Law / United States / Maryland

Maryland

United States law applies in Maryland Maryland is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Maryland, described on this page below, applies here too.
Maryland has 2 local jurisdictions Each local jurisdiction has law of its own, on a page of its own. All 2 are listed below.

15 of 18 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 3 enacted but not yet in force. As of 14 September 2026.

When they take effect12 of 15 carry a date, 3 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 7 instruments (7 in force) 2026: 3 instruments (1 in force, 2 enacted but not yet in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 6
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law6 instruments, 4 in force, 2 enacted but not yet in force

Research summary (304 words)

Maryland's AI-specific findings sit almost entirely in the criminal code and in sector statutes rather than a horizontal AI act: Crim. Law §3-809 and §11-208 extend the state's nonconsensual-intimate-imagery and child-pornography bans to a computer-generated image indistinguishable from the depicted person, and Elec. Law §16-905 (Ch. 444 of 2026, in force since June 1, 2026) bans an election deepfake intended to deceive voters.

Crim. Law §8-301(f)(2) (Ch. 445 of 2026) criminalizes using AI or a deepfake to impersonate or falsely depict a person with fraudulent intent, but is enacted and not yet in force as of the date shown, taking effect October 1, 2026.

Ins. §15-10B-05.1 (Ch. 747 of 2025, in force since October 1, 2025) requires health carriers, pharmacy benefits managers, and private review agents to ground AI-driven utilization-review determinations in an enrollee's own clinical record and keep a physician in the process.

Com. Law §§13-321 and 13-322 (Ch. 154 of 2026, enacted and not yet in force as of the date shown, taking effect October 1, 2026) bar a large food retailer and a third-party food delivery service provider from setting a price using dynamic pricing or artificial-intelligence-driven surveillance personal data, and separately require any other merchant who prices a good or service using dynamic pricing or personal data to disclose that the price was set by an algorithm or by using the consumer's personal data.

Maryland's general AI-governance measures, the 2024 Artificial Intelligence Governance Act (SB 818) and Executive Order 01.01.2024.02, bind only state government units and are not catalogued here; the Consumer Protection Act, Com. Law §§13-101 et seq., is a general unfair-and-deceptive-trade-practices statute naming no automated practice, and backstops the absence of a chatbot-specific disclosure statute; two 2026 companion-chatbot disclosure bills (SB 827 and HB 952) each passed one chamber but died in the other chamber's committee before adjournment.

AI prohibited practices

Computer-Generated Child Sexual Abuse Material

Md. Code Ann., Crim. Law §11-208official codified text, Maryland General Assembly

In force. Binds public and private bodies.

What this law does

Maryland's child pornography statute defines an image indistinguishable from an actual and identifiable child to include a computer-generated image created, adapted, or modified to appear as an actual and identifiable child, reaching AI-generated child sexual abuse material on the same terms as a real photograph.

A person may not knowingly possess and retain, or knowingly access and view, such a visual representation of a child under 16 engaged in sadomasochistic abuse, sexual conduct, or a state of sexual excitement. A first violation is a misdemeanor and a second or later violation is a felony.

What it requires

HB 895 / Ch. 154 (2026), Surveillance Pricing and Algorithmic Price Disclosure (Protection from Predatory Pricing Act)

Md. Code Ann., Com. Law §§13-321, 13-322official chapter law text, Maryland General Assembly

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

Enacted April 28, 2026 as Chapter 154 and taking effect October 1, 2026, this law bars a food retailer (a business establishment of at least 15,000 square feet that sells food exempt from the state sales and use tax) and a third-party food delivery service provider from engaging in dynamic pricing, offering a price personalized to a consumer based on the consumer's personal data, including through artificial intelligence or models that retrain or recalibrate in near real time, or from using surveillance personal data to set a higher price for that food for a specific consumer or group of consumers.

Separately, any other merchant that sets the price of a consumer good or service using dynamic pricing or personal data and then advertises, labels, or otherwise communicates that price must include a clear and conspicuous disclosure stating that the price was set by an algorithm or by using the consumer's personal data; this broader disclosure duty exempts conduct regulated under the Insurance Article, a financial institution subject to the Gramm-Leach-Bliley Act, a food retailer already covered by the dynamic-pricing ban, and a lower price offered to a merchant's own employee.

