What Ohio’s Cybersecurity Safe Harbor and Kentucky’s New Privacy Law Mean for Businesses Operating in Both States

Hexagonal icons representing data backup and IT services, including cloud storage, databases, servers, file recovery, and cybersecurity.

Plenty of businesses around this area operate on both sides of the river: an office in Blue Ash, a warehouse in Hebron, maybe a couple of sales reps working out of Lawrenceburg When it comes to data protection, the rules attach to the state. This means one company can be running under two regimes at the same time.

Ohio and Kentucky have taken opposite approaches, and the gap between them got wider on January 1, 2026. We work with businesses across the Cincinnati and Northern Kentucky market, so this comes up on both sides of the bridge. If this is you, here’s what you need to know.

Ohio’s Data Protection Act: A Written Security Program Buys You a Legal Defense

Ohio passed the Data Protection Act, Senate Bill 220, back in 2018. Gov. John Kasich signed it on August 3, 2018, it took effect that November, and it sits in the Ohio Revised Code at sections 1354.01 through 1354.05. It was the first law of its kind in the country.

Here’s how it works. Write a cybersecurity program, keep it current, follow it, and make sure it conforms to one of eight recognized frameworks. Do that, and you get an affirmative defense against tort claims brought after a data breach. The qualifying frameworks include the NIST Cybersecurity Framework, the CIS Critical Security Controls, the ISO/IEC 27000 family, FedRAMP, FISMA, HIPAA, and HITECH. Businesses that take payment cards can qualify through PCI-DSS paired with one of the others.

An affirmative defense is a narrow thing. Anyone can still sue you after a breach; what the law hands you is something to plead once you’re in court, along with a shift in who carries the burden of proof.

Two details make this more reachable than owners tend to expect. The standard scales to your business, so the size and complexity of the company, the sensitivity of the data you hold, what security tools cost and whether they’re available to you, and the resources you have to spend all factor into whether your program qualifies. And the bar is reasonable conformity with a framework rather than perfect compliance.

The whole thing is voluntary. It sets no minimum security standard and creates no liability for businesses that ignore it. Ohio built a carrot and skipped the stick.

Ohio has no comprehensive consumer privacy law

Ohio still has no comprehensive consumer privacy law. House Bill 376 stalled in 2021, House Bill 345 was introduced in 2023 and never passed, and the 2026 bill called the Ohio Privacy Act (House Bill 801) applies to state government agencies rather than private businesses. Ohio residents have no state-law right to see, correct, or delete the personal data a company holds on them.

Kentucky’s Consumer Data Protection Act Took Effect January 1, 2026

Kentucky residents got those rights this year. The Kentucky Consumer Data Protection Act was signed by Gov. Andy Beshear on April 4, 2024, took effect January 1, 2026, and is codified at KRS 367.3611 through 367.3629.

Under the KCDPA, Kentucky consumers can confirm that a business is processing their data, access it, correct it, delete it, get a portable copy, and opt out of targeted advertising, data sales, and certain kinds of profiling. Sensitive data requires opt-in consent. Covered businesses have 45 days to respond to a request and have to give consumers a way to appeal a denial. They also have to keep appropriate administrative, technical, and physical safeguards around the data itself.

The Kentucky Attorney General enforces the law, and that office stood up a new Office of Data Privacy to handle it.

Who the Kentucky law applies to, and why smaller companies should still watch it

Before anyone panics: the KCDPA has high applicability thresholds. It reaches businesses that control or process the personal data of 100,000 or more Kentucky consumers in a calendar year, or 25,000 or more if the company draws over half its gross revenue from selling personal data. There is no revenue-only trigger.

Most companies in Boone, Kenton, and Campbell counties are nowhere near 100,000 Kentucky consumers. A 60-person manufacturer in Florence or a regional accounting firm in Erlanger almost certainly falls outside it.

There are still two reasons to keep an eye on this. Data protection assessment requirements apply to processing activities created on or after June 1, 2026, which means covered companies are working through that right now. And the law reaches processors, meaning businesses that handle data on someone else’s behalf. In practice, covered customers pass obligations down through their vendor contracts, and that’s usually how a smaller company first runs into a privacy law it isn’t directly subject to.

Indiana’s Consumer Data Protection Act took effect the same day, January 1, 2026. Two of the three states in this metro now have comprehensive privacy laws.

How to Document One Program That Satisfies Both States

Start by figuring out which entity holds what. Payroll files for Kentucky employees, customer records sitting in a CRM, backups living in a data center three states away: which law applies depends on where the data subject lives and which entity controls the data, and most companies have never written any of that down.

From there, pick a framework and put the program in writing. The NIST Cybersecurity Framework and the CIS Controls are the two that small and midsize businesses can work with without hiring a compliance team. Writing it down is the specific act that qualifies you in Ohio, and Kentucky’s security obligations rest on the same set of controls, so one project covers both sides of the river. This is the part most owners hand to an IT partner, because the documentation only holds up if the controls behind it stay maintained.

Somewhere in there, count your Kentucky consumers properly. Plenty of companies eyeball that number and guess low.

Most of this gets done once and then maintained. The part that surprises people is that a single company can sit under two sets of rules at the same time, and a breach is an expensive way to find that out.

If you hold customer or employee data on both sides of the river and nobody has written down which entity holds what, start there. CMIT Solutions of Cincinnati & Northern Kentucky handles security programs, framework documentation, and the controls underneath them for businesses across the metro. Get in touch and we’ll map where your data sits.

This is general information about state law, not legal advice. Talk to your attorney about how these laws apply to your specific business.

 

Back to Blog

Share:

Related Posts

Screen with 0s and 1s and the word "outsourcing" for IT departments

Why Outsource Your IT Department?

Cincinnati Businesses come to us when they have a problem. They come…

Read More
What is cybersecurity and why do companies need it

What Is Cybersecurity (and Why Do Companies Need It)?

Occurrences of computer network attacks are now as common among large corporations…

Read More
Managed IT Services for Healthcare

Managed IT Services for Healthcare Providers Offers Three Excellent Benefits

The pace of advances in consumer technology over the past 10 years…

Read More