Oregon's Consumer Privacy Act (OCPA), enacted as Senate Bill 619 and effective July 1, 2024, has generated questions in the conservation and environmental monitoring community that don't have obvious answers in the statute text. The law is modeled on the Virginia Consumer Data Protection Act framework, which means it inherits both that law's consumer-protective strengths and its ambiguities around non-traditional data categories.
For organizations using satellite-based land monitoring tools — whether you're a conservation NGO, a state agency, or a private company with supply chain exposure in Oregon — the central question is this: when satellite imagery is collected over privately held land parcels and analyzed to generate change detection records, does that data processing touch personal data under OCPA? And if it does, what obligations follow?
This article is an analytical walkthrough of the relevant statutory provisions, not legal advice. If your organization has material compliance exposure, engage Oregon-licensed counsel. But understanding the statutory framework well enough to ask the right questions is a reasonable starting point, and that's what we'll try to provide here.
OCPA's Scope: Who and What It Covers
OCPA applies to controllers (entities that determine the purposes and means of processing personal data) that conduct business in Oregon or produce products or services targeted to Oregon residents, and that during a calendar year: (a) control or process personal data of 100,000 or more Oregon consumers, or (b) control or process personal data of 25,000 or more consumers while deriving more than 25% of gross revenue from selling personal data. These are the threshold tests under ORS 646A.570.
Most conservation NGOs and early-stage environmental monitoring companies will not meet these volume thresholds. A forestry nonprofit monitoring riparian corridors in the Willamette Valley, a small team running satellite change detection over Oregon timber harvests — these organizations almost certainly process fewer than 100,000 Oregon consumers' personal data annually and don't derive 25%+ of revenue from selling it. The thresholds create a practical small-organization carve-out that applies to much of the conservation sector.
However, the threshold analysis doesn't end the inquiry if your organization shares data with or processes data on behalf of a larger controller — a federal agency, a large timber company, or an ESG data aggregator — that does meet the thresholds. In that case, your organization may be operating as a processor under OCPA, which carries its own obligations including data processing agreements and security requirements.
Is Geospatial Parcel Data "Personal Data" Under OCPA?
OCPA defines personal data as "information that is linked or reasonably linkable to an identified or identifiable individual." This is the definitional hinge that determines whether satellite-derived land monitoring data is within scope at all.
Parcel-level land records in Oregon are public data — the Oregon Department of Revenue maintains statewide assessment and taxation files, and county assessors publish parcel geometries with owner-of-record information. A parcel polygon (a set of GPS coordinates defining a property boundary) is, on its own, not personal data. Coordinates don't identify a person.
The linkability question is where analysis becomes more fact-specific. If your monitoring system stores change detection records that include a parcel ID, and your system also has access to (or routinely queries against) the county assessor's ownership database to identify the parcel owner, then the change detection record becomes reasonably linkable to an identified individual — the landowner. In that configuration, the change detection record takes on personal data characteristics.
The practical implication: monitoring pipelines that process parcel-level detections against public ownership records without separating those datasets may inadvertently create personal data processing. A detection record that says "parcel 12-34-567 experienced a 0.4-hectare clearing event on 2025-09-14, owned by [individual name]" is personal data in a way that "parcel 12-34-567 experienced a 0.4-hectare clearing event on 2025-09-14" arguably is not, if that parcel ID is not routinely linked to named individuals in your data architecture.
Sensitive Data Categories and Geolocation
OCPA designates certain categories as "sensitive data" subject to heightened obligations, including the requirement to obtain opt-in consent for processing. The categories include — and this is where environmental monitoring practitioners need to pay attention — "precise geolocation data," defined as information that identifies a consumer's location within a radius of 1,750 feet (approximately 533 meters).
The sensitive geolocation provision is designed to protect against consumer location tracking. Its scope as applied to parcel-level land monitoring is genuinely ambiguous. The statutory definition refers to "a consumer's location," which most naturally reads as the location of a person (their whereabouts at a given time), not the location of their property. Property location is static public information, not dynamic location tracking.
A reasonable interpretation is that parcel coordinates do not constitute precise geolocation data under OCPA because they describe property location, not consumer location. The legislative history of analogous state laws (Virginia, Colorado, Connecticut) consistently frames precise geolocation as a consumer mobility and surveillance concern, not a property records concern. That said, this is an interpretation, not a resolved legal question.
