Ohio
Ohio Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

Ohio law requires businesses to notify affected residents of a data breach within 45 days of discovery under Ohio Rev. Code 1349.19. Businesses that maintain a qualifying written cybersecurity program may claim an affirmative defense against tort claims under the Ohio Data Protection Act.
If your business handles personal information belonging to Ohio residents, a data breach triggers specific legal obligations. Ohio Rev. Code 1349.19 sets out who must be notified, what information triggers the duty, and how quickly you need to act. Ohio stands out among state breach notification laws for two reasons: it imposes escalating daily penalties for noncompliance, and it offers a separate cybersecurity safe harbor under the Ohio Data Protection Act (ORC Chapter 1354) that can shield businesses from tort liability if they maintain recognized cybersecurity programs.
This guide covers the full scope of Ohio's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, enforcement penalties, the cybersecurity safe harbor, and how the law connects to the state's broader data privacy framework.
Who Must Comply With Ohio's Breach Notification Law
Ohio's breach notification law applies to any person that owns or licenses computerized data that includes personal information of Ohio residents. The term "person" includes individuals, corporations, business trusts, estates, trusts, partnerships, and associations.
The law also covers entities that do not own or license the data but maintain it on behalf of another person. If a data maintainer discovers a breach, it must notify the data owner or licensee of the breach. The data owner then carries the obligation to notify affected consumers.
Scope does not depend on where a business is located, but it is not unlimited either. ORC 1349.19(A)(6) gives "person" the same meaning as in Ohio Rev. Code 1.59, "except that 'person' includes a business entity only if the business entity conducts business in this state." An out-of-state business that conducts business in Ohio is covered. Merely holding data about an Ohio resident, without conducting business in the state, is not the trigger.
For purposes of the statute, a resident is an individual whose principal mailing address as reflected in the business's records is in Ohio.
What Qualifies as a Breach of Security
Under ORC 1349.19, a breach of the security of the system means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information and that causes, is reasonably believed to have caused, or is reasonably believed will cause a material risk of identity theft or other fraud to the person or property of a resident.
The "material risk" threshold is significant. Not every unauthorized access triggers notification. The business must evaluate whether the breach creates a real risk of identity theft or fraud.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the entity for the purposes of the entity's business does not constitute a breach, provided the personal information is not used for an unlawful purpose and is not subject to further unauthorized disclosure.
The Encryption and Redaction Safe Harbor
Ohio provides a clear safe harbor for encrypted or redacted data. Personal information that has been encrypted, redacted, or altered by any method or technology that renders the data elements unreadable does not trigger the notification requirement. 
"Redacted" means altered or truncated so that no more than the last four digits of a Social Security number, driver's license number, state ID number, account number, or credit/debit card number is accessible.
What Personal Information Triggers the Law
Under ORC 1349.19(A)(7), personal information means an individual's first name or first initial and last name in combination with and linked to any one or more of the following data elements, when the data elements are not encrypted, redacted, or made unreadable:
- Social Security number
- Driver's license number or state identification card number
- Account number or credit or debit card number, in combination with and linked to any required security code, access code, or password that would permit access to an individual's financial account
Ohio's definition of personal information is narrower than many states. It does not include biometric data, medical information, health insurance numbers, or passport numbers.
Notification Timeline
Ohio requires notification within 45 days of the discovery or notification of a breach. The 45-day clock starts when the business becomes aware of the breach, not when it completes its investigation.
Delays are permitted only when:
- A law enforcement agency determines that the disclosure will impede a criminal investigation or jeopardize national security (the business must provide disclosure without unreasonable delay after the law enforcement agency indicates it will no longer be impeded)
- The delay is necessary to determine the scope of the breach, identify affected individuals, or restore the reasonable integrity of the system (but these activities must not extend beyond the 45-day period)
Who Must Be Notified
Affected Individuals
Every Ohio resident whose personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person must receive notification, if the breach causes, is reasonably believed to have caused, or is reasonably believed will cause a material risk of identity theft or other fraud.
ORC 1349.19 does not prescribe what the notice to consumers must say. Unlike many state breach statutes, it sets out the permitted delivery methods in division (E) and leaves the wording and content of the consumer notice to the business. There is no statutory checklist of required elements.
The one content-related requirement in the statute runs to consumer reporting agencies rather than to consumers: division (G) requires the notification to nationwide consumer reporting agencies to convey the timing, distribution, and content of the disclosure given to Ohio residents.
