(2) A covered entity or vendor complies with subsection (1) of this section if the covered entity or vendor:
(a) Complies with a state or federal law that provides greater protection to personal information than the protections that this section provides.
(b) Complies with regulations promulgated under Title V of the Gramm-Leach-Bliley Act of 1999 (15 U.S.C. 6801 to 6809) as in effect on January 1, 2020, if personal information that is subject to ORS 646A.600 to 646A.628 is also subject to the Act.
(c) Complies with regulations that implement the Health Insurance Portability and Accountability Act of 1996 (45 C.F.R. parts 160 and 164) and the Health Information Technology for Economic and Clinical Health Act of 2009 (P.L. 111-5, Title XIII, 123 Stat. 226), as those Acts were in effect on January 1, 2020, if personal information that is subject to ORS 646A.600 to 646A.628 is also subject to those Acts.
(d) Implements an information security program that includes:
(A) Administrative safeguards such as:
(i) Designating one or more employees to coordinate the security program;
(ii) Identifying reasonably foreseeable internal and external risks with reasonable regularity;
(iii) Assessing whether existing safeguards adequately control the identified risks;
(iv) Training and managing employees in security program practices and procedures with reasonable regularity;
(v) Selecting service providers that are capable of maintaining appropriate safeguards and practices, and requiring the service providers by contract to maintain the safeguards and practices;
(vi) Adjusting the security program in light of business changes, potential threats or new circumstances; and
(vii) Reviewing user access privileges with reasonable regularity;
(B) Technical safeguards such as:
(i) Assessing risks and vulnerabilities in network and software design and taking reasonably timely action to address the risks and vulnerabilities;
(ii) Applying security updates and a reasonable security patch management program to software that might reasonably be at risk of or vulnerable to a breach of security;
(iii) Monitoring, detecting, preventing and responding to attacks or system failures; and
(iv) Regularly testing, monitoring and taking action to address the effectiveness of key controls, systems and procedures; and
(C) Physical safeguards such as:
(i) Assessing, in light of current technology, risks of information collection, storage, usage, retention, access and disposal and implementing reasonable methods to remedy or mitigate identified risks;
(ii) Monitoring, detecting, preventing, isolating and responding to intrusions timely and with reasonable regularity;
(iii) Protecting against unauthorized access to or use of personal information during or after collecting, using, storing, transporting, retaining, destroying or disposing of the personal information; and
(iv) Disposing of personal information, whether the covered entity or vendor disposes of the personal information on or off the covered entity’s or vendor’s premises or property, after the covered entity or vendor no longer needs the personal information for business purposes or as required by local, state or federal law by burning, pulverizing, shredding or modifying a physical record and by destroying or erasing electronic media so that the information cannot be read or reconstructed.
(3) A covered entity or vendor complies with subsection (2)(d)(C)(iv) of this section if the covered entity or vendor contracts with another person engaged in the business of record destruction to dispose of personal information in a manner that is consistent with subsection (2)(d)(C)(iv) of this section.
(4) A covered entity or vendor in an action or proceeding may affirmatively defend against an allegation that the covered entity or vendor has not complied with subsection (1) of this section with respect to personal information that is subject to ORS 646A.600 to 646A.628 but is not subject to an Act described in subsection (2)(b) or (c) of this section by showing that, with respect to the personal information that is subject to ORS 646A.600 to 646A.628, the covered entity or vendor developed, implemented and maintained reasonable security measures that would be required for personal information subject to the applicable Act.
(5) Notwithstanding subsection (2) of this section, a person that is an owner of a small business as defined in ORS 285B.123 (2) complies with subsection (1) of this section if the person’s information security and disposal program contains administrative, technical and physical safeguards and disposal measures that are appropriate for the size and complexity of the small business, the nature and scope of the small business’s activities, and the sensitivity of the personal information the small business collects from or about consumers. [2007 c.759 §12; 2015 c.357 §3; 2018 c.10 §6; 2019 c.180 §4]
Structure 2021 Oregon Revised Statutes
Volume : 16 - Trade Practices, Labor and Employment
Chapter 646A - Trade Regulation
Section 646A.030 - Definitions for ORS 646A.030 to 646A.042.
Section 646A.032 - Price list for health spa services.
Section 646A.034 - Contracts; contents.
Section 646A.038 - Moneys paid prior to facility opening; disposition; priority of claim; refund.
Section 646A.050 - Definitions.
Section 646A.052 - Form of purchase agreement.
Section 646A.060 - Purchase of used goods; records; application to pawnbrokers.
Section 646A.064 - Definitions for ORS 646A.064 to 646A.067.
Section 646A.066 - Applicability to local ordinances.
Section 646A.068 - Penalty for violating ORS 646A.065.
Section 646A.070 - Sale of telephonic equipment; disclosure requirements; enforcement; penalty.
Section 646A.072 - Exceptions to disclosure requirements.
Section 646A.075 - Required information prior to purchase of dog.
Section 646A.080 - Sale of novelty item containing mercury; penalty.
Section 646A.081 - Prohibition on sale or installation of mercury vapor outdoor lighting fixtures.
Section 646A.092 - Advertisements for sale or lease of motor vehicle; exceptions.
Section 646A.100 - Definitions for ORS 646A.100 to 646A.110.
Section 646A.104 - Information required in notice of intent.
Section 646A.108 - Prohibited conduct.
Section 646A.110 - Applicability of ORS 646A.100 to 646A.110 and 646A.112.
Section 646A.112 - Injunction of sham sale; evidence; attorney fees; defense; definitions.
Section 646A.120 - Definitions for ORS 646A.120 to 646A.134.
Section 646A.122 - Applicability of ORS 646A.120 to 646A.134.
Section 646A.124 - General disclosure requirements.
Section 646A.126 - Specific disclosure requirements.
Section 646A.128 - Provisions prohibited in lease-purchase agreements.
Section 646A.130 - Reinstatement of lease-purchase agreement by consumer; receipt for each payment.
Section 646A.132 - Renegotiation or extension of lease-purchase agreement.
Section 646A.134 - Disclosures required in advertisement for lease-purchase agreements.
Section 646A.140 - Definitions for ORS 646A.140 and 646A.142.
Section 646A.142 - Rental vehicle collision damage waiver notice.
Section 646A.150 - Applicability of ORS 646A.150 to 646A.172.
Section 646A.152 - Definitions for ORS 646A.150 to 646A.172.
Section 646A.156 - Required contents of service contracts.
Section 646A.158 - Prohibited conduct.
Section 646A.164 - Complaints and investigations confidential; exceptions.
Section 646A.166 - Refusal to continue or suspension or revocation of registration.
Section 646A.168 - Assessment fee; rules; purpose; registration fee.
Section 646A.172 - Rules; exemption of certain obligors.
Section 646A.200 - Definitions for ORS 646A.202 and 646A.204.
Section 646A.204 - Customer information.
Section 646A.214 - Verification of identity in credit or debit card transactions.
Section 646A.220 - Credit card solicitation; required disclosure; definitions.
Section 646A.222 - Charge card solicitation; required disclosure; definitions.
Section 646A.230 - Action by Attorney General or district attorney; civil and criminal penalties.
Section 646A.274 - Definitions for ORS 646A.276 and 646A.278.
Section 646A.278 - Requirements for sale of gift card that expires.
Section 646A.280 - Definitions for ORS 646A.280 to 646A.290.
Section 646A.282 - Simulated invoices prohibited.
Section 646A.284 - Cause of action by Attorney General; judgment; attorney fees.
Section 646A.286 - Cause of action by private party; judgment; attorney fees.
Section 646A.288 - Presumptions in cause of action brought under ORS 646A.284 or 646A.286.
Section 646A.290 - Construction; other remedies.
Section 646A.293 - Definitions for ORS 646A.293 and 646A.295.
Section 646A.295 - Prohibited actions; requirements; timing; failure to obtain consent; exceptions.
Section 646A.300 - Definitions for ORS 646A.300 to 646A.322.
Section 646A.306 - Repurchase of inventory by supplier; effect of new retailer agreement.
Section 646A.308 - Civil action for supplier’s failure to pay; venue.
Section 646A.310 - Prohibited conduct by supplier.
Section 646A.314 - New or relocated dealership; notice; area of responsibility.
Section 646A.316 - Warranty claims; payment; time for completion.
Section 646A.318 - Warranty claims; processing.
Section 646A.320 - Retailer’s improvements to products.
Section 646A.322 - Remedies; arbitration; cause of action; attorney fees; injunctive relief.
Section 646A.340 - Definitions for ORS 646A.340 to 646A.348.
Section 646A.342 - Prohibited conduct; required verifications and notice.
Section 646A.344 - Bond or letter of credit; action; exceptions.
Section 646A.360 - Unsolicited facsimile machine transmissions.
Section 646A.370 - Definitions for ORS 646A.370 to 646A.374.
Section 646A.372 - Limits on usage of automatic dialing and announcing device.
Section 646A.374 - Prohibited actions.
Section 646A.400 - Definitions for ORS 646A.400 to 646A.418.
Section 646A.402 - Availability of remedy.
Section 646A.404 - Consumer’s remedies; manufacturer’s affirmative defenses.
Section 646A.414 - Limitations on actions against dealers.
Section 646A.416 - Limitation on commencement of action.
