Maryland
Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Maryland does not have a standalone biometric privacy law. Instead, the Maryland Online Data Privacy Act (MODPA) classifies biometric data as sensitive personal information, restricting collection to what is strictly necessary to deliver a requested product or service, banning its sale outright, and authorizing only the Attorney General to enforce violations.
Maryland takes a different approach to biometric privacy than states with standalone biometric statutes like Illinois or Texas. Rather than creating a separate biometric privacy law, Maryland folded strong biometric protections into its comprehensive Maryland Online Data Privacy Act (MODPA), signed by Governor Wes Moore on May 9, 2024.
What makes Maryland's framework notable is the strict necessity standard. Businesses cannot collect biometric data just because a consumer clicks "I agree." They must prove the data is essential to delivering a specific product or service the consumer requested. Combined with an outright ban on selling biometric data, this puts Maryland among the most protective states in the country for biometric privacy.
Here is how the law works and what it means for Maryland residents, employers, and businesses.
How Maryland Defines Biometric Data
MODPA defines "biometric data" as data generated by automatic measurements of a consumer's biological characteristics that can be used to uniquely authenticate that consumer's identity. The enrolled bill text lists specific examples:
- Fingerprints
- Voiceprints
- Retina or iris images
- Other unique biological characteristics used for authentication
Maryland's breach notification statute (Md. Code Com. Law 14-3501) uses a slightly different but overlapping definition, adding "genetic print" to the list of protected biometric identifiers.
What Is Not Biometric Data
MODPA excludes certain data from the biometric definition:
- Digital or physical photographs
- Audio or video recordings
- Data generated from photographs or recordings, unless generated specifically to identify a particular consumer
This means a security camera recording alone does not qualify as biometric data. However, if a business runs that footage through facial recognition software to identify specific people, the extracted data becomes biometric data under the law.
The Broader Definition Problem
Maryland's biometric data definition is notably broader than most other states. MODPA covers biological characteristics that "can be used" to authenticate identity, not just those that "are used" or "are intended to be used" for that purpose. This distinction matters. A business that collects data capable of identifying someone but never actually deploys it for authentication still holds biometric data under MODPA.

Sensitive Data Classification and the Strict Necessity Standard
Under MODPA, biometric data is classified as sensitive personal data. This places it in the highest protection tier alongside genetic data, precise geolocation, data about children, and information revealing racial or ethnic origin, religious beliefs, or sexual orientation.
The sensitive data classification triggers MODPA's strict necessity requirement. Controllers may only collect, process, or share biometric data when it is "strictly necessary to provide or maintain a specific product or service requested by the consumer."
This is a higher bar than most state privacy laws set. In California, for example, businesses can process sensitive data with notice and the option for consumers to limit use. In Maryland, the question is whether the biometric data collection is essential to delivering what the consumer asked for.
Practical examples:
- A bank that uses fingerprint authentication for mobile app login can collect fingerprints because the consumer requested the service
- A retail store that scans customer faces for marketing analytics likely fails the strict necessity test because facial recognition is not necessary to sell products
- A retailer that scans customer fingerprints for loyalty-program check-in may face scrutiny over whether biometric collection is truly the only way to identify members (employee time clocks fall outside MODPA, since workers acting in an employment context are not consumers under the law)
Prohibition on Selling Biometric Data
MODPA contains what the Maryland Attorney General's office describes as a blanket prohibition: businesses cannot sell biometric data. Period.
This is the first prohibition of its kind under any state comprehensive privacy law. Other states allow the sale of sensitive data if the consumer provides opt-in consent. Maryland does not. Even if a consumer explicitly agrees, a business still cannot sell their biometric information.
The ban extends to leasing, trading, or otherwise transferring biometric data for monetary or other valuable consideration. Transfers to processors acting on the controller's behalf under a valid contract are permitted, but transfers to independent third parties for their own purposes are not.
Consumer Rights Over Biometric Data
Maryland residents have several rights regarding their biometric data under MODPA:
Right to Access. Consumers can request confirmation of whether a business is processing their biometric data and obtain a copy of that data.
Right to Deletion. Consumers can request that a business delete their biometric data. The business must comply and direct any processors to delete it as well.
Right to Correction. Consumers can request correction of inaccurate biometric data.
Right to Opt Out. Consumers can opt out of targeted advertising and the sale of personal data. Businesses must honor universal opt-out preference signals.
Right to Data Portability. Consumers can request their biometric data in a portable, readily usable format.
Businesses must establish one or more secure and reliable methods for consumers to submit these requests (Md. Code Com. Law 14-4707(f)). For opt-out requests covering targeted advertising or the sale of personal data, the statute lists a clear and conspicuous link on the controller's website as one method a controller may use, alongside recognizing a universal opt-out preference signal. Businesses cannot retaliate against consumers who exercise these rights.
Breach Notification Requirements for Biometric Data
Maryland's Personal Information Protection Act (Md. Code Com. Law 14-3501 through 14-3508) imposes specific requirements when biometric data is compromised in a security breach. For a detailed breakdown, see our Maryland Data Breach Notification Laws guide.
Key requirements:
- 45-day deadline. Businesses must notify affected individuals as soon as reasonably practicable, but no later than 45 days after discovering or being notified of the breach
- AG notification first. The Maryland Attorney General must be notified before individual consumers receive notice
- 10-day rule for service providers. Third-party service providers that maintain biometric data on behalf of another business must notify the data owner within 10 days of discovering the breach
- Biometric data in the PI definition. The statute specifically includes biometric data generated by automatic measurements of biological characteristics (fingerprint, voiceprint, genetic print, retina or iris image) in the definition of personal information
Required Notice Content
Breach notifications involving biometric data must include:
- A description of the compromised information
- Business contact information and a toll-free number
- Contact details for the three major credit bureaus
- FTC and Maryland Attorney General contact information
- Identity theft prevention resources
Maryland's breach notification statute (Md. Code Com. Law 14-3504) allows notice by mail, telephone, or email if the consumer consented. Substitute notice is permitted only when the business does not have sufficient contact information to notify affected individuals directly, and it must combine an email notice (if an email address is available), a conspicuous posting on the business's website, and notice to major statewide print or broadcast media.

Employer Obligations
MODPA's consumer protections, including the strict necessity standard and the ban on selling biometric data, generally do not extend to biometric data Maryland employers collect about their own workers. MODPA defines "consumer" to exclude an individual acting in a commercial or employment context, and an employee, owner, director, officer, or contractor whose communications or transactions with a business occur only within that role (Md. Code Com. Law 14-4701(h)(2)). Because MODPA's rights and restrictions run to "consumers" as defined, a fingerprint time clock or facial-recognition badge reader used only on employees currently falls outside MODPA's reach.
That does not leave employee biometric data unregulated. Maryland's Personal Information Protection Act breach notification statute (Md. Code Com. Law 14-3504) is not limited to MODPA's consumer definition, so an employer must still notify affected workers, using the same 45-day and AG-first rules described above, if their biometric data is exposed in a security breach. Employers also remain subject to ordinary negligence and data-security duties under Maryland law, and to any federal statutes that touch a specific biometric context, such as GINA for genetic information.
Maryland also regulates one employer biometric practice directly, but at the hiring stage rather than on the job. Under Md. Code, Lab. & Empl. 3-717, an employer may not use a facial recognition service to create a facial template during an applicant's interview for employment unless the applicant consents by signing a waiver. The waiver must state, in plain language, the applicant's name, the date of the interview, that the applicant consents to the use of facial recognition during the interview, and whether the applicant read the waiver. The section defines a facial recognition service as technology that analyzes facial features and is used for recognition or persistent tracking of individuals in still or video images, and it applies only to interviews, so it does not govern fingerprint time clocks or badge readers used on current employees.
Outside of that provision, Maryland currently has no statute requiring opt-in consent, a strict-necessity showing, or a sale ban before an employer deploys a biometric time clock or facial-recognition access system for its own workforce.

Enforcement and Penalties
The Maryland Office of the Attorney General, through the Consumer Protection Division, has exclusive enforcement authority over MODPA. There is no private right of action, meaning individual consumers cannot sue businesses directly for biometric data violations.
Penalty Structure
- First violation: Up to $10,000 per violation
- Subsequent violations: Up to $25,000 per violation
- Additional remedies: Injunctive relief, restitution, economic damages, and disgorgement of profits
Cure Period
Before initiating a formal enforcement action, the Attorney General may issue a notice of violation if the problem is curable. The controller or processor then has 60 days to fix the issue. If they cure the violation within that window, the AG may not pursue penalties for that specific issue.
