Law / Ohio

Ohio

age

Ohio has enacted laws in two families.

The Parental Notification by Social Media Operators Act (2023) requires parental consent for minors under 16 to hold social media accounts; it was permanently enjoined by a federal district court in April 2025, but the Sixth Circuit reversed that ruling on June 18, 2026 and instructed the lower court to enter judgment for the state, so the law is poised to become enforceable once the appellate mandate issues (NetChoice had until July 16, 2026 to seek rehearing).

A separate adult content age verification law took effect September 30, 2025, though the Attorney General's office has found most major pornography sites are not complying, citing an interactive-computer-service exemption lawmakers are now working to close.

privacy

Ohio has no comprehensive consumer personal-data-protection statute; two 2026-session bills, House Bill 801 (the Ohio Privacy Act) and House Bill 807, remain in committee.

Ohio's breach notification statute, Ohio Rev. Code Sec. 1349.19, is confirmed here against its own codified text at codes.ohio.gov: a prior research pass found that host unreachable (a TLS certificate mismatched to a different domain), but it was reachable this pass through a stealth browser tier, so the statute's own definitions and enforcement provisions are read directly rather than through the Attorney General's consumer-facing paraphrase.

A person that owns or licenses computerized data including personal information must disclose a breach to an affected Ohio resident in the most expedient time possible and no later than 45 days following discovery, and, once a single breach affects more than 1,000 residents, to every nationwide consumer reporting agency.

Personal information is limited to a name combined with a Social Security number, a driver's license or state identification card number, or a financial account, credit, or debit card number with an access code, and it excludes information lawfully available to the general public from government records or widely distributed media; it carries no biometric, genetic, or student-data element, a confirmed absence rather than an unread gap.

Ohio's general definition of person, incorporated by cross-reference and narrowed to a business entity that conducts business in Ohio, does not include a state agency or other governmental body, so the notification duty binds only private actors. The Attorney General has exclusive authority to investigate and bring a civil action for a violation, with escalating per-day civil penalties, and the statute creates no private right of action.

Separately, Ohio Rev. Code ch. 1354, described by secondary trackers as a voluntary cybersecurity-framework safe harbor rather than an independent duty, was not independently read this pass and is not recorded as its own instrument.

7 instruments named 3 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

HB 96, Internet Age Verification for Obscenity or Material Harmful to Juveniles

cite Ohio Rev. Code sections 1349.10 and 1349.101 stage RECENT in force 11 months effective 2025-09-30 source official statute text

Any entity that sells, disseminates, or presents material or a performance that is obscene or harmful to juveniles on the internet must verify that a user, and any person creating an account or subscription, is 18 or older using reasonable methods such as government-issued identification, a commercial age verification system, or transactional data, and must reverify age every two years.

The law exempts entities that qualify as interactive computer services under federal law, an exemption the Attorney General says most major pornography sites are relying on to avoid compliance, and which lawmakers were considering narrowing as of early 2026.

Note and primary source

Breach notification

Security Breach Notification Act

cite Ohio Rev. Code Sec. 1349.19 stage IN FORCE in force since 2007-03-30 source official Ohio statute text, Ohio Revised Code section 1349.19, codes.ohio.gov

Any person that owns or licenses computerized data including personal information must disclose a breach of the security of the system to an affected Ohio resident, in the most expedient time possible and no later than 45 days following discovery, subject to a law-enforcement delay.

Personal information is a name combined with a Social Security number, a driver's license or state identification card number, or a financial account, credit, or debit card number with an access code, and excludes information lawfully available to the general public from government records or widely distributed media; it carries no biometric, genetic, or student-data element.

Person has the meaning given in Ohio Rev. Code Sec. 1.59, an individual, corporation, business trust, estate, trust, partnership, or association with no government or governmental subdivision named, except that a business entity counts as a person only if it conducts business in Ohio, so this duty binds private actors, not the state or its political subdivisions.

A financial institution already subject to federal breach-notice requirements and a HIPAA covered entity are each exempt from this section. Once a single breach affects more than 1,000 Ohio residents, the person must also notify every nationwide consumer reporting agency without unreasonable delay.

The Attorney General has exclusive authority under Ohio Rev. Code Sec. 1349.192 to investigate and bring a civil action for a violation, with a civil penalty of up to $1,000 per day rising to $5,000 per day after 60 days and $10,000 per day after 90 days of an intentional or reckless violation, and the statute creates no private right of action.

Most recently amended by Senate Bill 126 (126th General Assembly), effective March 30, 2007; secondary reporting describes the original enactment as House Bill 104 (126th General Assembly), signed 2005, not independently confirmed against primary text this pass.

What it asks of an app

Social media and minors

HB 33, Parental Notification by Social Media Operators Act

cite Ohio Rev. Code section 1349.09 stage ENJOINED enforcement paused by a court effective 2024-01-15 source official statute text and appellate opinion

Operators of social media platforms directed to or reasonably expected to be accessed by children must obtain verifiable parental consent, through methods such as a signed form, credit card verification, phone or video call, or government ID, before allowing a child under 16 to create an account. Operators must also disclose available content moderation and parental control features.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.