🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-OH · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 17 sources retrieved model claude-sonnet-5 ·

United States – Ohio

US-OH schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 24 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
24Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A real, enforceable framework exists (federal FTC Act + Ohio breach-notification statute + AG consumer-protection authority) but it is narrow, sectoral and reactive rather than a comprehensive omnibus regime — amber reflects partial, non-comprehensive coverage rather than a total gap.

Primary frameworkFTC Act Section 5 (federal) + Ohio Revised Code §1349.19 (breach notification) + Ohio Data Protection Act, ORC Ch. 1354 (voluntary cybersecurity safe harbor)
Supervisory authorityOhio Attorney General
Traffic-light rationale — AmberA real, enforceable framework exists (federal FTC Act + Ohio breach-notification statute + AG consumer-protection authority) but it is narrow, sectoral and reactive rather than a comprehensive omnibus regime — amber reflects partial, non-comprehensive coverage rather than a total gap.

Sub-modules (5)

Regulator And AuthorityAmber

The Ohio Attorney General enforces the state's consumer-protection and breach-notification statutes; there is no dedicated Ohio privacy regulator with rulemaking authority analogous to a DPA.

Claims (1):

  • The Ohio Attorney General is the principal state enforcement authority for consumer-protection and data-breach matters in Ohio, operating without a dedicated omnibus privacy statute.

Act And InstrumentsAmber

Instruments in force: FTC Act §5 (federal baseline); ORC §1349.19 breach-notification statute; Ohio Data Protection Act (2018 SB 220, effective 2018-11-02) voluntary cybersecurity safe harbor. A comprehensive Ohio Personal Privacy Act (HB 376) was introduced in 2021 but was placed on hold and has not been re-enacted.

Claims (3):

  • The FTC Act's Section 5 general unfair/deceptive-practices authority applies nationally, including to entities operating in Ohio, as the federal baseline for privacy-adjacent enforcement absent a comprehensive statute.
  • The Ohio Data Protection Act (2018 SB 220) was launched as part of the Ohio Attorney General's CyberOhio Initiative and went into effect on 2 November 2018, offering a voluntary cybersecurity safe harbor rather than mandatory minimum security standards.
  • Ohio's comprehensive consumer-privacy bill, the Ohio Personal Privacy Act (House Bill 376), was introduced in 2021 but was placed on hold, and no comprehensive Ohio consumer-privacy statute has been enacted as of mid-2026 (Ohio is not among the 19 states listed as having enacted comprehensive privacy laws).

Material ScopeAmber

Ohio's breach statute covers only a narrow definition of 'personal information' (name plus SSN/driver's license/financial account identifiers) rather than the broad 'personal data' concept used in omnibus regimes.

Claims (1):

  • Ohio's breach-notification statute (ORC §1349.19) defines covered 'personal information' narrowly — an individual's name combined with identifiers such as Social Security number, driver's license number, or financial account/access data — narrower than the 'personal data' concept in omnibus regimes.

Territorial ScopeAmber

Consistent with the general pattern of US state breach-notification statutes, Ohio's law applies to any entity holding covered personal information of Ohio residents regardless of where the entity is established.

Claims (1):

  • US state breach-notification statutes, including Ohio's, generally apply to any organization holding covered personal information of that state's residents regardless of the organization's place of establishment.

Regulator Registration And FilingRed

No controller/processor registration or filing regime exists in Ohio; there is no omnibus statute establishing such an obligation.

Absence provenance: not recorded. Searched: Ohio Attorney General registration privacy, Ohio Revised Code data controller registration.

Category narrative82 words

Ohio has no dedicated data-protection regulator or comprehensive privacy statute. The governing framework is a composite of (a) the FTC's general Section 5 unfair/deceptive-practices authority, which applies nationally including Ohio, and (b) Ohio-specific instruments limited to breach notification (ORC §1349.19 and related §§1347.12, 1349.191-.192) and a voluntary cybersecurity safe-harbor statute (the Ohio Data Protection Act, 2018 SB 220). The Ohio Attorney General is the principal state-level enforcement actor for consumer-protection/privacy-adjacent matters, operating under general consumer-protection authority rather than a dedicated privacy statute.

