Ohio Passes Law Providing Safe Harbor for Businesses Suffering Data Breach

Robinson+Cole Data Privacy + Security Insider
Contact

The Ohio legislature recently passed S.B. 220, which gives businesses that suffer a data breach an affirmative defense against tort claims brought in class action suits.

The law goes into effect on November 2, 2018. Basically, the law gives the business a safe harbor if the business implements and complies with “a recognized cybersecurity framework.” The law lists the recognized cybersecurity frameworks that are included in the safe harbor, which are the well-known existing frameworks, such as:

  • NIST frameworks
  • HIPAA
  • Title V of Gramm-Leach-Bliley Act
  • PCI standards

The Act does not require minimum standards, and allows businesses to adopt a framework that is appropriate for the business, but the adoption and maintenance of the framework will be scrutinized if a business asserts the affirmative defense.

The legislation does not unilaterally provide a safe harbor as many data breach notification laws do for the adoption of statutorily approved encryption technology, but instead, allows the business to assert the safe harbor as an affirmative defense against the suit. It further does not allow a private right of action for plaintiffs to assert if a business does not implement a cybersecurity framework for its organization and then suffers a data breach.

The purpose of the Act is to “encourage businesses to achieve a higher level of cybersecurity through voluntary action.”

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide