Security requirements for Internet-connected devices
ORS 646A.813 (IoT security)
Data security
Requires makers of consumer internet-connected devices sold in Oregon to build in reasonable security features, such as a unique preset password or forcing the user to set new credentials on first use.
- Where
- Oregon
- Citation
- ORS 646A.813; 646.607(13)
- Status
- In force
- In force since
- 2020-01-01
- Enforced by
- Oregon Attorney General (unlawful trade practice under ORS 646.607)
- People can sue
- No
- Penalties
- Unlawful trade practice: injunction and civil penalties up to $25,000 per willful violation (ORS 646A.813(6); 646.642(3)).
- Applies to
- Manufacturers that make and sell or offer to sell in Oregon connected devices used primarily for personal, family or household purposes
- Excludes HIPAA-regulated activity and FDA-regulated medical devices (ORS 646A.813(4))
Security duties
- Equip connected devices with reasonable security features appropriate to the device and data, such as a unique preprogrammed password per device, a requirement to create new authentication before first access, or compliance with applicable federal security requirements.ORS 646A.813(2)
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.