Law note · Ohio
Security Breach Notification Act
Any person that owns or licenses computerized data including personal information must disclose a breach of the security of the system to an affected Ohio resident, in the most expedient time possible and no later than 45 days following discovery, subject to a law-enforcement delay.
Personal information is a name combined with a Social Security number, a driver's license or state identification card number, or a financial account, credit, or debit card number with an access code, and excludes information lawfully available to the general public from government records or widely distributed media; it carries no biometric, genetic, or student-data element.
Person has the meaning given in Ohio Rev. Code Sec. 1.59, an individual, corporation, business trust, estate, trust, partnership, or association with no government or governmental subdivision named, except that a business entity counts as a person only if it conducts business in Ohio, so this duty binds private actors, not the state or its political subdivisions.
A financial institution already subject to federal breach-notice requirements and a HIPAA covered entity are each exempt from this section. Once a single breach affects more than 1,000 Ohio residents, the person must also notify every nationwide consumer reporting agency without unreasonable delay.
The Attorney General has exclusive authority under Ohio Rev. Code Sec. 1349.192 to investigate and bring a civil action for a violation, with a civil penalty of up to $1,000 per day rising to $5,000 per day after 60 days and $10,000 per day after 90 days of an intentional or reckless violation, and the statute creates no private right of action.
Most recently amended by Senate Bill 126 (126th General Assembly), effective March 30, 2007; secondary reporting describes the original enactment as House Bill 104 (126th General Assembly), signed 2005, not independently confirmed against primary text this pass.
What it asks of an app
- Notify an affected Ohio resident of a security breach involving their personal information in the most expedient time possible and no later than 45 days after discovery.
- Notify every nationwide consumer reporting agency without unreasonable delay if a single breach affects more than 1,000 Ohio residents.
- Do not rely on this statute to cover a breach of biometric, genetic, or student data alone. Ohio's personal information definition carries no such element.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Ohio statute text, Ohio Revised Code section 1349.19, codes.ohio.gov