EnglishEspañol
Ohio flag

Ohio

Ohio Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

Ohio Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Ohio residents of a data breach?

Ohio requires notification within 45 days of discovering a breach under ORC 1349.19. Delays are permitted only for law enforcement purposes, and the 45-day deadline applies even during the investigation period.

What penalties does Ohio impose for failing to provide breach notification?

Ohio uses escalating daily penalty ceilings: a court may impose up to $1,000 per day for the first 60 days of noncompliance, up to $5,000 per day from days 61 through 90, and up to $10,000 per day beyond 90 days. Each amount is a maximum the court sets after weighing factors such as bad faith, and the penalties apply only to intentional or reckless failures to comply.

What is the Ohio Data Protection Act cybersecurity safe harbor?

Under ORC Chapter 1354, businesses that maintain a written cybersecurity program conforming to a recognized framework (such as the NIST frameworks, CIS Controls, or ISO 27000) get an affirmative defense against tort claims alleging the business failed to implement reasonable security controls. PCI-DSS counts only when it is paired with one of those frameworks, never on its own. The defense does not protect against regulatory penalties.

Does Ohio's breach notification law cover biometric data?

No. Ohio's breach notification law (ORC 1349.19) has a narrow definition of personal information limited to SSNs, driver's license numbers, state ID numbers, and financial account numbers with security codes. Biometric data, medical records, and health insurance information are not covered.

Can individuals sue a business in Ohio for failing to provide breach notification?

No. Ohio's breach notification law does not create a private right of action. Only the Attorney General can bring enforcement actions. However, individuals may bring tort claims related to the breach itself, which is where the ORC 1354 cybersecurity safe harbor becomes relevant.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the Ohio breach notification guidance: removed a list of notice contents that ORC 1349.19 does not actually require, clarified that the law reaches out-of-state businesses only if they conduct business in Ohio, separated the unconditional HIPAA exemption from the conditional financial-institution exemption, explained that PCI-DSS qualifies for the Data Protection Act safe harbor only alongside another recognized framework, and restated the daily penalties as court-set maximums for intentional or reckless noncompliance.

Corrected the substitute-notice section to describe Ohio's two distinct legal paths (large/high-cost breaches vs. small businesses) instead of blending them, fixed a penalty-total arithmetic error (up to $510,000, not over $600,000, for a 120-day delay), corrected the electronic-notice standard, restored the full three-way breach-harm test in two places, and added the HITECH Act to the recognized cybersecurity frameworks list.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the consumer-reporting-agency notification trigger to 'more than 1,000 residents' (the statute's actual threshold) and replaced the invented 'internal privacy policy' safe harbor with the statute's actual narrower mechanism: a preexisting notification contract between two persons.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Ohio Rev. Code 1349.19 - Security Breach Notification(codes.ohio.gov).gov
  2. Ohio Rev. Code 1349.191 - Investigation of Noncompliance(codes.ohio.gov).gov
  3. Ohio Rev. Code 1349.192 - Civil Penalties(codes.ohio.gov).gov
  4. Ohio Rev. Code Chapter 1354 - Data Protection Act(codes.ohio.gov).gov
  5. Ohio Rev. Code 1354.02 - Safe Harbor Requirements(codes.ohio.gov).gov
  6. Ohio AG - Personal Information for Consumers(ohioattorneygeneral.gov).gov
  7. Ohio Rev. Code 1354.03 - Reasonable Conformance to a Cybersecurity Framework(codes.ohio.gov)
Share: