Ohio Privacy Law
Ohio is one of the few states whose breach statute never requires notice to the Attorney General at all. Section 1349.19 sends notice to residents within forty-five days and, above a thousand residents, to the nationwide credit bureaus — and stops there. The Attorney General’s leverage comes instead from a penalty schedule that escalates with delay: up to $1,000 per day for the first sixty days of intentional or reckless non-compliance, up to $5,000 per day from day sixty-one, and up to $10,000 per day from day ninety-one. Ohio also took a route no other state took first, offering businesses an affirmative defence rather than a mandate: the Data Protection Act of 2018 lets a defendant in a tort suit over a breach raise conformity with one of eleven named security frameworks as a defence. And Ohio’s minors-and-social-media statute is now on the opposite trajectory from Arkansas’s: the Sixth Circuit reversed the permanent injunction against it in June 2026.
Sector-Specific Privacy Laws in Ohio
Ohio Data Protection Act (R.C. 1354.01 to 1354.05)
Senate Bill 220 of the 132nd General Assembly, effective November 2, 2018, created a safe harbour rather than a duty. Section 1354.02(A) offers a covered entity a choice of two programs: a written cybersecurity program with administrative, technical and physical safeguards protecting personal information, or one protecting both personal information and “restricted information”, in either case reasonably conforming to an industry recognised framework. Subsection (B) requires the program to be designed to protect the security and confidentiality of the information, to protect against anticipated threats, and to protect against unauthorized access likely to result in a material risk of identity theft or other fraud. Subsection (C) makes the appropriate scale of the program a function of the entity’s size and complexity, the nature and scope of its activities, the sensitivity of the information, the cost and availability of tools, and the resources available to it. Subsection (D) is the payoff: an entity satisfying those requirements is entitled to an affirmative defence to any tort cause of action brought under Ohio law or in Ohio courts alleging that a failure to implement reasonable information security controls resulted in a data breach. Section 1354.03 lists the qualifying frameworks — the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53 and 800-53a, FedRAMP, the CIS Critical Security Controls, and the ISO/IEC 27000 family, plus the HIPAA security rule, Title V of Gramm-Leach-Bliley, FISMA and HITECH for regulated entities, and the PCI data security standard in combination with one of the others — and gives one year to conform to a revised framework after its publication date.
Cybersecurity Requirements for Insurance Companies (R.C. ch. 3965)
Senate Bill 273 of the 132nd General Assembly, effective March 20, 2019, puts insurance licensees on a much shorter clock than the general breach statute. Section 3965.04(A) requires a licensee to notify the Superintendent of Insurance as promptly as possible after determining that a cybersecurity event involving nonpublic information in its possession has occurred, and in no event later than three business days after that determination, where either of two criteria is met. The first is that Ohio is the licensee’s state of domicile in the case of an insurer or its home state in the case of an independent insurance agent, and the event has a reasonable likelihood of materially harming a consumer or a material part of the licensee’s normal operations. The second is that the licensee reasonably believes the nonpublic information involved relates to 250 or more consumers residing in Ohio and the event either requires notice to a government body, self-regulatory agency or other supervisory body under state or federal law, or has a reasonable likelihood of materially harming an Ohio consumer or a material part of the licensee’s normal operations. Subsection (B) then requires the licensee to supply as much of a specified list of information as possible.
Consumer Sales Practices Act (R.C. ch. 1345)
Section 1345.07 sets out the Attorney General’s remedies where there is reasonable cause to believe a supplier has engaged in an act or practice violating the chapter and action would be in the public interest. Those remedies are a declaratory judgment that the act or practice violates section 1345.02, 1345.03 or 1345.031; a temporary restraining order, preliminary injunction or permanent injunction, with a civil penalty of not more than $5,000 for each day of violation of that order where the supplier received notice of the action, rising to between $5,000 and $15,000 per day where the restrained practice also violates section 1349.81; and — unusually among state consumer statutes — a class action under Civil Rule 23 brought by the Attorney General on behalf of consumers who engaged in consumer transactions in Ohio, for damage caused by a practice enumerated in section 1345.02, by violation of a rule adopted before the transaction, or by an act previously determined by an Ohio court to violate the chapter and committed after that decision was made available for public inspection. Where a supplier operates under a licence or authorisation issued by the Supreme Court or a state agency, the Attorney General must notify that body immediately on commencing the action.
Data Breach Notification in Ohio
Section 1349.19(B)(1) requires a person owning or licensing computerized data that includes personal information to disclose a breach to any Ohio resident whose personal information was, or reasonably is believed to have been, accessed and acquired by an unauthorized person, but only if that access and acquisition causes or reasonably is believed will cause a material risk of identity theft or other fraud to the resident. That material-risk qualifier is built into the definition of a breach itself in subsection (A)(1)(a), so it governs both the trigger and the duty. Subsection (B)(2) fixes the outer limit at forty-five days from discovery or notification, subject to the law-enforcement delay in subsection (D), which uniquely also covers a determination that disclosure would jeopardize homeland or national security. The definition of personal information in subsection (A)(7) is narrow by current standards — Social Security number, driver’s licence or state identification card number, and a financial account or card number with the code that would permit access — and the section has not been amended since Senate Bill 126 took effect on March 30, 2007. Subsection (E) provides two substitute-notice routes: the general one at a cost above $250,000 or a class above 500,000, and a second for a business entity with ten employees or fewer facing notification costs above $10,000, which substitutes a quarter-page newspaper advertisement run weekly for three consecutive weeks in the entity’s local area. Subsection (G) requires notice to the nationwide consumer reporting agencies above 1,000 residents in a single occurrence, and forbids delaying resident notice in order to give it. Subsection (H) makes any waiver of the section void and unenforceable, and subsection (F) exempts federally examined financial institutions and HIPAA covered entities entirely.
Residents must be notified in the most expedient time possible but not later than 45 days following discovery or notification of the breach. No Attorney General notification requirement; the nationwide consumer reporting agencies are notified where more than 1,000 Ohio residents are involved in a single occurrence. Complaints are taken by the Ohio Attorney General, which enforces the statute.
How Ohio Enforces Its Privacy Laws
Exclusive authority, and a penalty that grows with delay. Section 1349.192(A)(1) gives the Attorney General exclusive authority to bring a civil action in a court of common pleas for relief including a temporary restraining order, preliminary or permanent injunction and civil penalties, on an appearance that a person has failed to comply with section 1349.19 or that a state or local agency has failed to comply with section 1347.12. The penalty is mandatory once the court makes the finding — the section says the court “shall impose” it — and is calculated per day across the three tiers. Subsection (A)(3) directs the court to consider all relevant factors in setting the amount, including whether the high managerial officer, agent or employee with supervisory responsibility for compliance acted in bad faith.
Costs of the investigation are recoverable separately. Section 1349.192(B) makes any person found to have failed to comply with section 1349.19 liable to the Attorney General for the costs of conducting the investigation under section 1349.191 and of bringing the action, over and above the per-day penalty. Subsection (C) states that the rights and remedies the section provides are in addition to any other rights or remedies provided by law, so the consumer-sales route in chapter 1345 remains available on the same facts.
Recent Enforcement in Ohio
DNA Diagnostics Center — $200,000 fine and a new cybersecurity program, February 16, 2023. Attorney General Dave Yost announced on February 16, 2023 that Ohio and Pennsylvania had negotiated agreements with DNA Diagnostics Center, a Fairfield, Ohio company providing paternity and other DNA testing, over a 2021 data breach affecting more than 45,000 consumers in the two states. Social Security numbers and other personal data of roughly 33,000 Ohioans and 12,500 Pennsylvanians were exposed. The offices’ account of the facts is that the company had hired a third party to conduct data-breach monitoring, that the contractor detected a breach in May 2021 and repeatedly attempted to notify the company by email, and that employees overlooked those emails for more than two months, during which attackers installed malware on the network and extracted data — data the company had purchased from another firm to expand its portfolio rather than its own customer records. The joint investigation found the company made unfair and deceptive statements about its cybersecurity and failed to employ reasonable measures to detect and prevent a breach. Under the Ohio agreement the company paid a $200,000 fine, instituted a cybersecurity program meeting industry standards, agreed to have that program assessed by a certified third party, and agreed to comply with the Consumer Sales Practices Act in its future collection, use and protection of personal information.
Pending Privacy Legislation
Ohio’s recent legislative and appellate activity has concentrated on minors and social media rather than on general consumer privacy. The Parental Notification by Social Media Operators Act was enacted as part of Am. Sub. H.B. 33 of the 135th General Assembly and codified at R.C. 1349.09, requiring a covered operator to obtain verifiable consent from a parent or guardian for a child under sixteen to contract to use the service, to send the parent notice of the terms of service, and to provide a means of withdrawing consent. It was slated to take effect January 15, 2024 and was enjoined before it did. The Southern District of Ohio granted NetChoice summary judgment on April 16, 2025 and permanently enjoined enforcement; the Attorney General appealed on May 12, 2025; and on June 18, 2026 the Sixth Circuit reversed and remanded with instructions to enter judgment for the Attorney General, with Judge Clay announcing the judgment, Judge Batchelder concurring in the judgment separately and Judge Ritz dissenting. Nothing in the breach statute at R.C. 1349.19 has changed since Senate Bill 126 of the 126th General Assembly took effect on March 30, 2007.
Federal Privacy Laws That Apply in Ohio
Federal privacy law applies in Ohio by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, Ohio obligations run through the state’s breach-notification statute and the Ohio Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach Ohio Businesses
With no comprehensive state statute, most privacy obligations on a Ohio business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Ohio businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Ohio itself has none, and any business holding personal information about Ohio residents is subject to the state’s breach-notification statute described above.
Ohio Privacy Law FAQ
Does an Ohio breach have to be reported to the Attorney General?
How do Ohio’s breach-notification penalties work?
What is Ohio’s cybersecurity safe harbour and what does it protect against?
Which security frameworks satisfy the Ohio Data Protection Act?
How fast must an Ohio insurance licensee report a cybersecurity event?
Is Ohio’s social media parental notification law enforceable?
Can a small Ohio business use a newspaper advertisement instead of individual notices?
What counts as personal information under Ohio’s breach statute?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- R.C. 1349.19 — Private disclosure of security breach of computerized personal information data statute
- R.C. 1349.192 — Civil action by attorney general for violation of disclosure laws statute
- R.C. 1354.02 — Safe harbor requirements statute
- R.C. 1354.03 — Reasonable conformance to an industry recognized framework statute
- R.C. 1345.07 — Remedies of attorney general statute
- R.C. 3965.04 — Notification to superintendent of insurance statute
- Ohio Attorney General — $200,000 agreement with DNA Diagnostics over a data breach agency
- NetChoice, LLC v. Yost — Sixth Circuit opinion reversing the injunction, No. 25-3371 (June 18, 2026) decision
- NetChoice, LLC v. Yost — district court opinion and permanent injunction (S.D. Ohio Apr. 16, 2025) decision
- NetChoice, LLC v. Yost — docket, S.D. Ohio No. 2:24-cv-00047 docket
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.