This cure period is not permanent. It applies only to alleged violations occurring on or before April 1, 2027; after that date, the AG can pursue enforcement actions without first offering a cure opportunity.
Enforcement Timeline
MODPA took effect on October 1, 2025, and the Consumer Protection Division has had authority to enforce it, including using the discretionary cure period, from that date. The cure period itself has a fixed end date: under Md. Code Com. Law 14-4714, the Division may offer a 60-day cure opportunity only for alleged violations occurring on or before April 1, 2027. After that date, the AG can pursue enforcement actions without first offering a cure opportunity.
For breach notification violations, enforcement runs through the Maryland Consumer Protection Act. Violations are treated as unfair or deceptive trade practices, which carry their own penalty structure.

Pending and Related Legislation
Maryland continues to consider additional biometric privacy protections beyond MODPA.
SB 169 (Biometric Identifiers). Introduced in a prior session, this bill would have created a standalone biometric privacy law similar to Illinois BIPA, including a private right of action. While it did not pass, it signals legislative interest in going further than MODPA's AG-only enforcement model.
HB 264 (Maryland Data Privacy and Protection Act of 2026). This bill was enacted as Chapter 435, approved by the Governor on May 12, 2026, and takes effect October 1, 2026. It limits the personal information that state government units can collect, maintain, and retain, requires deletion or de-identification of certain personal data, mandates privacy notices on agency websites, and requires each state unit to designate a Privacy Officer.
SB 182 (Facial Recognition Technology). This bill establishes requirements and prohibitions for law enforcement use of facial recognition technology and mandates training programs through the Department of Public Safety and Correctional Services. It was approved by the Governor in the 2024 session as Chapter 808.
These bills reflect a broader trend in Maryland toward layered biometric protections, with MODPA as the foundation and targeted legislation addressing specific use cases.
How Maryland Compares to Other States
Maryland's biometric protections sit in the middle tier among U.S. states, but with some uniquely strong features.
| Feature | Maryland (MODPA) | Illinois (BIPA) | California (CCPA/CPRA) |
|---|---|---|---|
| Law Type | Comprehensive privacy law | Standalone biometric statute | Comprehensive privacy law |
| Consent Model | Strict necessity (no consent override) | Written informed consent before collection | Notice + right to limit use |
| Sale of Biometric Data | Banned entirely | Prohibited | Opt-out available |
| Private Right of Action | No | Yes ($1,000-$5,000 per violation) | Data breaches only ($100-$750) |
| Enforcement | AG only | Private lawsuits + AG | CPPA + AG + limited private |
| Penalties | $10,000-$25,000 per violation | $1,000-$5,000 per violation (private) | $2,663-$7,988 per violation |
| Cure Period | 60 days | None | None (30-day AG cure repealed by CPRA, effective 2023) |
Maryland's strict necessity standard and absolute ban on biometric data sales are stronger than California's framework. However, the lack of a private right of action means enforcement depends entirely on the Attorney General's priorities and resources.
Sources and References
This article references Maryland statutes, enrolled bill text, and official state government publications. For the full text of MODPA, visit the Maryland General Assembly website. For AG enforcement guidance and complaint filing, visit the Maryland Attorney General's data privacy page.
This article provides general legal information about Maryland data privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Maryland government sources.
More Maryland Laws
Frequently Asked Questions
Does Maryland have a standalone biometric privacy law like Illinois BIPA?
No. Maryland does not have a separate biometric privacy statute. Instead, biometric data is protected as sensitive personal data under the Maryland Online Data Privacy Act (MODPA), which took effect October 1, 2025 and has been enforceable since that date. MODPA classifies biometric data alongside genetic data, precise geolocation, and other sensitive categories, giving it the highest level of protection within the comprehensive privacy framework.
Can I sue a company in Maryland for misusing my biometric data?
No. MODPA does not include a private right of action. Only the Maryland Attorney General, through the Consumer Protection Division, can bring enforcement actions for biometric data violations. If you believe a business has mishandled your biometric data, you can file a complaint with the AG's office at 410-576-6300 or toll-free at 1-888-743-0023. For data breaches involving biometric data, the breach notification statute also relies on AG enforcement rather than private lawsuits.
What biometric data does Maryland law protect?
MODPA protects data generated by automatic measurements of biological characteristics that can be used to uniquely authenticate a consumer's identity. This includes fingerprints, voiceprints, retina or iris images, and other unique biological characteristics. The law does not cover plain photographs, audio recordings, or video recordings unless that data is specifically generated to identify a particular consumer. Maryland's breach notification law also covers genetic prints in its biometric definition.
