EnglishEspañol
Ohio flag

Ohio

Ohio Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 8, 2026. · 10 primary sources cited on this page. How we verify our legal content

Ohio Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Ohio have a biometric privacy law?

No. Ohio has no dedicated biometric privacy statute and no comprehensive consumer privacy law that covers biometric data. The only Ohio law that treats biometric records as protected data within a general data-security scheme is the Insurance Data Security Act (ORC Chapter 3965), which applies exclusively to insurance licensees. One narrow separate statute, ORC 3301.947, bars collecting students' biometric information during state achievement testing. Private businesses in Ohio can generally collect, use, and store biometric data like fingerprints and facial scans without specific state-level consent or notice requirements.

Does Ohio's breach notification law cover biometric data?

No. Ohio's breach notification law (ORC Section 1349.19) defines personal information to include Social Security numbers, driver's license numbers, and financial account numbers, but it does not include biometric identifiers. A data breach that exposes only biometric data, such as fingerprint templates or facial recognition records, does not trigger notification obligations under this law.

What is the Ohio Data Protection Act safe harbor?

The Ohio Data Protection Act (ORC Chapter 1354), enacted through Senate Bill 220 in 2018, gives businesses an affirmative defense in tort lawsuits if they maintain a written cybersecurity program that conforms to a recognized industry framework such as NIST, ISO 27000, or CIS Critical Security Controls. This defense can apply to lawsuits arising from breaches involving biometric data, but it does not create any consumer rights or require consent for data collection.

Can my employer collect my fingerprints in Ohio without my consent?

Under Ohio state law, yes. Ohio does not have a law requiring employers to obtain consent before collecting biometric data for workplace purposes like timekeeping or building access. However, employers with operations in states that do regulate biometric data, such as Illinois or Texas, must comply with those states' laws for employees located there. Federal laws like HIPAA may also apply in specific healthcare or medical contexts.

Is Ohio considering passing a biometric privacy law?

Through the most recent bill-tracking check, no comprehensive consumer data privacy bill or standalone biometric privacy bill has been introduced in Ohio's current 136th General Assembly (2025-2026). Previous attempts, including the Ohio Personal Privacy Act (HB 376 in 2021-2022 and HB 345 in 2023-2024), both failed to advance. Ohio remains one of a shrinking number of states without comprehensive privacy legislation that would cover biometric data.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the Insurance Data Security Act section: the three-business-day breach report to the Superintendent applies only when ORC 3965.04's domicile or 250-consumer criteria are met, the "inherence factors, such as a biometric characteristic" language is re-attributed to ORC 3965.01(N)(3) rather than 3965.02, and the page now covers ORC 3301.947, which bars collecting students' biometric information during state achievement testing.

Corrected the age-verification section: current Ohio law authorizes photo identification or transactional data only, and visual age verification software remains a pending proposal in HB 84.

Independently fact-checked against the cited primary sources

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Ohio breach notification statute(codes.ohio.gov).gov
  2. Ohio Data Protection Act (Chapter 1354)(codes.ohio.gov).gov
  3. Ohio Data Protection Act safe harbor requirements(codes.ohio.gov).gov
  4. Ohio Data Protection Act recognized frameworks(codes.ohio.gov).gov
  5. Ohio Data Protection Act definitions(codes.ohio.gov).gov
  6. Ohio Insurance Data Security Act(codes.ohio.gov).gov
  7. Senate Bill 220 - Ohio Data Protection Act(legislature.ohio.gov).gov
  8. Ohio HB 96 age verification law(legislature.ohio.gov).gov
  9. Ohio HB 345 Personal Privacy Act (135th GA)(legislature.ohio.gov).gov
  10. Ohio Attorney General(ohioattorneygeneral.gov).gov
  11. ORC 3301.947 - Privacy of data during testing (bars collecting students' biometric information)(codes.ohio.gov)
  12. ORC 3965.01 - Insurance Data Security Act definitions (multifactor authentication; nonpublic information includes biometric records)(codes.ohio.gov)
  13. ORC 3965.02 - Insurance Data Security Act information security program(codes.ohio.gov)
  14. ORC 3965.04 - Notification to superintendent (three-business-day criteria)(codes.ohio.gov)
  15. ORC 3701.75 - Authenticating health care records (biometric access control device)(codes.ohio.gov)
Share: