Ohio Privacy Laws: Breach Notice, Recording, and Safe Harbor

Ohio privacy laws are a patchwork rather than a single statute. The state has not passed a comprehensive consumer data privacy act, so your protections come from targeted Ohio laws on data breaches, recording, publicity rights, minors on social media, and workplace conduct, backed by federal laws that cover health records, financial data, credit reports, and children’s online information. What you can demand, and from whom, depends entirely on which category your data falls into.

No General Consumer Privacy Statute in Ohio

Unlike a growing number of states, Ohio has not enacted a broad consumer privacy law giving residents the right to see what businesses know about them, delete that data, or opt out of its sale. A proposal called the Ohio Personal Privacy Act was introduced in 2021 but never became law.

The practical result: if a retailer, app, or data broker collects and sells your personal information, no Ohio-specific statute gives you the tools to stop it unless the data falls into a protected category covered by one of the laws below. Businesses in Ohio still have to follow the targeted rules that do exist, and any applicable federal privacy law, but there is no general right to control everyday consumer data collection.

Data Breach Notification

Ohio’s breach notification law requires any business or government agency that maintains computerized personal data to notify affected residents when a breach creates a real risk of identity theft or fraud.1Ohio Legislative Service Commission. Ohio Code 1349.19 – Private Disclosure of Security Breach of Computerized Personal Information Data The law defines personal information as your name combined with at least one sensitive element: a Social Security number, a driver’s license or state ID number, or a financial account number paired with any security code or password needed to access it. Encrypted or otherwise unreadable data is not covered by the notification requirement.

When a qualifying breach happens, notice must go out as quickly as possible and no later than 45 days after discovery.1Ohio Legislative Service Commission. Ohio Code 1349.19 – Private Disclosure of Security Breach of Computerized Personal Information Data Law enforcement can request a delay if notification would interfere with a criminal investigation, but otherwise the 45-day clock applies firmly. The statute does not prescribe what the notice must contain, so the detail you receive can vary from letter to letter.

If a single breach affects more than 1,000 Ohio residents, the business must also notify all nationwide consumer reporting agencies about the timing and scope of the breach.1Ohio Legislative Service Commission. Ohio Code 1349.19 – Private Disclosure of Security Breach of Computerized Personal Information Data Enforcement of the notification law runs exclusively through the Ohio Attorney General; there is no private right of action for consumers to sue a company directly for a late or missing notice.2Ohio Legislative Service Commission. Ohio Code 1349.192 – Civil Action for Failure to Comply

Recording Conversations

Ohio is a one-party consent state. You can legally record any conversation you take part in without telling the other people involved.3Ohio Legislative Service Commission. Ohio Code 2933.52 – Interception of Wire, Oral, or Electronic Communications The same rule covers recordings made with permission from someone else in the conversation. The essential requirement is that at least one participant consents.

Where people get into trouble is recording conversations they are not part of. Intercepting a call between two other people, planting a hidden microphone, or using software to capture messages between third parties is illegal. The statute makes no exception for suspecting a spouse of infidelity or wanting to monitor a teenager’s calls. If you are not a party and no party has consented, you are breaking the law.

Illegal interception is a fourth-degree felony in Ohio.3Ohio Legislative Service Commission. Ohio Code 2933.52 – Interception of Wire, Oral, or Electronic Communications And a caveat worth knowing: even a recording that is legal under Ohio’s one-party rule can create liability if the person on the other end is in a state that requires all-party consent. That state’s law can reach you.

Right of Publicity

Ohio law prohibits using someone’s persona for commercial purposes without written consent.4Ohio Legislative Service Commission. Ohio Revised Code Chapter 2741 – Right of Publicity in Individual’s Persona “Persona” covers a person’s name, voice, signature, photograph, image, likeness, or distinctive appearance, provided any of those elements have commercial value.5Ohio Legislative Service Commission. Ohio Revised Code 2741.01 – Right of Publicity in Individual’s Persona Definitions The prohibition reaches advertising, product promotion, fundraising, and travel marketing.

The right is not limited to living people. Publicity rights last 60 years after death for individuals domiciled or residing in Ohio, and heirs or assignees can enforce them during that period.4Ohio Legislative Service Commission. Ohio Revised Code Chapter 2741 – Right of Publicity in Individual’s Persona

A plaintiff can recover actual damages plus any profits the violator earned, or elect statutory damages between $2,500 and $10,000.6Ohio Legislative Service Commission. Ohio Code 2741.07 – Damages in Civil Action to Enforce Publicity Right Treble damages, attorney’s fees, and court costs are available when the violator knowingly used the persona without authorization, and punitive damages are available in appropriate cases under Ohio’s general punitive damages statute.

Social Media and Children Under 16

Ohio requires social media operators with Ohio users to obtain verifiable parental consent before allowing a child under 16 to create an account or agree to terms of service.7Ohio Legislative Service Commission. Ohio Code 1349.09 – Parental Consent for Minors on Social Media That age is higher than the federal COPPA threshold of 13, so Ohio teenagers get an extra layer of protection.

Accepted verification methods include a signed and returned consent form, a credit card or payment system that notifies the primary account holder, a call to a toll-free number staffed by trained personnel, a video conference, or verification through government-issued identification. If the parent does not consent, the platform must deny the child access.

Consent is not permanent. A parent who initially agrees can notify the platform of a withdrawal, and the operator then has 30 days to terminate the child’s account.7Ohio Legislative Service Commission. Ohio Code 1349.09 – Parental Consent for Minors on Social Media

Privacy at Work

Ohio employees have limited privacy on company equipment. Employers can monitor emails, internet activity, and files kept on company-owned computers and phones, and most establish that authority through acceptable-use policies that new hires sign. The existence of that policy generally ends the argument over whether monitoring was permitted.

Personal devices and accounts are different territory. Tracking activity on a company network is one thing; demanding login credentials for an employee’s personal social media profile is another, and many courts have declined to allow it. Ohio has no specific statute banning that practice, so where the line falls depends on the facts and any written policy in place.

One federal restriction applies flatly to Ohio employers. The Employee Polygraph Protection Act prohibits most private employers from requiring or even suggesting that employees or applicants take a lie detector test, and it bars discipline for refusing, filing a complaint, or participating in a related proceeding.8U.S. Department of Labor. Employee Polygraph Protection Act Violations can trigger civil penalties of up to $26,262 per incident.

Federal Laws That Fill the Gaps

Because Ohio lacks a comprehensive privacy statute, several federal laws carry most of the weight for specific categories of data. These apply in Ohio regardless of state law.

Health Information

The Health Insurance Portability and Accountability Act requires healthcare providers, insurers, and their business associates to protect electronic health information. Under a 2025 update to the HIPAA Security Rule, encryption is now mandatory for all electronic protected health information both at rest and in transit; the prior treatment of encryption as merely “addressable” has been eliminated. Data that meets NIST encryption standards with an uncompromised key is considered “secured,” so a breach of that data does not trigger notification.

Financial Data

The Gramm-Leach-Bliley Act requires banks, lenders, insurers, and other financial institutions to explain their data-sharing practices, including what they collect, who they share it with, and how they protect it.9Federal Trade Commission. Gramm-Leach-Bliley Act Customers can opt out of certain third-party sharing, and institutions must maintain a written information security program with administrative, technical, and physical safeguards.

Credit Reports

The Fair Credit Reporting Act controls who can pull your credit report and what happens when it’s wrong. Only parties with a recognized need can access it, such as creditors evaluating a loan application, landlords screening tenants, or employers with your written consent.10Consumer Financial Protection Bureau. A Summary of Your Rights Under the Fair Credit Reporting Act You get one free disclosure from each nationwide credit bureau every 12 months, and credit agencies must investigate disputes and correct or remove inaccurate information, usually within 30 days.

Negative information generally falls off after seven years; bankruptcies can stay up to ten. You can place a security freeze, which blocks new creditors from accessing your report without your authorization, and fraud alerts lasting one year, or seven years for confirmed identity theft victims.10Consumer Financial Protection Bureau. A Summary of Your Rights Under the Fair Credit Reporting Act

Children Online

The federal Children’s Online Privacy Protection Act requires websites, apps, and online services to obtain verifiable parental consent before collecting personal information from children under 13. Ohio’s social media law raises that threshold to 16 for social media platforms specifically, so Ohio children aged 13 to 15 get state protection that goes beyond COPPA alone.

A Note for Businesses: The Cybersecurity Safe Harbor

Ohio’s Data Protection Act is a business-side incentive, not a consumer right. A company that builds and maintains a cybersecurity program conforming to a recognized industry framework earns an affirmative defense against lawsuits claiming it failed to implement reasonable security controls after a breach.11Ohio Legislative Service Commission. Ohio Code 1354.02 – Safe Harbor Requirements Qualifying frameworks include the NIST Cybersecurity Framework, several NIST Special Publications, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, and the ISO/IEC 27000 family; companies already regulated under HIPAA, GLBA, or similar federal laws can qualify by conforming to those requirements.12Ohio Legislative Service Commission. Ohio Code 1354.03 – Industry Recognized Cybersecurity Frameworks The safe harbor is a defense a company must prove in court, not immunity from being sued.