Law / United States / Maryland

Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty

Md. Code Ann. Com. Law sections 14-3502, 14-3503 (Maryland Personal Information Protection Act, Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194))

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 January 2008.

A security baseline statutes rule binding private bodies.

As of 14 September 2026.

What it requires

  • This binds any business that owns, maintains, or licenses the personal information of a Maryland resident; a business already complying with the security, notification, or destruction rules set by its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or HIPAA, is deemed to comply with this duty.
  • Absent that safe harbor, implement and maintain reasonable security procedures and practices, appropriate to the nature of the personal information held and the size of the business, to protect it from unauthorized access, use, modification, or disclosure.
  • When destroying a customer's, an employee's, or a former employee's records containing personal information, take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology.
  • Where a nonaffiliated third-party service provider will receive personal information under a written contract entered into on or after January 1, 2009, require by that contract that the provider also implement and maintain reasonable security procedures and practices appropriate to the information disclosed.
  • A violation is enforced only by the Office of the Attorney General's Consumer Protection Division, as an unfair or deceptive trade practice, for injunctive relief and a civil penalty of up to $10,000 per violation ($25,000 for a repeat violation); any person harmed may also bring a private action for injury or loss, and Title 13's own misdemeanor provision may extend to a violation of this duty.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Title 13's own criminal provision, Commercial Law section 13-411(a), makes a violation of any provision of that title a misdemeanor, on conviction a fine of up to $1,000 or imprisonment of up to one year or both, in addition to any civil penalties. Section 14-3508 subjects a violation of the safeguards and secure-disposal duty to Title 13's enforcement and penalty provisions generally, so whether section 13-411's misdemeanor extends to this duty, as distinct from the section 13-410 civil penalty alone, has not been construed in the Office of the Attorney General's own published compliance guidance or located in any other primary source.

Penalty structure

Civil penalty under Commercial Law section 13-410(a) for a first violation; section 13-410(b) raises the amount to up to $25,000 per violation once a merchant has already been found to have violated Title 13 and repeats the same violation. The statute names no aggregate cap. Maryland's separate breach-notification duty (section 14-3504) is filed under this jurisdiction's privacy row.

Rule
Per violation only
As of
14 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
10,000

Who enforces it

Enforcement body

Commercial Law section 14-3508 deems a violation of the safeguards and secure-disposal duty an unfair or deceptive trade practice under Title 13 of the Commercial Law Article (the Maryland Consumer Protection Act) and subjects it to that title's enforcement and penalty provisions, so it is enforced by the Office of the Attorney General's Consumer Protection Division; Commercial Law section 13-408 also lets any person harmed bring a private action.

Settledness

As of
14 September 2026
Guidance link
https://oag.maryland.gov/i-need-to/Pages/Guidelines-for-Businesses-to-Comply-with-the-Maryland-Personal-Information-Protection-Act.aspx
Guidance body
Office of the Attorney General of Maryland
Open questions
Does Commercial Law section 14-3508's incorporation of Title 13's 'enforcement and penalty provisions' reach the criminal misdemeanor in section 13-411, or only the civil penalty in section 13-410?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A business that owns, maintains, or licenses the personal information of a Maryland resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and the nature and size of the business, to protect it from unauthorized access, use, modification, or disclosure.

When destroying a customer's, an employee's, or a former employee's records containing personal information, the business must take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology.

Where the business discloses personal information to a nonaffiliated third-party service provider under a written contract entered into on or after January 1, 2009, it must require the provider by that contract to implement and maintain the same kind of reasonable security procedures and practices.

A business already complying with the security, notification, or destruction rules of its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or HIPAA, is deemed to be in compliance with this subtitle.

A violation is an unfair or deceptive trade practice under Title 13 of the Commercial Law Article, enforceable by the Attorney General for injunctive relief and a civil penalty of up to $10,000 per violation, $25,000 for a repeat violation, under Commercial Law section 13-410, and Commercial Law section 13-408 also lets any person bring a private action to recover for injury or loss the violation caused.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Maryland Code, Commercial Law Article, Title 14, Subtitle 35

Back to the example  ·  Lint your app