Ohio
Ohio Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 8, 2026. · 10 primary sources cited on this page. How we verify our legal content

Ohio has no dedicated biometric privacy statute and no comprehensive consumer privacy law covering biometric data. The breach notification law (ORC Section 1349.19) does not include biometric identifiers. The Ohio Data Protection Act (ORC Chapter 1354) offers businesses a cybersecurity safe harbor but grants individuals no biometric rights. Insurance licensees are the only businesses that face explicit biometric data-security obligations, under ORC Chapter 3965.
Ohio stands out as a state that has taken a unique approach to data security without directly addressing biometric privacy. While many states have moved toward comprehensive consumer privacy laws or dedicated biometric statutes, Ohio has instead focused on incentivizing good cybersecurity practices through its first-in-the-nation safe harbor law.
If you are looking for an overview of Ohio's broader data protection landscape, see the parent guide to Ohio Data Privacy Laws.
Ohio Does Not Have a Dedicated Biometric Privacy Law
Ohio has not enacted a standalone biometric privacy statute. Unlike Illinois, which passed the Biometric Information Privacy Act (BIPA) in 2008, or Texas, which enacted its Capture or Use of Biometric Identifier Act, Ohio has no law that specifically regulates how private businesses collect, store, use, or destroy biometric identifiers like fingerprints, facial geometry, iris scans, or voiceprints.
This means that in Ohio, private companies can generally collect and use biometric data without obtaining specific written consent, without providing a biometric data retention schedule, and without offering individuals a private right of action if their biometric information is mishandled.
Ohio residents who interact with biometric systems at retail stores, gyms, banks, or through smartphone applications do not have state-level biometric privacy rights comparable to what residents of Illinois, Texas, or Washington enjoy.

Breach Notification Law: Biometric Data Is Not Covered
Ohio's breach notification statute, ORC Section 1349.19, requires businesses to notify Ohio residents when a security breach compromises their unencrypted personal information. The law has been in effect since March 30, 2007.
However, the statute defines "personal information" narrowly. Protected data elements include:
- Social Security numbers
- Driver's license or state identification card numbers
- Account numbers, credit card numbers, or debit card numbers with associated security codes or passwords
Biometric identifiers are notably absent from this list. A breach that exposes fingerprint databases, facial recognition templates, or iris scan records does not trigger notification obligations under ORC 1349.19, as long as none of the listed traditional identifiers are also compromised.
The Ohio Attorney General enforces the breach notification law and can bring civil actions against businesses that fail to notify affected individuals.
The Ohio Data Protection Act: A Safe Harbor, Not a Privacy Law
Ohio made national headlines in 2018 when Governor John Kasich signed Senate Bill 220, creating the Ohio Data Protection Act (ODPA), codified in ORC Chapter 1354. Ohio was the first state in the nation to offer a legal safe harbor for businesses that implement recognized cybersecurity frameworks.
The ODPA does not create new consumer privacy rights. Instead, it provides an affirmative defense to tort claims arising from data breaches. A business that creates, maintains, and complies with a written cybersecurity program that reasonably conforms to a recognized industry framework can use that compliance as a defense in Ohio courts.
Recognized Cybersecurity Frameworks
Under ORC Section 1354.03, the following frameworks qualify for safe harbor protection:
Industry frameworks:
- NIST Framework for Improving Critical Infrastructure Cybersecurity
- NIST Special Publication 800-171
- NIST Special Publications 800-53 and 800-53a
- FedRAMP Security Assessment Framework
- Center for Internet Security (CIS) Critical Security Controls
- ISO/IEC 27000 family of standards
Regulatory compliance frameworks:
- HIPAA Security Rule (45 CFR Part 164 Subpart C)
- Gramm-Leach-Bliley Act Title V
- Federal Information Security Modernization Act (FISMA) of 2014
- HITECH Act
The PCI Data Security Standard also qualifies when combined with any of the industry frameworks above.
How the Safe Harbor Applies to Biometric Data
The ODPA protects both "personal information" (as defined in ORC 1349.19) and "restricted information," which covers data that alone or in combination with other information can distinguish or trace an individual's identity.
Biometric data could potentially fall under the "restricted information" category. A business that collects biometric data and maintains a cybersecurity program conforming to NIST or ISO 27000 standards would be better positioned to defend against tort claims if that biometric data were breached.
However, this is a defense mechanism, not a rights-granting statute. The ODPA does not require consent for biometric data collection, does not mandate retention schedules, and does not give individuals the right to request deletion of their biometric information.

Insurance Data Security Act: The Exception for Biometric Records
The only Ohio statute that treats biometric records as protected data within a general data-security scheme is the Insurance Data Security Act, ORC Chapter 3965. It is not, however, the only Ohio law that mentions biometric data: ORC Section 3301.947 bars collecting students' biometric information during state achievement testing, and ORC Section 3701.75 recognizes "a biometric access control device" as one way to secure electronic signatures on health care records.
Under ORC Section 3965.01, the definition of "nonpublic information" includes an individual's data when combined with "biometric records." Insurance licensees must implement cybersecurity programs that protect this nonpublic information, including biometric records.
The law also recognizes biometric characteristics as a valid form of multi-factor authentication. That language sits in the definitions section: ORC Section 3965.01, division (N)(3), defines multifactor authentication to include "inherence factors, such as a biometric characteristic," alongside knowledge factors like a password and possession factors like a token.
The operative duty sits elsewhere. ORC Section 3965.02 requires each licensee to determine which security measures are appropriate based on its risk assessment and then implement them, and division (D)(2)(g) of that section lists "effective controls, which may include multifactor authentication procedures for accessing nonpublic information." Section 3965.02 does not itself use the word biometric.
Insurance licensees must notify the Ohio Superintendent of Insurance as promptly as possible after determining that a cybersecurity event involving nonpublic information has occurred, and in no event later than three business days after that determination. ORC Section 3965.04 applies that deadline only when one of two criteria is met:
- Ohio is the licensee's state of domicile, or its home state in the case of an independent insurance agent, and the event has a reasonable likelihood of materially harming a consumer or a material part of the licensee's normal operations; or
- The licensee reasonably believes the nonpublic information involved relates to 250 or more consumers residing in Ohio, and the event either requires notice to a government body, self-regulatory agency, or other supervisory body under state or federal law, or has a reasonable likelihood of causing that same material harm.
A cybersecurity event that meets neither criterion does not carry the three-business-day reporting deadline to the superintendent.
This law only applies to entities licensed under Ohio insurance regulations. It does not extend biometric protections to the general public or to industries outside the insurance sector.
A Narrow Ohio Ban: Biometric Data in State Student Testing
Ohio does have one statute that flatly prohibits biometric collection, though its reach is deliberately narrow. ORC Section 3301.947 governs data gathered during state achievement testing and provides that in the course of that testing, "no student's or a student's family's social security numbers, religious affiliation, political party affiliation, voting history, or biometric information shall be collected, tracked, housed with, reported to, or shared with any entity, including the federal or state government."
This is a flat prohibition rather than a consent framework, which makes it different in kind from the notice-and-consent model used by Illinois BIPA. It is also confined to the testing context: it says nothing about biometric collection elsewhere in a school setting, and it gives students and families no private right of action.
Employer Use of Biometric Data in Ohio
Ohio does not regulate employer collection or use of biometric data in the workplace. There is no state law requiring employers to:
- Provide written notice before collecting fingerprints, facial scans, or other biometric identifiers
- Obtain employee consent before enrolling them in biometric timekeeping or access control systems
- Publish a biometric data retention and destruction schedule
- Limit the sharing or sale of employee biometric data to third parties
Ohio employers commonly use fingerprint scanners for time and attendance tracking, facial recognition for building access, and palm vein readers for secure facility entry. None of these practices are specifically regulated by Ohio state law.
Employees who believe their biometric data has been misused may explore claims under general Ohio tort law, such as invasion of privacy or negligence, but these claims require meeting traditional tort elements and do not carry the statutory damages available under laws like Illinois BIPA.
Federal laws like HIPAA (for healthcare settings) or the Americans with Disabilities Act (which restricts certain medical examinations) may apply in specific workplace contexts, but these are not Ohio-specific biometric privacy protections.
Age Verification and Biometric Facial Estimation
Ohio House Bill 96, signed into law on June 30, 2025 and effective September 30, 2025, requires websites that publish material harmful to minors to verify that visitors are at least 18 years old.
The enacted law authorizes only two verification routes: a commercial system using photo identification, or public or private transactional data (R.C. 1349.10(A)(10)). It does not authorize biometric facial age estimation. A separate pending bill, HB 84, would permit visual age verification software, but as of August 2026 it has passed only the House and remains in the Senate Judiciary Committee.
HB 96 includes a notable data minimization requirement: any data collected during age verification must be deleted immediately after verification is complete, unless the data is needed for account subscription or billing purposes. This represents one of the few instances where Ohio law directly addresses the handling of biometric-adjacent data.

Failed Attempts at Comprehensive Privacy Legislation
Ohio has considered comprehensive consumer privacy legislation multiple times, and each attempt has stalled:
HB 376 (134th General Assembly, 2021-2022). The first version of the Ohio Personal Privacy Act was introduced in July 2021. It did not advance out of committee.
HB 345 (135th General Assembly, 2023-2024). A revised version of the Ohio Personal Privacy Act was introduced in November 2023. This bill would have applied to businesses with $25 million or more in Ohio revenue, or those processing personal data of 100,000 or more Ohio consumers. The bill was referred to the Government Oversight Committee, where it died without a vote.
136th General Assembly (2025-2026). Through the most recent bill-tracking check, no comprehensive consumer data privacy bill has been introduced in the current legislative session. The HB 345 number in the 136th General Assembly was assigned to an unrelated bill concerning voyeurism penalties.
Had any of these bills passed, they would likely have classified biometric data as sensitive personal data requiring opt-in consent, similar to the approach taken by Virginia, Colorado, and Connecticut.
How Ohio Compares to Other States
Ohio's lack of biometric privacy protections places it in the minority among states that have significant technology sectors and large populations.
States with dedicated biometric privacy statutes. Illinois, Texas, and Washington all have standalone biometric privacy laws with specific consent, notice, and data handling requirements.
States with comprehensive privacy laws covering biometrics. More than 20 states now have comprehensive consumer privacy laws that classify biometric data as sensitive data. These include California, Virginia, Colorado, Connecticut, and Kentucky, among others.
States in a similar position to Ohio. A shrinking number of states still lack both a dedicated biometric privacy statute and a comprehensive consumer privacy law. Ohio is unusual because it has an innovative cybersecurity safe harbor law but has not translated that into direct consumer privacy protections for biometric data.
Ohio's Data Protection Act safe harbor remains a distinctive feature. No other state offers the same type of affirmative defense for businesses that follow recognized cybersecurity frameworks. This approach encourages data security investment but does not grant individuals control over their biometric information.
Sources and References
This article references Ohio statutes and official state government publications. For the full text of Ohio's breach notification law, visit ORC Section 1349.19 on the Ohio Legislature's website. For the Ohio Data Protection Act, see ORC Chapter 1354. For the Insurance Data Security Act, see ORC Chapter 3965. For information about Ohio's cybersecurity safe harbor, review the Senate Bill 220 summary from the Ohio Legislature.
This article provides general legal information about Ohio biometric privacy laws and data protection. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Ohio government sources.
More Ohio Laws
Frequently Asked Questions
Does Ohio have a biometric privacy law?
No. Ohio has no dedicated biometric privacy statute and no comprehensive consumer privacy law that covers biometric data. The only Ohio law that treats biometric records as protected data within a general data-security scheme is the Insurance Data Security Act (ORC Chapter 3965), which applies exclusively to insurance licensees. One narrow separate statute, ORC 3301.947, bars collecting students' biometric information during state achievement testing. Private businesses in Ohio can generally collect, use, and store biometric data like fingerprints and facial scans without specific state-level consent or notice requirements.
Does Ohio's breach notification law cover biometric data?
No. Ohio's breach notification law (ORC Section 1349.19) defines personal information to include Social Security numbers, driver's license numbers, and financial account numbers, but it does not include biometric identifiers. A data breach that exposes only biometric data, such as fingerprint templates or facial recognition records, does not trigger notification obligations under this law.
What is the Ohio Data Protection Act safe harbor?
The Ohio Data Protection Act (ORC Chapter 1354), enacted through Senate Bill 220 in 2018, gives businesses an affirmative defense in tort lawsuits if they maintain a written cybersecurity program that conforms to a recognized industry framework such as NIST, ISO 27000, or CIS Critical Security Controls. This defense can apply to lawsuits arising from breaches involving biometric data, but it does not create any consumer rights or require consent for data collection.
Can my employer collect my fingerprints in Ohio without my consent?
Under Ohio state law, yes. Ohio does not have a law requiring employers to obtain consent before collecting biometric data for workplace purposes like timekeeping or building access. However, employers with operations in states that do regulate biometric data, such as Illinois or Texas, must comply with those states' laws for employees located there. Federal laws like HIPAA may also apply in specific healthcare or medical contexts.
Is Ohio considering passing a biometric privacy law?
Through the most recent bill-tracking check, no comprehensive consumer data privacy bill or standalone biometric privacy bill has been introduced in Ohio's current 136th General Assembly (2025-2026). Previous attempts, including the Ohio Personal Privacy Act (HB 376 in 2021-2022 and HB 345 in 2023-2024), both failed to advance. Ohio remains one of a shrinking number of states without comprehensive privacy legislation that would cover biometric data.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Insurance Data Security Act section: the three-business-day breach report to the Superintendent applies only when ORC 3965.04's domicile or 250-consumer criteria are met, the "inherence factors, such as a biometric characteristic" language is re-attributed to ORC 3965.01(N)(3) rather than 3965.02, and the page now covers ORC 3301.947, which bars collecting students' biometric information during state achievement testing.
Corrected the age-verification section: current Ohio law authorizes photo identification or transactional data only, and visual age verification software remains a pending proposal in HB 84.
Independently fact-checked against the cited primary sources
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Ohio Revised Code
§ 3965.02Information security programIn force
(A) Each licensee shall develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
§ 1349.19Private disclosure of security breach of computerized personal information dataIn forcecited in 5 of our articles
(A) As used in this section: (1)(a) "Breach of the security of the system" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information owned or licensed by a person and that causes, reasonably is believed to have caused,…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts treat section 1349.19 as a breach-disclosure duty, not a consumer remedy. In Young v. City of Logan (2025) a magistrate judge recommended dismissing a claim under it, noting only the attorney general may sue for noncompliance; Mulkey v. RoundPoint Mortgage Servicing Corporation (2021) cited its definition of personal information.
Opinions citing this section in our collection:
- Jessica v. Ohio Dept. of Job & Family Servs. (Ohio Court of Appeals 2025, 2025 Ohio 2604)“…JFS’s offer of one year of free credit monitoring. See also R.C. 1349.19(B)(1) (requiring any “person that owns…”
- Losch & Assocs., Inc. v. Polonczyk (Ohio Court of Appeals 2016, 2016 Ohio 4950)✓An insurance agent claimed he was fired for reporting agency misconduct and invoked the public policy in Ohio's data-breach notification statute; the appeals court did not decide whether that policy supports a wrongful-discharge claim, holding he had resigned instead.
- Young v. City of Logan (District Court, S.D. Ohio 2025)✓A pro se plaintiff said police took his checks during a trespass call and gave them to another man, suing under the breach-notification statute; on initial screening the magistrate found it inapplicable, noting only the attorney general may sue, and recommended dismissal.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Ohio Data Privacy Laws: Safe Harbor & Consumer Rights (2026), Ohio Employee Monitoring Laws: Workplace Surveillance and GPS Tracking (2026), Ohio Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 1354.01DefinitionsIn forcecited in 4 of our articles
As used in this chapter: (A) "Business" means any limited liability company, limited liability partnership, corporation, sole proprietorship, association, state institution of higher education as defined in section 3345.011 of the Revised Code, private college as defined in section 3365.01 of the…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Waseleski v. City of Brooklyn (District Court, N.D. Ohio 2025)“…formation. Ohio Data Protection Act (SB 220), codified at Ohio Rev. Code §§ 1354.01–1354.05. First, the factual pleadings…”
- Mulkey v. RoundPoint Mortgage Servicing Corporation (District Court, N.D. Ohio 2021)“…ate certain protections for stored data, specifically PII. Ohio Rev. Code Ann. § 1354.01 (West). Therefore, the fact that a stat…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 1354.02Safe harbor requirementsIn forcecited in 3 of our articles
(A) A covered entity seeking an affirmative defense under sections 1354.01 to 1354.05 of the Revised Code shall do one of the following: (1) Create, maintain, and comply with a written cybersecurity program that contains administrative, technical, and physical safeguards for the protection of…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Gales v. Ohio Lottery Comm. (Ohio Court of Claims 2025, 2025 Ohio 5189)“…hese cybersecurity decisions can be otherwise inferred from R.C. 1354.02(D)(1) providing “an affirmative defense…”
- Giddings v. CBIZ Benefits & Insurance Services, Inc. (District Court, N.D. Ohio 2025)“…ata security industry protocols as set forth in the Act. O.R.C. §1354.02. However, they explicitly refrained fr…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 1354.03Reasonable conformanceIn forcecited in 2 of our articles
A covered entity's cybersecurity program, as described in section 1354.02 of the Revised Code, reasonably conforms to an industry recognized cybersecurity framework for purposes of that section if division (A), (B), or (C) of this section is satisfied.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Ohio breach notification statute(codes.ohio.gov).gov
- Ohio Data Protection Act (Chapter 1354)(codes.ohio.gov).gov
- Ohio Data Protection Act safe harbor requirements(codes.ohio.gov).gov
- Ohio Data Protection Act recognized frameworks(codes.ohio.gov).gov
- Ohio Data Protection Act definitions(codes.ohio.gov).gov
- Ohio Insurance Data Security Act(codes.ohio.gov).gov
- Senate Bill 220 - Ohio Data Protection Act(legislature.ohio.gov).gov
- Ohio HB 96 age verification law(legislature.ohio.gov).gov
- Ohio HB 345 Personal Privacy Act (135th GA)(legislature.ohio.gov).gov
- Ohio Attorney General(ohioattorneygeneral.gov).gov
- ORC 3301.947 - Privacy of data during testing (bars collecting students' biometric information)(codes.ohio.gov)
- ORC 3965.01 - Insurance Data Security Act definitions (multifactor authentication; nonpublic information includes biometric records)(codes.ohio.gov)
- ORC 3965.02 - Insurance Data Security Act information security program(codes.ohio.gov)
- ORC 3965.04 - Notification to superintendent (three-business-day criteria)(codes.ohio.gov)
- ORC 3701.75 - Authenticating health care records (biometric access control device)(codes.ohio.gov)