Sources and claims (6)
  1. ProbableNAAGThe Ohio Attorney General is the principal state enforcement authority for consumer-protection and data-breach matters in Ohio, operating without a dedicated omnibus privacy statute.observed
  2. ConfirmedFederal Trade CommissionThe FTC Act's Section 5 general unfair/deceptive-practices authority applies nationally, including to entities operating in Ohio, as the federal baseline for privacy-adjacent enforcement absent a comprehensive statute.observed
  3. ConfirmedIAPPThe Ohio Data Protection Act (2018 SB 220) was launched as part of the Ohio Attorney General's CyberOhio Initiative and went into effect on 2 November 2018, offering a voluntary cybersecurity safe harbor rather than mandatory minimum security standards.observed
  4. ConfirmedIAPPOhio's comprehensive consumer-privacy bill, the Ohio Personal Privacy Act (House Bill 376), was introduced in 2021 but was placed on hold, and no comprehensive Ohio consumer-privacy statute has been enacted as of mid-2026 (Ohio is not among the 19 states listed as having enacted comprehensive privacy laws).observed
  5. ProbableDataGuidance (OneTrust)Ohio's breach-notification statute (ORC §1349.19) defines covered 'personal information' narrowly — an individual's name combined with identifiers such as Social Security number, driver's license number, or financial account/access data — narrower than the 'personal data' concept in omnibus regimes.observed
  6. ProbableDataGuidance (OneTrust)US state breach-notification statutes, including Ohio's, generally apply to any organization holding covered personal information of that state's residents regardless of the organization's place of establishment.observed

#

No enumerated lawful bases, no general consent standard, and no special-category regime exist under Ohio or applicable sectoral-federal law outside of narrow sector carve-outs (e.g., HIPAA for health data, which is a federal sectoral overlay tracked separately).

Traffic-light rationale — RedNo enumerated lawful bases, no general consent standard, and no special-category regime exist under Ohio or applicable sectoral-federal law outside of narrow sector carve-outs (e.g., HIPAA for health data, which is a federal sectoral overlay tracked separately).

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-basis framework (GDPR Art 6 analogue) exists under Ohio or general US federal law; processing legality is instead tested reactively against FTC Act §5 unfairness/deception standards.

Claims (1):

  • Ohio has no enumerated lawful-basis statute analogous to GDPR Article 6; general commercial data processing is regulated reactively via FTC Act Section 5 unfair/deceptive-practices review rather than a proactive lawful-basis requirement.

Special CategoriesRed

No general statutory 'special category' data regime exists in Ohio; sensitive-data protections are confined to sector overlays (health via HIPAA, financial via GLBA) tracked under sectoral_watch.

Absence provenance: not recorded. Searched: Ohio special category personal data statute, Ohio sensitive personal information law.

Pseudonymisation And AnonymisationRed

No Ohio statutory definition or safe harbor for pseudonymisation/anonymisation exists; the Ohio Data Protection Act's safe harbor concerns cybersecurity-program conformity, not data de-identification.

Absence provenance: not recorded. Searched: Ohio pseudonymisation anonymisation safe harbor statute.

Category narrative72 words

Ohio has no GDPR-style enumerated lawful-basis regime. Processing is governed by sector-specific notice-and-consent/opt-out models (e.g., GLBA opt-out for financial nonpublic personal information) and general FTC deception/unfairness review, rather than an affirmative lawful-basis test. There is no general statutory definition of 'special category' data or a codified pseudonymisation/anonymisation safe harbor at the state level; the Ohio Data Protection Act references NIST/HIPAA/GLBA/FISMA/PCI security frameworks but these govern security posture, not lawful-basis or special-category classification.

Sources and claims (2)
  1. ConfirmedFederal Trade CommissionOhio has no enumerated lawful-basis statute analogous to GDPR Article 6; general commercial data processing is regulated reactively via FTC Act Section 5 unfair/deceptive-practices review rather than a proactive lawful-basis requirement.observed
  2. ConfirmedIAPPUnder GLBA Title V, financial institutions must provide privacy notices and an opportunity for consumers to opt out of certain disclosures of nonpublic personal information to nonaffiliated third parties — an opt-out consent model rather than an opt-in/affirmative-consent standard.observed

#

No omnibus consumer-rights statute exists in Ohio; this is a genuine, confirmed regulatory gap rather than an under-researched area.

Traffic-light rationale — RedNo omnibus consumer-rights statute exists in Ohio; this is a genuine, confirmed regulatory gap rather than an under-researched area.

Sub-modules (5)

Access RightRed

No general right of access to personal data held by commercial entities exists under Ohio law.

Claims (1):

  • Ohio has not enacted a comprehensive consumer-privacy statute and therefore confers no general statutory right of access to personal data held by commercial entities; Ohio is absent from the list of 19 US states with enacted comprehensive privacy laws as of the most recent tracking.

Rectification And ErasureRed

No general right to correct or delete personal data exists under Ohio law absent sector-specific carve-outs.

Absence provenance: not recorded. Searched: Ohio right to delete personal data statute, Ohio right to correction consumer data.

Restriction And ObjectionRed

No general right to restrict processing or object to processing/profiling exists under Ohio law.

Absence provenance: not recorded. Searched: Ohio right to object processing profiling opt-out statute.

Data PortabilityRed

No statutory data-portability right exists under Ohio law.

Absence provenance: not recorded. Searched: Ohio data portability consumer right statute.

Deadlines And Response WindowsRed

Because no general consumer data-subject-rights regime exists, there are no associated statutory response-window deadlines in Ohio (breach-notification timing is tracked under controller_processor_duties.breach_notification, which is a distinct obligation).

Absence provenance: not recorded. Searched: Ohio consumer data request response deadline statute.

Category narrative53 words

Ohio confers no general statutory access, rectification, erasure, restriction, objection, or portability rights on consumers with respect to commercial data processing. Such rights exist only within narrow federal sectoral carve-outs (e.g., HIPAA access rights for designated health records), which are tracked under sectoral_watch rather than as a general consumer right in this JID.

Sources and claims (1)
  1. ConfirmedIAPPOhio has not enacted a comprehensive consumer-privacy statute and therefore confers no general statutory right of access to personal data held by commercial entities; Ohio is absent from the list of 19 US states with enacted comprehensive privacy laws as of the most recent tracking.observed

#

Breach notification is a binding, in-force obligation (amber-to-green on that narrow point) but accountability/DPIA/DPO/ROPA/security-mandate infrastructure that exists in omnibus regimes is entirely voluntary or absent in Ohio, pulling the module rating to amber overall.

Primary frameworkOhio Data Protection Act (ORC Ch. 1354, voluntary safe harbor) + ORC §1349.19 breach notification (mandatory)
Supervisory authorityOhio Attorney General
Traffic-light rationale — AmberBreach notification is a binding, in-force obligation (amber-to-green on that narrow point) but accountability/DPIA/DPO/ROPA/security-mandate infrastructure that exists in omnibus regimes is entirely voluntary or absent in Ohio, pulling the module rating to amber overall.

Sub-modules (7)

Accountability And DpiaRed

No mandatory accountability principle or DPIA-trigger regime exists in Ohio; the Data Protection Act's cybersecurity-program element is voluntary and tied only to litigation safe harbor, not a standalone compliance duty.

Claims (1):

  • The Ohio Data Protection Act explicitly does not set minimum data-security standards or impose liability on businesses that fail to maintain a conforming cybersecurity program; compliance is voluntary and incentive-based rather than a mandatory accountability duty.

Dpo RequirementsRed

No DPO appointment threshold or independence requirement exists under Ohio law.

Absence provenance: not recorded. Searched: Ohio data protection officer appointment requirement statute.

Ropa RequirementsRed

No records-of-processing-activities obligation exists under Ohio law.

Absence provenance: not recorded. Searched: Ohio records of processing activities requirement.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists under Ohio law.

Absence provenance: not recorded. Searched: Ohio joint controller data sharing agreement statute.

Security MeasuresAmber

The Ohio Data Protection Act incentivizes, via an affirmative tort defense, businesses to create and maintain a written cybersecurity program reasonably conforming to one of several named industry frameworks, but it does not itself impose mandatory minimum security standards or liability for non-compliance.

