← All jurisdictions
OH · data breach notification

Ohio

med

Ohio Rev. Code §§1349.19–192

Individual deadline
45 days
Trigger standard
Risk of harm
AG / regulator
Not required
Notice to individuals45 calendar days from discovery
Risk-of-harm standardnotice where breach reasonably believed to cause material risk of identity theft or fraud
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeNot required for private-entity breaches.
Credit reporting agenciesNotify CRAs above 1,000 residents.
Substitute noticeTypically available above $250,000 cost / 500,000 affected (verify).
Private right of actionNo, enforcement by the state.
Notes
Ohio Data Protection Act (§1354): affirmative-defense safe harbor for conforming cybersecurity programs

Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Ohio breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →