Enhance your TRUST relationship with PRIVACY and SECURITY. Privacy Made Simple!

   +1 866 267 0049   830 NE Pop Tilton Place, Jensen Beach, FL 34957

Ohio
Privacy Laws

Overview

BREACH NOTIFICATION – Mandated Timeframe
Within 45 days

FINES & PENALTIES – Violations
Max $1,000/day & $10,000 after 90 days

Legal

Regulation Levels

  • Breach Reporting

    Breach Reporting

  • Consumer Notification

    Consumer Notification

  • Vendor Management

    Vendor Management

  • Vendor Contract Required

    Vendor Contract Required

PRIVACY AND SECURITY LAWS

Laws related to personal information and privacy and security.

QUICK FACTS

Ohio Privacy Law Information

PRIVACY PROGRAM

Organizations must create, maintain, and comply with a written cybersecurity program that contains administrative, technical, and physical safeguards for the protection of personal information.

BREACH REPORTING

If any state residents are affected by a breach, the breached Organization must give notice to each affected individual within 45 days of discovery of the breach. If more than 1,000 residents of this state are involved in a single occurrence of a breach, notification is required, without unreasonable delay, to all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis.

CONSUMER NOTIFICATION

If a breach affects residents of other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.

VENDOR/THIRD PARTIES

Vendors must notify Organizations as soon as possible after the discovery of a breach or suspected breach. The Organization will be responsible to complete any required regulatory reporting and consumer notification.

INDUSTRY SPECIFIC LAWS

Ohio passed the Insurance Data Security Law, which includes requirements for insurance licensees to protect personal information and investigate and respond to data breaches. Licensees must comply with the breach notification requirements, including Commissioner notification within 3 business days.

FINES & PENALTIES

The Attorney General may bring an action for violations of the breach notification requirements that brings a penalty of up to $1,000 per day for failed compliance. Further failure to comply will result in fines of $5,000 per day after 60 days and $10,000 per day after 90 days.

Ohio Statutes and Laws

OHIO REV. CODE § 1349.17

Restricting recording credit card, telephone or social security numbers

OHIO REV. CODE § 1349.18

Printing credit card number and expiration date on receipt

OHIO REV. CODE § 1349.19

Private disclosure of security breach of computerized personal information data

OHIO REV. CODE §§ 1354.01 – 1354.05

Definitions

OHIO REV. CODE §§ 3965.01 – 3965.11

Cybersecurity Requirements for Insurance Companies

DISCLAIMER

The information provided is not legal guidance or recommendations and are for informational purposes only.