Claims (2):

  • To qualify for the Ohio Data Protection Act's affirmative-defense safe harbor, a covered entity must create, maintain, and comply with a written cybersecurity program that reasonably conforms to one of several named frameworks, including the NIST Cybersecurity Framework and NIST SP 800-53/800-53A/800-171.
  • Recognized cybersecurity frameworks that qualify an entity for the Ohio Data Protection Act's safe harbor also include the HIPAA Security Rule, GLBA Title V, FISMA, and the PCI Data Security Standard.

Breach NotificationGreen

Ohio's breach-notification statute (ORC §1349.19, with related provisions at §§1347.12, 1349.191-.192) mandates notification obligations in the event of a security breach involving computerized personal information, but is confined to notification and does not create broader consumer privacy rights.

Claims (1):

  • Ohio's data-breach notification statute addresses notification obligations only and does not establish comprehensive consumer privacy rights such as access, deletion, or opt-out.

Retention And DisposalRed

No general statutory retention-limitation or disposal-duty regime exists under Ohio law outside sector-specific overlays.

Absence provenance: not recorded. Searched: Ohio data retention limitation disposal requirement statute.

Category narrative77 words

Ohio imposes no general accountability, DPIA, DPO, ROPA, or joint-controller regime. The one operative Ohio-specific instrument is the Data Protection Act's voluntary cybersecurity safe harbor, which incentivizes (but does not mandate) alignment with recognized frameworks (NIST CSF, NIST SP 800-53/-53A/-171, HIPAA Security Rule, GLBA Title V, FISMA, PCI-DSS) in exchange for an affirmative tort defense. Breach notification is separately and mandatorily governed by ORC §1349.19 (and related §§1347.12, 1349.191-.192). No general retention/disposal mandate exists outside sectoral overlays.

Sources and claims (4)
  1. ConfirmedIAPPThe Ohio Data Protection Act explicitly does not set minimum data-security standards or impose liability on businesses that fail to maintain a conforming cybersecurity program; compliance is voluntary and incentive-based rather than a mandatory accountability duty.observed
  2. ConfirmedIAPPTo qualify for the Ohio Data Protection Act's affirmative-defense safe harbor, a covered entity must create, maintain, and comply with a written cybersecurity program that reasonably conforms to one of several named frameworks, including the NIST Cybersecurity Framework and NIST SP 800-53/800-53A/800-171.observed
  3. ConfirmedIAPPRecognized cybersecurity frameworks that qualify an entity for the Ohio Data Protection Act's safe harbor also include the HIPAA Security Rule, GLBA Title V, FISMA, and the PCI Data Security Standard.observed
  4. ConfirmedDataGuidance (OneTrust)Ohio's data-breach notification statute addresses notification obligations only and does not establish comprehensive consumer privacy rights such as access, deletion, or opt-out.observed

#

This is a confirmed structural absence consistent with the US sectoral model; no transfer-mechanism infrastructure exists to evaluate at the Ohio level.

Traffic-light rationale — RedThis is a confirmed structural absence consistent with the US sectoral model; no transfer-mechanism infrastructure exists to evaluate at the Ohio level.

Sub-modules (6)

Transfer MechanismsRed

No Ohio or applicable federal general-purpose cross-border transfer mechanism (adequacy/SCC/BCR/derogation) exists for commercial personal data.

Absence provenance: not recorded. Searched: Ohio cross-border data transfer mechanism statute, US federal data transfer adequacy framework.

Adequacy ReceivedRed

No adequacy decisions are received by Ohio/the US at the state level; this concept does not apply outside omnibus regimes.

Absence provenance: not recorded. Searched: Ohio adequacy decision received.

Adequacy GrantedRed

Ohio does not grant adequacy decisions; this concept is not applicable to a US sub-national jurisdiction lacking an omnibus statute.

Absence provenance: not recorded. Searched: Ohio adequacy decision granted.

Sccs And BcrsRed

No Ohio-specific SCC or BCR framework exists.

Absence provenance: not recorded. Searched: Ohio standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement exists under Ohio law.

Absence provenance: not recorded. Searched: Ohio transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate applies to commercial personal data in Ohio.

Absence provenance: not recorded. Searched: Ohio data localisation mandate statute.

Category narrative41 words

Neither Ohio nor US federal sectoral law maintains a GDPR-style cross-border transfer regime. There are no Ohio-specific adequacy determinations (received or granted), no SCC/BCR analogue, no transfer-impact-assessment requirement, and no data-localisation mandate applicable to general commercial data at the state level.

#

Financial and insurance sector overlays are well-evidenced and binding; other sectors (telecoms, employment, credit-scoring, education) show no Ohio-specific instrument and are carried as gaps.

Primary frameworkGLBA Title V (financial) + Ohio Insurance Data Security Standards Act + HIPAA (health, federal)
Traffic-light rationale — AmberFinancial and insurance sector overlays are well-evidenced and binding; other sectors (telecoms, employment, credit-scoring, education) show no Ohio-specific instrument and are carried as gaps.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA Title V imposes an affirmative and continuing obligation on financial institutions to protect the security and confidentiality of customers' nonpublic personal information, enforced by the FTC (for entities not otherwise regulated) and other federal/state financial regulators.

Claims (2):

  • Under GLBA Title V, each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and protect the security and confidentiality of nonpublic personal information.
  • The FTC has enforcement jurisdiction over the GLBA Privacy Rule for financial institutions and other persons not regulated by other federal or state agencies, and state insurance authorities are responsible for issuing regulations and enforcing GLBA with respect to insurance providers.

Health Sector OverlayAmber

HIPAA's Security Rule is named as one of the qualifying frameworks under the Ohio Data Protection Act's safe harbor, indicating HIPAA operates as the substantive health-data protection regime in Ohio rather than any state-specific health-privacy statute.

Claims (1):

  • The HIPAA Security Rule is listed among the industry-recognized cybersecurity frameworks a covered entity may adopt to qualify for the Ohio Data Protection Act's litigation safe harbor.

Telecoms And EprivacyRed

No Ohio-specific ePrivacy/telecoms-privacy analogue (e.g., cookie-consent statute) was identified.

Absence provenance: not recorded. Searched: Ohio ePrivacy telecoms privacy cookie statute.

Employment DataRed

No Ohio-specific employment-data privacy statute was identified.

Absence provenance: not recorded. Searched: Ohio employment data privacy statute.

Credit And ScoringAmber

Credit-related data handling in Ohio is governed by the federal Fair Credit Reporting Act rather than an Ohio-specific credit-scoring privacy statute; this module entry is carried at lower confidence pending direct primary-source verification.

Absence provenance: not recorded. Searched: Ohio credit scoring data privacy statute.

EducationRed

No Ohio-specific student-data privacy statute distinct from federal FERPA was identified in this run.

Absence provenance: not recorded. Searched: Ohio student data privacy statute education.

InsuranceGreen

Ohio enacted an Insurance Data Security Standards statute establishing cybersecurity requirements for licensed insurance entities operating in the state.

Claims (1):

  • Ohio's Governor signed an insurance data-security standards bill establishing cybersecurity obligations for insurance entities licensed in the state.
Category narrative82 words

In the absence of an Ohio omnibus statute, sectoral federal overlays do the substantive work: GLBA Title V governs financial-institution nonpublic personal information (enforced by the FTC, federal banking regulators, and state insurance authorities), Ohio has separately enacted an Insurance Data Security Standards statute aligning with the NAIC Insurance Data Security Model Law, and HIPAA governs health information as one of the named safe-harbor frameworks under the Ohio Data Protection Act. No Ohio-specific telecoms/ePrivacy, employment-data, credit-scoring, or education-sector privacy statute was identified.

Sources and claims (4)
  1. ConfirmedIAPPUnder GLBA Title V, each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and protect the security and confidentiality of nonpublic personal information.observed
  2. ConfirmedFederal Trade CommissionThe FTC has enforcement jurisdiction over the GLBA Privacy Rule for financial institutions and other persons not regulated by other federal or state agencies, and state insurance authorities are responsible for issuing regulations and enforcing GLBA with respect to insurance providers.observed
  3. ConfirmedIAPPThe HIPAA Security Rule is listed among the industry-recognized cybersecurity frameworks a covered entity may adopt to qualify for the Ohio Data Protection Act's litigation safe harbor.observed
  4. ProbableDataGuidance (OneTrust)Ohio's Governor signed an insurance data-security standards bill establishing cybersecurity obligations for insurance entities licensed in the state.observed

#

Confirmed absence of Ohio-specific adtech/commercial-privacy statutes; only the reactive federal baseline applies.

