EnglishEspañol
Maryland flag

Maryland

Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Maryland have a standalone biometric privacy law like Illinois BIPA?

No. Maryland does not have a separate biometric privacy statute. Instead, biometric data is protected as sensitive personal data under the Maryland Online Data Privacy Act (MODPA), which took effect October 1, 2025 and has been enforceable since that date. MODPA classifies biometric data alongside genetic data, precise geolocation, and other sensitive categories, giving it the highest level of protection within the comprehensive privacy framework.

Can I sue a company in Maryland for misusing my biometric data?

No. MODPA does not include a private right of action. Only the Maryland Attorney General, through the Consumer Protection Division, can bring enforcement actions for biometric data violations. If you believe a business has mishandled your biometric data, you can file a complaint with the AG's office at 410-576-6300 or toll-free at 1-888-743-0023. For data breaches involving biometric data, the breach notification statute also relies on AG enforcement rather than private lawsuits.

What biometric data does Maryland law protect?

MODPA protects data generated by automatic measurements of biological characteristics that can be used to uniquely authenticate a consumer's identity. This includes fingerprints, voiceprints, retina or iris images, and other unique biological characteristics. The law does not cover plain photographs, audio recordings, or video recordings unless that data is specifically generated to identify a particular consumer. Maryland's breach notification law also covers genetic prints in its biometric definition.

Can my employer collect my fingerprints for a time clock in Maryland?

MODPA's consumer protections do not currently apply to biometric data an employer collects about its own employees, because MODPA defines consumer to exclude individuals acting in an employment context (Md. Code Com. Law 14-4701(h)(2)). That means the strict necessity standard and the sale ban do not reach a fingerprint time clock used only for employee attendance. Maryland's separate breach notification law still requires an employer to notify workers if their biometric data is exposed in a security breach, and ordinary negligence and data-security duties still apply.

How quickly must a business notify me if my biometric data is breached in Maryland?

Under Maryland's breach notification law (Md. Code Com. Law 14-3504), a business must notify affected individuals within 45 days of discovering or being notified of a breach involving biometric data. The business must also notify the Maryland Attorney General before sending individual notices. Third-party service providers that maintain biometric data for another business must notify the data owner within 10 days of discovering the breach.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Added Maryland's employer facial-recognition consent statute (Lab. & Empl. 3-717) to the employer section, corrected the California cure-period row in the state comparison table (the 30-day cure was repealed by the CPRA effective 2023), and clarified that MODPA's clear-and-conspicuous-link method is one optional way to accept opt-out requests rather than a requirement covering every consumer right.

Corrected this page's Employer Obligations section, which had wrongly applied MODPA's strict-necessity standard and biometric-sale ban to employee data (MODPA's consumer definition excludes employment-context individuals); fixed the breach-notice substitute-notice trigger, the cure-period sunset date (April 1, 2027, not 2026), a mislinked HB 264 citation, HB 264's enactment status (signed as Chapter 435), and SB 182's session year (2024, not 2025).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Fixed a statute misattribution: the biometric-identifier definition (including 'genetic print') is in Md. Code Com. Law 14-3501, not 14-3504 (which the linked corpus text confirms defines only 'breach of the security of a system' with no biometric definition at all).

Fixed a Maryland PIPA citation link that displayed '14-3501' but pointed at section 14-3504's statute text; the href now matches the displayed section number.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Maryland Online Data Privacy Act (SB 541)(mgaleg.maryland.gov).gov
  2. MODPA Enrolled Bill Text (Ch. 455)(mgaleg.maryland.gov).gov
  3. Maryland Breach Notification Statute (14-3504)(mgaleg.maryland.gov).gov
  4. Maryland AG Data Privacy Page(oag.maryland.gov).gov
  5. Maryland AG PIPA Business Guidelines(oag.maryland.gov).gov
  6. Maryland Biometrics Subject Index (2025 Session)(mgaleg.maryland.gov).gov
  7. HB 264 - Maryland Data Privacy and Protection Act of 2026(mgaleg.maryland.gov).gov
  8. Md. Code, Labor & Employment 3-717 - Facial Recognition Service in Employment Interviews(mgaleg.maryland.gov)
  9. Md. Code, Commercial Law 14-4707 - MODPA Controller Duties and Consumer Request Methods(mgaleg.maryland.gov)
  10. Cal. Civ. Code 1798.155 - CCPA Administrative Fines (no cure period)(leginfo.legislature.ca.gov)
Share: