{
 "jurisdiction_id": "US-OH",
 "jurisdiction": "United States – Ohio",
 "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 24,
  "sub_modules": 57,
  "source_register": 17
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A real, enforceable framework exists (federal FTC Act + Ohio breach-notification statute + AG consumer-protection authority) but it is narrow, sectoral and reactive rather than a comprehensive omnibus regime — amber reflects partial, non-comprehensive coverage rather than a total gap.",
   "claims": [
    {
     "statement": "The Ohio Attorney General is the principal state enforcement authority for consumer-protection and data-breach matters in Ohio, operating without a dedicated omnibus privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC Act's Section 5 general unfair/deceptive-practices authority applies nationally, including to entities operating in Ohio, as the federal baseline for privacy-adjacent enforcement absent a comprehensive statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Ohio Data Protection Act (2018 SB 220) was launched as part of the Ohio Attorney General's CyberOhio Initiative and went into effect on 2 November 2018, offering a voluntary cybersecurity safe harbor rather than mandatory minimum security standards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-ohios-data-protection-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Ohio's comprehensive consumer-privacy bill, the Ohio Personal Privacy Act (House Bill 376), was introduced in 2021 but was placed on hold, and no comprehensive Ohio consumer-privacy statute has been enacted as of mid-2026 (Ohio is not among the 19 states listed as having enacted comprehensive privacy laws).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ohios-personal-privacy-act-on-hold-to-give-legislators-more-time-to-digest/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Ohio's breach-notification statute (ORC §1349.19) defines covered 'personal information' narrowly — an individual's name combined with identifiers such as Social Security number, driver's license number, or financial account/access data — narrower than the 'personal data' concept in omnibus regimes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/legal-research/private-disclosure-security-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "US state breach-notification statutes, including Ohio's, generally apply to any organization holding covered personal information of that state's residents regardless of the organization's place of establishment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/ohio-privacy-bill-introduced-house",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No enumerated lawful bases, no general consent standard, and no special-category regime exist under Ohio or applicable sectoral-federal law outside of narrow sector carve-outs (e.g., HIPAA for health data, which is a federal sectoral overlay tracked separately).",
   "claims": [
    {
     "statement": "Ohio has no enumerated lawful-basis statute analogous to GDPR Article 6; general commercial data processing is regulated reactively via FTC Act Section 5 unfair/deceptive-practices review rather than a proactive lawful-basis requirement.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Under GLBA Title V, financial institutions must provide privacy notices and an opportunity for consumers to opt out of certain disclosures of nonpublic personal information to nonaffiliated third parties — an opt-out consent model rather than an opt-in/affirmative-consent standard.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/guide-to-the-gramm-leach-bliley-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No omnibus consumer-rights statute exists in Ohio; this is a genuine, confirmed regulatory gap rather than an under-researched area.",
   "claims": [
    {
     "statement": "Ohio has not enacted a comprehensive consumer-privacy statute and therefore confers no general statutory right of access to personal data held by commercial entities; Ohio is absent from the list of 19 US states with enacted comprehensive privacy laws as of the most recent tracking.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification is a binding, in-force obligation (amber-to-green on that narrow point) but accountability/DPIA/DPO/ROPA/security-mandate infrastructure that exists in omnibus regimes is entirely voluntary or absent in Ohio, pulling the module rating to amber overall.",
   "claims": [
    {
     "statement": "The Ohio Data Protection Act explicitly does not set minimum data-security standards or impose liability on businesses that fail to maintain a conforming cybersecurity program; compliance is voluntary and incentive-based rather than a mandatory accountability duty.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-ohios-data-protection-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "To qualify for the Ohio Data Protection Act's affirmative-defense safe harbor, a covered entity must create, maintain, and comply with a written cybersecurity program that reasonably conforms to one of several named frameworks, including the NIST Cybersecurity Framework and NIST SP 800-53/800-53A/800-171.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-ohios-data-protection-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Recognized cybersecurity frameworks that qualify an entity for the Ohio Data Protection Act's safe harbor also include the HIPAA Security Rule, GLBA Title V, FISMA, and the PCI Data Security Standard.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-ohios-data-protection-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Ohio's data-breach notification statute addresses notification obligations only and does not establish comprehensive consumer privacy rights such as access, deletion, or opt-out.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/legal-research/ohio-revised-code-disclosure-security-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "This is a confirmed structural absence consistent with the US sectoral model; no transfer-mechanism infrastructure exists to evaluate at the Ohio level.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and insurance sector overlays are well-evidenced and binding; other sectors (telecoms, employment, credit-scoring, education) show no Ohio-specific instrument and are carried as gaps.",
   "claims": [
    {
     "statement": "Under GLBA Title V, each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and protect the security and confidentiality of nonpublic personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/guide-to-the-gramm-leach-bliley-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC has enforcement jurisdiction over the GLBA Privacy Rule for financial institutions and other persons not regulated by other federal or state agencies, and state insurance authorities are responsible for issuing regulations and enforcing GLBA with respect to insurance providers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/how-comply-privacy-consumer-financial-information-rule-gramm-leach-bliley-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The HIPAA Security Rule is listed among the industry-recognized cybersecurity frameworks a covered entity may adopt to qualify for the Ohio Data Protection Act's litigation safe harbor.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-ohios-data-protection-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Ohio's Governor signed an insurance data-security standards bill establishing cybersecurity obligations for insurance entities licensed in the state.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/ohio-governor-signs-insurance-data-security-standards",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Confirmed absence of Ohio-specific adtech/commercial-privacy statutes; only the reactive federal baseline applies.",
   "claims": [
    {
     "statement": "A subset of enacted US state comprehensive privacy laws prohibit consent obtained through manipulative or deceptive dark patterns; Ohio, having no comprehensive privacy law, has no equivalent statutory prohibition.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/u-s-states-leverage-existing-models-of-privacy-legislation",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Confirmed absence of Ohio biometric/algorithmic-governance statutes relative to the small set of US states that have legislated in this space.",
   "claims": [
    {
     "statement": "Among US states, only Illinois, Washington and Texas have passed biometric-specific privacy legislation; Ohio has not enacted a comparable biometric-information-privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/how-should-we-regulate-facial-recognition-technology",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "A federal sectoral floor (COPPA) exists and state AGs assist in its enforcement, but no Ohio-specific instrument supplements it, and several sub-modules are wholly unaddressed at the state level.",
   "claims": [
    {
     "statement": "State attorneys general, including through coordinated NAAG efforts, participate in enforcing federal children's-privacy legislation such as COPPA alongside the FTC, in the absence of an Ohio-specific children's-data statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-ohio/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Real AG enforcement capacity exists and is active nationally (state AGs coordinate on breach enforcement), but Ohio-specific penalty schedules, recent enforcement actions, and private-right-of-action status could not be confirmed to Confirmed-level certainty from available sources in this run.",
   "claims": [
    {
     "statement": "Following a successful enforcement action for violation of state data-breach laws, attorneys general may pursue remedies including injunctions requiring companies to update systems/governance and civil penalties as provided under state consumer-protection statutes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "US state privacy-enforcement activity increased in the most recent tracked period, led by Texas and California, alongside coordinated multistate attorney-general breach enforcement; no Ohio-specific major action was identified as part of this trend.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/what-increasing-privacy-enforcement-activity-means-for-us-privacy-legislation",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A minority of US state data-breach-notification statutes allow a private right of action for noncompliance, while the majority rely exclusively on attorney-general enforcement; Ohio's specific position on this point was not independently confirmed in this run.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Ohio's comprehensive privacy bill (Ohio Personal Privacy Act, HB 376) remains on hold following its 2021 introduction, with no confirmed reintroduction or enactment identified as of this run.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ohios-personal-privacy-act-on-hold-to-give-legislators-more-time-to-digest/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}