The B2B and Government Exemptions
OCPA contains important limitations on its scope that are directly relevant to conservation monitoring. ORS 646A.570(2) excludes from the definition of consumer "an individual acting in a commercial or employment context." This means OCPA's consumer rights provisions — access, correction, deletion, opt-out — do not apply to data processed in a B2B or government context.
For environmental monitoring organizations whose clients are other businesses or government agencies (a federal land management bureau, a state forestry department, an ESG team at a commodity company), the individual consumer rights provisions of OCPA largely don't apply to the core data processing relationship. A forest ranger who accesses deforestation alerts as part of their government employment is not exercising OCPA consumer rights over that data.
OCPA also contains a research exemption: processing for the purpose of "public interest, scientific, or historical research, or statistical purposes" is subject to a compatibility test (the research purpose must be compatible with the original collection purpose) but not to the full range of OCPA obligations. Conservation research organizations may qualify for this exemption for scientific monitoring programs, though the exemption has limits and doesn't eliminate all requirements.
Practical Steps for Conservation Organizations
Based on the foregoing analysis, here is a practical checklist for conservation and environmental monitoring organizations assessing OCPA exposure:
- Threshold check: Do you process personal data of 100,000 or more Oregon consumers annually? If not, you're almost certainly outside OCPA's direct application as a controller — but document this conclusion.
- Data architecture review: Does your monitoring system routinely link parcel change detection records to named property owners (by querying county assessor records)? If yes, consider whether that linkage is architecturally necessary or whether de-identified parcel ID records serve the monitoring purpose equally well.
- Processor obligations: If you process data on behalf of a larger organization that does meet OCPA thresholds, ensure you have a data processing agreement in place that satisfies ORS 646A.574(5) requirements, including data security provisions and limitations on subprocessing.
- Privacy notice: If you do collect personal data from Oregon residents (e.g., your platform has individual users who are Oregon residents and you collect usage data linked to their accounts), ensure your privacy notice describes geospatial data processing consistent with ORS 646A.575.
- Research exemption documentation: If you are a research organization relying on the public interest/scientific research exemption, document the research purpose and ensure your data practices are consistent with that purpose — the exemption isn't self-executing.
What This Means for Platform Operators Specifically
For a company operating a satellite monitoring platform where conservation NGOs and supply chain teams access deforestation alerts — we'll describe our own situation here directly — the OCPA analysis works out roughly as follows.
We process satellite-derived change detection records that are spatially tied to parcel coordinates. We do not routinely link parcel records to named individuals in our data processing pipeline; our detection records reference polygon IDs and spatial coordinates, not owner names. Our client organizations may independently perform that linkage on their end using public property records — but that's their data processing, not ours.
Our platform users (the people logging in to view alerts) are individuals whose account data we process. For Oregon-resident users, OCPA applies to that account data processing in a conventional sense: we need a privacy notice, we need to honor access and deletion requests, and we process only the account data necessary for platform operation. That's standard privacy practice and the same obligations we'd have under California's CPRA or Washington's My Health MY Data Act for users in those states.
The interesting and genuinely unresolved question is whether, in the future, satellite monitoring data becomes more granular and more person-linked — if imagery resolution reaches a point where individual activity on a land parcel (a person operating equipment, for instance) is consistently identifiable. At that point, the analysis changes significantly. Current Sentinel-2 at 10 m resolution cannot identify individuals, and that's the honest boundary between environmental monitoring and personal surveillance.
Staying Current as Oregon Rulemaking Proceeds
OCPA is a relatively new law and the Oregon Department of Justice's Consumer Protection Section is still developing interpretive guidance. The law's text does not resolve every geospatial edge case, and formal rulemaking or enforcement actions in the next few years will clarify many of the ambiguities discussed here.
Organizations that document their analysis now — why they concluded they're outside scope, or what safeguards they put in place if they concluded they're within scope — are in a far better position when regulators ask questions than organizations that never examined the question at all. That documentation habit applies regardless of whether you ultimately conclude OCPA creates obligations for your specific monitoring activities.