Ohio’s Data Protection Act (SB 220) comes into force today, the first US state law giving a legal “safe harbour” to organisations with a recognised cybersecurity programme.
Key points
- Organisations that maintain a written cybersecurity programme reasonably conforming to an industry framework gain an affirmative defence to breach-related tort claims.
- Recognised frameworks include ISO/IEC 27001, NIST CSF, NIST SP 800-171, CIS Controls and PCI DSS.
- The programme must be scaled to the organisation’s size, activities and data sensitivity.
- Compliance is voluntary.
The law shows how frameworks such as ISO/IEC 27001 can reduce legal exposure. UK organisations serving Ohio customers can benefit from certification, and other states are expected to follow.
Source: Ohio Revised Code Chapter 1354 (Ohio Laws)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.