Section 646A.430 - Definitions for ORS 646A.430 to 646A.450.
Section 646A.432 - Applicability of ORS 646A.430 to 646A.450; applicability of other law.
Section 646A.434 - Sale of vehicle protection product; conditions and requirements.
Section 646A.436 - Warrantor registration; requirements; expiration; fees; rules.
Section 646A.438 - Reimbursement insurance; requirements; insurer qualifications.
Section 646A.440 - Required provisions of reimbursement insurance policy; cancellation; notice.
Section 646A.444 - Recordkeeping requirements for warrantor; record retention.
Section 646A.446 - Prohibited conduct for warrantor.
Section 646A.448 - Prohibited activities.
Section 646A.450 - Rules; investigative powers of department.
Section 646A.460 - Definitions for ORS 646A.460 to 646A.476.
Section 646A.462 - Express warranty; duration.
Section 646A.464 - Repair of assistive device.
Section 646A.466 - Replacement or refund after attempt to repair.
Section 646A.468 - Procedures for replacement or refund.
Section 646A.470 - Sale or lease of returned assistive device.
Section 646A.472 - Dispute resolution.
Section 646A.476 - Civil action for damages; attorney fees; limitation on actions.
Section 646A.480 - Definitions for ORS 646A.480 to 646A.495.
Section 646A.482 - Estimate required before beginning work; contents; evaluation.
Section 646A.490 - Additional prohibited actions; reassembly required; copies.
Section 646A.495 - Owner designee; waiver of authorization requirement.
Section 646A.500 - Legislative findings; declaration of purpose.
Section 646A.504 - Definitions for ORS 646A.500 to 646A.514.
Section 646A.506 - Prohibited conduct.
Section 646A.510 - Exemptions.
Section 646A.525 - Definitions for ORS 646A.525 to 646A.535.
Section 646A.540 - Definitions; labeling and packaging requirements; preemption.
Section 646A.542 - Requirement to document compliance.
Section 646A.544 - Local government enforcement; notice required; penalties.
Section 646A.560 - Legislative findings.
Section 646A.562 - Definitions for ORS 646A.560 to 646A.566.
Section 646A.564 - Standards for mercury content in electric lamps; exceptions.
Section 646A.575 - Definitions for ORS 646A.575 to 646A.590.
Section 646A.577 - Limited license required; application; fee; renewal; prohibited representations.
Section 646A.582 - Written disclosure requirements.
Section 646A.585 - Exceptions to license requirement; prohibited representations; acts of employees.
Section 646A.592 - Enforcement.
Section 646A.602 - Definitions for ORS 646A.600 to 646A.628.
Section 646A.606 - Security freeze; requirements; proof of authority; effect.
Section 646A.610 - Fees not permitted.
Section 646A.612 - Conditions for lifting or removing security freeze.
Section 646A.614 - Effect of security freeze on use of consumer reports or protective records.
Section 646A.624 - Powers of director; penalties.
Section 646A.628 - Allocation of moneys.
Section 646A.640 - Definitions.
Section 646A.643 - License requirement to engage in debt buying; exemptions.
Section 646A.652 - Required notices.
Section 646A.655 - Compliance with director’s standards; rules.
Section 646A.658 - Prohibited practices.
Section 646A.664 - Enforcement actions; penalties.
Section 646A.667 - Preemption.
Section 646A.683 - Requirement to report increase in drug price; exemptions.
Section 646A.692 - Civil penalty.
Section 646A.695 - Annual fees assessed against drug manufacturers; rules.
Section 646A.702 - Definitions for ORS 646A.702 to 646A.720.
Section 646A.705 - Persons that are not foreclosure consultants.
Section 646A.710 - Foreclosure consulting contract; requirements; void provisions.
Section 646A.720 - Prohibited acts of foreclosure consultant.
Section 646A.725 - Definitions for ORS 646A.725 to 646A.750.
Section 646A.730 - Persons that are not equity purchasers.
Section 646A.735 - Written contract; requirements; void provisions; power of attorney prohibited.
Section 646A.745 - Required and prohibited acts.
Section 646A.755 - Acts not precluded.
Section 646A.770 - Definitions.
Section 646A.773 - Applicability of Insurance Code; statement of costs; exemptions.
Section 646A.781 - Cancellation and expiration; refunds; effect of sale, assignment or transfer.
Section 646A.784 - Reimbursement insurance policies for guaranteed asset protection waivers.
Section 646A.787 - Fiduciary responsibilities.
Section 646A.800 - Late fees on delinquent cable service accounts; amount; disclosure; notice.
Section 646A.808 - Obtaining personal information by false representation via electronic media.
Section 646A.813 - Security requirements for Internet-connected devices; exemptions; penalty.