EnglishEspañol
Maryland flag

Maryland

Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Maryland residents of a data breach?

Maryland law requires notification within 45 days after the business discovers or is notified of the breach. This is one of the shorter fixed deadlines among U.S. states. The timeline may be extended if law enforcement determines that notification would impede a criminal investigation or jeopardize homeland or national security. Once law enforcement clears the delay, notice is due by the end of the original 45-day period, or within 7 days of the clearance determination if that 45-day period has already elapsed.

Does Maryland require notification to the Attorney General before notifying individuals?

Yes. Maryland is one of the few states that requires businesses to notify the Attorney General before sending individual notifications. The AG notice must include the number of affected Maryland residents, a description of the breach, steps taken in response, the notification timeline, and a sample of the notice to be sent to individuals.

Is encrypted data exempt from Maryland's breach notification law?

Encrypted data qualifies for a safe harbor under Maryland law. If personal information was encrypted, redacted, or otherwise rendered unreadable, notification is not required for businesses under § 14-3504, regardless of whether an encryption key was later compromised. A separate rule for state and local government agencies under § 10-1305 does remove the safe harbor if the government unit knows the encryption key was broken.

Can individuals sue for a breach notification violation in Maryland?

Not directly under § 14-3504 itself, but § 14-3508 deems a breach notification violation an unfair or deceptive trade practice under Maryland's Consumer Protection Act (Title 13), and Title 13's § 13-408 lets any person injured by such a violation bring a civil action and recover attorney's fees. So affected individuals may have a private right of action through that route, in addition to the Attorney General's enforcement authority. Individuals may also still pursue claims under common law theories such as negligence, breach of contract, or other applicable statutes.

How does MODPA affect data breach obligations in Maryland?

The Maryland Online Data Privacy Act (MODPA), effective October 1, 2025, adds a comprehensive privacy framework on top of the existing breach notification law. MODPA requires strict data minimization, bars collecting or processing sensitive data except where strictly necessary to provide or maintain a specific product or service the consumer requested, and requires data protection assessments. While it does not directly amend the breach notification statute, a breach involving MODPA-regulated data could trigger enforcement under both laws, with penalties up to $10,000 per violation under each.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the statutory citation for the breach definition to Com. Law § 14-3504(a), stated both branches of the law-enforcement delay deadline, and rewrote the MODPA sensitive-data discussion to reflect the strict-necessity standard and the COPPA under-13 definition of "child".

Corrected an overstated claim that Maryland's breach notification law bars private lawsuits (a violation is a Consumer Protection Act unfair-or-deceptive-trade-practice under Section 14-3508, which Section 13-408 lets injured consumers sue over), updated the Attorney General citation link, and tightened the substitute-notice and personal-information-exclusion wording to match the statute's exact text.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected two rules that the article had misapplied from Maryland's government-agency breach statute to private businesses: the compromised-encryption-key carve-back and the $100,000/175,000 substitute-notice thresholds are government-only under § 10-1305, not part of the business rule at § 14-3504. Also fixed a miscount of personal-information categories (eight, not nine) to match both the statute and the article's own list.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Md. Code, Com. Law § 14-3504(mgaleg.maryland.gov).gov
  2. Md. Code, Com. Law § 14-3501(mgaleg.maryland.gov).gov
  3. Md. Code, Com. Law § 14-3508(mgaleg.maryland.gov).gov
  4. Md. Code, Com. Law § 13-410(mgaleg.maryland.gov).gov
  5. Md. Code, State Govt. § 10-1305(mgaleg.maryland.gov).gov
  6. Maryland Attorney General: Identity Theft & Data Breach Information(oag.maryland.gov).gov
  7. Maryland Online Data Privacy Act (SB 541)(mgaleg.maryland.gov).gov
  8. Md. Code, Com. Law § 14-4707 (MODPA controller duties and prohibitions)(mgaleg.maryland.gov)
  9. Md. Code, Com. Law § 14-4701 (MODPA definitions)(mgaleg.maryland.gov)
Share: