Law note · Maryland

Maryland Personal Information Protection Act (MPIPA), breach notification

cite Md. Code Ann., Com. Law §§ 14-3501, 14-3504 (Title 14, Subtitle 35) stage IMMINENT commencement not set reviewed 2026-08-27

The Maryland Personal Information Protection Act, a separate chapter untouched by MODPA's enactment or later recodification, requires a business that owns, licenses, or maintains computerized data including personal information to notify each affected Maryland individual once it determines a likelihood the breach caused or will cause misuse, as soon as reasonably practicable and no later than 45 days after concluding its investigation, with an extension to 30 days after any law-enforcement delay is cleared.

'Personal information' includes biometric data generated by automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, genetic print, or retina or iris image, used to uniquely authenticate identity when accessing a system or account, alongside the more familiar Social Security, driver's license, or financial account number data elements.

MPIPA's own enforcement section, § 14-3508, makes a violation an unfair or deceptive trade practice subject to Title 13's enforcement and penalty provisions, and unlike MODPA's § 14-4713, it does not exclude § 13-408, the Maryland Consumer Protection Act's private-action-for-damages provision, so a MPIPA violation is privately actionable through that route.

What it asks of an app

  • Notify each affected Maryland individual as soon as reasonably practicable, and no later than 45 days after concluding your breach investigation, once you determine a likelihood that personal information has been or will be misused.
  • Treat biometric data used to uniquely authenticate identity when accessing a system or account, such as a fingerprint, voiceprint, or retina or iris image, as its own triggering data element for this notification duty, separate from a name combined with a Social Security or financial account number.
  • Where notification is delayed for a law enforcement investigation or to determine the breach's scope, notify within 30 days after that delay is cleared.
  • Expect a MPIPA violation to be privately actionable. Unlike MODPA, MPIPA's enforcement section does not exclude the Consumer Protection Act's private-action-for-damages provision.

When LexLint raises it

Declared activities: processes_biometrics, processes_voice, crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Maryland statute text, Commercial Law Article, Title 14 Subtitle 35, Maryland General Assembly statute lookup

← Back to the example  ·  Lint your app →