EnglishEspañol
Maryland flag

Maryland

Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the statutory citation for the breach definition to Com. Law § 14-3504(a), stated both branches of the law-enforcement delay deadline, and rewrote the MODPA sensitive-data discussion to reflect the strict-necessity standard and the COPPA under-13 definition of "child".

Corrected an overstated claim that Maryland's breach notification law bars private lawsuits (a violation is a Consumer Protection Act unfair-or-deceptive-trade-practice under Section 14-3508, which Section 13-408 lets injured consumers sue over), updated the Attorney General citation link, and tightened the substitute-notice and personal-information-exclusion wording to match the statute's exact text.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected two rules that the article had misapplied from Maryland's government-agency breach statute to private businesses: the compromised-encryption-key carve-back and the $100,000/175,000 substitute-notice thresholds are government-only under § 10-1305, not part of the business rule at § 14-3504. Also fixed a miscount of personal-information categories (eight, not nine) to match both the statute and the article's own list.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Md. Code, Com. Law § 14-3504(mgaleg.maryland.gov).gov
  2. Md. Code, Com. Law § 14-3501(mgaleg.maryland.gov).gov
  3. Md. Code, Com. Law § 14-3508(mgaleg.maryland.gov).gov
  4. Md. Code, Com. Law § 13-410(mgaleg.maryland.gov).gov
  5. Md. Code, State Govt. § 10-1305(mgaleg.maryland.gov).gov
  6. Maryland Attorney General: Identity Theft & Data Breach Information(oag.maryland.gov).gov
  7. Maryland Online Data Privacy Act (SB 541)(mgaleg.maryland.gov).gov
  8. Md. Code, Com. Law § 14-4707 (MODPA controller duties and prohibitions)(mgaleg.maryland.gov)
  9. Md. Code, Com. Law § 14-4701 (MODPA definitions)(mgaleg.maryland.gov)
Share: