A single missing opt-out link on your website used to buy thirty days to fix it. As of January 1, 2026, it buys nothing.
Oregon’s Consumer Privacy Act (OCPA) cure period has expired, and the Attorney General can now open an investigation or file a lawsuit the moment a violation surfaces, with no warning letter first.
Most Portland business owners know privacy compliance matters. Fewer know exactly where their own systems stand or what to check first. That’s the gap a trusted IT provider in Portland can help close.
This guide lays out five concrete steps you can take right now, whether your team handles them internally or you bring in an established IT company in Portland.
Step 1: Confirm Whether You’re in Scope
The OCPA doesn’t apply to every business in Portland, and plenty of local companies fall outside its reach entirely. The OCPA law measures each business by its annual data volume and revenue. That standard catches more businesses than most owners expect, regardless of headcount or industry.
A business or nonprofit is covered if it meets any of the following in a calendar year:
- It controls or processes the personal data of 100,000 or more Oregon consumers.
- It controls or processes the data of 25,000 or more Oregon consumers and gets 25% or more of its gross revenue from selling personal data.
- It’s a nonprofit that meets either threshold above, a group that’s been covered since July 2025.
- It’s an auto manufacturer collecting Oregon consumer data, a group that’s been covered regardless of size since September 2025.
The part that catches a lot of Portland business owners off guard is how personal data gets counted toward those thresholds. Email marketing platforms, loyalty program sign-ups, and website analytics tools all count toward the total. A business can cross the threshold just by adding a new tool, well before anyone reviews the numbers.
Step 2: Audit What Personal Data You Actually Hold
Once you know you’re in scope, the next task is mapping what personal data your business holds and where it lives. Most Portland businesses underestimate this list, because personal data doesn’t just mean the fields sitting in a customer database.
A thorough audit usually turns up personal data in each of these places:
- Customer relationship management (CRM) systems and email marketing platforms
- Website analytics tools and advertising pixels
- Loyalty program and rewards platforms
- Geolocation data collected through mobile apps, Wi-Fi analytics, or ad tracking tools
That last category deserves particular attention right now. Selling precise geolocation data, meaning data accurate to within about 1,750 feet, is banned outright in Oregon as of January 1, 2026, and a customer’s consent doesn’t change that.
If your business works with any vendor that collects location data, this is the point to find out exactly what happens to it.
Step 3: Implement Global Privacy Control Recognition
As of January 1, 2026, covered businesses have to honor universal opt-out signals sent through a customer’s browser or privacy extension, a system known as Global Privacy Control (GPC).
When a customer broadcasts a “don’t sell my data” signal, your website must recognize and honor it automatically. A customer shouldn’t have to opt out one page at a time anymore.
Meeting this requirement takes real configuration across your website, your CRM, and any marketing tool that uses customer data for targeted ads. A privacy notice update alone won’t make a website honor the signal automatically.
Once GPC recognition is set up, it’s worth testing the signal yourself to confirm it works the way your privacy notice says it does.
Step 4: Review Vendor and Data-Sharing Agreements
Closing gaps in your own systems solves only part of the problem, because a lot of personal data moves through vendors and third-party platforms your business doesn’t directly control.
Under the OCPA, these companies are called processors, and the contracts your business signs with them need to reflect that responsibility.
Pull the agreements you have with your marketing platform, your CRM provider, your ad network, and any analytics tool that touches customer data. Check whether each contract spells out how that vendor handles Oregon consumer data, honors deletion requests, and responds if a data-sharing arrangement changes.
A vendor that isn’t compliant on its own end can still leave your business exposed, even when your own systems are in order.
Step 5: Get a Compliance Review Before a Complaint Arrives
Waiting for a complaint to arrive is the highest-risk option available now. On Data Privacy Day, January 28, 2026, Oregon Attorney General Dan Rayfield’s office publicly promoted the state’s new Universal Opt-Out tool for consumers and confirmed that covered businesses and nonprofits are now fully accountable for OCPA compliance, since the law’s cure period has expired.
A compliance review lets you fix issues on your own schedule. Look for a review covering:
- Your website’s opt-out mechanisms and Global Privacy Control setup
- Data flows across your CRM, marketing platforms, and ad tools
- Vendor contracts and processor agreements
- Your breach response plan, including MFA and encryption
Civil penalties for OCPA violations can reach $7,500 per violation, an expense a proactive review can help you avoid.
Close the Gap Before Oregon Does
Centerlogic’s managed cybersecurity team can review your website, your CRM, and your marketing stack against Oregon’s updated privacy standards and hand you a clear, practical plan for closing whatever we find.
Get in touch to schedule your compliance-focused security review today, before a complaint schedules it for you.
FAQs
- Does the OCPA apply to my small Portland business?
It depends on your data volume and revenue, not your business size. Companies handling data for 100,000 or more Oregon consumers, or 25,000 or more combined with a quarter of revenue from data sales, meet the threshold. An IT company in Portland that already knows the OCPA can review your numbers and confirm exactly where you stand. - What’s Global Privacy Control, and does my business have to support it?
Global Privacy Control (GPC) is a browser signal that tells a website a visitor doesn’t want their data sold or used for targeted advertising. Covered businesses have had to honor it automatically since January 1, 2026, which usually means configuration work across your website and marketing tools. - Can I still sell geolocation data if a customer agrees to it?
No. Selling precise geolocation data is banned outright in Oregon as of January 1, 2026, and a customer’s consent doesn’t change that. Businesses that work with location-based advertising or analytics vendors should confirm exactly how that data gets used. - What happens if my business violates the OCPA now that the cure period has ended?
The Attorney General can pursue enforcement right away, without sending a warning letter first. Civil penalties can reach $7,500 per violation, and a single gap across a CRM, a website, and an ad platform can add up fast. - How can an IT provider in Portland help with OCPA compliance?
An experienced IT provider in Portland can configure Global Privacy Control recognition, map where personal and geolocation data moves through your systems, and build the cybersecurity Portland businesses need to meet Oregon’s updated standards. - Where should I start if I haven’t looked at any of this yet?
Start with Step 1: confirming whether your business meets the OCPA’s thresholds. From there, a compliance review from a provider of IT services in Portland can map the rest of the work in one pass instead of five separate projects.


