Privacy Law Library

Maryland Age-Appropriate Design Code Act (Maryland Kids Code)

Maryland Kids Code

Children · Location

The Maryland Kids Code requires large online businesses whose products children under 18 are reasonably likely to use to design those products in children's best interests. Covered entities must complete data protection impact assessments, set high-privacy defaults for children, and avoid default profiling, default precise geolocation tracking, unnecessary data collection, and dark patterns. NetChoice's First Amendment challenge (NetChoice v. Brown, D. Md. No. 1:25-cv-00322) survived a motion to dismiss in November 2025 and is in discovery; the law has not been enjoined.

Where
Maryland
Citation
Md. Code, Com. Law §§ 14-4801 to 14-4813 (enacted by 2024 Md. Laws chs. 460 and 461 as §§ 14-4601 to 14-4612, since renumbered)
Status
In force
In force since
2024-10-01
Enforced by
Consumer Protection Division, Office of the Attorney General (14-4808)
People can sue
No
Penalties
Unfair, abusive, or deceptive trade practice enforced under Title 13 (except § 13-410); civil penalties up to $2,500 per affected child per negligent violation and $7,500 per affected child per intentional violation (14-4808). Entities in substantial compliance get written notice and a 90-day cure opportunity before penalties (14-4809). No private right of action (14-4810(1)).
Applies to
  • For-profit entities doing business in Maryland that collect consumers' personal data and determine the purposes and means of processing, and that have over $25 million in annual gross revenue (CPI-adjusted), buy, receive, sell, or share personal data of 50,000+ consumers, households, or devices, or derive at least 50% of revenue from selling personal data (14-4801(h))
  • Online services, products, or features reasonably likely to be accessed by children under 18, judged by COPPA child-directed status, audience evidence, child-targeted ads, internal research, or actual or constructive knowledge that a user is a child (14-4801(e), (s))
  • Does not apply to GLBA-, HITECH-, or HIPAA-regulated data held by compliant entities, or clinical-trial information (14-4802)

What a privacy notice must say

  • Present privacy information, terms, policies, and community standards concisely and prominently in language suited to the children likely to use the product, and provide accessible tools to exercise privacy rights and report concerns.Com. Law 14-4805(4)-(5)

Practices it requires

  • Collect only data reasonably necessary for a product the child is actively and knowingly engaged with, and use it only for the purpose for which it was collected.Com. Law 14-4806(a)(3)-(4)
  • Do not collect a child's precise geolocation by default unless strictly necessary and time-limited, and show an obvious signal while collecting it.Com. Law 14-4806(a)(5)-(6)
  • Do not use dark patterns to extract extra personal data, circumvent privacy protections, or act against children's best interests.Com. Law 14-4806(a)(7)
  • Do not let anyone other than a parent or guardian monitor a child's online activity without first notifying the child and the parent or guardian; limit data used for age estimation or likely-audience determinations to what is reasonably necessary.Com. Law 14-4806(a)(8)-(9), (c)
  • Configure children's default privacy settings to a high level of privacy unless there is a compelling best-interests reason otherwise.Com. Law 14-4805(3)
  • Do not process a child's personal data inconsistently with children's best interests, and do not profile a child by default absent safeguards and necessity or a compelling reason.Com. Law 14-4806(a)(1)-(2)

Other duties

  • Keep assessment documentation while the product is likely accessed by children, review within 90 days of material processing changes, and produce the list of assessments within 5 business days and any assessment within 7 business days of a Division request.Com. Law 14-4805(1)-(2), 14-4807
  • Prepare a data protection impact assessment for each online product reasonably likely to be accessed by children, weighing risks from contacts, conduct, contracts, engagement-extending design features, data practices, experiments, and algorithms; existing products needed assessments by 2026-04-01 and new products need one before launch.Com. Law 14-4804 · From 2026-04-01

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Litigation status is from CourtListener docket entries (a secondary mirror of PACER): complaint filed 2025-02-03; order denying motion to dismiss (ECF 58-59) 2025-11-24; leave to file second amended complaint granted 2026-04-20 and 2026-07-07; discovery ongoing as of a 2026-09-23 protective-order ruling. No preliminary-injunction motion or ruling was found; the opinions themselves were not read. | Chapter 460 (the Senate cross-file, SB 571) was not separately fetched.

Research reference, not legal advice.