Law / United States / Maryland
Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty
Md. Code Ann. Com. Law sections 14-3502, 14-3503 (Maryland Personal Information Protection Act, Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194))
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2008.
A security baseline statutes rule binding private bodies.
As of 14 September 2026.
What it requires
- This binds any business that owns, maintains, or licenses the personal information of a Maryland resident; a business already complying with the security, notification, or destruction rules set by its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or HIPAA, is deemed to comply with this duty.
- Absent that safe harbor, implement and maintain reasonable security procedures and practices, appropriate to the nature of the personal information held and the size of the business, to protect it from unauthorized access, use, modification, or disclosure.
- When destroying a customer's, an employee's, or a former employee's records containing personal information, take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology.
- Where a nonaffiliated third-party service provider will receive personal information under a written contract entered into on or after January 1, 2009, require by that contract that the provider also implement and maintain reasonable security procedures and practices appropriate to the information disclosed.
- A violation is enforced only by the Office of the Attorney General's Consumer Protection Division, as an unfair or deceptive trade practice, for injunctive relief and a civil penalty of up to $10,000 per violation ($25,000 for a repeat violation); any person harmed may also bring a private action for injury or loss, and Title 13's own misdemeanor provision may extend to a violation of this duty.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Title 13's own criminal provision, Commercial Law section 13-411(a), makes a violation of any provision of that title a misdemeanor, on conviction a fine of up to $1,000 or imprisonment of up to one year or both, in addition to any civil penalties. Section 14-3508 subjects a violation of the safeguards and secure-disposal duty to Title 13's enforcement and penalty provisions generally, so whether section 13-411's misdemeanor extends to this duty, as distinct from the section 13-410 civil penalty alone, has not been construed in the Office of the Attorney General's own published compliance guidance or located in any other primary source.
Penalty structure
Civil penalty under Commercial Law section 13-410(a) for a first violation; section 13-410(b) raises the amount to up to $25,000 per violation once a merchant has already been found to have violated Title 13 and repeats the same violation. The statute names no aggregate cap. Maryland's separate breach-notification duty (section 14-3504) is filed under this jurisdiction's privacy row.
- Rule
- Per violation only
- As of
- 14 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 10,000
Who enforces it
Enforcement body
Commercial Law section 14-3508 deems a violation of the safeguards and secure-disposal duty an unfair or deceptive trade practice under Title 13 of the Commercial Law Article (the Maryland Consumer Protection Act) and subjects it to that title's enforcement and penalty provisions, so it is enforced by the Office of the Attorney General's Consumer Protection Division; Commercial Law section 13-408 also lets any person harmed bring a private action.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://oag.maryland.gov/i-need-to/Pages/Guidelines-for-Businesses-to-Comply-with-the-Maryland-Personal-Information-Protection-Act.aspx
- Guidance body
- Office of the Attorney General of Maryland
- Open questions
- Does Commercial Law section 14-3508's incorporation of Title 13's 'enforcement and penalty provisions' reach the criminal misdemeanor in section 13-411, or only the civil penalty in section 13-410?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A business that owns, maintains, or licenses the personal information of a Maryland resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and the nature and size of the business, to protect it from unauthorized access, use, modification, or disclosure.
When destroying a customer's, an employee's, or a former employee's records containing personal information, the business must take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology.
Where the business discloses personal information to a nonaffiliated third-party service provider under a written contract entered into on or after January 1, 2009, it must require the provider by that contract to implement and maintain the same kind of reasonable security procedures and practices.
A business already complying with the security, notification, or destruction rules of its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or HIPAA, is deemed to be in compliance with this subtitle.
A violation is an unfair or deceptive trade practice under Title 13 of the Commercial Law Article, enforceable by the Attorney General for injunctive relief and a civil penalty of up to $10,000 per violation, $25,000 for a repeat violation, under Commercial Law section 13-410, and Commercial Law section 13-408 also lets any person bring a private action to recover for injury or loss the violation caused.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Maryland Code, Commercial Law Article, Title 14, Subtitle 35