惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
D
DataBreaches.Net
B
Blog RSS Feed
博客园_首页
The GitHub Blog
The GitHub Blog
I
InfoQ
L
LangChain Blog
G
Google Developers Blog
M
MIT News - Artificial intelligence
美团技术团队
腾讯CDC
V
Visual Studio Blog
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Oregon Prohibition on Public Body Disclosures to Data Bro...
2026-06-09 · via Privacy & Cybersecurity Law Blog

Oregon Prohibition on Public Body Disclosures to Data Brokers for Federal Immigration Purposes Now In Effect

Effective June 5, 2026, Oregon Senate Bill 1587 prohibits any state government, local government and special government bodies (each a “public body”) from disclosing personally identifiable information to a data broker unless the data broker first provides a written attestation to the public body that the information will not be sold or otherwise transferred to any entity that will use the information to enforce federal immigration law.

The following key provisions are included in the law:

  • Personally Identifiable Information. Personally identifiable information is defined as information that can be used to distinguish or trace an individual’s identity or, when combined with other personal or identifying information, is linked or linkable to a specific individual.
  • Data Broker. A data broker is defined as a business entity or part of a business entity that collects and sells or licenses brokered personal data to another person. “Brokered personal data” includes the following data elements about an Oregon resident if categorized or organized for sale or licensing to another person:
    • the resident individual’s name or the name of a member of the resident individual’s immediate family or household;
    • the resident individual’s address or an address for a member of the resident individual’s immediate family or household;
    • the resident individual’s date or place of birth;
    • the maiden name of the resident individual’s mother;
    • biometric information about the resident individual;
    • the resident individual’s social security number or the number of any other government-issued identification for the resident individual; or
    • other information that, alone or in combination with other information that is sold or licensed, can reasonably be associated with the resident individual.
  • Rejection of Attestation. If a public body reasonably believes that a data broker’s written attestation contains material misrepresentations, falsehoods or omissions, the public body must reject the written attestation and decline to disclose personally identifiable information to the data broker.
  • No Limitation on Disclosure Pursuant to Legal or Court-Ordered Requests. Notably, a public body is allowed to disclose personally identifiable information if:
    • required under Oregon law;
    • required by a court order of competent jurisdiction; or
    • the information is available to the general public and is only disclosed under the same terms and conditions under which the information is available to the general public.
Subscribe

Recent Posts

Categories

Tags

Archives