Maryland
Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Maryland's Personal Information Protection Act requires businesses to notify affected residents of a data breach within 45 days of discovery, under Md. Code Com. Law 14-3504. Before sending individual notices, businesses must first notify the Maryland Attorney General, making Maryland one of the few states to require AG notification ahead of consumer outreach.
Maryland takes data breach notification seriously. Under the Maryland Personal Information Protection Act (MPIPA), businesses that experience a security breach must act fast, notifying both the Attorney General and affected individuals within a tight 45-day window. This is one of the shorter deadlines among U.S. states, and the requirement to notify the AG first adds an extra layer of accountability.
The law, codified at Md. Code, Com. Law § 14-3504, applies to any business that owns, licenses, or maintains computerized data containing personal information of Maryland residents. A separate statute, Md. Code, State Govt. § 10-1305, imposes parallel obligations on state and local government agencies.
This guide breaks down who must comply, what triggers the notification obligation, the AG-first reporting process, enforcement mechanisms, and how the new Maryland Online Data Privacy Act (MODPA) adds to the picture.
What Qualifies as a Breach of Security
Under § 14-3501, a "breach of the security of a system" means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a business.
The definition focuses on actual acquisition, not mere access. If someone accesses a system without authorization but does not acquire personal information, the notification requirement may not apply.
Maryland includes a good faith exception. An employee or agent who acquires personal information in the normal course of business does not trigger breach notification, as long as the information is not used for an unauthorized purpose or disclosed further.

The Encryption Safe Harbor
Maryland provides a clear safe harbor for encrypted data. If the compromised personal information was encrypted, redacted, or otherwise rendered unreadable or unusable, the notification obligation does not apply, regardless of whether an encryption key was later compromised.
A compromised-encryption-key carve-back does exist in Maryland law, but only for state and local government agencies under a separate statute, Md. Code, State Govt. § 10-1305: a government unit is not required to notify unless it knows the encryption key has been broken. That carve-back does not apply to businesses under § 14-3504. Businesses should still document their encryption practices to demonstrate that the safe harbor applies.
Personal Information That Triggers Notification
Maryland has one of the broader definitions of protected personal information among state breach notification laws. Under § 14-3501(e), personal information means an individual's first name or first initial and last name combined with any one or more of the following data elements (when not encrypted, redacted, or otherwise protected):
- Social Security number, individual taxpayer identification number (ITIN), or passport number, or other federal government-issued identification number
- Driver's license number or Maryland state identification card number
- Financial account number, credit card number, or debit card number, combined with any required security code, access code, or password that permits access to the account
- Health information, including information about mental or physical health conditions, medical history, or treatment by a healthcare professional
- Health insurance policy number, subscriber identification number, or other unique identifier used by a health insurer, combined with a unique identifier used by the insurer or employer
- Biometric data, including fingerprints, voice prints, genetic prints, retinal or iris images, and other unique biological characteristics used for authentication
- Genetic information, including data from DNA analysis, chromosomes, alleles, genomes, and genetic sequence polymorphisms
- Username or email address combined with a password or security question and answer that would permit access to an online account
This list is notably comprehensive. Maryland was among the early states to include biometric data, genetic information, and health insurance identifiers as protected categories.
What Does Not Count as Personal Information
Publicly available information lawfully obtained from federal, state, or local government records is excluded from the definition. Information that is widely distributed through media is also excluded.

The 45-Day Notification Deadline
Maryland imposes a firm 45-day deadline for notifying affected individuals. Under § 14-3504, businesses must provide notice no later than 45 days after discovering or being notified of the breach.
The clock starts at discovery, not at the conclusion of an investigation. This is a meaningful distinction. Some states start the clock only after the business has confirmed the breach through investigation. Maryland's approach puts more pressure on businesses to move quickly.
Investigation Requirement
Before sending notifications, a business must conduct a good-faith, reasonable, and prompt investigation to determine whether personal information has been or will be misused as a result of the breach. If the investigation determines that misuse of personal information has not occurred and is not reasonably likely to occur, notification may not be required.
However, the business must document that determination and maintain records for three years. This documentation requirement gives the Attorney General a basis for reviewing whether the decision not to notify was justified.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that it would impede a criminal investigation or jeopardize national security. Once law enforcement gives clearance, the business must notify affected individuals within seven days.

Attorney General Notification: The AG-First Rule
Maryland stands out among state breach notification laws for its AG-first notification requirement. Under § 14-3504, businesses must notify the Office of the Attorney General before sending notifications to affected individuals.
The AG notification must include:
- The number of Maryland residents affected by the breach
- A description of the breach, including when and how it occurred
- The steps the business has taken or plans to take in response to the breach
- The timeline for when individual notifications will be sent
- A sample copy of the notice that will go to affected individuals
This AG-first approach gives the Attorney General's office an opportunity to review the breach and the planned notification before consumers receive it. It also allows the AG to coordinate with the business if the notification is inadequate or if the breach raises broader consumer protection concerns.
Breach notifications should be directed to the Identity Theft Unit of the Consumer Protection Division at 200 St. Paul Place, Baltimore, MD 21202, or by email to idtheft@oag.state.md.us.
Methods of Individual Notification
Maryland permits several methods for notifying affected individuals:
- Written notice mailed to the most recent address on file
- Email notice, if the individual has previously consented to electronic communications or if the business conducts its business primarily through online transactions
- Telephonic notice to the most recent phone number on file
- Substitute notice, available when specific conditions are met
Substitute Notice
A business may use substitute notice only if it does not have sufficient contact information to provide direct notice. Unlike the parallel rule for government agencies, Maryland's business substitute-notice provision does not include a cost or affected-individual-count threshold.
Substitute notice requires all three of the following: sending email to affected individuals whose addresses are available, posting a conspicuous notice on the company's website, and notifying major statewide media outlets.
Required Content of Individual Notices
Individual breach notifications must include:
- A description of the categories of personal information compromised
- Contact information for the business
- Contact information for consumer reporting agencies
- Contact details for the Federal Trade Commission and the Maryland Attorney General, along with information about identity theft prevention
Special Rule for Email-Only Breaches
When a breach involves only access to an email account without other personal information, the business may provide a simplified notification directing the affected individual to change their password and security questions.
Third-Party Data Handlers
Businesses that maintain personal information on behalf of another entity (such as cloud providers, payment processors, or IT vendors) have separate obligations. A third-party data handler must notify the data owner within 10 days of discovering a breach.
The third-party handler cannot charge the data owner any fees for providing information about the breach. This provision prevents vendors from monetizing breach information at the expense of timely notification.
Government Agency Obligations
State and local government agencies in Maryland are subject to parallel breach notification requirements under Md. Code, State Govt. § 10-1305. The obligations are similar to those for private businesses, with a few differences.
Government agencies must notify affected individuals "as soon as reasonably practicable" after investigation. They must also notify the Attorney General before individual notification. Certain state agencies are additionally required to notify the Department of Information Technology.
The substitute notice thresholds differ for government agencies: the cost threshold is $100,000 and the affected individuals threshold is 175,000.
Enforcement and Penalties
AG Enforcement Through Consumer Protection Act
Under § 14-3508, violations of Maryland's breach notification law constitute unfair or deceptive trade practices under Title 13 of the Commercial Law article, which is Maryland's Consumer Protection Act.
This means the Attorney General's Consumer Protection Division has full enforcement authority, including the power to:
- Bring civil actions against violating businesses
- Issue cease and desist orders
- Seek restitution for affected consumers
- Impose civil penalties
Penalty Amounts
Under § 13-410, a business that violates the law faces fines of up to $10,000 per violation. A business that repeats the same violation after a prior finding faces fines of up to $25,000 per repeat violation.
When calculating penalties, the Consumer Protection Division considers the severity of the violation, the business's good faith efforts, its prior violation history, and the deterrent effect of the penalty amount.
No Private Right of Action
Maryland's breach notification law does not create a private right of action. Individual consumers cannot sue businesses directly for failing to comply with notification requirements. Enforcement rests exclusively with the Attorney General.
However, individuals may still pursue claims under common law theories such as negligence, breach of contract, or other applicable statutes.

How MODPA Affects Data Breach Obligations
The Maryland Online Data Privacy Act (MODPA), which took effect on October 1, 2025, adds a comprehensive privacy framework that operates alongside the existing breach notification law. While MODPA does not replace or directly amend § 14-3504, it has significant implications for breach prevention and response.
