#
A real, enforceable framework exists (federal FTC Act + Ohio breach-notification statute + AG consumer-protection authority) but it is narrow, sectoral and reactive rather than a comprehensive omnibus regime — amber reflects partial, non-comprehensive coverage rather than a total gap.
Sub-modules (5)
Regulator And AuthorityAmber
The Ohio Attorney General enforces the state's consumer-protection and breach-notification statutes; there is no dedicated Ohio privacy regulator with rulemaking authority analogous to a DPA.
Claims (1):
- The Ohio Attorney General is the principal state enforcement authority for consumer-protection and data-breach matters in Ohio, operating without a dedicated omnibus privacy statute.
Act And InstrumentsAmber
Instruments in force: FTC Act §5 (federal baseline); ORC §1349.19 breach-notification statute; Ohio Data Protection Act (2018 SB 220, effective 2018-11-02) voluntary cybersecurity safe harbor. A comprehensive Ohio Personal Privacy Act (HB 376) was introduced in 2021 but was placed on hold and has not been re-enacted.
Claims (3):
- The FTC Act's Section 5 general unfair/deceptive-practices authority applies nationally, including to entities operating in Ohio, as the federal baseline for privacy-adjacent enforcement absent a comprehensive statute.
- The Ohio Data Protection Act (2018 SB 220) was launched as part of the Ohio Attorney General's CyberOhio Initiative and went into effect on 2 November 2018, offering a voluntary cybersecurity safe harbor rather than mandatory minimum security standards.
- Ohio's comprehensive consumer-privacy bill, the Ohio Personal Privacy Act (House Bill 376), was introduced in 2021 but was placed on hold, and no comprehensive Ohio consumer-privacy statute has been enacted as of mid-2026 (Ohio is not among the 19 states listed as having enacted comprehensive privacy laws).
Material ScopeAmber
Ohio's breach statute covers only a narrow definition of 'personal information' (name plus SSN/driver's license/financial account identifiers) rather than the broad 'personal data' concept used in omnibus regimes.
Claims (1):
- Ohio's breach-notification statute (ORC §1349.19) defines covered 'personal information' narrowly — an individual's name combined with identifiers such as Social Security number, driver's license number, or financial account/access data — narrower than the 'personal data' concept in omnibus regimes.
Territorial ScopeAmber
Consistent with the general pattern of US state breach-notification statutes, Ohio's law applies to any entity holding covered personal information of Ohio residents regardless of where the entity is established.
Claims (1):
- US state breach-notification statutes, including Ohio's, generally apply to any organization holding covered personal information of that state's residents regardless of the organization's place of establishment.
Regulator Registration And FilingRed
No controller/processor registration or filing regime exists in Ohio; there is no omnibus statute establishing such an obligation.
Absence provenance: not recorded. Searched: Ohio Attorney General registration privacy, Ohio Revised Code data controller registration.
Sources and claims (6)
- ProbableNAAG — The Ohio Attorney General is the principal state enforcement authority for consumer-protection and data-breach matters in Ohio, operating without a dedicated omnibus privacy statute.observed
- ConfirmedFederal Trade Commission — The FTC Act's Section 5 general unfair/deceptive-practices authority applies nationally, including to entities operating in Ohio, as the federal baseline for privacy-adjacent enforcement absent a comprehensive statute.observed
- ConfirmedIAPP — The Ohio Data Protection Act (2018 SB 220) was launched as part of the Ohio Attorney General's CyberOhio Initiative and went into effect on 2 November 2018, offering a voluntary cybersecurity safe harbor rather than mandatory minimum security standards.observed
- ConfirmedIAPP — Ohio's comprehensive consumer-privacy bill, the Ohio Personal Privacy Act (House Bill 376), was introduced in 2021 but was placed on hold, and no comprehensive Ohio consumer-privacy statute has been enacted as of mid-2026 (Ohio is not among the 19 states listed as having enacted comprehensive privacy laws).observed
- ProbableDataGuidance (OneTrust) — Ohio's breach-notification statute (ORC §1349.19) defines covered 'personal information' narrowly — an individual's name combined with identifiers such as Social Security number, driver's license number, or financial account/access data — narrower than the 'personal data' concept in omnibus regimes.observed
- ProbableDataGuidance (OneTrust) — US state breach-notification statutes, including Ohio's, generally apply to any organization holding covered personal information of that state's residents regardless of the organization's place of establishment.observed