Ohio § 1354.02
Full text of Ohio Ohio Revised Code § 1354.02, with citation guidance and answers to common questions.
§ 1354.02.
(A) A covered entity seeking an affirmative defense under sections 1354.01 to 1354.05 of the Revised Code shall do one of the following: (1) Create, maintain, and comply with a written cybersecurity program that contains administrative,
technical, and physical safeguards for the protection of personal information and
that reasonably conforms to an industry recognized cybersecurity framework, as described
in section 1354.03 of the Revised Code ; or (2) Create, maintain, and comply with a written cybersecurity program that contains administrative,
technical, and physical safeguards for the protection of both personal information
and restricted information and that reasonably conforms to an industry recognized
cybersecurity framework, as described in section 1354.03 of the Revised Code . (B) A covered entity's cybersecurity program shall be designed to do all of the following
with respect to the information described in division (A)(1) or (2) of this section,
as applicable: (1) Protect the security and confidentiality of the information; (2) Protect against any anticipated threats or hazards to the security or integrity of
the information; (3) Protect against unauthorized access to and acquisition of the information that is
likely to result in a material risk of identity theft or other fraud to the individual
to whom the information relates. (C) The scale and scope of a covered entity's cybersecurity program under division (A)(1)
or (2) of this section, as applicable, is appropriate if it is based on all of the
following factors: (1) The size and complexity of the covered entity; (2) The nature and scope of the activities of the covered entity; (3) The sensitivity of the information to be protected; (4) The cost and availability of tools to improve information security and reduce vulnerabilities; (5) The resources available to the covered entity. (D)(1) A covered entity that satisfies divisions (A)(1), (B), and (C) of this section is
entitled to an affirmative defense to any cause of action sounding in tort that is
brought under the laws of this state or in the courts of this state and that alleges
that the failure to implement reasonable information security controls resulted in
a data breach concerning personal information. (2) A covered entity that satisfies divisions (A)(2), (B), and (C) of this section is
entitled to an affirmative defense to any cause of action sounding in tort that is
brought under the laws of this state or in the courts of this state and that alleges
that the failure to implement reasonable information security controls resulted in
a data breach concerning personal information or restricted information.
Frequently Asked Questions About Ohio § 1354.02
What does Ohio Revised Code § 1354.02 cover?
Section 1354.02 is part of the Ohio Revised Code, the codified statutory law of Ohio. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.
How do I cite Ohio § 1354.02?
A common citation format is "Ohio Revised Code § 1354.02" (Ohio). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.
Is this the official text of Ohio law?
No. This page is for research and education and may not include the most recent amendments. For official current law, check the Ohio official source linked on this page or consult a licensed Ohio attorney.
How does Ohio § 1354.02 apply to my situation?
Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Ohio can advise on how this section applies to you. Contact your state or local bar association for a referral.
Sources & Verification
Not legal advice. Verify against the official source and consult a licensed attorney in Ohio.