Below is a high-level comparison of media sanitization and Ohio's digital safe harbor law. It is intended for technical and business leaders who want to understand quickly how the two interact. It is not legal advice and is not a substitute for counsel.
Protecting sensitive data and disposing of it properly are responsibilities for organizations of every size. Ohio's Data Protection Act, often called the digital safe harbor law, and NIST 800-88, the federal guideline for media sanitization, serve different purposes, but they complement each other: one sets a legal incentive, the other describes the technical practice that satisfies it.
What the Ohio Data Protection Act is
Enacted in 2018 as Ohio Revised Code Chapter 1354, the Data Protection Act provides an affirmative defense for organizations that experience a data breach involving personal information, if they can show they had created, maintained, and complied with a written cybersecurity program that reasonably conforms to a recognized framework. Organizations that follow best practices, including proper data disposal, may be shielded from certain tort claims that would otherwise follow a breach.
Key provisions
- A written cybersecurity program. The program must reasonably conform to a recognized framework such as the NIST Cybersecurity Framework, NIST SP 800-171 or 800-53, the CIS Controls, or an applicable regulatory regime like HIPAA or GLBA. A media sanitization policy, regular risk assessments, employee training, and technical safeguards belong in it.
- Scale and scope. The program must be appropriate to the size of the business, the sensitivity of the information, and the resources available.
- Proper data disposal. Every framework the statute recognizes includes disposal controls. Following industry standards for destroying personal information when it is no longer needed is part of conforming.
What NIST 800-88 is
NIST SP 800-88, Guidelines for Media Sanitization, is the federal framework for securely removing data from electronic storage media so it cannot be recovered. Revision 2 has been final since September 2025. It defines three methods:
- Clear: overwriting data so it cannot be recovered with ordinary tools, while the media remains usable.
- Purge: more intensive techniques that render data unrecoverable even by laboratory methods. These commands are media-specific and do not use the general read-write path; Revision 2 points to IEEE 2883 for the technique that matches each media type.
- Destroy: physically destroying the media so it cannot be reused or reconstructed. The most secure method, and the only one whose result you can see.
Regulators, auditors, and courts reference NIST 800-88 because it is the recognized standard.
How the two interact
Safe harbor through adherence to best practices
The statute asks you to prove you followed a recognized framework. Media sanitization to NIST 800-88 is how the disposal portion of any of those frameworks is satisfied in practice. Implementing the appropriate technique for each media type, and being able to show it, is evidence that you took reasonable steps. But not every sanitization option is appropriate for every organization. Each one must do its own risk analysis and choose the level that fits the sensitivity of its data.
Reducing risk and liability
Following NIST 800-88 reduces the chance of data surviving on decommissioned devices, which is where a surprising number of breaches begin. An organization that has already implemented documented destruction can present a strong defense that it took reasonable care.
Documentation
The safe harbor turns on what you can demonstrate. NIST 800-88 specifies the records to keep: the method used, the devices sanitized, the personnel involved, and verification. A Certificate of Destruction with serial numbers is the artifact that makes the defense concrete.
The bottom line
Ohio's Data Protection Act and NIST 800-88 together give organizations a path to both legal protection and real data security. Adopt a recognized framework, sanitize media to NIST 800-88 at the level your data requires, and document it. In an era of increasing privacy concerns, proactive disposal is not just a legal obligation; it is a commitment to the people whose information you hold.
Mansfield Technologies provides on-site mobile destruction for organizations with high-security needs. We destroy drives, SSDs, tapes, and paper at your site, under your supervision, and we are one of very few providers able to perform mobile destruction of classified media to NSA/CSS 9-12. Contact us if that is the level your data requires.
This document is not legal advice and is not a replacement for proper legal counsel.
