Ohio

Ohio Privacy Law

Ohio is one of the few states whose breach statute never requires notice to the Attorney General at all. Section 1349.19 sends notice to residents within forty-five days and, above a thousand residents, to the nationwide credit bureaus — and stops there. The Attorney General’s leverage comes instead from a penalty schedule that escalates with delay: up to $1,000 per day for the first sixty days of intentional or reckless non-compliance, up to $5,000 per day from day sixty-one, and up to $10,000 per day from day ninety-one. Ohio also took a route no other state took first, offering businesses an affirmative defence rather than a mandate: the Data Protection Act of 2018 lets a defendant in a tort suit over a breach raise conformity with one of eleven named security frameworks as a defence. And Ohio’s minors-and-social-media statute is now on the opposite trajectory from Arkansas’s: the Sixth Circuit reversed the permanent injunction against it in June 2026.

Sector-Specific Privacy Laws in Ohio

Ohio Data Protection Act (R.C. 1354.01 to 1354.05)

Senate Bill 220 of the 132nd General Assembly, effective November 2, 2018, created a safe harbour rather than a duty. Section 1354.02(A) offers a covered entity a choice of two programs: a written cybersecurity program with administrative, technical and physical safeguards protecting personal information, or one protecting both personal information and “restricted information”, in either case reasonably conforming to an industry recognised framework. Subsection (B) requires the program to be designed to protect the security and confidentiality of the information, to protect against anticipated threats, and to protect against unauthorized access likely to result in a material risk of identity theft or other fraud. Subsection (C) makes the appropriate scale of the program a function of the entity’s size and complexity, the nature and scope of its activities, the sensitivity of the information, the cost and availability of tools, and the resources available to it. Subsection (D) is the payoff: an entity satisfying those requirements is entitled to an affirmative defence to any tort cause of action brought under Ohio law or in Ohio courts alleging that a failure to implement reasonable information security controls resulted in a data breach. Section 1354.03 lists the qualifying frameworks — the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53 and 800-53a, FedRAMP, the CIS Critical Security Controls, and the ISO/IEC 27000 family, plus the HIPAA security rule, Title V of Gramm-Leach-Bliley, FISMA and HITECH for regulated entities, and the PCI data security standard in combination with one of the others — and gives one year to conform to a revised framework after its publication date.

Cybersecurity Requirements for Insurance Companies (R.C. ch. 3965)

Senate Bill 273 of the 132nd General Assembly, effective March 20, 2019, puts insurance licensees on a much shorter clock than the general breach statute. Section 3965.04(A) requires a licensee to notify the Superintendent of Insurance as promptly as possible after determining that a cybersecurity event involving nonpublic information in its possession has occurred, and in no event later than three business days after that determination, where either of two criteria is met. The first is that Ohio is the licensee’s state of domicile in the case of an insurer or its home state in the case of an independent insurance agent, and the event has a reasonable likelihood of materially harming a consumer or a material part of the licensee’s normal operations. The second is that the licensee reasonably believes the nonpublic information involved relates to 250 or more consumers residing in Ohio and the event either requires notice to a government body, self-regulatory agency or other supervisory body under state or federal law, or has a reasonable likelihood of materially harming an Ohio consumer or a material part of the licensee’s normal operations. Subsection (B) then requires the licensee to supply as much of a specified list of information as possible.

Consumer Sales Practices Act (R.C. ch. 1345)

Section 1345.07 sets out the Attorney General’s remedies where there is reasonable cause to believe a supplier has engaged in an act or practice violating the chapter and action would be in the public interest. Those remedies are a declaratory judgment that the act or practice violates section 1345.02, 1345.03 or 1345.031; a temporary restraining order, preliminary injunction or permanent injunction, with a civil penalty of not more than $5,000 for each day of violation of that order where the supplier received notice of the action, rising to between $5,000 and $15,000 per day where the restrained practice also violates section 1349.81; and — unusually among state consumer statutes — a class action under Civil Rule 23 brought by the Attorney General on behalf of consumers who engaged in consumer transactions in Ohio, for damage caused by a practice enumerated in section 1345.02, by violation of a rule adopted before the transaction, or by an act previously determined by an Ohio court to violate the chapter and committed after that decision was made available for public inspection. Where a supplier operates under a licence or authorisation issued by the Supreme Court or a state agency, the Attorney General must notify that body immediately on commencing the action.

Data Breach Notification in Ohio

Section 1349.19(B)(1) requires a person owning or licensing computerized data that includes personal information to disclose a breach to any Ohio resident whose personal information was, or reasonably is believed to have been, accessed and acquired by an unauthorized person, but only if that access and acquisition causes or reasonably is believed will cause a material risk of identity theft or other fraud to the resident. That material-risk qualifier is built into the definition of a breach itself in subsection (A)(1)(a), so it governs both the trigger and the duty. Subsection (B)(2) fixes the outer limit at forty-five days from discovery or notification, subject to the law-enforcement delay in subsection (D), which uniquely also covers a determination that disclosure would jeopardize homeland or national security. The definition of personal information in subsection (A)(7) is narrow by current standards — Social Security number, driver’s licence or state identification card number, and a financial account or card number with the code that would permit access — and the section has not been amended since Senate Bill 126 took effect on March 30, 2007. Subsection (E) provides two substitute-notice routes: the general one at a cost above $250,000 or a class above 500,000, and a second for a business entity with ten employees or fewer facing notification costs above $10,000, which substitutes a quarter-page newspaper advertisement run weekly for three consecutive weeks in the entity’s local area. Subsection (G) requires notice to the nationwide consumer reporting agencies above 1,000 residents in a single occurrence, and forbids delaying resident notice in order to give it. Subsection (H) makes any waiver of the section void and unenforceable, and subsection (F) exempts federally examined financial institutions and HIPAA covered entities entirely.

Residents must be notified in the most expedient time possible but not later than 45 days following discovery or notification of the breach. No Attorney General notification requirement; the nationwide consumer reporting agencies are notified where more than 1,000 Ohio residents are involved in a single occurrence. Complaints are taken by the Ohio Attorney General, which enforces the statute.

How Ohio Enforces Its Privacy Laws

Exclusive authority, and a penalty that grows with delay. Section 1349.192(A)(1) gives the Attorney General exclusive authority to bring a civil action in a court of common pleas for relief including a temporary restraining order, preliminary or permanent injunction and civil penalties, on an appearance that a person has failed to comply with section 1349.19 or that a state or local agency has failed to comply with section 1347.12. The penalty is mandatory once the court makes the finding — the section says the court “shall impose” it — and is calculated per day across the three tiers. Subsection (A)(3) directs the court to consider all relevant factors in setting the amount, including whether the high managerial officer, agent or employee with supervisory responsibility for compliance acted in bad faith.

Costs of the investigation are recoverable separately. Section 1349.192(B) makes any person found to have failed to comply with section 1349.19 liable to the Attorney General for the costs of conducting the investigation under section 1349.191 and of bringing the action, over and above the per-day penalty. Subsection (C) states that the rights and remedies the section provides are in addition to any other rights or remedies provided by law, so the consumer-sales route in chapter 1345 remains available on the same facts.

Recent Enforcement in Ohio

DNA Diagnostics Center — $200,000 fine and a new cybersecurity program, February 16, 2023. Attorney General Dave Yost announced on February 16, 2023 that Ohio and Pennsylvania had negotiated agreements with DNA Diagnostics Center, a Fairfield, Ohio company providing paternity and other DNA testing, over a 2021 data breach affecting more than 45,000 consumers in the two states. Social Security numbers and other personal data of roughly 33,000 Ohioans and 12,500 Pennsylvanians were exposed. The offices’ account of the facts is that the company had hired a third party to conduct data-breach monitoring, that the contractor detected a breach in May 2021 and repeatedly attempted to notify the company by email, and that employees overlooked those emails for more than two months, during which attackers installed malware on the network and extracted data — data the company had purchased from another firm to expand its portfolio rather than its own customer records. The joint investigation found the company made unfair and deceptive statements about its cybersecurity and failed to employ reasonable measures to detect and prevent a breach. Under the Ohio agreement the company paid a $200,000 fine, instituted a cybersecurity program meeting industry standards, agreed to have that program assessed by a certified third party, and agreed to comply with the Consumer Sales Practices Act in its future collection, use and protection of personal information.

Pending Privacy Legislation

Ohio’s recent legislative and appellate activity has concentrated on minors and social media rather than on general consumer privacy. The Parental Notification by Social Media Operators Act was enacted as part of Am. Sub. H.B. 33 of the 135th General Assembly and codified at R.C. 1349.09, requiring a covered operator to obtain verifiable consent from a parent or guardian for a child under sixteen to contract to use the service, to send the parent notice of the terms of service, and to provide a means of withdrawing consent. It was slated to take effect January 15, 2024 and was enjoined before it did. The Southern District of Ohio granted NetChoice summary judgment on April 16, 2025 and permanently enjoined enforcement; the Attorney General appealed on May 12, 2025; and on June 18, 2026 the Sixth Circuit reversed and remanded with instructions to enter judgment for the Attorney General, with Judge Clay announcing the judgment, Judge Batchelder concurring in the judgment separately and Judge Ritz dissenting. Nothing in the breach statute at R.C. 1349.19 has changed since Senate Bill 126 of the 126th General Assembly took effect on March 30, 2007.