In practice, businesses commonly describe the incident, identify the categories of personal information involved, give a way to contact the company, and point recipients toward monitoring their accounts. Those are drafting conventions, and often the requirements of other states' statutes, since one breach usually triggers several states' laws at once. They are not obligations imposed by ORC 1349.19.
Consumer Reporting Agencies
When a breach affects more than 1,000 Ohio residents in a single occurrence, the business must notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. This notification must include the timing, distribution, and content of the consumer notice.
Attorney General
The Ohio Attorney General has authority to investigate suspected noncompliance under ORC 1349.191. While the statute does not require proactive AG notification for every breach, the AG can initiate investigations and demand information.
Methods of Notification
Businesses can provide notification through:
- Written notice sent to the individual's last known address
- Electronic notice, if the business's primary method of communication with the resident is by electronic means
- Telephone notice directly to the affected individual
Substitute Notice
Ohio Rev. Code 1349.19(E) sets out two separate substitute notice paths, and the required format depends on which one applies.
Large-class or high-cost breaches. Substitute notice is available if the business demonstrates that:
- The cost of providing notice would exceed $250,000, or
- The affected class exceeds 500,000 Ohio residents, or
- The business does not have sufficient contact information
For this path, substitute notice must include: email notice to affected residents where an email address is on file, conspicuous posting on the business's website, and notification to major media outlets whose combined audience reach equals or exceeds 75 percent of Ohio's population. A newspaper advertisement is not required here.
Small businesses. A business entity with 10 or fewer employees may use substitute notice if the cost of providing notice would exceed $10,000. This path requires a paid advertisement in a local newspaper covering at least one-quarter page, published once a week for three consecutive weeks, plus conspicuous posting on the business's website and notification to major media outlets in the entity's geographic area.
Ohio's substitute notice rules are unusual in tying the required format, including whether a newspaper ad applies at all, to which of these two triggers the business meets.
Enforcement and Penalties
Escalating Daily Penalties
Ohio employs an escalating penalty structure under ORC 1349.192 for intentional or reckless noncompliance:
- Up to $1,000 per day for the first 60 days of noncompliance
- Up to $5,000 per day from days 61 through 90
- Up to $10,000 per day from day 91 onward
Each figure is a ceiling, not a fixed daily charge. ORC 1349.192(A)(1) directs the court to impose a civil penalty of up to the stated amount, and division (A)(3) requires it to consider all relevant factors, including whether the officer or employee responsible for compliance acted in bad faith.

This means a business that intentionally delays notification for 120 days faces civil penalties of up to $510,000: up to $60,000 for the first 60 days, up to $150,000 for days 61 through 90, and up to $300,000 for days 91 through 120.
Attorney General Enforcement
Under ORC 1349.191, the Attorney General may investigate suspected noncompliance and bring civil actions. The AG can also seek injunctive relief to prevent ongoing violations.
No Private Right of Action
Ohio's breach notification law does not create a private right of action. Individuals cannot sue businesses directly under ORC 1349.19 for breach notification failures. Enforcement is limited to the Attorney General.

The Ohio Data Protection Act Safe Harbor
Separate from the breach notification statute, the Ohio Data Protection Act (ORC Chapter 1354), enacted in 2018 through Senate Bill 220, provides an affirmative defense against tort claims arising from data breaches.
How the Safe Harbor Works
Under ORC 1354.02, a business that creates, maintains, and complies with a written cybersecurity program that reasonably conforms to a recognized cybersecurity framework is entitled to an affirmative defense against any cause of action sounding in tort that alleges the failure to implement reasonable security controls resulted in a data breach.
Recognized Cybersecurity Frameworks
ORC 1354.03 sets out three separate routes to "reasonable conformance." They are not interchangeable, and only the first works as a standalone list.
Route one: a framework listed in division (A). Any of these qualifies on its own, or in combination with others:
- NIST Framework for Improving Critical Infrastructure Cybersecurity
- NIST Special Publication 800-171
- NIST Special Publications 800-53 and 800-53a
- FedRAMP Security Assessment Framework
- CIS Critical Security Controls for Effective Cyber Defense
- ISO/IEC 27000 family of standards
Route two: a regulatory regime under division (B). This route is open only to a business that is regulated by the state, the federal government, or both, or is otherwise subject to the law in question. That business's program must conform to the entirety of the current version of one of:
- HIPAA security requirements, 45 CFR Part 164 Subpart C
- Title V of the Gramm-Leach-Bliley Act
- The Federal Information Security Modernization Act of 2014 (FISMA)
- The HITECH Act, 45 CFR Part 162
A business that is not regulated by or subject to one of those laws cannot reach the safe harbor by voluntarily adopting its security requirements.