Can my employer collect my fingerprints for a time clock in Maryland?
MODPA's consumer protections do not currently apply to biometric data an employer collects about its own employees, because MODPA defines consumer to exclude individuals acting in an employment context (Md. Code Com. Law 14-4701(h)(2)). That means the strict necessity standard and the sale ban do not reach a fingerprint time clock used only for employee attendance. Maryland's separate breach notification law still requires an employer to notify workers if their biometric data is exposed in a security breach, and ordinary negligence and data-security duties still apply.
How quickly must a business notify me if my biometric data is breached in Maryland?
Under Maryland's breach notification law (Md. Code Com. Law 14-3504), a business must notify affected individuals within 45 days of discovering or being notified of a breach involving biometric data. The business must also notify the Maryland Attorney General before sending individual notices. Third-party service providers that maintain biometric data for another business must notify the data owner within 10 days of discovering the breach.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Added Maryland's employer facial-recognition consent statute (Lab. & Empl. 3-717) to the employer section, corrected the California cure-period row in the state comparison table (the 30-day cure was repealed by the CPRA effective 2023), and clarified that MODPA's clear-and-conspicuous-link method is one optional way to accept opt-out requests rather than a requirement covering every consumer right.
Corrected this page's Employer Obligations section, which had wrongly applied MODPA's strict-necessity standard and biometric-sale ban to employee data (MODPA's consumer definition excludes employment-context individuals); fixed the breach-notice substitute-notice trigger, the cure-period sunset date (April 1, 2027, not 2026), a mislinked HB 264 citation, HB 264's enactment status (signed as Chapter 435), and SB 182's session year (2024, not 2025).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Fixed a statute misattribution: the biometric-identifier definition (including 'genetic print') is in Md. Code Com. Law 14-3501, not 14-3504 (which the linked corpus text confirms defines only 'breach of the security of a system' with no biometric definition at all).
Fixed a Maryland PIPA citation link that displayed '14-3501' but pointed at section 14-3504's statute text; the href now matches the displayed section number.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maryland Code, Commercial Law Article
§ 14-4707In forcecited in 5 of our articles
§14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data; (3) Process personal data in violation of State or federal laws that prohibit unlawful discrimination; (4) Process the personal data of a consumer for the purposes of targeted advertising if the controller knew or should have known that the consumer is under the age of 18 years; (5) Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years; (6) Discriminate against a consumer for exercising a consumer right contained in this subtitle, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; (7) Collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in or otherwise unlawfully makes unavailable the equal enjoyment of goods or…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Privacy Laws: MODPA Consumer Rights Guide (2026), What Is MODPA? Maryland Online Data Privacy Act, MODPA Consumer Rights: Maryland Data Privacy
§ 14-3504In forcecited in 4 of our articles
§14–3504. (a) In this section: (1) “Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business; and (2) “Breach of the security of a system” does not include the good faith acquisition of personal information by an employee or agent of a business for the purposes of the business, provided that the personal information is not used or subject to further unauthorized disclosure. (b) (1) A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in the State, when it discovers or is notified that it incurred a breach of the security of a system, shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information of the individual has been or will be misused as a result of the breach.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026), Maryland Identity Theft Laws
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Maryland Online Data Privacy Act (SB 541)(mgaleg.maryland.gov).gov
- MODPA Enrolled Bill Text (Ch. 455)(mgaleg.maryland.gov).gov
- Maryland Breach Notification Statute (14-3504)(mgaleg.maryland.gov).gov
- Maryland AG Data Privacy Page(oag.maryland.gov).gov
- Maryland AG PIPA Business Guidelines(oag.maryland.gov).gov
- Maryland Biometrics Subject Index (2025 Session)(mgaleg.maryland.gov).gov
- HB 264 - Maryland Data Privacy and Protection Act of 2026(mgaleg.maryland.gov).gov
- Md. Code, Labor & Employment 3-717 - Facial Recognition Service in Employment Interviews(mgaleg.maryland.gov)
- Md. Code, Commercial Law 14-4707 - MODPA Controller Duties and Consumer Request Methods(mgaleg.maryland.gov)
- Cal. Civ. Code 1798.155 - CCPA Administrative Fines (no cure period)(leginfo.legislature.ca.gov)