Federal Privacy Laws That Apply in Ohio

Federal privacy law applies in Ohio by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

Outside those federal sectors, Ohio obligations run through the state’s breach-notification statute and the Ohio Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.

Industry Rules That Reach Ohio Businesses

With no comprehensive state statute, most privacy obligations on a Ohio business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Ohio businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Ohio itself has none, and any business holding personal information about Ohio residents is subject to the state’s breach-notification statute described above.

Ohio Privacy Law FAQ

Does an Ohio breach have to be reported to the Attorney General?
Section 1349.19 imposes no such requirement on private entities. Subsection (G) requires notice only to all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, and only where the breach requires disclosure to more than one thousand Ohio residents in a single occurrence. Subsection (I) separately preserves the Attorney General’s power to investigate under section 1349.191 and bring a civil action under section 1349.192 for an alleged failure to comply.
How do Ohio’s breach-notification penalties work?
They escalate by day and by tier. Under section 1349.192(A)(1) a court that finds an intentional or reckless failure to comply shall impose up to $1,000 for each day of non-compliance; where the failure has run more than sixty days, up to $5,000 for each day from the sixty-first; and where it has run more than ninety days, up to $10,000 for each day from the ninety-first, with the earlier tiers still applying to the earlier days. Penalties go to the consumer protection enforcement fund created by section 1345.51, and the violator is also liable for the Attorney General’s investigation and litigation costs.
What is Ohio’s cybersecurity safe harbour and what does it protect against?
Sections 1354.01 to 1354.05 give a covered entity an affirmative defence — not immunity and not a compliance mandate. Section 1354.02(D) provides that an entity meeting the program, design and scale requirements is entitled to an affirmative defence to any cause of action sounding in tort, brought under Ohio law or in Ohio courts, alleging that a failure to implement reasonable information security controls resulted in a data breach. The defence covers breaches of personal information, or of both personal and restricted information where the broader program in subsection (A)(2) is maintained.
Which security frameworks satisfy the Ohio Data Protection Act?
Section 1354.03(A) names the NIST framework for improving critical infrastructure cybersecurity, NIST special publication 800-171, NIST special publications 800-53 and 800-53a, the FedRAMP security assessment framework, the CIS critical security controls for effective cyber defense, and the ISO/IEC 27000 family. Subsection (B) adds, for regulated entities, the HIPAA security requirements at 45 C.F.R. part 164 subpart C, Title V of Gramm-Leach-Bliley, FISMA and HITECH. Subsection (C) allows the PCI data security standard where it is combined with conformity to another listed framework. Subsections (A)(2) and (D) give one year to conform after a revision is published.
How fast must an Ohio insurance licensee report a cybersecurity event?
Section 3965.04(A) requires notice to the Superintendent of Insurance as promptly as possible and in no event later than three business days after determining a cybersecurity event has occurred, on either of two triggers: Ohio is the licensee’s state of domicile or home state and the event has a reasonable likelihood of materially harming a consumer or a material part of normal operations; or the licensee reasonably believes 250 or more Ohio consumers are involved and the event either requires notice to another supervisory body or carries that same likelihood of material harm.
Is Ohio’s social media parental notification law enforceable?
The permanent injunction against it has been reversed. The Parental Notification by Social Media Operators Act, H.B. 33 of the 135th General Assembly codified at R.C. 1349.09, requires a covered operator to obtain verifiable consent from a parent or guardian before a child under sixteen may contract to use the service. Judge Algenon L. Marbley granted NetChoice summary judgment and permanently enjoined the Act on April 16, 2025. On June 18, 2026 the Sixth Circuit held in NetChoice, LLC v. Yost, No. 25-3371, that a majority of the panel agreed NetChoice had failed to establish the Act is facially unconstitutional, and reversed the judgment and remanded with instructions to enter judgment in favour of the Attorney General.
Can a small Ohio business use a newspaper advertisement instead of individual notices?
Section 1349.19(E)(5) provides that route specifically for a business entity with ten employees or fewer that demonstrates the cost of providing the required notices will exceed $10,000. Substitute notice then consists of all three of: a paid advertisement in a local newspaper distributed where the business is located, covering at least one-quarter of a page and published weekly for three consecutive weeks; conspicuous posting on the entity’s website if it has one; and notification to major media outlets in the entity’s geographic area.
What counts as personal information under Ohio’s breach statute?
Section 1349.19(A)(7)(a) lists three data elements — a Social Security number, a driver’s licence number or state identification card number, and an account number or credit or debit card number in combination with a required security code, access code or password permitting access to a financial account — each combined with and linked to the individual’s first name or first initial and last name, and each unencrypted, unredacted and not otherwise rendered unreadable. Subsection (A)(9) defines “redacted” as truncation to no more than the last four digits.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.