Data Minimization Reduces Breach Risk
MODPA requires businesses to limit personal data collection to what is "reasonably necessary and proportionate" to provide a specific product or service requested by the consumer. This strict data minimization standard means businesses should be holding less personal data overall, which reduces both the likelihood and the potential impact of a data breach.
Sensitive Data Protections
MODPA classifies certain categories as sensitive personal data, including biometric data, genetic data, health information, precise geolocation, and data concerning children under 18. Businesses must obtain consent before processing sensitive data and are prohibited from selling it entirely. A breach involving sensitive data could trigger enforcement under both MODPA and the breach notification statute.
Additional Enforcement Layer
MODPA violations are also classified as unfair or deceptive trade practices, giving the Attorney General parallel enforcement authority. Before bringing an action, the AG may issue a notice of violation and provide at least 60 days for the business to cure the violation if a cure is possible. This 60-day cure period does not apply to the separate breach notification obligations under § 14-3504.
Data Protection Assessments
MODPA requires businesses to conduct data protection assessments for high-risk processing activities. If a business fails to conduct required assessments and then suffers a breach, that failure could strengthen the AG's enforcement case under both MODPA and the breach notification law.
How Maryland Compares
Maryland's 45-day notification deadline is among the shorter windows nationally. Florida requires notification within 30 days, while many states use a vaguer "most expedient time possible" standard without a fixed deadline. Maryland's AG-first notification requirement is also distinctive. Most states require AG notification at the same time as individual notification, or only above certain thresholds. Maryland's approach of requiring AG notice before individual notice gives the state more oversight of the process.
The breadth of Maryland's personal information definition, covering eight categories including biometric and genetic data, places it in the upper tier of state protections.
For a broader view of Maryland's data privacy landscape, including the MODPA framework, see our Maryland Data Privacy Laws overview.
This article provides general legal information about Maryland data breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Maryland for guidance specific to your situation.
More Maryland Laws
Frequently Asked Questions
How quickly must a business notify Maryland residents of a data breach?
Maryland law requires notification within 45 days after the business discovers or is notified of the breach. This is one of the shorter fixed deadlines among U.S. states. The timeline may be extended if law enforcement determines that notification would impede a criminal investigation, but once cleared, notification must occur within seven days.
Does Maryland require notification to the Attorney General before notifying individuals?
Yes. Maryland is one of the few states that requires businesses to notify the Attorney General before sending individual notifications. The AG notice must include the number of affected Maryland residents, a description of the breach, steps taken in response, the notification timeline, and a sample of the notice to be sent to individuals.
Is encrypted data exempt from Maryland's breach notification law?
Encrypted data qualifies for a safe harbor under Maryland law. If personal information was encrypted, redacted, or otherwise rendered unreadable, notification is not required for businesses under § 14-3504, regardless of whether an encryption key was later compromised. A separate rule for state and local government agencies under § 10-1305 does remove the safe harbor if the government unit knows the encryption key was broken.
Can individuals sue for a breach notification violation in Maryland?
No. Maryland's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute through the Consumer Protection Division. However, affected individuals may still pursue claims under common law theories such as negligence, breach of contract, or other applicable statutes.
How does MODPA affect data breach obligations in Maryland?
The Maryland Online Data Privacy Act (MODPA), effective October 1, 2025, adds a comprehensive privacy framework on top of the existing breach notification law. MODPA requires strict data minimization, consent for sensitive data processing, and data protection assessments. While it does not directly amend the breach notification statute, a breach involving MODPA-regulated data could trigger enforcement under both laws, with penalties up to $10,000 per violation under each.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected two rules that the article had misapplied from Maryland's government-agency breach statute to private businesses: the compromised-encryption-key carve-back and the $100,000/175,000 substitute-notice thresholds are government-only under § 10-1305, not part of the business rule at § 14-3504. Also fixed a miscount of personal-information categories (eight, not nine) to match both the statute and the article's own list.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 5 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Maryland Code, Commercial Law Article
§ 13-410In forcecited in 4 of our articles
§13–410. (a) A merchant who engages in a violation of this title is subject to a fine not exceeding $10,000 for each violation. (b) A merchant who has been found to have engaged in a violation of this title and who subsequently repeats the same violation is subject to a fine not exceeding $25,000 for each subsequent violation. (c) The fines provided for in subsections (a) and (b) of this section are civil penalties and are recoverable by the State in a civil action or an administrative cease and desist action under § 13–403(a) and (b) of this subtitle or after an administrative hearing has been held under § 13–403(d)(3) and (4) of this subtitle. (d) The Consumer Protection Division shall consider the following in setting the amount of the penalty imposed in an administrative proceeding: (1) The severity of the violation for which the penalty is assessed; (2) The good faith of the violator; (3) Any history of prior violations; (4) Whether the amount of the penalty will achieve the desired deterrent purpose; and (5) Whether the issuance of a cease and desist order, including restitution, is insufficient for the protection of consumers.
Official text (excerpt) · as of 2026-07-29 · Read the full section at mgaleg.maryland.gov
Also relied on in: MODPA Compliance Checklist: Maryland Privacy, MODPA Consumer Rights: Maryland Data Privacy, What Is MODPA? Maryland Online Data Privacy Act
§ 14-3501In force
§14–3501. (a) In this subtitle the following words have the meanings indicated. (b) (1) “Business” means a sole proprietorship, partnership, corporation, association, or any other business entity, whether or not organized to operate at a profit. (2) “Business” includes a financial institution organized, chartered, licensed, or otherwise authorized under the laws of this State, any other state, the United States, or any other country, and the parent or subsidiary of a financial institution. (c) “Encrypted” means the protection of data in electronic or optical form using an encryption technology that renders the data indecipherable without an associated cryptographic key necessary to enable decryption of the data. (d) “Health information” means any information regarding an individual’s medical history, medical condition, or medical treatment or diagnosis. (e) (1) “Personal information” means: (i) An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the data elements are not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable: 1.
Official text (excerpt) · as of 2026-07-29 · Read the full section at mgaleg.maryland.gov
Cited in 1 court opinionsMost recently applied by a court: 2016
Leading cases: Chambliss v. CareFirst, Inc. (District Court, D. Maryland 2016, 189 F. Supp. 3d 564)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 14-3504In forcecited in 3 of our articles
§14–3504. (a) In this section: (1) “Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business; and (2) “Breach of the security of a system” does not include the good faith acquisition of personal information by an employee or agent of a business for the purposes of the business, provided that the personal information is not used or subject to further unauthorized disclosure. (b) (1) A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in the State, when it discovers or is notified that it incurred a breach of the security of a system, shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information of the individual has been or will be misused as a result of the breach.
Official text (excerpt) · as of 2026-07-29 · Read the full section at mgaleg.maryland.gov
Also relied on in: Maryland Data Privacy Laws: MODPA Consumer Rights Guide (2026), Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 14-3508In force
§14–3508. A violation of this subtitle: (1) Is an unfair or deceptive trade practice within the meaning of Title 13 of this article; and (2) Is subject to the enforcement and penalty provisions contained in Title 13 of this article.
Official text (excerpt) · as of 2026-07-29 · Read the full section at mgaleg.maryland.gov
Cited in 2 court opinionsMost recently applied by a court: 2023
Leading cases: In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295) · Johnson v. Think Computer Corporation (District Court, D. Maryland 2023)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Maryland Code, State Government Article
§ 10-1305In force
§10–1305. (a) (1) In this section, “breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a unit. (2) “Breach of the security of a system” does not include the good faith acquisition of personal information by an employee or agent of a unit for the purposes of the unit, provided that the personal information is not used or subject to further unauthorized disclosure. (b) (1) If a unit that collects computerized data that includes personal information of an individual discovers or is notified of a breach of the security of a system, the unit shall conduct in good faith a reasonable and prompt investigation to determine whether the unauthorized acquisition of personal information of the individual has resulted in or is likely to result in the misuse of the information.
Official text (excerpt) · as of 2026-07-29 · Read the full section at mgaleg.maryland.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Md. Code, Com. Law § 14-3504(mgaleg.maryland.gov).gov
- Md. Code, Com. Law § 14-3501(mgaleg.maryland.gov).gov
- Md. Code, Com. Law § 14-3508(mgaleg.maryland.gov).gov
- Md. Code, Com. Law § 13-410(mgaleg.maryland.gov).gov
- Md. Code, State Govt. § 10-1305(mgaleg.maryland.gov).gov
- Maryland Attorney General: Breach Notices(marylandattorneygeneral.gov).gov
- Maryland Online Data Privacy Act (SB 541)(mgaleg.maryland.gov).gov