Neither provision creates a private right of action. Before bringing an enforcement action, the Division of Consumer Protection must give 45 days' written notice and an opportunity to cure. A violation is subject to a civil fine of up to $10,000 per violation, rising to $25,000 for a repeat violation.

What it requires

SB 141 / Ch. 444 (2026), Election Deepfake Prohibition

Md. Code Ann., Elec. Law §16-905official chapter law text, Maryland General Assembly

In force 4 months, effective 1 June 2026. Binds public and private bodies.

What this law does

Effective June 1, 2026, a person may not knowingly or with reckless disregard create, use, or disseminate a deepfake, defined as an image, audio recording, or video recording intentionally created or manipulated with generative artificial intelligence or other digital technology to produce a realistic but false depiction an ordinary person would conclude is authentic, where the person intends the deepfake to impede or influence a voter's decision, misrepresent voter-registration or election facts, or induce or deter a ballot-question petition signature, and the act results in or is intended to result in harm to a voter or petition.

The prohibition exempts satire or parody and exempts a broadcaster, website, or periodical that carries a clear and conspicuous disclosure that content may be deceptive. A violation is a misdemeanor.

What it requires

SB 360 / Ch. 219 (2025), AI-Generated Deepfakes in Nonconsensual Intimate Imagery

Md. Code Ann., Crim. Law §3-809official codified text, Maryland General Assembly

In force since 1 July 2025. Binds public and private bodies.

What this law does

Maryland's nonconsensual intimate imagery statute defines a prohibited visual representation to include a computer-generated image that is indistinguishable from the depicted person, reaching an AI-generated deepfake on the same terms as an unaltered photograph.

A person may not knowingly distribute such an image showing another identifiable person with intimate parts exposed or engaged in sexual activity, with intent to harm, harass, intimidate, threaten, or coerce, or with knowledge or reckless disregard that the person did not consent, where that person had a reasonable expectation the image would remain private. Violation is a misdemeanor, and the depicted person also has a civil cause of action for defamation per se or invasion of privacy.

What it requires

SB 8 / Ch. 445 (2026), AI and Deepfake Identity Fraud

Md. Code Ann., Crim. Law §8-301(f)(2)official chapter law text, Maryland General Assembly

In force in 8 days, effective 1 October 2026. Binds public and private bodies.

What this law does

Enacted May 12, 2026 as Chapter 445 and taking effect October 1, 2026, this law extends Maryland's identity-fraud statute to bar knowingly, willfully, and with fraudulent intent using artificial intelligence or a deepfake representation to impersonate, falsely depict, or claim to represent another person with intent to defraud, mislead, or cause harm. A victim of that conduct may bring a civil action and seek an injunction and other appropriate relief.

A first-tier violation involving one victim is a felony, and a violation involving two or more victims carries a higher penalty tier.

What it requires

AI risk obligations

HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review

Md. Code Ann., Ins. §15-10B-05.1official codified text, Maryland General Assembly

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

Effective October 1, 2025, a carrier, pharmacy benefits manager, or private review agent that uses artificial intelligence, an algorithm, or other software tool to conduct utilization review must base its determinations on the enrollee's own medical or clinical history and individual clinical circumstances rather than a group dataset alone, keep a health care provider in the determination process, ensure fair and non-discriminatory application, and make the tool available for audit by the Insurance Commissioner.

The tool may not directly or indirectly cause harm to an enrollee, and it may not itself deny, delay, or modify health care services. A companion reporting section requires carriers to disclose to the Commissioner, case by case, whether AI, an algorithm, or other software tool was used in each adverse coverage decision.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (283 words)

The Maryland Online Data Privacy Act (MODPA), Md. Code Ann., Com. Law sections 14-4701 to 14-4714 (Title 14, Subtitle 47), is Maryland's comprehensive consumer-privacy regime, effective October 1, 2025. MODPA was enacted as House Bill 567, Chapter 454 (2024 Regular Session), under numbering the enrolled bill itself calls Subtitle 46; the Department of Legislative Services has since recodified the same provisions at Subtitle 47 in the live code, and Subtitle 47 is the citation used here.

MODPA reaches a wider population of controllers than most peer acts, applying at 35,000 consumers processed rather than the more common 100,000-consumer floor, with no independent revenue threshold. It has no separate lawful-basis list, instead imposing affirmative duties directly and gating sensitive data on strict necessity or consent.

Maryland has no dedicated biometric statute; genetic and biometric data collected to uniquely identify a person is folded into MODPA's sensitive-data category outright, and MODPA's biometric-data definition claws back data generated from a photograph, video, or audio recording the moment that data is generated to identify a specific consumer, so an identifier a product derives from a public recording for identification purposes falls inside sensitive data here.

A separate chapter, the Maryland Personal Information Protection Act (MPIPA), Md. Code Ann., Com. Law sections 14-3501 to 14-3508 (Title 14, Subtitle 35), governs breach notification and lists biometric data used to authenticate identity as its own triggering data element.

MODPA enforcement is exclusive to the Attorney General's Division of Consumer Protection; MODPA expressly excludes the Maryland Consumer Protection Act's private-action-for-damages provision from its enforcement scheme, so MODPA carries no private right of action. MPIPA's own enforcement section carries no such exclusion, so unlike MODPA, a MPIPA breach-notification violation is privately actionable.

Breach notification

Maryland Personal Information Protection Act (MPIPA), breach notification

Md. Code Ann., Com. Law §§ 14-3501, 14-3504 (Title 14, Subtitle 35)official Maryland statute text, Commercial Law Article, Title 14 Subtitle 35, Maryland General Assembly statute lookup

Commencement not set. Binds private bodies.

What this law does

The Maryland Personal Information Protection Act, a separate chapter untouched by MODPA's enactment or later recodification, requires a business that owns, licenses, or maintains computerized data including personal information to notify each affected Maryland individual once it determines a likelihood the breach caused or will cause misuse, as soon as reasonably practicable and no later than 45 days after discovering or being notified of the breach, extended by 7 days after a law-enforcement delay is cleared where that falls later than the original 45-day deadline.

'Personal information' includes biometric data generated by automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, genetic print, or retina or iris image, used to uniquely authenticate identity when accessing a system or account, alongside the more familiar Social Security, driver's license, or financial account number data elements.

MPIPA's own enforcement section, § 14-3508, makes a violation an unfair or deceptive trade practice subject to Title 13's enforcement and penalty provisions, and unlike MODPA's § 14-4713, it does not exclude § 13-408, the Maryland Consumer Protection Act's private-action-for-damages provision, so a MPIPA violation is privately actionable through that route.

What it requires

Comprehensive regime

Maryland Online Data Privacy Act (MODPA), general applicability and controller/processor duties

Md. Code Ann., Com. Law §§ 14-4701, 14-4702 (Title 14, Subtitle 47)official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

MODPA governs private-sector processing of Maryland residents' personal data.

It applies to a person that conducts business in Maryland or targets products or services to Maryland residents and, in the preceding calendar year, either controlled or processed at least 35,000 consumers' personal data (excluding data processed solely to complete a payment transaction) or controlled or processed at least 10,000 consumers' personal data while deriving more than 20% of gross revenue from selling personal data.

MODPA carries no independent revenue threshold, and its 35,000-consumer floor is materially lower than many peer states' 100,000-consumer floor. A controller determines the purpose and means of processing; a processor processes on a controller's behalf.

What it requires

Data subject rights

Maryland Online Data Privacy Act (MODPA), consumer rights and appeal

Md. Code Ann., Com. Law § 14-4705official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

MODPA gives a Maryland consumer the right, exercisable against a controller, to confirm processing, access their personal data, correct inaccuracies, delete data, obtain a portable copy for automated-processing data, obtain a list of categories of third parties their data was disclosed to, and opt out of targeted advertising, sale, or profiling in furtherance of solely automated decisions with legal or similarly significant effects.

A controller must respond within 45 days of receipt, with one 45-day extension available if the controller informs the consumer of the extension and its reason within the initial period, and must establish a conspicuous process to appeal a refusal.

