying nonprofits |
Oregon's broad sensitive-data definition and what it means for fingerprinting
ORS 646A.575 requires controllers to obtain opt-in consent before processing sensitive data. The definition is the longest and most inclusive of any US state law. It covers precise geolocation, racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, biometric data (including fingerprints in the traditional sense), genetic data, personal data of a known child, 'transgender or nonbinary status', and 'status as a victim of a crime'.
A browser fingerprint hash is not, by itself, sensitive data under OCPA. The hash becomes a sensitive-data gateway the moment it is used to derive or infer one of the listed categories. If a controller uses a fingerprint to link browsing behaviour on health forums to a specific Oregon consumer's profile, that processing may cross into the mental or physical health category. If the fingerprint is used to link activity on LGBTQ+ community sites to a consumer's identity, it may cross into the transgender or nonbinary category. If the fingerprint is used to identify returning visitors to a victim-support platform or crime-reporting service, it may implicate the victim-of-crime category.
These categories - transgender status and victim-of-crime status - are unique to Oregon. Controllers who have reviewed their fingerprinting deployments for VCDPA or CPA compliance may not have considered them, because those laws do not list them. Any deployment that links fingerprint-derived identifiers to datasets involving those populations needs a separate opt-in consent mechanism under OCPA, distinct from the opt-out handling that suffices for non-sensitive purposes.
Data Protection Assessments under OCPA
ORS 646A.582 requires controllers to conduct and document a Data Protection Assessment (DPA) before engaging in processing that involves targeted advertising, sale of personal data, sensitive-data processing, or profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, financial injury, physical injury, intrusion upon solitude, or other substantial injury to Oregon consumers.
The assessment must weigh the benefits of the processing against the risks to the consumer. It must be retained and made available to the Oregon AG on request. There is no prescribed format under OCPA, unlike Colorado's Rule 8 specifications, but the AG's authority to demand production means the absence of a documented assessment is itself a compliance gap.
For a fingerprinting deployment used to power targeted advertising, an adequate OCPA assessment names the signal categories collected, the hash construction, the retention window, the third-party recipients, any de-identification claims, and the consumer-facing transparency and opt-out mechanism. For a deployment that may touch the sensitive-data categories unique to Oregon (transgender status, victim-of-crime status), the assessment should additionally document the population characteristics of the consumer base and the safeguards in place to prevent inferences in those categories.
Universal Opt-Out Mechanism: mandatory from 1 January 2026
ORS 646A.576 requires controllers to provide a clear and conspicuous mechanism for consumers to opt out of targeted advertising, sale, and profiling. From 1 January 2026, Oregon will recognise Universal Opt-Out Mechanisms - the Oregon AG has confirmed that the Global Privacy Control browser signal qualifies as a valid UOOM under OCPA.
This means a fingerprinting deployment that fires before checking for a GPC header on an Oregon browser is in violation of ORS 646A.576 from 1 January 2026 onward, even if the consumer never manually visited the on-site opt-out page. The UOOM check belongs upstream of any fingerprint call that serves targeted advertising or sale-flagged purposes. Fraud-prevention and analytics flows, which are not targeted advertising or sale, are not subject to the UOOM gate - but those flows must be architecturally separated from the regulated flows to defend that distinction.
Controllers that already honour GPC for Colorado (mandatory since 1 July 2024) or Connecticut (mandatory since 2024) can extend the same signal-check architecture to Oregon. The GPC check is jurisdiction-agnostic at the browser level; the controller's application layer determines which state's rules apply based on the consumer's location.
Oregon AG enforcement: context and signalled priorities
- OCPA commercial enforcement began on 1 July 2024. The Oregon Department of Justice has not yet published named enforcement settlements under OCPA as of this page's review date. The enforcement record is still building, consistent with most state laws in their first 12 months.
- The Oregon AG has signalled focus on UOOM compliance as a priority area for 2025-2026 enforcement, consistent with the mandatory UOOM recognition that takes effect 1 January 2026. Controllers who are not honouring GPC are likely to face early scrutiny.
- Oregon's UTPA (Unlawful Trade Practices Act, ORS 646.607-646.608) provides a parallel enforcement pathway. The AG can pursue data-privacy related deceptive-practices claims under UTPA in addition to or instead of OCPA claims. Early Oregon enforcement on privacy matters has historically layered UTPA claims alongside the primary statute, which can increase penalty exposure beyond the OCPA cap.
- The nonprofit applicability from 1 July 2025 is a novel provision with no enforcement precedent in any other US state. The AG's office has indicated it will apply the same threshold tests to nonprofits as to commercial controllers, and that nonprofits should not expect a grace period beyond the statutory effective date.
- The cure-period sunset on 1 January 2026 aligns Oregon's enforcement posture with Colorado's (sunset 1 July 2025) and Connecticut's. In those states, the AG's post-sunset enforcement pattern has been to cite UOOM failures and missing DPA documentation as the first-wave violation categories.
How Benny the Doorman fits into an OCPA-aware deployment
Benny is a fingerprinting SDK and hosted API. It collects browser and device signals, constructs a stable identifier, and returns it to the controller's application. The consent gating, UOOM check, and purpose-separation logic belong in the controller's own application layer - Benny is designed to be called only after the controller has determined that the processing is permitted for the relevant purpose and the relevant Oregon consumer.
Three steps for an OCPA-aware deployment. First, install a GPC header check and a preference-centre flag upstream of every Benny call that serves targeted advertising or sale-flagged purposes. From 1 January 2026 this is a mandatory obligation under ORS 646A.576, not a best-practice recommendation. The check should resolve before the fingerprint call fires, so that Benny's API is never invoked for a regulated purpose when the consumer has signalled a UOOM opt-out.
Second, complete and document a Data Protection Assessment under ORS 646A.582 for each purpose before go-live. Benny's documentation enumerates the signal categories collected, the hash construction algorithm, the default retention window, and the per-call data flow - the technical details that populate the processing-activity and risk sections of a DPA. If your deployment may touch populations associated with Oregon's unique sensitive-data categories (transgender status, victim-of-crime status), the assessment should include a documented analysis of that risk and the controls in place.
Third, keep the regulated fingerprint flow (targeted advertising, sale) and the exempt fingerprint flow (anti-fraud, bot mitigation) architecturally separate. The ORS 646A.576 opt-out right must be honoured on the regulated flow without breaking the exempt flow. Separate API calls, separate data retention scopes, and separate logging make the distinction auditable if the Oregon AG requests production of the DPA or related records.
Frequently asked questions
Is browser fingerprinting illegal under OCPA?
No. Fingerprinting is not banned in Oregon. It is regulated as personal data when the fingerprint can be linked back to an identified or identifiable Oregon consumer, under ORS 646A.570's definition of personal data. Lawful use requires honouring opt-out requests for targeted advertising, sale, and covered profiling; respecting the Universal Opt-Out Mechanism (GPC) from 1 January 2026; and completing a Data Protection Assessment before deploying fingerprinting for any of those purposes.
Does OCPA cover nonprofits?
Yes, from 1 July 2025. Oregon is the only US state whose comprehensive privacy law expressly applies to qualifying nonprofits. A nonprofit that processes personal data of at least 100,000 Oregon consumers in a calendar year, or at least 25,000 Oregon consumers while deriving more than 25% of its gross revenue from the sale of personal data, is a controller under OCPA with the same fingerprinting obligations as a commercial entity.
What makes Oregon's sensitive-data definition different from other state laws?
ORS 646A.575 includes 'transgender or nonbinary status' and 'status as a victim of a crime' as sensitive-data categories requiring opt-in consent before processing. No other US state privacy law lists these categories. A fingerprint used as a join key to derive inferences in those categories triggers opt-in consent, even if the fingerprint itself is not otherwise sensitive.
Do I need consent for fingerprinting under OCPA?
For most fingerprinting purposes, OCPA is an opt-out regime, not opt-in. Processing is permitted by default unless the consumer opts out of targeted advertising, sale, or covered profiling. Opt-in consent is required only when fingerprinting is used to process or derive inferences about sensitive-data categories listed in ORS 646A.575 - precise geolocation, health data, biometric or genetic data, and the Oregon-unique categories of transgender status and victim-of-crime status.
Is sharing fingerprint hashes with an ad-tech partner a 'sale' under OCPA?
More likely yes in Oregon than in Virginia. Oregon's sale definition includes 'monetary or other valuable consideration', aligning with Colorado and Connecticut. Non-monetary data sharing with an ad-tech partner - in exchange for audience matching, attribution lift, or other value - is more likely to qualify as sale under OCPA than under VCDPA's monetary-only definition. Controllers should default to treating such sharing as sale for Oregon consumers unless a qualified attorney has confirmed otherwise.
Do I have to honour Global Privacy Control under OCPA?
Yes, from 1 January 2026. Oregon recognises Universal Opt-Out Mechanisms under ORS 646A.576 and the AG has confirmed that GPC qualifies. A fingerprinting deployment that ignores a GPC signal from an Oregon browser is in violation of ORS 646A.576 after that date, even if the consumer never used the on-site opt-out. The UOOM check must resolve before the fingerprint API call fires for any targeted-advertising or sale-flagged purpose.
What happens after the cure period sunsets on 1 January 2026?
Until 31 December 2025, the Oregon AG must provide 30 days' written notice and an opportunity to cure before initiating a formal enforcement action. After 1 January 2026, the AG can proceed on the first identified violation without any notice period. Fingerprinting deployments that have not addressed UOOM handling, Data Protection Assessment documentation, or purpose separation before that date face first-strike enforcement exposure.
When do I need a Data Protection Assessment for fingerprinting under OCPA?
ORS 646A.582 requires a Data Protection Assessment before engaging in targeted advertising, sale of personal data, sensitive-data processing, or profiling that presents a reasonably foreseeable risk of substantial injury to Oregon consumers. The assessment must weigh benefits against risks and be retained for production to the AG on request. There is no prescribed format under OCPA, but the absence of a documented assessment is itself a compliance gap.
What are the fines for non-compliant fingerprinting under OCPA?
Civil penalties under ORS 646A.589 reach up to $7,500 per intentional violation. Enforcement is by the Oregon Attorney General; there is no private right of action under OCPA. The Oregon AG may also pursue parallel claims under the Unlawful Trade Practices Act (ORS 646.607-646.608), which can add a separate penalty exposure for deceptive data-handling practices.
How does OCPA compare to VCDPA for fingerprinting?
Four meaningful differences. Oregon's sale definition includes 'other valuable consideration', making non-monetary data sharing more likely to count as sale than under VCDPA's monetary-only definition. Oregon's sensitive-data categories include transgender status and victim-of-crime status, which Virginia does not cover. Oregon's UOOM recognition is mandatory from 1 January 2026, while Virginia's GPC obligation has been in place since 1 January 2025. And Oregon's cure period sunsets on 1 January 2026, while Virginia retains a notice-and-cure mechanism. Maximum civil penalties are the same at $7,500 per intentional violation.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

