Law / United States / Ohio

Ohio Data Protection Act, cybersecurity program safe harbor

Ohio Rev. Code sections 1354.01 to 1354.05 (enacted by Senate Bill 220, 132nd General Assembly, effective November 2, 2018; section 1354.01 last amended by House Bill 66, 132nd General Assembly, effective April 5, 2019)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 2 November 2018.

A security baseline statutes rule binding private bodies.

As of 17 September 2026.

What it requires

  • This is an optional safe harbor, not a mandatory duty: no Ohio law requires a business to create a cybersecurity program, and this chapter reaches only a covered entity, any business that accesses, maintains, communicates, or processes personal information (as defined by Ohio Revised Code 1349.19) or restricted information in or through a system, network, or service located inside or outside Ohio, that chooses to seek the affirmative defense described below.
  • To seek that defense, create, maintain, and comply with a written cybersecurity program with administrative, technical, and physical safeguards, covering personal information alone or personal information together with restricted information, and scale the program to the covered entity's size and complexity, the nature and scope of its activities, the sensitivity of the information protected, the cost and availability of security tools, and the resources available to it.
  • Make the program reasonably conform to the current version of the NIST Cybersecurity Framework, NIST Special Publication 800-171, NIST Special Publications 800-53 and 800-53A, the FedRAMP security assessment framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family, alone or in combination, or, if already regulated under it, reasonably conform to the entirety of the Health Insurance Portability and Accountability Act (HIPAA) security rule, Gramm-Leach-Bliley Act Title V, the Federal Information Security Modernization Act, or HITECH, or comply with the PCI Data Security Standard together with one of the first group's frameworks.
  • Adopt a revised or amended version of the chosen framework or standard no later than one year after its publication date, to keep the program's reasonable conformance current.
  • A covered entity that does this earns an affirmative defense to a tort claim under Ohio law alleging that its failure to implement reasonable information security controls caused a data breach concerning the information its program covers; the chapter creates no cause of action of its own, and nothing in it may be read to create a private right of action, including a class action.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

No state regulator administers or enforces sections 1354.01 to 1354.05; the chapter creates no duty to build a program and no cause of action to compel one, since section 1354.04 bars any private right of action, including a class action, with respect to any act or practice it regulates. A covered entity's only exposure is defending a tort claim brought under other law, where it may raise the chapter's affirmative defense for itself.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Ohio Data Protection Act, sections 1354.01 to 1354.05 of the Ohio Revised Code, extends an affirmative defense to any cause of action sounding in tort that is brought under the laws of this state or in the courts of this state and that alleges that the failure to implement reasonable information security controls resulted in a data breach concerning personal information, to a covered entity that creates, maintains, and complies with a written cybersecurity program that reasonably conforms to an industry recognized cybersecurity framework.

A covered entity is a business that accesses, maintains, communicates, or processes personal information or restricted information in or through one or more systems, networks, or services located in or outside this state, and the defense reaches personal information and restricted information together where the covered entity's program covers both.

The scale and scope of that program is appropriate if it is based on the size and complexity of the covered entity, the nature and scope of its activities, the sensitivity of the information to be protected, the cost and availability of tools to improve information security and reduce vulnerabilities, and the resources available to the covered entity.

Reasonable conformance is satisfied by the current version of the framework for improving critical infrastructure cybersecurity developed by NIST, NIST special publication 800-171, NIST special publications 800-53 and 800-53a, the FedRAMP security assessment framework, the CIS critical security controls, or the ISO/IEC 27000 family, alone or in combination.

Alternatively, reasonable conformance is satisfied by reasonably conforming to the entirety of the current version of the Health Insurance Portability and Accountability Act (HIPAA) security rule, Gramm-Leach-Bliley Act Title V, the Federal Information Security Modernization Act of 2014, or the Health Information Technology for Economic and Clinical Health Act for a covered entity already regulated under one of them, or by complying with the PCI data security standard together with one of the first group's frameworks.

A covered entity must reasonably conform to a revised or amended framework not later than one year after its publication. This is an optional safe harbor and not a duty: sections 1354.01 to 1354.05 shall not be construed to provide a private right of action, including a class action, with respect to any act or practice regulated under those sections, so no covered entity can be sued for lacking a program and no state regulator administers this chapter.

An insurer or other licensee that meets Ohio's separate insurance-sector cybersecurity law, Ohio Revised Code Chapter 3965, is deemed by that chapter's own section 3965.02(J) to have a program that reasonably conforms to an industry recognized cybersecurity framework for purposes of this safe harbor.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Ohio Revised Code Chapter 1354, Ohio Laws (Legislative Service Commission)

Back to the example  ·  Lint your app