Doe v. Columbus
CourtOhio Court of Appeals
Date FiledSeptember 24, 2026
Docket25AP-798 & 25AP-799
JudgeBoggs
StatusPublished
📰 News Coverage: Read the LAWS.com news report on this case
Full Opinion
[Cite as Doe v. Columbus, 2026-Ohio-3743.]
IN THE COURT OF APPEALS OF OHIO
TENTH APPELLATE DISTRICT
John Doe et al., :
Plaintiffs-Appellants, : Nos. 25AP-798
(C.P.C. No. 24CV-6195)
v. : and
No. 25AP-799
City of Columbus, : (C.P.C. No. 24CV-6428)
Defendant-Appellee. : (REGULAR CALENDAR)
D E C I S I O N
Rendered on September 24, 2026
On brief: Meyer Wilson Werning Co., LPA, Matthew R.
Wilson, and Jared W. Connors; Cooper & Elliot, LLC, Rex H.
Elliott, and Spencer C. Meador; Arnold & Clifford, LLP,
James E. Arnold, Damion M. Clifford, Gerhardt A. Gosnell II,
and Damien C. Kitte; Schiff & Associates Co., L.P.A., Scott W.
Schiff, and Zachary L. Schiff, for appellants. Argued:
Jared W. Connors.
On brief: Zachary M. Klein, City Attorney, Lara N. Baker-
Morrish, Westley M. Phillips, and Paul M. Bernhart; Vorys,
Sater, Seymour and Pease LLP, Christopher L. Ingram, John
Landolfi, Henry J. Moseley, Celina J. Needle, Margaret S.
Echols, for appellee. Argued: Christopher L. Ingram.
APPEALS from the Franklin County Court of Common Pleas
BOGGS, P.J.
{¶ 1} Plaintiffs-appellants, John Doe Nos. 1 through 5 and Jane Doe, appeal the
Franklin County Court of Common Pleas’ judgments granting a motion by defendant-
appellee, the City of Columbus, to dismiss appellants’ complaints, which asserted claims
arising from a cyberattack on the city’s information technology (“IT”) system in July 2024.
For the following reasons, we reverse the trial court’s judgments.
Nos. 25AP-798 & 25AP-799 2
I. FACTS AND PROCEDURAL BACKGROUND
{¶ 2} These consolidated appeals stem from two cases, each of which named the
city as the sole defendant, filed in the trial court in August 2024. Appellants identified as
John Doe Nos. 1 and 2 filed case No. 24CV-6195 on August 9, 2024, and appellants
identified as John Does Nos. 1 through 8 and Jane Doe No. 1 filed case No. 24CV-6428 on
August 20, 2024. The trial court consolidated the cases on November 7, 2024, after which
appellants filed a Consolidated Amended Class Action Complaint (the “consolidated
complaint”), individually and on behalf of a class of “[a]ll persons whose [personally
identifiable information (“PII”)] was released and compromised in the [July 2024] Data
Breach[.]” (Dec. 20, 2024 Consol. Compl. at ¶ 124.) Appellants John Does Nos. 1 through
5, who are city-employees, also brought this action on behalf of a subclass of individuals
consisting of “[a]ll employees of the [city] . . . whose PII was compromised in the Data
Breach[.]” Id. at ¶ 125. The consolidated complaint alleges claims of
negligence/recklessness, negligence per se, breach of implied contract, invasion of privacy,
and breach of fiduciary duty, all arising out of the July 2024 cyberattack.
{¶ 3} Appellants are five city employees who provided personal information to the
city in connection with their employment and one non-employee who provided personal
information to the city in connection with a visit to city hall and payment of a parking ticket.
John Doe No. 1 is an undercover city police officer who received notification that his PII is
on the Dark Web and who fears for his safety and financial security as a result. John Doe
No. 2 is a city police officer whose bank account revealed unauthorized purchases and who
received a text message after the cyberattack demanding a ransom to avoid release of his
information on the Dark Web. John Doe No. 3, also a city police officer, has spent time and
money since the cyberattack to ensure that his stolen data would not be used. John Doe
No. 4, a city employee, has received ransom emails threatening to distribute his PII. John
Doe No. 5, a city firefighter, has received alerts that his credit card has been compromised
and information indicating that his Social Security number and work email address are
accessible on the Dark Web. The final appellant, Jane Doe, has never been a city employee,
but she provided her driver’s license to the city to gain access to city hall and provided
personal information to the city when she paid a parking ticket. A credit-monitoring service
Nos. 25AP-798 & 25AP-799 3
has notified her that her PII has appeared on the Dark Web. All appellants allege they have
suffered actual injury from the theft and exposure of their PII.
{¶ 4} In the consolidated complaint, appellants allege that the city “failed to
maintain reasonable security safeguards or protocols to protect the Class’s PII and failed to
adequately train its employees on cybersecurity.” Id. at ¶ 5; see also id. at ¶ 49. More
specifically, they allege the city “failed to design and structure its IT systems to limit the
possible harm from a breach, including but not limited to compartmentalizing City systems
so that a breach of one system will not implicate all City systems,” id. at ¶ 50, and “failed to
design and structure its IT systems to ensure that access is controlled and monitored to
prevent breaches of this type and to allow the City to identify the source and circumstances
of the breach.” Id. at ¶ 51. Appellants maintain that the city failed to follow industry
standards and federal guidelines for data security and that, by downplaying the impact of
the breach, it delayed remedial action and exacerbated the resultant harm. Appellants
allege the activities “at issue in this litigation-the operation of a city-wide IT infrastructure—
are Proprietary Activities as defined by [R.C.] 2744.01(G)(1).” Id. at ¶ 18.
{¶ 5} Because the trial court decided this matter under Civ.R. 12(B)(6), based solely
on its determination that the city is entitled to political-subdivision immunity under R.C.
Chapter 2744, we focus primarily on the alleged facts in the consolidated complaint that
relate to the question of immunity.
{¶ 6} The city, a municipal corporation, “maintains a host of city services, including
but not limited to first responders such as the Columbus Police Department (‘CPD’) and the
Columbus Fire Department. The City is also responsible for the Franklin County Municipal
Court.” Id. at ¶ 21. “In connection with providing these services, [the city] has a
Department of Technology (‘DoT’), which has a ‘primary mission [of] supporting and
partnering with public facing agencies across the City in using technology to serve the
residents and businesses of Columbus and Central Ohio.’ ” Id. at ¶ 22, quoting
https://www.columbus.gov/Government/Departments/Technology/About-DoT. The
DoT “operates by ‘planning, designing, procuring, and delivering information technology,
telecommunications, and media services in partnership with City departments, City
Council, boards and commissions, and other government entities.’ ” Id. at ¶ 23, quoting
https://www.columbus.gov/Government/Departments/Technology/About-DoT.
Nos. 25AP-798 & 25AP-799 4
{¶ 7} The city maintains a “single, unified IT system for all City services and
entities.” Id. at ¶ 28. It “maintains, via its consolidated [IT] infrastructure, the electronic
records for all City operations.” Id. at ¶ 2. Those records include “highly sensitive [PII] and
other sensitive information about both its current and former City employees and citizens
who interact with the City in various capacities.” Id. at ¶ 3. Appellants allege the city
“agreed it would safeguard the data” in its possession “in accordance with its internal
policies, and state and federal law.” Id. at ¶ 29.
{¶ 8} On July 19, 2024, “particularly sophisticated” cybercriminals targeted the
city’s IT system with a cyberattack. Id. at ¶ 54. The city publicly acknowledged the
cyberattack on July 29, 2024 and stated in a press release that the DoT had “ ‘quickly
identified the threat and took action to significantly limit potential exposure, which
included severing internet connectivity.’ ” Id. at ¶ 35. On July 31, 2024, however,
cybercriminals posted on the Internet that they were in possession of data, including PII,
from the city’s IT system and that they would make available for sale on the Dark Web if
the city did not pay a ransom. The city notified employees on August 1, 2024 that
cybercriminals had accessed its data, and the city offered employees two years of credit-
monitoring service.
{¶ 9} On August 5, 2024, cybercriminals attempted to auction 6.5 terabytes of the
city’s data, including “ ‘internal login and passwords of employees, a full dump of servers
with emergency services applications of the city, [and] access from city video cameras.’ ”
Id. at ¶ 40. A portion of the stolen data was released to the Dark Web on August 8, 2024.
Columbus Mayor Andrew Ginther stated on August 13, 2024 that the released data was
either encrypted or corrupted and was, thus, unusable by bad actors, but “data security
professionals have reviewed the information on the Dark Web and have been able to
identify the PII of City of Coumbus employees and citizens.” Id. at ¶ 44. Appellants claim
they have evidence that their information has been delivered onto the Dark Web in usable
form.
{¶ 10} In the consolidated complaint, appellants, on behalf of the proposed class and
subclass, seek declaratory, injunctive, and other equitable relief, in addition to money
damages, interest, and attorney fees. They claim the city breached its duties by utilizing
inadequate security practices and was negligent in failing to prevent the data breach. They
Nos. 25AP-798 & 25AP-799 5
claim the city failed to follow guidelines issued by the Federal Trade Commission (“FTC”),
which has encouraged that “the need for data security should be factored into all business
decision-making,” as well as relevant industry standards. Id. at ¶ 114.
{¶ 11} Pursuant to Civ.R. 12(B)(6), the city filed a motion to dismiss the
consolidated complaint for failure to state a claim upon which relief could be granted. The
city argued it is entitled to political-subdivision immunity from appellants’ tort-based
claims, that appellants lack standing to sue, and that the consolidated complaint otherwise
fails to state cognizable claims against the city. After full briefing by the parties, the trial
court rejected the city’s standing argument and held that appellants alleged sufficient facts
to establish standing under Ohio law. Nevertheless, the trial court granted the city’s motion
to dismiss, concluding, as a matter of law, that the city is entitled to political-subdivision
immunity under R.C. Chapter 2744.
{¶ 12} Appellants filed a timely notice of appeal.
II. ASSIGNMENT OF ERROR
{¶ 13} Appellants raise a single assignment of error, challenging only the trial court’s
dismissal of their tort claims: “Because cybersecurity is a proprietary function, not a
governmental function, the trial court erred in granting the City of Columbus political
subdivision immunity on Plaintiffs-Appellants’ tort-based claims.” (Appellants’ Brief at 1.)
III. DISCUSSION
A. Political-Subdivision Immunity
{¶ 14} R.C. Chapter 2744, Ohio’s Political Subdivision Tort Liability Act, “generally
shields political subdivisions from tort liability in order to preserve their fiscal integrity.”
Riscatti v. Prime Properties Ltd. Partnership, 2013-Ohio-4530, ¶ 15, citing Hubbell v.
Xenia, 2007-Ohio-4839, ¶ 23, and R.C. 2744.02(A)(1). R.C. Chapter 2744 sets out a three-
tiered analysis for determining whether a political subdivision is immune from liability.
Doe v. Greenville City Schools, 2022-Ohio-4618, ¶ 9. First, R.C. 2744.02(A)(1) sets out a
general rule that political subdivisions and their employees are immune, but “[t]hat
immunity. . . is not absolute.” Id. at ¶ 10, citing Hill v. Urbana, 1997-Ohio-400. As to the
first tier of the immunity analysis here, there is no dispute that the city, as a municipal
corporation, is a political subdivision under R.C. 2744.01(F) and is, therefore,
presumptively immune from tort liability.
Nos. 25AP-798 & 25AP-799 6
{¶ 15} In addition to setting out a general rule of immunity, R.C. 2744.02(A)(1)
classifies the functions of political subdivisions as either governmental functions or
proprietary functions and states that the general rule of immunity is limited by R.C.
2744.02(B), which lists five exceptions to that rule, when a political subdivision is not
immune. Greene Cty. Agricultural Soc. v. Liming, 2000-Ohio-486, ¶ 25. Under the second
tier of the analysis for determining whether a political subdivision is immune from liability,
courts must decide whether any of the exceptions to immunity set out in R.C. 2744.02(B)
apply. Id. In its motion to dismiss, the city argued that appellants cannot establish the
applicability of any exception under R.C. 2744.02(B) to the general rule of immunity.
{¶ 16} The only potentially applicable exception—and the only exception appellants
raised in the consolidated complaint and in their memorandum in opposition to the city’s
motion to dismiss—is R.C. 2744.02(B)(2), which states, in part: “political subdivisions are
liable for injury, death, or loss to person or property caused by the negligent performance
of acts by their employees with respect to proprietary functions of the political
subdivisions.” (Emphasis added.) Appellants allege in the consolidated complaint, “The
activities of [the city] at issue in this litigation—the operation of a city-wide IT
infrastructure—are Proprietary Activities as defined by [R.C.] 2744.01(G)(1).” (Consol.
Compl. at ¶ 18.) The city, on the other hand, argues that the operation of its IT
infrastructure is a governmental function to which the R.C. 2744.02(B)(2) exception to
immunity does not apply.
{¶ 17} If none of the exceptions to immunity listed in R.C. 2744.02(B) applies, the
trial court’s analysis is at an end, and the political subdivision retains immunity. See
Liming at ¶ 26. But if one or more of the R.C. 2744.02(B) exceptions does apply, the court
must proceed to the third and final tier of the immunity analysis, by which it must
determine if one of the defenses contained in R.C. 2744.03 applies to reinstate the political
subdivision’s immunity. Id. at ¶ 25, citing Cater v. Cleveland, 1998-Ohio-421, ¶ 15. Having
agreed with the city that appellants could not establish an applicable exception to immunity
under R.C. 2744.02, the trial court held that the city was entitled to immunity without
having to reach the third tier of the immunity analysis.
Nos. 25AP-798 & 25AP-799 7
B. Civ.R. 12(B)(6) and Standard of Review
{¶ 18} The city moved the trial court for dismissal pursuant to Civ.R. 12(B)(6),
arguing that the consolidated complaint failed to state a claim upon which relief could be
granted, because the city is entitled to immunity under R.C. Chapter 2744. A Civ.R.
12(B)(6) motion to dismiss tests the sufficiency of the complaint. Volbers-Klarich v.
Middletown Mgt., 2010-Ohio-2057, ¶ 11, citing Assn. for the Defense of the Washington
Local School Dist. v. Kiger, 42 Ohio St.3d 116, 117 (1989). When ruling on a Civ.R. 12(B)(6)
motion to dismiss, the court must presume the truth of all factual allegations in the
complaint and make all reasonable inferences in favor of the non-moving party. Mitchell
v. Lawson Milk Co., 40 Ohio St.3d 190, 192 (1988). The court need not, however, accept as
true unsupported conclusions of law contained in a complaint. See id. at 193. Before the
court may dismiss a complaint under Civ.R. 12(B)(6), it must appear beyond doubt that the
plaintiff can prove no set of facts in support of his claim that would entitle him to relief.
Schmitz v. NCAA, 2018-Ohio-4391, ¶ 10, citing O’Brien v. Univ. Community Tenants
Union, Inc., 42 Ohio St.2d 242, 245 (1975).
{¶ 19} Although a political subdivision’s entitlement to immunity is generally a
question of law, “[t]his does not mean . . . that the immunity question always can be
determined at the earliest stage of litigation,” as “questions of law may require courts to
evaluate ‘both facts and evidence in reaching its legal determination.’ ” Harris Farms, LLC
v. Madison Twp. Trustees, 2018-Ohio-4123, ¶ 38 (4th Dist.), quoting Pangle v. Joyce,
1996-Ohio-381. A trial court may properly grant a Civ.R. 12(B)(6) motion to dismiss based
upon an affirmative defense, like political-subdivision immunity, only when the affirmative
defense is conclusively established from the face of the complaint. Molnar v. Green, 2019-
Ohio-3083, ¶ 13 (9th Dist.), citing Brannon v. Edman, 2018-Ohio-70, ¶ 9 (9th Dist.).
Because a plaintiff is under no obligation to prove his case in the complaint, a plaintiff
“ ‘ “need not affirmatively dispose of the immunity question altogether at the pleading
stage.” ’ ” Id., quoting Chunyo v. Gauntner, 2017-Ohio-5555, ¶ 10 (9th Dist.), quoting Scott
v. Columbus Dept. of Pub. Utils., 2011-Ohio-677, ¶ 8 (10th Dist.). Indeed, a plaintiff is not
required to anticipate and plead specific facts to counteract a political subdivision’s
affirmative defense of sovereign immunity to withstand a motion to dismiss. Id. at ¶ 14,
citing Rogers v. Akron City School Sys., 2008-Ohio-2962, ¶ 19. Instead, a plaintiff needs
Nos. 25AP-798 & 25AP-799 8
only allege a set of facts that, if proven, would plausibly allow for recovery. Scott at ¶ 8.
Requiring a plaintiff to demonstrate an exception to immunity in the complaint would be
tantamount to “requiring the plaintiff to overcome a motion for summary judgment at the
pleading stage.” Id.
{¶ 20} We review a dismissal pursuant to Civ.R. 12(B)(6) de novo. Schmitz at ¶ 10,
citing Perrysburg Twp. v. Rossford, 2004-Ohio-4362, ¶ 5. Because the trial court
dismissed this case pursuant to Civ.R. 12(B)(6), we may look only to the consolidated
complaint and, like the trial court, must presume the factual allegations are true and make
all reasonable inferences in appellants’ favor. Id. at ¶ 3.
C. Application of R.C. 2744.02(B)(2)
{¶ 21} Because the city is undisputedly a political subdivision covered by the general
rule of immunity under the first tier of the immunity analysis, we turn to the second tier of
that analysis and consider the applicability of the exceptions to immunity listed in R.C.
2744.02(B). Particularly, we consider the applicability of R.C. 2744.02(B)(2), which
removes a political subdivision’s immunity for loss caused by its employee’s negligent
performance of acts with respect to the political subdivision’s proprietary functions.
Application of R.C. 2744.02(B)(2) here thus depends on whether appellants allege
negligence with respect to a governmental function or with respect to a proprietary
function.
{¶ 22} “[W]hether a function is proprietary or governmental often depends on the
particular facts of the case.” Scott at ¶ 17, citing Beauford v. Columbus, 1981 Ohio App.
LEXIS 12838 *4 (10th Dist. Oct. 13, 1981). A function is a governmental function if it is
specifically listed in R.C. 2744.01(C)(2) or if it satisfies one of the criteria in R.C.
2744.01(C)(1)(a) through (c). Proprietary functions, on the other hand, are listed in R.C.
2744.01(G)(2) or defined by criteria listed in R.C. 2744.01(G)(1). The definitions of
governmental functions and proprietary functions are “mutually exclusive.” 5812 Invest.
Group, LLC, v. Columbus, 2024-Ohio-5930, ¶ 15 (10th Dist.), citing Liming, 2000-Ohio-
486. “Where . . . the activity alleged in a complaint is not clearly a governmental function
based on the face of the complaint, a Civ.R. 12(B)(6) motion to dismiss, on the basis of R.C.
Chapter 2744 immunity, must be denied.” Scott at ¶ 17.
Nos. 25AP-798 & 25AP-799 9
{¶ 23} The city’s IT operations do not fall within any of the specifically listed
governmental or proprietary functions listed in R.C. 2744.01(C)(2) or (G)(2). Therefore,
like the trial court, we must look to R.C. 2744.01(C)(1) and (G)(1) to characterize the city’s
activity as governmental or proprietary. In its motion to dismiss, the city argued that its IT
infrastructure constitutes a governmental function under R.C. 2744.01(C)(1)(b) and (c).
R.C. 2744.01(C)(1) states, in relevant part:
“Governmental function” means a function of a political
subdivision . . . that satisfies any of the following: . . .
(b) A function that is for the common good of all citizens of the
state;
(c) A function that promotes or preserves the public peace,
health, safety, or welfare; that involves activities that are not
engaged in or not customarily engaged in by nongovernmental
persons; and that is not specified in division (G)(2) of this
section as a proprietary function.
Appellants, on the other hand, argued in response that operation of the city’s IT
infrastructure is a proprietary function under R.C. 2744.01(G)(1), which states, in part:
(1) “Proprietary function” means a function of a political
subdivision . . . that satisfies both of the following:
(a) The function is not one described in division (C)(1)(a) or (b)
of this section and is not one specified in division (C)(2) of this
section;
(b) The function is one that promotes or preserves the public
peace, health, safety, or welfare and that involves activities that
are customarily engaged in by nongovernmental persons.
{¶ 24} The trial court agreed with the city that its IT infrastructure constitutes a
governmental function under R.C. 2744.01(C)(1)(b) and (c), because it “supports core
public services, such as police, fire, and administrative operations.” (Sept. 26, 2025
Decision & Entry Granting Def. City of Columbus’ Mot. to Dismiss Filed Jan. 17, 2025 at
10.) It stated that the factual allegations in the consolidated complaint “describe an
integrated system for executing essential public services, rather than a service customarily
provided by private entities to the general public.” Id. at 12. It also noted that the city
operates its IT infrastructure through the DoT, which is established by the Columbus
Nos. 25AP-798 & 25AP-799 10
Municipal Code and is tasked with city wide responsibilities for technology management
and coordination.
{¶ 25} As they did in the trial court, appellants argue on appeal that the consolidated
complaint alleges negligence with respect to the city’s performance of a proprietary
function, for which the city is not entitled to immunity. They argue that the city’s IT and
cybersecurity activities are functions that do not benefit all citizens of the state under R.C.
2744.02(C)(1)(b) and that they do not qualify as a governmental function under R.C.
2744.02(C)(1)(c) because nongovernmental entities customarily engage in similar IT and
cybersecurity activities.
{¶ 26} To determine whether a function is a governmental or a proprietary function,
a court must first “ ‘ “defin[e] what . . . the political subdivision is actually doing when
performing the function.” ’ ” Alcus v. Bainbridge Twp., 2020-Ohio-543, ¶ 70 (11th Dist.),
quoting Kenko Corp. v. Cincinnati, 2009-Ohio-4189, ¶ 27 (1st Dist.), quoting Allied
Erecting & Dismantling Co., Inc. v. Youngstown, 2002-Ohio-5179, ¶ 41 (7th Dist.). A court
must “ ‘look at the particular, specific activity that allegedly resulted in the plaintiff’s
injury.’ ” 5812 Invest. Group, LLC at ¶ 19, quoting DSS Servs., L.L.C., v. Eitel’s Towing,
LLC, 2019-Ohio-3158, ¶ 18 (10th Dist.).
{¶ 27} The consolidated complaint characterizes the activities at issue as the city’s
“operation of a city-wide IT infrastructure” through which the city maintains electronic
records for all city operations and PII about current and former employees and citizens who
otherwise interact with the city. (Consol. Compl. at ¶ 18.) According to appellants, the July
2024 data breach occurred because the city “failed to maintain reasonable security
safeguards or protocols” to protect PII and “failed to adequately train its employees on
cybersecurity.” Id. at ¶ 5. Appellants challenge the “design and structure” of the city’s IT
system, id. at ¶ 50-51, as well as the city’s response to the breach.
{¶ 28} We will address in turn the trial court’s conclusions that the consolidated
complaint alleges negligence with respect to the city’s performance of a governmental
function under R.C. 2744.01(C)(1)(b) and (c).
1. R.C. 2744.01(C)(1)(b)
{¶ 29} Under R.C. 2744.01(C)(1)(b), governmental function includes “[a] function
that is for the common good of all citizens of the state.” Appellants argue that the city’s IT
Nos. 25AP-798 & 25AP-799 11
operations, and particularly its cybersecurity practices, were not undertaken for the
common good of all Ohioans, because they benefit only those individuals whose personal
information is held by the city. But the trial court rejected that argument as a too narrow
reading of R.C. 2744.01(C)(1)(b). The trial court cited Georgantonis v. Reading, 2020-
Ohio-3961 (1st Dist.), and Lyons v. Teamhealth Midwest Cleveland, 2011-Ohio-5501 (8th
Dist.), for the broad proposition that municipal functions involving public safety and
administration serve the common good of all Ohio citizens.
{¶ 30} As relevant here, the First District Court of Appeals held in Georgantonis that
a city’s operation and maintenance of a street-lighting system constituted a governmental
function under R.C. 2744.01(C)(1)(b) and (c). The court of appeals rejected the appellants’
argument that the street-lighting system was not for the common good of all state citizens
because it was geographically limited and benefited only visitors to nearby streets. The
court stated, “where, as here, the function is related specifically to the safety of the public,
courts have found the function to be for the common good of all state citizens.” Id. at ¶ 27.
See also Nordonia Landscape Supplies, LLC v. Akron, 2020-Ohio-2809, ¶ 10 (9th Dist.)
(removal of snow and ice from public roads is for the common good of all state citizens
because it makes vehicular travel safer and more convenient); Svette v. Caplinger, 2007-
Ohio-664, ¶ 17 (4th Dist.) (operation of a 911 service is a governmental function performed
for the common good of all citizens); Lyons (emergency dispatch service serves the
common good of all citizens).
{¶ 31} The Supreme Court of Ohio, however, has warned Ohio courts against
reading R.C. 2744.01(C)(1)(b) too broadly. Doing so, it stated, “would subsume the
definition of a governmental function found in R.C. 2744.01(C)(1)(c),” because “ ‘[a]ny
activity that promotes or preserves the public peace, health, safety, and welfare would also
fall within a broad definition of what is for the common good of all citizens of the state, thus
obscuring the legislature’s purpose in crafting a distinction between activities engaged in
or customarily engaged in by nongovernment persons and those that are not.’ ” Liming,
2000-Ohio-486, at ¶ 36, quoting Greene Cty. Agricultural Soc. v. Liming, 1999 Ohio App.
LEXIS 3710, *13-14 (2d Dist. Aug. 13, 1999). In other words, the Supreme Court instructed
that not every activity that promotes or preserves the public peace, health, safety, and
welfare can be considered an activity that is for the common good of all state citizens. The
Nos. 25AP-798 & 25AP-799 12
Supreme Court held in Liming that the Greene County Agricultural Society acted in a
proprietary function when it conducted a hog show at the Greene County Fair and when it
subsequently investigated the eligibility of one of the winning hogs. With respect to R.C.
2744.01(C)(1)(b), the Supreme Court stated, “The activities at issue benefit only some of the
citizens of the state, not all citizens.” Id. See also Ryll v. Columbus Fireworks Display Co.,
Inc., 2002-Ohio-2584, ¶ 24 (fireworks sponsored by municipality did not benefit all citizens
of the state); Alcus, 2020-Ohio-543, at ¶ 115 (11th Dist.) (“The Township’s maintenance of
its grounds only benefits some of the citizens of the state, mainly Township employees who
work there, and to some extent, the visitors who are permitted access, not all citizens of the
state.”).
{¶ 32} We cannot conclude, based solely on the allegations in the consolidated
complaint, that either the city’s maintenance and operation of its IT infrastructure or the
security safeguards it employed to protect PII stored within that system is an activity
performed for the common benefit of all citizens of the state.1 While the city uses IT
functionality in its provision of governmental functions like police, fire, and emergency
response, we must focus on the specific activity that allegedly resulted in appellants’
injuries. See 5812 Invest. Group, LLC, 2024-Ohio-5930, at ¶ 19 (10th Dist.). Indeed, in
Liming, the Supreme Court recognized that, while holding a county fair might be a
governmental function, the issue “is not whether holding a county fair is a governmental
function; rather, it is the more specific question of whether conducting the hog show at the
county fair and conducting the investigation into the allegations of irregularity surrounding
the entry of [the winning hog] are governmental functions.” Liming at ¶ 39. The Supreme
Court answered that question in the negative.
{¶ 33} To characterize the city’s maintenance and operation of its IT infrastructure,
and its protection of PII maintained therein, as activity related specifically to the safety of
the public and as a governmental function that benefits all citizens of the state simply
1 We acknowledge that the Fourth District Court of Appeals has concluded, with no analysis, that designating
street numbers and the development of an orderly system to do so served the common good of all state citizens
and, thus, constituted a governmental function under R.C. 2744.01(C)(1)(b). Nihiser v. Hocking Cty. Bd. of
Commrs., 2013-Ohio-3849, ¶ 17 (4th Dist.). With respect to its additional conclusion that the case involved a
governmental function under R.C. 2744.01(C)(1)(c), the Fourth District stated that street-number designation
assists timely and accurate emergency response. Id., citing Lyons. We disagree, however, that such an
attenuated connection to public safety justifies that court’s conclusion that the case involved a governmental
function under R.C. 2744.01(C)(1)(b).
Nos. 25AP-798 & 25AP-799 13
because public-facing city departments utilize the city’s IT systems stretches the precedent
the trial court cites too thinly. The provision of street lighting in Georgantonis and the
removal of snow and ice from public roads in Nordonia Landscape Supplies directly
enhanced the safety of public roads, open to all citizens, and can reasonably be understood
as extending that benefit to all citizens of the state, whether or not a particular citizen takes
advantage of driving upon those particular roads. There is no similar direct relationship
between the city’s maintenance and operation of its IT infrastructure and public safety. At
best, the public may indirectly benefit from the city’s provision of an IT infrastructure when
other city departments use that infrastructure to provide independent public-safety
services. The specific activity at issue here, however, directly benefits only those individuals
whose PII the city maintains in its IT systems, whereas a large swath of Ohio’s citizenry
undoubtedly has no connection to the city of Columbus, has provided no PII to the city, and
obtains no benefit whatsoever from the city’s IT infrastructure. We therefore conclude,
contrary to the trial court, that appellants’ claims do not involve a governmental function
under R.C. 2744.01(C)(1)(b).
2. R.C. 2744.02(C)(1)(c)
{¶ 34} We now turn to the trial court’s determination that appellants’ claims involve
a governmental function under R.C. 2744.01(C)(1)(c), i.e. a function “that promotes or
preserves the public peace, health, safety, or welfare; that involves activities that are not
engaged in or not customarily engaged in by nongovernmental persons; and that is not
specified in division (G)(2) of this section as a proprietary function.”
{¶ 35} Appellants argue that the city’s maintenance and operation of its integrated
IT system, and particularly its cybersecurity practices, cannot qualify as governmental
functions under R.C. 2744.01(C)(1)(c) because non-governmental entities customarily
perform those same activities. The relevant question is whether appellants pled facts
sufficient to demonstrate that the city’s activities vis-à-vis its IT infrastructure and
cybersecurity practices are activities customarily engaged in by nongovernmental persons.
See Doe v. Cleveland Metro. School Dist., 2012-Ohio-2497, ¶ 31 (8th Dist.). In Doe, the
appellant failed to plead facts demonstrating that the city’s actions in distributing grants
for educational purposes and assisting and overseeing the program for which those funds
Nos. 25AP-798 & 25AP-799 14
were provided were activities that are customarily conducted by non-governmental
persons. Id. at ¶ 32.
{¶ 36} There can be no doubt that non-governmental entities customarily maintain
and operate IT systems and implement cybersecurity practices, and the city does not argue
otherwise. Instead, contrary to the plain statutory language, the city seeks to shift the focus
with respect to the second prong of R.C. 2744.01(C)(1)(c) from who performs the activity to
who benefits from it. In support of that effort, the city cites Dalrymple v. Westerville, 2022-
Ohio-4094, ¶ 34 (10th Dist.), in which this court stated, “ ‘an activity that is customarily
performed by nongovernmental persons does not render proprietary an overarching
function that is governmental.’ ” Id., quoting McDonald v. Lacy, 2018-Ohio-2753, ¶ 18 (2d
Dist.), citing Shank v. Springfield, 1995 Ohio App. LEXIS 1818 (2d Dist. May 3, 1995.).
Dalrymple, however, does not support the city’s effort to distract from the statutorily
required consideration whether its relevant activity is an activity customarily performed by
nongovernmental entities. The appellant in Dalrymple claimed the city promised her grant
money but then withheld that money based on zoning and building-code requirements the
city had imposed with respect to renovations to her property. She argued that the issuance
of grant money is an activity customarily performed by non-governmental persons and,
therefore, constituted a proprietary function. Yet this court held that the appellant’s claims
arose out of the city’s performance of a governmental function, focusing not on the issuance
of grant money but on the city’s basis for withholding that money from the appellant. We
reasoned that the city engaged in a governmental function when it provided appellant
advice on compliance with building and zoning codes, and we stated, “the issue of grant
funds cannot be divorced from the fact that program funding (provided under the city’s
Façade Improvement Program and earmarked for improvements made to buildings in the
city’s historic district) was contingent upon an applicant’s compliance with applicable
building and zoning code requirements[.]” Id. at ¶ 38.
{¶ 37} Similarly, in McDonald, the Second District stated, “the construction (and
reconstruction) of [a] median was part of the city’s Entryway Enhancement Project, which
was a governmental function. So the activities connected with that project must be
considered in that context.” Id. at ¶ 19. That is the takeaway from Dalrymple and
McDonald: context matters. When a political subdivision engages in an overarching
Nos. 25AP-798 & 25AP-799 15
governmental function, individual components of its activities in support of that
governmental function do not become proprietary simply because, in another context, they
may be performed by non-governmental persons.
{¶ 38} The city also argues that activities necessary to perform governmental
functions constitute governmental functions themselves, but the cases it cites do not
support such a broad rule of law. For example, in Wolanin v. Holmes, 2007-Ohio-3410,
the Eighth District Court of Appeals held that operation of an internal shuttle on zoo
grounds was part of the political subdivision’s maintenance and operation of a zoo, which
is expressly defined as a governmental function under R.C. 2744.01(C)(2)(u)(iii). The court
did not conclude that operation of the shuttle was a governmental function because it was
necessary to the maintenance and operation of the zoo, but because it constituted
maintenance and operation of the zoo itself. In Moncrief v. Bohn, the Eighth District Court
of Appeals rejected the appellant’s argument that the Cuyahoga County Metropolitan
Housing Authority, acting as a landlord, was engaged in a proprietary function, because
operation of a public housing authority is itself a governmental function under R.C.
2744.01(C)(2). Moncrief, 2014-Ohio-837, ¶ 13 (8th Dist.), citing Moore v. Lorain Metro.
Hous. Auth., 2009-Ohio-1250, ¶ 17. The housing authority’s activity in Moncrief was
inherently part of operating a public housing authority. In Akron ex rel. Christman-Resch
v. Akron, 2005-Ohio-715 (9th Dist.), the court of appeals held that the city’s trapping of at-
large cats was part of its enforcement of city ordinances, and enforcement of the law is a
governmental function under R.C. 2744.01(C)(2)(i). The activities in those cases fell within
expressly defined governmental functions; the courts did not designate them as such
because they were necessary to the performance of other governmental functions.
{¶ 39} Citing Wilson v. Stark Cty. Dept of Human Servs., 70 Ohio St.3d 450 (1994),
the city argues that its integrated IT system is a governmental function because it is an
instrumentality through which it carries out governmental functions. The issue in Wilson
was whether immunity under R.C. Chapter 2744 extended to a county human services
department. The Supreme Court of Ohio recognized that the statutory definition of
“governmental function” includes the operation of a human services department. Id. at
452, citing R.C. 2744.01(C)(2)(m). It was unnecessary for the Supreme Court to determine
whether the county human services department was, itself