Route three: PCI-DSS combined with a division (A) framework. Under ORC 1354.03(C)(1), a program qualifies if it reasonably complies with both the current version of the payment card industry (PCI) data security standard and conforms to the current version of another applicable framework listed in division (A). PCI-DSS on its own never earns the affirmative defense, no matter how thoroughly a business complies with it.
Limitations of the Safe Harbor
The safe harbor is an affirmative defense only. It does not provide blanket immunity. The business must raise the defense in court and demonstrate that it maintained reasonable conformance with its chosen framework. The defense also does not protect against regulatory enforcement actions under ORC 1349.191 or claims under other statutes.
When a cybersecurity framework is updated, the business has one year to conform to the new version before the safe harbor applies to the updated standard.
Exemptions
Federal Compliance Exemptions
A person may instead follow a preexisting contractual notification provision entered into with another person before the breach occurred, in lieu of the statute's own disclosure procedure, provided the contract does not conflict with or waive any provision of Ohio's breach notification statute.
The statute also contains two federal carve-outs, and they work differently from one another.
Under ORC 1349.19(F)(2), the section "does not apply to any person or entity that is a covered entity as defined in 45 C.F.R. 160.103, as amended." That exclusion turns on status alone. A HIPAA covered entity sits outside ORC 1349.19 whether or not it complies with the federal breach notification rule, though that federal rule continues to apply to it on its own terms.
Under ORC 1349.19(F)(1), the exemption for a financial institution, trust company, or credit union, or an affiliate of one, is conditional. It applies only where the institution is required by federal law to notify its customers of an information security breach and is subject to examination by its functional government regulatory agency for compliance with that federal law.
This article provides general legal information about Ohio data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Ohio for guidance specific to your situation.
More Ohio Laws
Frequently Asked Questions
How quickly must a business notify Ohio residents of a data breach?
Ohio requires notification within 45 days of discovering a breach under ORC 1349.19. Delays are permitted only for law enforcement purposes, and the 45-day deadline applies even during the investigation period.
What penalties does Ohio impose for failing to provide breach notification?
Ohio uses escalating daily penalty ceilings: a court may impose up to $1,000 per day for the first 60 days of noncompliance, up to $5,000 per day from days 61 through 90, and up to $10,000 per day beyond 90 days. Each amount is a maximum the court sets after weighing factors such as bad faith, and the penalties apply only to intentional or reckless failures to comply.
What is the Ohio Data Protection Act cybersecurity safe harbor?
Under ORC Chapter 1354, businesses that maintain a written cybersecurity program conforming to a recognized framework (such as the NIST frameworks, CIS Controls, or ISO 27000) get an affirmative defense against tort claims alleging the business failed to implement reasonable security controls. PCI-DSS counts only when it is paired with one of those frameworks, never on its own. The defense does not protect against regulatory penalties.
Does Ohio's breach notification law cover biometric data?
No. Ohio's breach notification law (ORC 1349.19) has a narrow definition of personal information limited to SSNs, driver's license numbers, state ID numbers, and financial account numbers with security codes. Biometric data, medical records, and health insurance information are not covered.
Can individuals sue a business in Ohio for failing to provide breach notification?
No. Ohio's breach notification law does not create a private right of action. Only the Attorney General can bring enforcement actions. However, individuals may bring tort claims related to the breach itself, which is where the ORC 1354 cybersecurity safe harbor becomes relevant.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Ohio breach notification guidance: removed a list of notice contents that ORC 1349.19 does not actually require, clarified that the law reaches out-of-state businesses only if they conduct business in Ohio, separated the unconditional HIPAA exemption from the conditional financial-institution exemption, explained that PCI-DSS qualifies for the Data Protection Act safe harbor only alongside another recognized framework, and restated the daily penalties as court-set maximums for intentional or reckless noncompliance.
Corrected the substitute-notice section to describe Ohio's two distinct legal paths (large/high-cost breaches vs. small businesses) instead of blending them, fixed a penalty-total arithmetic error (up to $510,000, not over $600,000, for a 120-day delay), corrected the electronic-notice standard, restored the full three-way breach-harm test in two places, and added the HITECH Act to the recognized cybersecurity frameworks list.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the consumer-reporting-agency notification trigger to 'more than 1,000 residents' (the statute's actual threshold) and replaced the invented 'internal privacy policy' safe harbor with the statute's actual narrower mechanism: a preexisting notification contract between two persons.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Ohio Revised Code
§ 1349.19Private disclosure of security breach of computerized personal information dataIn forcecited in 5 of our articles
(A) As used in this section: (1)(a) "Breach of the security of the system" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information owned or licensed by a person and that causes, reasonably is believed to have caused,…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts treat section 1349.19 as a breach-disclosure duty, not a consumer remedy. In Young v. City of Logan (2025) a magistrate judge recommended dismissing a claim under it, noting only the attorney general may sue for noncompliance; Mulkey v. RoundPoint Mortgage Servicing Corporation (2021) cited its definition of personal information.
Opinions citing this section in our collection:
- Jessica v. Ohio Dept. of Job & Family Servs. (Ohio Court of Appeals 2025, 2025 Ohio 2604)“…JFS’s offer of one year of free credit monitoring. See also R.C. 1349.19(B)(1) (requiring any “person that owns…”
- Losch & Assocs., Inc. v. Polonczyk (Ohio Court of Appeals 2016, 2016 Ohio 4950)✓An insurance agent claimed he was fired for reporting agency misconduct and invoked the public policy in Ohio's data-breach notification statute; the appeals court did not decide whether that policy supports a wrongful-discharge claim, holding he had resigned instead.
- Young v. City of Logan (District Court, S.D. Ohio 2025)✓A pro se plaintiff said police took his checks during a trespass call and gave them to another man, suing under the breach-notification statute; on initial screening the magistrate found it inapplicable, noting only the attorney general may sue, and recommended dismissal.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Ohio Data Privacy Laws: Safe Harbor & Consumer Rights (2026), Ohio Employee Monitoring Laws: Workplace Surveillance and GPS Tracking (2026), Ohio Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 1349.192Civil action by attorney general for violation of disclosure lawsIn forcecited in 2 of our articles
(A)(1) The attorney general shall have the exclusive authority to bring a civil action in a court of common pleas for appropriate relief under this section, including a temporary restraining order, preliminary or permanent injunction, and civil penalties, if it appears that a state agency or an…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
§ 1349.191Investigation of noncompliance with disclosure lawsIn forcecited in 2 of our articles
(A) As used in this section and section 1349.192 of the Revised Code: (1) "Agency of a political subdivision" has the same meaning as in section 1347.12 of the Revised Code. (2) "Business" has the same meaning as in section 1349.19 of the Revised Code.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- NetChoice, LLC v. David Yost (Court of Appeals for the Sixth Circuit 2026)“…Operator if he “has reason to believe” it is noncompliant. Ohio Rev. Code § 1349.191(B). He then may bring a civil action “[…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 1354.02Safe harbor requirementsIn forcecited in 3 of our articles
(A) A covered entity seeking an affirmative defense under sections 1354.01 to 1354.05 of the Revised Code shall do one of the following: (1) Create, maintain, and comply with a written cybersecurity program that contains administrative, technical, and physical safeguards for the protection of…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at codes.ohio.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Gales v. Ohio Lottery Comm. (Ohio Court of Claims 2025, 2025 Ohio 5189)“…hese cybersecurity decisions can be otherwise inferred from R.C. 1354.02(D)(1) providing “an affirmative defense…”
- Giddings v. CBIZ Benefits & Insurance Services, Inc. (District Court, N.D. Ohio 2025)“…ata security industry protocols as set forth in the Act. O.R.C. §1354.02. However, they explicitly refrained fr…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Explore the law
This article also draws on these acts and chapters (opening at their first section): Ohio Revised Code § 1354.01 (Definitions)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Ohio Rev. Code 1349.19 - Security Breach Notification(codes.ohio.gov).gov
- Ohio Rev. Code 1349.191 - Investigation of Noncompliance(codes.ohio.gov).gov
- Ohio Rev. Code 1349.192 - Civil Penalties(codes.ohio.gov).gov
- Ohio Rev. Code Chapter 1354 - Data Protection Act(codes.ohio.gov).gov
- Ohio Rev. Code 1354.02 - Safe Harbor Requirements(codes.ohio.gov).gov
- Ohio AG - Personal Information for Consumers(ohioattorneygeneral.gov).gov
- Ohio Rev. Code 1354.03 - Reasonable Conformance to a Cybersecurity Framework(codes.ohio.gov)