EnglishEspañol
Ohio flag

Ohio

Ohio Data Privacy Laws: Safe Harbor & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 28 primary sources cited on this page. How we verify our legal content

Ohio Data Privacy Laws: Safe Harbor & Consumer Rights (2026)

Frequently Asked Questions

Does Ohio have a comprehensive consumer data privacy law?

No. As of May 2026, Ohio does not have a comprehensive consumer data privacy law. Ohio residents lack the broad access, deletion, correction, and opt-out rights available in California, Virginia, Colorado, Texas, and more than 20 other states. The narrow exception is ORC Chapter 3904, the Insurance Information and Privacy Protection Act, which gives access, correction, and deletion rights against life, health, and disability insurers only. Ohio has attempted to pass the Ohio Personal Privacy Act through HB 376 (2021) and HB 345 (2023), both of which died in committee. A new bill, HB 801 (136th GA), is pending but is narrowly focused on state government data sharing, not consumer rights.

What is the Ohio Data Protection Act and does it protect consumers?

The Ohio Data Protection Act (ORC Chapter 1354, effective November 2, 2018) is a voluntary safe-harbor law for businesses. It provides an affirmative defense to tort lawsuits when a business maintains a qualifying written cybersecurity program conforming to a recognized framework like NIST, ISO/IEC 27000, or CIS Controls. It does NOT grant consumers any rights to access, correct, delete, or opt out of the use of their personal data. Ohio residents receive no direct benefit from the law other than the indirect effect of encouraging better business cybersecurity.

How quickly must Ohio businesses notify residents after a data breach?

Under ORC 1349.19, businesses must notify affected Ohio residents as quickly as possible but no later than 45 days after discovering the breach. Notification may be by written letter, telephone, or electronic means. When a breach affects more than 1,000 Ohio residents, the entity must also notify all nationwide consumer reporting agencies. Law enforcement may request a delay if notification would compromise a criminal investigation.

What is Ohio HB 801 and is it a consumer privacy law?

Ohio HB 801, introduced March 31, 2026, and referred to the House Committee on Technology and Innovation on May 13, 2026, would enact ORC section 149.61 as the Ohio Privacy Act. It is not a comprehensive consumer privacy statute. The bill would restrict Ohio state government entities from collecting, recording, or sharing personal data with out-of-state entities except as required by law or for government operations. It addresses government data practices, not the rights of consumers against private businesses.

What penalties apply to Ohio data privacy violations?

Penalties depend on the statute. Under the breach notification law (ORC 1349.19), civil penalties for intentional or reckless noncompliance reach up to $1,000 per day for the first 60 days, $5,000 per day from 60 to 90 days, and $10,000 per day after 90 days. Under the Consumer Sales Practices Act (ORC Chapter 1345), courts can impose civil penalties of up to $25,000 per violation, but only when that practice was already declared unlawful by rule or a prior published court decision; a first-instance violation carries no such penalty. Violations of court orders can result in penalties of $5,000 per day. Insurance licensees under ORC Chapter 3965 have their own penalty structure enforced by the Ohio Department of Insurance.

What federal laws protect Ohio residents' data privacy?

Several federal laws fill significant gaps in Ohio state coverage. HIPAA protects health information held by covered entities. The Gramm-Leach-Bliley Act covers financial institutions. FERPA protects student education records. COPPA covers children's online data collection. The FTC Act Section 5 applies to deceptive or unfair data practices. The TAKE IT DOWN Act (platform obligations effective May 19, 2026) requires removal of nonconsensual intimate imagery within 48 hours. The American Privacy Rights Act did not pass and has not been reintroduced.

What did the Bayview settlement mean for Ohio residents?

The Ohio Department of Commerce joined a $20 million multistate settlement with Bayview Asset Management LLC and affiliates, announced January 8, 2025. A data breach at those mortgage companies affected 138,906 Ohio residents. The settlement required Bayview to improve its cybersecurity practices, undergo independent assessments, and provide affected consumers with credit monitoring services. The action was led by state financial regulators in California, Maryland, North Carolina, and Washington State as a multistate coalition.

Can Ohio residents opt out of data sales to third parties?

Not as a general right. No Ohio statute grants residents a general right to opt out of the sale or sharing of their personal data by private businesses. The closest thing is ORC 3904.13, which bars a life, health, or disability insurer, agent, or insurance support organization from disclosing personal information collected in an insurance transaction except in the circumstances the statute lists. That is a restriction on the insurer, not a consumer opt-out. Ohio residents can limit data sharing in federally regulated sectors: they can opt out of certain information-sharing by financial institutions under GLBA, and they can direct healthcare providers not to share information for marketing under HIPAA. Comprehensive opt-out rights require either a federal law (which does not currently exist) or the enactment of a comprehensive Ohio consumer privacy statute.

Updates

Corrected the categorical statement that Ohio gives residents no privacy rights against private businesses by adding a section on the Insurance Information and Privacy Protection Act (ORC Chapter 3904), which grants access, correction, and deletion rights against life, health, and disability insurers; fixed a cross-reference so the recognized cybersecurity frameworks are cited to ORC 1354.03 rather than 1354.02; and clarified that the Data Protection Act safe harbor reaches restricted information only when the business's written program actually covers it.

Corrected the HB 801 introduction date, added ORC 1349.19's HIPAA-covered-entity breach-notification exemption, clarified that Ohio's enhanced Consumer Sales Practices Act penalties (the $25,000 Attorney General fine and consumer treble-damages/$200 floor) apply only where the underlying practice was already declared unlawful, fixed the cybersecurity-framework citation and added two omitted NIST publications, added the consent-based exception to the SSN-recording restriction, added the elder-victim restitution/fine provision under the identity fraud statute, restated the full three-tier civil penalty structure for government-agency breach noncompliance, and corrected the COPPA rule update date to January/April 2025.

Independently fact-checked against the cited primary sources

Corrected the penalty-authority citation: the $1,000/$5,000/$10,000-per-day graduated civil penalty schedule for ORC 1349.19 breach-notification violations is established by ORC 1349.192, not ORC 1349.191 (which is only the AG's investigation/subpoena statute). Added the 1349.192 citation alongside the existing 1349.191 reference.

Governing law re-checked for recent changes

Corrected the insurance breach-notification trigger (domicile requires BOTH domicile AND material harm, plus a separate 250-consumer alternative path), split the identity-fraud felony tiers into the correct general vs. protected-class scales (a $150,000+ loss against a non-protected-class victim is a second-degree felony, not first-degree), and clarified that the cybersecurity-framework conformance clock runs from publication date for NIST/FedRAMP/CIS/ISO frameworks vs. effective date only for the regulatory frameworks (HIPAA/GLBA/FISMA/HITECH).

Governing law re-checked for recent changes

Full May 2026 refresh: added Ohio Dept of Commerce Bayview $20M settlement (Jan 2025, 138,906 Ohioans); added HB 801 (136th GA, March 2026, Ohio Privacy Act, narrow state-government scope, pending House Committee on Technology and Innovation); added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025, FTC enforcement active May 19, 2026); updated APRA status (died 118th Congress Jan 2025, not reintroduced in 119th Congress); clarified Ohio Data Protection Act is voluntary safe-harbor only, not a consumer-rights law; added Marriott/Starwood CSPA enforcement (Oct 2024, $52M multistate, $1.5M to Ohio); expanded federal overlay, consumer guidance, and FAQ section; updated SourcesList with 26 verified sources.

Reviewed and approved by an editor

Sources and References

  1. Ohio Revised Code Chapter 1354 -- Ohio Data Protection Act(codes.ohio.gov).gov
  2. Ohio Revised Code Section 1354.02 -- Safe Harbor Requirements(codes.ohio.gov).gov
  3. Ohio Revised Code Section 1354.03 -- Reasonable Conformance(codes.ohio.gov).gov
  4. Ohio Revised Code Section 1349.19 -- Data Breach Notification(codes.ohio.gov).gov
  5. Ohio Revised Code Section 1349.191 -- Investigation of Noncompliance(codes.ohio.gov).gov
  6. Ohio Revised Code Section 1349.192 -- Penalties(codes.ohio.gov).gov
  7. Ohio Revised Code Chapter 1347 -- Government Data Practices(codes.ohio.gov).gov
  8. Ohio Revised Code Section 1347.12 -- State Agency Breach Notification(codes.ohio.gov).gov
  9. Ohio Revised Code Section 1347.15 -- Confidential Personal Information Rules(codes.ohio.gov).gov
  10. Ohio Revised Code Chapter 1345 -- Consumer Sales Practices Act(codes.ohio.gov).gov
  11. Ohio Attorney General -- Consumer Protection Annual Report 2024(ohioattorneygeneral.gov).gov
  12. Ohio Attorney General -- Laws Protecting Consumers(ohioattorneygeneral.gov).gov
  13. Senate Bill 220 -- 132nd General Assembly(legislature.ohio.gov).gov
  14. Ohio Revised Code Chapter 3965 -- Insurance Data Security Act(codes.ohio.gov).gov
  15. Ohio Revised Code Section 3965.04 -- Insurance Breach Notification(codes.ohio.gov).gov
  16. Ohio Revised Code Section 3319.321 -- Student Records Protection(codes.ohio.gov).gov
  17. Ohio Revised Code Section 2913.49 -- Identity Fraud(codes.ohio.gov).gov
  18. Ohio Revised Code Section 1349.17 -- SSN and Credit Card Restrictions(codes.ohio.gov).gov
  19. House Bill 376 -- Ohio Personal Privacy Act (134th General Assembly)(legislature.ohio.gov).gov
  20. House Bill 345 -- Ohio Personal Privacy Act (135th General Assembly)(legislature.ohio.gov).gov
  21. NIST Cybersecurity Framework(nist.gov).gov
  22. FedRAMP(fedramp.gov).gov
  23. FTC -- COPPA Rule(ftc.gov).gov
  24. House Bill 801 - Ohio Privacy Act (136th GA)(legislature.ohio.gov).gov
  25. Ohio Dept of Commerce - Bayview $20M Multistate Settlement (Jan 2025)(com.ohio.gov).gov
  26. Ohio Attorney General - Consumer Protection Laws(ohioattorneygeneral.gov).gov
  27. FTC - TAKE IT DOWN Act Enforcement (May 2026)(ftc.gov).gov
  28. FTC - TAKE IT DOWN Act Statute Page(ftc.gov).gov
  29. IAPP - Analysis: Ohio's Data Protection Act(iapp.org)
  30. Ohio Revised Code Chapter 3904 - Insurance Information and Privacy Protection Act(codes.ohio.gov)
  31. Ohio Revised Code Section 3904.08 - Written Request for Access to Recorded Personal Information(codes.ohio.gov)
  32. Ohio Revised Code Section 3904.09 - Correction, Amendment or Deletion of Information(codes.ohio.gov)
  33. Ohio Revised Code Section 3904.02 - Applicability of Chapter(codes.ohio.gov)
Share: