← All jurisdictions
MD · data breach notification

Maryland

high

Md. Code, Com. Law §14-3501 et seq. (MPIPA)

Individual deadline
45 days
Trigger standard
Risk of harm
AG / regulator
Required
Notice to individuals45 calendar days from discovery
Risk-of-harm standardnotice unless investigation shows misuse has not occurred and is not reasonably likely
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeMaryland Attorney General, required for any affected resident; prior to individual notification
Written notice to OAG with sample consumer notice
Sequencing trap: AG must be notified before residents
Credit reporting agenciesNotify CRAs at 1,000+ residents.
Substitute noticeTypically available above $250,000 cost / 500,000 affected (verify).
Private right of actionNo, enforcement by the state.
PenaltiesUp to $1,000 first violation / $5,000 repeat, per violation

Rule last verified July 10, 2026 · confidence high. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Maryland breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →