Law / United States /
Maryland
Maryland Personal Information Protection Act (MPIPA), breach notification
Md. Code Ann., Com. Law §§ 14-3501, 14-3504 (Title 14, Subtitle 35)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A breach notification rule binding private bodies.
As of 2 September 2026.
What it requires
- Notify each affected Maryland individual as soon as reasonably practicable, and no later than 45 days after discovering or being notified of the breach, once you determine a likelihood that personal information has been or will be misused.
- Treat biometric data used to uniquely authenticate identity when accessing a system or account, such as a fingerprint, voiceprint, or retina or iris image, as its own triggering data element for this notification duty, separate from a name combined with a Social Security or financial account number.
- Where notification is delayed because a law enforcement agency says it would impede an investigation, notify within 7 days after that delay is cleared, or by the original 45-day deadline, whichever is later.
- Expect a MPIPA violation to be privately actionable. Unlike MODPA, MPIPA's enforcement section does not exclude the Consumer Protection Act's private-action-for-damages provision.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Reached through § 14-3508(2)'s incorporation of Title 13's enforcement and penalty provisions: § 13-410 subjects a merchant who violates Title 13, which a MPIPA breach-notice violation is under § 14-3508(1), to a civil fine of up to $10,000 for each violation, rising to up to $25,000 for each subsequent violation of the same kind. The fines are civil penalties recoverable by the State in a civil action or an administrative cease-and-desist proceeding; the Consumer Protection Division weighs the severity of the violation, the violator's good faith, any history of prior violations, the deterrent effect, and any corrective action taken in setting the amount.
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 10,000
Who enforces it
Enforcement body
Maryland Attorney General, Division of Consumer Protection, under Title 13's unfair or deceptive trade practice enforcement and penalty provisions, incorporated by § 14-3508
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Maryland Personal Information Protection Act, a separate chapter untouched by MODPA's enactment or later recodification, requires a business that owns, licenses, or maintains computerized data including personal information to notify each affected Maryland individual once it determines a likelihood the breach caused or will cause misuse, as soon as reasonably practicable and no later than 45 days after discovering or being notified of the breach, extended by 7 days after a law-enforcement delay is cleared where that falls later than the original 45-day deadline.
'Personal information' includes biometric data generated by automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, genetic print, or retina or iris image, used to uniquely authenticate identity when accessing a system or account, alongside the more familiar Social Security, driver's license, or financial account number data elements.
MPIPA's own enforcement section, § 14-3508, makes a violation an unfair or deceptive trade practice subject to Title 13's enforcement and penalty provisions, and unlike MODPA's § 14-4713, it does not exclude § 13-408, the Maryland Consumer Protection Act's private-action-for-damages provision, so a MPIPA violation is privately actionable through that route.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.