Uncategorized

  • Please Recommend a Moratorium and Responsible Data Center Standards

    To: Oregon Data Center Advisory Committee
    Subject: Please Recommend a Moratorium and Responsible Data Center Standards


    Hello Data Center Advisory Committee Members,

    I am writing to ask the committee to recommend a temporary statewide moratorium on permits and major public commitments for new data centers and substantial expansions.

    The moratorium should remain in place while Oregon develops a comprehensive regulatory framework governing electricity, water, land use, public costs, environmental impacts, public health, transparency, and community benefits.

    I appreciate the time and work the committee has devoted to this issue. The presentations have assembled a valuable body of information, but they have also demonstrated that Oregon still lacks the basic statewide systems needed to evaluate additional data-center development responsibly.

    Oregon does not yet have one authoritative inventory of existing and proposed data centers. The committee has heard different counts based on campuses, buildings, permits, and facilities. The preliminary electricity forecast is consequential but cannot yet be reproduced from publicly available facility-level assumptions. Water-use information remains inconsistent. Tax benefits are substantial, while project-level accounting of public costs, actual employment, infrastructure obligations, and community payments remains fragmented.

    These are not minor details that can be resolved after additional projects are approved. They are foundational questions that should be answered before Oregon makes long-term commitments involving electricity, water, land, tax policy, and public infrastructure.

    A moratorium should be specific and temporary

    I urge the committee to recommend a defined moratorium covering:

    • Permits for new large data centers
    • Permits for substantial expansions
    • New or expanded tax abatements and preferential tax treatment
    • Major public infrastructure commitments made specifically for proposed data centers
    • Utility commitments that could expose other customers to speculative or stranded costs

    The pause should apply to projects that have not received all final approvals necessary for construction and operation. It need not prevent routine maintenance, safety work, or lawful continued operation of existing facilities.

    A temporary moratorium would not determine Oregon’s permanent policy. It would preserve Oregon’s ability to create that policy before development decisions become irreversible.

    Oregon needs a consistent definition and public registry

    A statewide framework should begin with a clear definition of the projects it covers.

    One reasonable approach would be to include facilities meeting a substantial electricity-load or operational-size threshold, while excluding smaller institutional systems primarily supporting hospitals or public research.

    Oregon should establish a public registry identifying:

    • Facility and campus name
    • Owner, operator, and expected occupant
    • Location and parcel information
    • Development and operating status
    • Electricity-service provider
    • Expected and actual electric load
    • Water source and expected use
    • Generator inventory
    • Tax incentives and public agreements
    • Projected and actual jobs
    • Permits and approval documents

    The state should also reconcile the different facility counts presented to the committee and explain how campuses, buildings, facilities, projects, and permitted sites are being counted.

    Secret development negotiations should not substitute for public process

    The committee should recommend safeguards against nondisclosure agreements that prevent local governments from discussing prospective data-center projects with the public.

    Communities should not first learn about a major data center after essential decisions involving land, utilities, taxes, and infrastructure have effectively been made.

    Applications should receive meaningful public review, with:

    • Early public notice
    • Notice to nearby residents and community organizations
    • Public posting of application materials
    • Identification of the owner and prospective operator
    • Disclosure of projected jobs
    • Disclosure of planned electricity, water, land, and infrastructure use
    • Written explanations for claimed confidential information and redactions

    Public participation is not meaningful when basic project information remains confidential until late in the approval process.

    Annual reporting should be mandatory

    Oregon currently relies on a mixture of voluntary company reports, municipal totals, permit records, utility forecasts, tax-program data, and consultant estimates.

    That makes it difficult to compare projected impacts with actual outcomes.

    Every covered data center should file an annual public report addressing at least:

    • Total electricity consumption
    • Peak electricity demand
    • Source of electricity
    • Participation in demand-response or curtailment programs
    • Total water withdrawals and purchases
    • Water source
    • Consumptive use, discharge, and reclaimed-water use
    • Number of full-time-equivalent employees working on site
    • Contractor employment
    • Generator testing and emergency-operation hours
    • Fuel consumption and emissions
    • Property-tax exemptions
    • Community-service and school-support payments
    • Compliance with employment and community-benefit commitments

    Material differences between projected and actual resource use or employment should be explained publicly.

    Developers should bear project-related costs

    The committee should recommend a clear responsible-party principle: costs caused by a data-center project should be borne by the project, not shifted to households, small businesses, local governments, or the general public.

    That should include project-related costs for:

    • Electric generation, transmission, substations, and distribution
    • Water supply and treatment
    • Wastewater infrastructure
    • Roads and transportation improvements
    • Stormwater systems
    • Telecommunications
    • Fire and emergency response
    • Specialized permitting, monitoring, and enforcement
    • Decommissioning, removal, cleanup, and site restoration

    Before construction begins, developers should provide financial assurance sufficient to address abandonment, bankruptcy, incomplete construction, decommissioning, and restoration.

    This is particularly important because infrastructure may be built years before a facility reaches full operation, and some proposed projects may be delayed, reduced, transferred, or abandoned.

    Tax incentives should not continue without demonstrated public benefit

    Business Oregon’s 2025 facility data reported approximately $15.35 billion in exempt assessed value and approximately $233.56 million in estimated 2024–25 property-tax savings for 12 operating data-center authorizations.

    Those figures do not by themselves establish the net public cost, because companies may also make community-service payments, school-support payments, negotiated contributions, and payments on taxable property.

    However, they demonstrate that the public financial stakes are substantial.

    Oregon should not approve, renew, extend, or replace data-center tax benefits without a transparent demonstration that the project will produce a net public benefit.

    At minimum, the state should disclose:

    • Taxes otherwise due
    • Taxes exempted
    • Payments actually received
    • Infrastructure and administrative costs
    • Jobs promised
    • Jobs actually created
    • Wages and benefits
    • Local-hiring results
    • Compliance failures
    • Remedies available when commitments are not met

    Prospective investment and employment estimates should not be treated as completed public benefits.

    Public-health and community standards remain unresolved

    The committee’s work has focused heavily on electricity, water, land use, economics, and tax policy. A comprehensive framework must also address direct effects on nearby communities.

    The draft legislation circulating among advocates identifies several issues that deserve formal study and enforceable standards:

    • Continuous and low-frequency noise
    • Light pollution
    • Diesel-generator emissions
    • Generator testing schedules
    • Fire risks involving fuel, batteries, and electrical equipment
    • Wastewater composition and treatment
    • Effects on nearby homes, schools, health facilities, senior facilities, farmworker housing, tribal lands, and protected natural areas

    I am not asking the committee to endorse every proposed numerical threshold without further technical review. I am asking the committee to recognize that Oregon has not yet established comprehensive statewide standards for these impacts.

    That unresolved work supports a moratorium rather than continued approval under a fragmented regulatory system.

    Electricity, water, and land should not be allocated without public priorities

    The preliminary assessment estimated that Oregon data-center electricity consumption could rise from approximately 14.0 terawatt-hours in 2025 to approximately 24.8 terawatt-hours in 2030.

    That represents an increase from approximately 1,598 to 2,831 average megawatts.

    The facility list and assumptions underlying that projection have not yet been published. The public cannot determine which proposed projects are operating, contracted, probable, speculative, delayed, or constrained by transmission limitations.

    The committee should recommend that Oregon:

    • Protect residential and agricultural customers from service degradation or cost shifting
    • Separate committed loads from speculative utility inquiries
    • Require collateral, minimum payments, and exit charges
    • Prevent abandoned projects from leaving other customers responsible for infrastructure costs
    • Establish curtailment and emergency protocols before shortages occur
    • Ensure that demand response does not simply shift operations to high-emitting diesel generation
    • Evaluate whether scarce transmission, water, and industrial land have higher-priority public uses

    Water allocations should similarly be evaluated against existing municipal, residential, tribal, agricultural, ecological, and drought-resilience needs.

    Oregon should not permit resource-land rezoning for data centers without a clear statewide policy addressing agricultural land, water rights, cumulative infrastructure, and alternative locations such as brownfields and underused industrial sites.

    Oregon needs cumulative regional review

    Data-center impacts are often divided among separate agencies and proceedings:

    • A city or county reviews land use
    • A utility plans electricity service
    • DEQ permits generators
    • A municipality supplies water
    • Business Oregon administers tax incentives
    • Transportation and emergency-service effects are handled elsewhere

    Communities experience all of these impacts together.

    Oregon should require cumulative regional review that considers data-center campuses and associated infrastructure as a connected development system.

    That review should include:

    • Existing and proposed campuses
    • Transmission lines and substations
    • Water and wastewater infrastructure
    • Diesel generators
    • Roads and construction traffic
    • Housing and workforce effects
    • Agricultural-land conversion
    • Habitat and cultural resources
    • Effects on tribal rights and resources
    • Public-service capacity
    • Climate impacts

    Projects should not be divided into separate buildings, phases, companies, or permits in ways that obscure their combined effects.

    Conditions for lifting the moratorium

    I urge the committee to recommend that the moratorium remain in place until Oregon has established, at minimum:

    1. A statewide public data-center registry using consistent definitions.
    2. A reconciled electricity forecast separating operating, contracted, probable, speculative, delayed, and cancelled projects.
    3. Publication of the ECOnorthwest facility list, methodology, assumptions, and underlying tables.
    4. Ratepayer protections, including minimum payments, collateral requirements, exit charges, and transparent cost allocation.
    5. Standardized facility-level reporting for electricity, water, employment, incentives, emissions, generators, and land.
    6. Restrictions on nondisclosure agreements involving prospective projects and public bodies.
    7. Meaningful public notice and review before local or state commitments are made.
    8. Transparent project-level incentive and compliance ledgers.
    9. Net-public-benefit analysis rather than gross economic contribution alone.
    10. Cumulative regional-impact review.
    11. Public-health standards for noise, light, air emissions, wastewater, fire risk, and generator operation.
    12. Protection of agricultural land, natural resources, water supplies, and tribal rights.
    13. Developer responsibility for project-related infrastructure and administrative costs.
    14. Decommissioning plans and financial assurance.
    15. Meaningful participation by host communities, tribes, workers, utility customers, public-health experts, agricultural interests, and environmental organizations.

    The Legislature may also need a longer-term task force or public process to study technical standards, community benefits, labor protections, environmental safeguards, and enforcement mechanisms. That additional study should occur during the moratorium — not after another wave of projects has already received approvals.

    A temporary moratorium would not predetermine whether Oregon ultimately permits additional data centers. It would ensure that future decisions are made using reliable information, enforceable standards, transparent costs, and meaningful public participation.

    The committee’s work has shown that Oregon still has major questions to answer. Continuing to approve projects while those questions remain unresolved risks allowing development decisions to outrun the protections the committee was created to consider.

    Please include a temporary data-center moratorium and the development of comprehensive statewide standards among your recommendations to the Governor and Legislature.

    Thank you for your service and for the considerable time you have devoted to this issue.

    Sincerely,
    Jonathan Westmoreland
    Bend, Oregon


    Selected sources:

  • Why We Need Hackers

    A talk from ToorCamp on the history of hackers and researchers pushing back against surveillance overreach, and why that history matters now.

    This talk, recorded at ToorCamp, traces battles over encryption and security research — from Phil Zimmermann’s PGP fight with the U.S. government, to Cult of the Dead Cow’s clash with Microsoft over software security, to the researcher-led exposure of flaws in the Clipper Chip — and connects that history to today’s surveillance landscape, including automated license plate readers, data brokers, and mandatory age verification. Watch the full video below:

    Watch on YouTube: Why We Need Hackers

  • HR 2853 ACTION GUIDE

    What to Know Before You Write

    H.R. 2853 — the Combating Organized Retail Crime Act of 2025

    Federal Legislation · Now Before the U.S. Senate · Updated May 27, 2026

    Where the bill standsThe House passed H.R. 2853 on May 12, 2026, by a vote of 348–60. It is now engrossed and headed to the Senate, where it must clear committee and a floor vote before it can become law. That makes this the moment Oregonians can still weigh in — by contacting Senator Ron Wyden and Senator Jeff Merkley.[1]

    This guide explains, in plain language, what H.R. 2853 would do and lays out the key privacy and civil-liberties talking points you can raise when you email Oregon’s two U.S. senators or their staff. It is educational and informational. Use the points that matter most to you, in your own words — personal letters carry more weight than form letters.

    01What the Bill Does

    H.R. 2853 does two main things. The first is a set of criminal-law changes. The second — and the focus of most privacy concern — is the creation of a new federal coordination center.

    It strengthens federal criminal tools for retail and cargo theft.

    The bill expands criminal forfeiture, adds theft and stolen-goods offenses (18 U.S.C. §§ 659, 2314, 2315) as money-laundering predicates, treats gift cards and prepaid cards as “monetary instruments,” and lets prosecutors meet the $5,000 federal threshold by adding up thefts over a 12-month period rather than needing a single large theft.[2]

    It creates a retail-crime coordination center inside ICE.

    The bill directs the Secretary of Homeland Security to establish an Organized Retail and Supply Chain Crime Coordination Center, with its director appointed by the head of U.S. Immigration and Customs Enforcement. The Center would coordinate federal investigations, assist state and local police, build relationships with private companies, run an information-sharing system using existing DHS and DOJ databases, and enter agreements with private-sector entities. Its authority sunsets after seven years.[3]

    Worth stating plainly Organized retail and cargo theft are real problems, and the bill drew broad bipartisan support in the House. The question this guide raises is not whether the problem exists — it does — but whether a data-sharing center housed inside ICE should be built without the privacy guardrails that normally accompany this kind of information-sharing infrastructure.

    02Key Talking Points

    These are the points to raise with Oregon’s senators. You don’t need all of them — pick two or three that resonate and explain why they matter to you.

    Point 01

    A retail-theft problem is being handed to an immigration agency.

    The Center is placed inside Homeland Security Investigations, with its director appointed by ICE — not a consumer-protection body like the FTC or the Commerce Department. That structural choice means information gathered for retail-crime purposes sits inside the same agency that conducts immigration enforcement.

    You might sayI’m concerned that H.R. 2853 places a retail-crime data center inside ICE, and that the bill contains no limits preventing information from being used for immigration enforcement unrelated to the underlying case.

    Point 02

    It builds a fusion-center-style hub spanning many agencies.

    The Center can be staffed by detailees from CBP, the Secret Service, Postal Inspection, ATF, DEA, FBI, and state and local police, and can share resources with other DHS interagency centers. That lets data collected about retail theft move across unrelated enforcement domains — drugs, weapons, immigration, financial crimes — with no clear firewall between them.

    You might sayPlease ask what prevents retail-crime data in this Center from being repurposed for unrelated investigations across the many agencies that would have access.

    Point 03

    It opens direct data pipelines from private companies, with no rules on what flows through them.

    The Center is directed to build relationships with retailers and transportation companies and to receive investigative information from them. That could include security-camera footage, license-plate data, facial-recognition leads, loyalty-card and payment records, return histories, and proprietary “organized retail crime” databases — yet the bill never specifies what categories of data can or cannot be shared.

    You might sayThe bill should specify what private-sector data the Center may receive, and it should prohibit bulk transfers of customer, shopper, vehicle, or location data.

    Point 04

    It carves out an exception to a federal confidentiality law.

    The bill lets the Center’s director personally authorize disclosure of information otherwise protected under 18 U.S.C. § 1905 whenever it is deemed “operationally necessary” — an undefined term. While the approval cannot be delegated, there is no definition of the standard, no after-the-fact review, no notice to affected parties, and no limit on redisclosure.

    You might sayThe term “operationally necessary” is undefined and should be narrowed, with logging and after-the-fact review required for any disclosure of otherwise-protected information.

    Point 05

    The scope language invites mission creep.

    The covered-crime definition includes “other crimes related to” the core offenses — open-ended phrasing that could let the Center’s reach expand well beyond retail and cargo theft over time.

    You might sayPlease ask for a tighter definition of covered crimes, with a clear connection to organized retail or supply-chain theft.

    Point 06

    The basic privacy guardrails are simply missing.

    The bill does not require warrants before sensitive data is shared, data minimization, retention or deletion limits, audit logs of every search, independent civil-liberties audits, redress for people wrongly flagged, public posting of agreements with private companies, or limits on facial recognition, license-plate readers, and location data. A center this broad should carry those protections in the text.

    You might sayBefore the Senate advances this bill, it should add data minimization, retention limits, audit logging, independent civil-liberties audits, and a redress process for people wrongly identified.

    Point 07

    Strengthen what’s already good in the bill.

    The bill does include a seven-year sunset, a non-delegable approval requirement for confidential disclosures, and annual public trend reports — all worth keeping. But seven years is long enough for a surveillance system to become permanent in practice, and the required reports cover enforcement results rather than civil-liberties impacts.

    You might sayI’d urge a shorter reauthorization window — three years instead of seven — with a public civil-liberties audit before any renewal, and reporting that includes the number of U.S. persons affected and any immigration referrals.

    03Who to Contact

    Oregon is represented in the U.S. Senate by two senators. Both will vote on whether this bill advances. Contacting either or both — by email, phone, or their web contact form — puts your concerns on the record.[4]

    Sen. Ron Wyden

    Democrat · Oregon · Senior Senator

    Web contact form: wyden.senate.gov/contact/email-ron
    D.C. office: (202) 224-5244
    Bend field office: (541) 330-9142

    Sen. Jeff Merkley

    Democrat · Oregon · Junior Senator

    Web contact form: merkley.senate.gov/connect/contact
    D.C. office: (202) 224-3753
    Bend field office: (541) 318-1298

    Contact details confirmed against each senator’s official Senate website on May 27, 2026. Both senators maintain field offices in Bend’s Jamison Building. The web contact forms route your message to the staff who track this issue and are the most reliable channel.

    04How to Write an Effective Message

    • Identify yourself as an Oregon constituent and give your city. Staff sort mail by whether you live in the state.
    • Name the bill by number: H.R. 2853, the Combating Organized Retail Crime Act of 2025.
    • Lead with one specific ask — for example, “Please push for privacy amendments before this bill advances,” or “Please vote no unless these safeguards are added.”
    • Pick two or three talking points from Section 02 and put them in your own words. Specific and personal beats long and comprehensive.
    • Be brief and respectful. A few clear paragraphs is plenty. Staff log the position and the ask.
    • Ask for a response on where the senator stands. That prompts a substantive reply rather than a form acknowledgment.

    Subject

    Privacy concerns with H.R. 2853 — please seek amendments

    Message

    Dear Senator [Wyden / Merkley],

    I’m a constituent writing from [your city], Oregon. I’m contacting you about H.R. 2853, the Combating Organized Retail Crime Act of 2025, which the House passed on May 12 and which is now before the Senate.

    I understand organized retail and cargo theft are real problems. My concern is the new coordination center the bill creates inside ICE. As written, the bill places a data-sharing hub inside an immigration-enforcement agency, opens direct data pipelines from private retailers without specifying what data can be shared, and leaves out basic safeguards like data minimization, retention limits, audit logs, and a way for wrongly flagged people to seek correction.

    Before this bill advances, I’d ask you to push for those privacy protections to be written into the text, to narrow the undefined “operationally necessary” disclosure standard, and to support a shorter reauthorization window with a public civil-liberties audit before any renewal.

    Could you let me know where you stand on adding these safeguards? Thank you for your time.

    Sincerely,
    [Your name]
    [Your city], Oregon

    Sources

    [1] H.R. 2853 status and House vote (348–60, May 12, 2026): Congress.gov; engrossed-in-House text: GovInfo.
    [2] Criminal-law provisions (forfeiture, money-laundering predicates, gift-card coverage, 12-month aggregation): bill text via GovTrack and CBO cost estimate, cbo.gov.
    [3] Coordination Center, ICE placement, duties, and seven-year sunset: bill text; CBO estimate.
    [4] Oregon’s U.S. senators and office contact details confirmed via each senator’s official site: wyden.senate.gov and merkley.senate.gov.

    Bend Privacy Alliance

    Share freely · No copyright claimed · Verify before you act