What it requires

Enforcement supervision

Maryland Online Data Privacy Act (MODPA), Attorney General enforcement and cure period

Md. Code Ann., Com. Law §§ 14-4713, 14-4714official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

A MODPA violation is an unfair, abusive, or deceptive trade practice enforced under the Maryland Consumer Protection Act's (Title 13) machinery, except that MODPA expressly excludes section 13-408, the Consumer Protection Act's private-action-for-damages provision, from its enforcement scheme, so a MODPA violation is not independently privately actionable through that route.

Section 14-4713(b) preserves any other remedy provided by law as a savings clause, not a grant of a private cause of action. Before initiating an enforcement action for a violation occurring on or before April 1, 2027, the Division of Consumer Protection may, in its discretion, issue a notice of violation where it determines a cure is possible, giving the controller or processor at least 60 days to cure; there is no unconditional right to cure, and this mechanism itself sunsets.

What it requires

Sensitive categories

Maryland Online Data Privacy Act (MODPA), sensitive data and biometric consent

Md. Code Ann., Com. Law §§ 14-4701(d), (gg), 14-4707(a)official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

MODPA classifies genetic or biometric data, alongside racial or ethnic origin, religious belief, health data, sexuality, transgender or nonbinary status, national origin, citizenship or immigration status, a known child's data, and precise geolocation, as sensitive data.

A controller may not collect, process, or share sensitive data unless strictly necessary to provide a product or service the consumer requested, may never sell sensitive data, and may not process or sell a consumer's personal data for targeted advertising if it knew or should have known the consumer is under 18.

'Biometric data' means data from automatic measurement of a consumer's biological characteristics used to uniquely authenticate identity, including a fingerprint, voiceprint, or eye retina or iris image, and excludes a bare photograph or an audio or video recording, but claws that exclusion back the moment data generated from one is generated to identify a specific consumer.

What it requires

Scraping law2 instruments, 2 in force

Research summary (185 words)

Maryland diverges from federal scraping law in the computer_misuse and personal_data families. Its unauthorized-access statute defines only access, never authorization, and carries no publicly-available-data exception and no notice-based revocation clause, and it carries its own civil private right of action, distinct from the Maryland Online Data Privacy Act's enforcement scheme, for a person who suffers a specific and direct injury from a violation.

MODPA is the strictest data-minimization regime among the state comprehensive privacy acts researched and, unusually, narrows its own publicly-available-information exemption to exclude biometric data a business collected about a consumer without that consumer's knowledge, so a scraper harvesting public biometric identifiers, such as faces from public photos, cannot rely on the publicly-available exemption in Maryland even though the same photos would fall outside personal data if they were merely names or contact details.

Copyright, text-and-data-mining, and database rights add nothing beyond the federal position. ToS enforceability and the Maryland Consumer Protection Act's general unfair-and-deceptive-practices authority rest on general law with no Maryland case applying either to scraping, so neither earns its own instrument here. robots.txt carries no independent legal weight in Maryland.

Computer misuse

Maryland Unauthorized Access to Computers, with a civil private right of action

Md. Code Ann., Crim. Law § 7-302official text, Maryland General Assembly (mgaleg.maryland.gov)

In force. Binds public and private bodies.

What this law does

Section 7-302(c)(1) provides that a person may not intentionally, willfully, and without authorization access, attempt to access, cause to be accessed, or exceed the person's authorized access to all or part of a computer network, computer control language, computer, computer software, computer system, computer service, or computer database, or copy, attempt to copy, possess, or attempt to possess the contents of a computer database accessed in violation of that clause.

Reading the section end to end, only access is defined (to instruct, communicate with, store data in, retrieve or intercept data from, or otherwise use the resources of a computer program, system, or network); authorization and without authorization are never defined anywhere in the section, and it carries no publicly-available-data exception and no notice-based revocation clause of any kind, so there is no textual hook either way for how a Maryland court would treat a public, unauthenticated page.

Section 7-302(g) separately creates a civil private right of action: a person who has suffered a specific and direct injury because of a violation of this section may bring a civil action, recover actual damages and reasonable attorney's fees and court costs, and a prior criminal conviction is not a prerequisite to suit.

This civil right of action is independent of MODPA's own Attorney-General-only enforcement scheme and expands a scraper's exposure in Maryland beyond the criminal penalties in subsection (d).

What it requires

Personal data

Maryland Online Data Privacy Act (MODPA), publicly available information exemption and biometric carve-back

Md. Code Com. Law § 14-4601 et seq. as originally enacted (2024 Md. Laws ch. 454, HB 567), now codified at § 14-4701 et seq.official enacted chapter text, Maryland General Assembly (mgaleg.maryland.gov)

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

MODPA excludes publicly available information from personal data, defined to mean information lawfully made available through government records or that a controller reasonably believes the consumer lawfully made available to the public through widely distributed media.

Unusually among the comprehensive state privacy acts researched, the definition carries an express carve-back: publicly available information does not include biometric data collected by a business about a consumer without the consumer's knowledge, so a scraper harvesting public biometric identifiers, such as faces from public photos for facial-recognition purposes, cannot rely on the publicly-available exemption in Maryland even though the same photos would fall outside personal data entirely if they were merely names or contact details.

MODPA also carries the strictest data-minimization rule among the comprehensive state privacy acts, requiring a controller to limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service the consumer requested, with no separate or compatible disclosed purpose alternative of the kind most peer statutes carry.

The Act applies to a controller conducting business in Maryland, or targeting Maryland residents, that in the preceding calendar year controlled or processed personal data of at least 35,000 consumers (excluding payment-only data), or of at least 10,000 consumers while deriving more than 20% of gross revenue from personal-data sales. As enacted, the chapter was codified at Com. Law section 14-4601 et seq.

The 2025 Replacement Volume recodification to section 14-4701 et seq. is confirmed directly against the state's own statute lookup (mgaleg.maryland.gov): section 14-4601 now returns an unrelated Forensic Nurse Examiner Training Grant Program provision, while section 14-4701 carries this Act's own definitions and cross-references its consumer-rights section at section 14-4705, so section 14-4701 et seq. is the current citation.

The Act's own enactment clause states it shall take effect October 1, 2025, correcting an earlier drafting date. Enforcement runs through the penalty provisions of Title 13 of the Commercial Law Article (the Maryland Consumer Protection Act) except for section 13-408, that article's own private-right-of-action section, so there is no private right of action and enforcement is by the Maryland Attorney General.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (807 words)

Maryland's product-security and cyber-resilience posture rests on one enacted state statute, the Maryland Personal Information Protection Act's safeguards and secure-disposal duty, Commercial Law sections 14-3502 and 14-3503 (Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194), approved by Governor Martin O'Malley May 17, 2007 and effective January 1, 2008), which requires a business that owns, maintains, or licenses the personal information of a Maryland resident to implement and maintain reasonable security procedures and practices appropriate to the nature of that information and the size of the business, to take reasonable steps to protect personal information from unauthorized access when destroying records that contain it, and to require the same of a nonaffiliated third-party service provider by contract.

Commercial Law section 14-3507 deems a business already complying with the security, notification, or destruction rules of its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or Health Insurance Portability and Accountability Act (HIPAA), to be in compliance with the whole subtitle.

No enacted Maryland statute sets security requirements a connected device or software product must meet before or after it reaches the market: bills closely modeled on California's connected-device statute, Senate Bill 443 and a House companion, House Bill 888, considered by the House Economic Matters Committee as recently as February 2020, were introduced and did not advance past committee, and no successor bill was located in a later session, so this is a researched absence rather than a gap in coverage.

Maryland has no general private-sector duty to report an exploited vulnerability or a security incident to an authority.

Chapter 242 of the Laws of 2022 (S.B. 812) made the Office of Security Management and the State Chief Information Security Officer permanent within the Department of Information Technology and requires each unit of the Executive Branch of State government and certain local government entities, not a private business, to report a cybersecurity incident, so it belongs with this jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.

Chapter 243 of the Laws of 2022 (H.B. 1205, the Modernize Maryland Act of 2022) separately requires a public or private water or sewer system that serves 10,000 or more users and receives State financial assistance to assess its vulnerability to a cyber attack, develop a cybersecurity plan where appropriate, and report to the General Assembly; because the LexLint activity vocabulary cannot yet express a water or sewer utility operator as a bound role, it is deferred rather than flagged on a guess (#6740), and recorded here so a reader knows it exists.

The Maryland Insurance Administration separately administers the Maryland Insurance Data Security Act, Insurance Article Title 33 (Chapter 231 of the Laws of 2022, S.B. 207, based on the NAIC's Insurance Data Security Model Law), effective October 1, 2022, which requires a licensed insurance carrier to maintain a written information security program and notify the Insurance Commissioner of a cybersecurity event; because its bound party, an insurance licensee, is also a role the activity vocabulary cannot express, it too is deferred and recorded here rather than filed as an instrument.

Commercial Law section 14-3508 makes a violation of the safeguards and disposal duty an unfair or deceptive trade practice under Title 13 of the Commercial Law Article (the Maryland Consumer Protection Act) and subjects it to that title's enforcement and penalty provisions: the Attorney General's Consumer Protection Division may seek a civil penalty of up to $10,000 per violation and up to $25,000 for a repeat violation under Commercial Law section 13-410, and, unlike New York's SHIELD Act safeguards duty, Commercial Law section 13-408 also lets any person bring a private action to recover for an injury or loss the violation caused, plus attorney's fees.

Title 13's own criminal provision, section 13-411, makes a violation of that title a misdemeanor carrying a fine of up to $1,000 or imprisonment of up to one year; whether that reaches a safeguards or disposal violation through section 14-3508's incorporation of Title 13's penalty provisions, as distinct from the civil penalty alone, is not addressed in the Office of the Attorney General's own published compliance guidance and was not located in any other primary source.

Maryland's breach-notification duty, Commercial Law section 14-3504, the other half of the Maryland Personal Information Protection Act, is already this jurisdiction's privacy row rather than repeated here: it requires notice to an affected Maryland resident and, before that notice, to the Office of the Attorney General, once a business discovers or is notified of a breach of the security of a system.

The Maryland Online Data Privacy Act's own controller and processor obligations are this jurisdiction's comprehensive privacy regime and are researched there rather than duplicated here.

Security baseline statutes

Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty

Md. Code Ann. Com. Law sections 14-3502, 14-3503 (Maryland Personal Information Protection Act, Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194))Official statute text, Maryland Code, Commercial Law Article, Title 14, Subtitle 35

In force since 1 January 2008. Binds private bodies.

What this law does

A business that owns, maintains, or licenses the personal information of a Maryland resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and the nature and size of the business, to protect it from unauthorized access, use, modification, or disclosure.

When destroying a customer's, an employee's, or a former employee's records containing personal information, the business must take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology.

Where the business discloses personal information to a nonaffiliated third-party service provider under a written contract entered into on or after January 1, 2009, it must require the provider by that contract to implement and maintain the same kind of reasonable security procedures and practices.

A business already complying with the security, notification, or destruction rules of its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or Health Insurance Portability and Accountability Act (HIPAA), is deemed to be in compliance with this subtitle.

A violation is an unfair or deceptive trade practice under Title 13 of the Commercial Law Article, enforceable by the Attorney General for injunctive relief and a civil penalty of up to $10,000 per violation, $25,000 for a repeat violation, under Commercial Law section 13-410, and Commercial Law section 13-408 also lets any person bring a private action to recover for injury or loss the violation caused.

What it requires

Age gating law1 instrument, 1 in force

Research summary (76 words)

Maryland's Age-Appropriate Design Code Act, the Kids Code, has been in effect since October 1, 2024 and is being challenged in federal court by NetChoice, with a motion to dismiss denied in November 2025 and no injunction in place. Maryland has not enacted an adult content age verification law or an app store accountability law: bills on both topics stalled in committee in 2025 and 2026. No dedicated social media minor-access bill has advanced past introduction.

Age-appropriate design code

HB 603 / SB 571, Maryland Age-Appropriate Design Code Act (Kids Code)

Md. Code, Com. Law §§ 14-4801 to 14-4813 (Subtitle 48), 2024 Md. Laws ch. 461official Maryland Code statute text

In force since 1 October 2024. Binds private bodies.

What this law does

Requires online products reasonably likely to be accessed by children under 18 to set high default privacy settings, complete data protection impact assessments, and avoid data practices harmful to children. A First Amendment and federal preemption challenge by NetChoice survived a motion to dismiss in November 2025 and is proceeding without an injunction.

Note and primary source

Law in local jurisdictions2 with pages

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.