Primary frameworkFTC Act Section 5 (federal baseline only)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedConfirmed absence of Ohio-specific adtech/commercial-privacy statutes; only the reactive federal baseline applies.

Sub-modules (6)

Cookies And TrackersRed

No Ohio cookie/tracker consent statute exists.

Absence provenance: not recorded. Searched: Ohio cookie consent tracker law.

Dark PatternsRed

Dark-pattern prohibitions exist in a subset of other US comprehensive state privacy laws but Ohio, lacking such a law, has no equivalent prohibition.

Claims (1):

  • A subset of enacted US state comprehensive privacy laws prohibit consent obtained through manipulative or deceptive dark patterns; Ohio, having no comprehensive privacy law, has no equivalent statutory prohibition.

Opt Out SignalsRed

No Ohio requirement to honor universal opt-out signals (e.g., Global Privacy Control) exists.

Absence provenance: not recorded. Searched: Ohio opt-out signal Global Privacy Control requirement.

Clean Rooms And DcrRed

No Ohio clean-room/data-collaboration-room regulation exists.

Absence provenance: not recorded. Searched: Ohio data clean room regulation.

Cross Context AdvertisingRed

No Ohio 'sale'/'share' cross-context-advertising framework analogous to CPRA exists.

Absence provenance: not recorded. Searched: Ohio cross-context behavioral advertising sale share law.

Direct MarketingRed

No Ohio-specific direct-marketing consent/suppression statute beyond general federal telemarketing/CAN-SPAM frameworks was identified in this run.

Absence provenance: not recorded. Searched: Ohio direct marketing consent suppression statute.

Category narrative50 words

Ohio has no cookie/tracker consent statute, dark-pattern prohibition, opt-out-signal mandate, clean-room regulation, cross-context-advertising 'sale/share' framework, or direct-marketing consent regime comparable to those found in the 19 US states with comprehensive privacy laws. Commercial adtech practices in Ohio are governed only by the general federal FTC Act Section 5 deception/unfairness standard.

Sources and claims (1)
  1. ProbableIAPPA subset of enacted US state comprehensive privacy laws prohibit consent obtained through manipulative or deceptive dark patterns; Ohio, having no comprehensive privacy law, has no equivalent statutory prohibition.observed

#

Confirmed absence of Ohio biometric/algorithmic-governance statutes relative to the small set of US states that have legislated in this space.

Traffic-light rationale — RedConfirmed absence of Ohio biometric/algorithmic-governance statutes relative to the small set of US states that have legislated in this space.

Sub-modules (6)

Profiling RestrictionsRed

No Ohio statute restricts automated profiling.

Absence provenance: not recorded. Searched: Ohio profiling restriction statute automated decision.

Automated Decision Making TransparencyRed

No Ohio ADM transparency or explanation-right statute exists.

Absence provenance: not recorded. Searched: Ohio automated decision making transparency law.

Ai Risk AssessmentsRed

No Ohio AI-specific risk-assessment statute was identified in this run.

Absence provenance: not recorded. Searched: Ohio AI risk assessment law 2026.

Biometric RegimeRed

Ohio has not enacted a biometric-information-privacy statute; only Illinois (BIPA), Washington, and Texas have state biometric-specific privacy legislation among US states.

Claims (1):

  • Among US states, only Illinois, Washington and Texas have passed biometric-specific privacy legislation; Ohio has not enacted a comparable biometric-information-privacy statute.

Genetic DataRed

No Ohio-specific genetic-data privacy statute was identified.

Absence provenance: not recorded. Searched: Ohio genetic data privacy statute.

State Surveillance CarveoutsRed

No Ohio-specific codified state-surveillance carve-out distinct from general federal national-security exemptions was identified.

Absence provenance: not recorded. Searched: Ohio state surveillance carveout national security exemption.

Category narrative48 words

Ohio has no state-specific biometric-privacy statute; among US states, only Illinois, Washington and Texas have enacted biometric-specific privacy legislation, and Ohio is not among them. Correspondingly, Ohio has no profiling restriction, ADM transparency/explanation right, AI-specific risk-assessment mandate, genetic-data statute, or codified state-surveillance carve-out distinct from general federal frameworks.

Sources and claims (1)
  1. ConfirmedIAPPAmong US states, only Illinois, Washington and Texas have passed biometric-specific privacy legislation; Ohio has not enacted a comparable biometric-information-privacy statute.observed

#

A federal sectoral floor (COPPA) exists and state AGs assist in its enforcement, but no Ohio-specific instrument supplements it, and several sub-modules are wholly unaddressed at the state level.

Primary frameworkCOPPA (federal)
Traffic-light rationale — AmberA federal sectoral floor (COPPA) exists and state AGs assist in its enforcement, but no Ohio-specific instrument supplements it, and several sub-modules are wholly unaddressed at the state level.

Sub-modules (5)

Age VerificationRed

No Ohio-specific age-verification statute for data processing was identified.

Absence provenance: not recorded. Searched: Ohio age verification data processing statute.

Minor Profiling BansRed

No Ohio-specific statutory ban on profiling minors was identified.

Absence provenance: not recorded. Searched: Ohio minor profiling ban statute.

Education SettingsRed

No Ohio-specific education-settings data-privacy statute beyond federal FERPA was identified in this run.

Absence provenance: not recorded. Searched: Ohio education data privacy student statute.

Dependent AdultsRed

No Ohio-specific dependent-adult (elderly/incapacitated) data-protection statute was identified.

Absence provenance: not recorded. Searched: Ohio dependent adult data protection statute.

Category narrative39 words

Ohio relies on the federal Children's Online Privacy Protection Act (COPPA), enforced with attorney-general involvement, as its operative children's-data framework; no Ohio-specific age-verification, parental-consent, minor-profiling-ban, or education-settings privacy statute was identified. No Ohio-specific dependent-adult data-protection statute was identified either.

Sources and claims (1)
  1. ProbableNAAGState attorneys general, including through coordinated NAAG efforts, participate in enforcing federal children's-privacy legislation such as COPPA alongside the FTC, in the absence of an Ohio-specific children's-data statute.observed

#

Real AG enforcement capacity exists and is active nationally (state AGs coordinate on breach enforcement), but Ohio-specific penalty schedules, recent enforcement actions, and private-right-of-action status could not be confirmed to Confirmed-level certainty from available sources in this run.

Primary frameworkOhio consumer-protection/AG enforcement authority + FTC Act Section 5
Supervisory authorityOhio Attorney General
Traffic-light rationale — AmberReal AG enforcement capacity exists and is active nationally (state AGs coordinate on breach enforcement), but Ohio-specific penalty schedules, recent enforcement actions, and private-right-of-action status could not be confirmed to Confirmed-level certainty from available sources in this run.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Following a successful breach-law enforcement action, state attorneys general may pursue injunctions and civil penalties as set out under state consumer-protection laws; the specific Ohio penalty schedule was not independently confirmed via a primary Ohio Revised Code citation in this run.

Absence provenance: not recorded. Searched: Ohio breach notification civil penalty amount statute.

Claims (1):

  • Following a successful enforcement action for violation of state data-breach laws, attorneys general may pursue remedies including injunctions requiring companies to update systems/governance and civil penalties as provided under state consumer-protection statutes.

Enforcement Activity IndexAmber

National enforcement activity has intensified, led by Texas and California, with multistate AG coordination on breach matters; no Ohio-specific enforcement action in the last 12 months was located in this run.

Absence provenance: not recorded. Searched: Ohio Attorney General privacy enforcement action 2025 2026.

Claims (1):

  • US state privacy-enforcement activity increased in the most recent tracked period, led by Texas and California, alongside coordinated multistate attorney-general breach enforcement; no Ohio-specific major action was identified as part of this trend.

Regulator Funding And CapacityRed

No specific Ohio Attorney General privacy-unit funding/headcount data was located in this run.

Absence provenance: not recorded. Searched: Ohio Attorney General privacy enforcement unit funding headcount.

Collective Redress And Class ActionsAmber

No Ohio-specific collective-redress mechanism dedicated to privacy claims was confirmed; general Ohio class-action procedure (Ohio Civ. R. 23) may apply to breach-related tort claims but was not independently verified in this run.

Absence provenance: not recorded. Searched: Ohio class action privacy data breach Rule 23.

Private Right Of ActionAmber

Some, but not all, US state breach-notification statutes allow a private right of action; whether Ohio's statute does so was not conclusively confirmed via primary source in this run and should be treated as Uncertain pending direct Ohio Revised Code review.

Absence provenance: not recorded. Searched: Ohio breach notification statute private right of action.

Claims (1):

  • A minority of US state data-breach-notification statutes allow a private right of action for noncompliance, while the majority rely exclusively on attorney-general enforcement; Ohio's specific position on this point was not independently confirmed in this run.

Recent Developments 180DRed

No new Ohio comprehensive privacy legislation, enacted amendment, or adequacy-relevant development was identified within the last 180 days; the most recent substantive Ohio-specific development remains the 2021 introduction and subsequent hold of the Ohio Personal Privacy Act (HB 376), which has not been reintroduced or advanced to enactment as of this run.

Claims (1):

  • Ohio's comprehensive privacy bill (Ohio Personal Privacy Act, HB 376) remains on hold following its 2021 introduction, with no confirmed reintroduction or enactment identified as of this run.
Category narrative95 words

Enforcement in Ohio is carried out principally by the Ohio Attorney General under general consumer-protection authority and by the FTC under Section 5, rather than under a dedicated privacy-enforcement statute with codified maximum penalties. Ohio's breach-notification statute is enforced by the Attorney General; the Ohio Data Protection Act creates no independent enforcement mechanism at all (it is a voluntary safe harbor). No comprehensive collective-redress/class-action mechanism or general private right of action for privacy violations was confirmed for Ohio in this run; this should be treated as an open verification item rather than a settled negative.

Sources and claims (4)
  1. ProbableNAAGFollowing a successful enforcement action for violation of state data-breach laws, attorneys general may pursue remedies including injunctions requiring companies to update systems/governance and civil penalties as provided under state consumer-protection statutes.observed
  2. ProbableIAPPUS state privacy-enforcement activity increased in the most recent tracked period, led by Texas and California, alongside coordinated multistate attorney-general breach enforcement; no Ohio-specific major action was identified as part of this trend.observed
  3. UncertainNAAGA minority of US state data-breach-notification statutes allow a private right of action for noncompliance, while the majority rely exclusively on attorney-general enforcement; Ohio's specific position on this point was not independently confirmed in this run.observed
  4. ProbableIAPPOhio's comprehensive privacy bill (Ohio Personal Privacy Act, HB 376) remains on hold following its 2021 introduction, with no confirmed reintroduction or enactment identified as of this run.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Ohio
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 24 claim(s), 17 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (breach_notification sub-module), and sectoral_watch (financial_sector_overlay, insurance) achieved the strongest grounding, anchored on T1 FTC sources plus T2 DataGuidance/IAPP legal-research summaries of ORC §1349.19 and the Ohio Data Protection Act (SB 220). lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups are dominated by confirmed-absence findings (T2/T3 corroborated) rather than T1 primary-statute citations, since no primary Ohio Revised Code full-text portal was reachable within this run's allowlist. enforcement_and_redress relies substantially on T3 NAAG/IAPP general-pattern sources rather than an Ohio-specific primary enforcement-action record; Ohio-specific penalty amounts, recent (12-month) enforcement actions, and private-right-of-action status could not be elevated above Probable/Uncertain confidence.

Unresolved questions (6):

  • Does Ohio's breach-notification statute (ORC §1349.19 et seq.) provide a private right of action, or is enforcement exclusively vested in the Attorney General?
  • What is the exact civil-penalty schedule (if any) applicable to Ohio Attorney General enforcement of the breach-notification statute?
  • Has the Ohio Personal Privacy Act (or a successor comprehensive privacy bill) been reintroduced in the current Ohio General Assembly session, and what is its current legislative status?
  • Does Ohio Revised Code Chapter 1347 (state-agency personal-information systems) create individual access/correction rights against state-agency data processing distinct from the private-sector breach-notification regime, and if so, what is its precise scope?
  • What are the specific requirements and effective date of the Ohio Insurance Data Security Standards statute, and does it track the NAIC Insurance Data Security Model Law verbatim?
  • Has the Ohio Attorney General brought any privacy- or breach-related enforcement actions in the last 12 months that should populate enforcement_activity_index?

Escalate to primary-source review: yes