Maryland Personal Information Protection Act

MPIPA
active

Maryland's data security and breach notification law requires businesses holding Maryland residents' personal information to keep reasonable security, destroy records securely, and flow security requirements down to service providers. After a breach, a business must investigate and, unless misuse is not likely, notify affected residents within 45 days, notifying the Attorney General first. The 2022 revisions added genetic information and set the 45-day and 10-day deadlines.

Jurisdiction

Maryland

Jurisdiction Type

state

Country

United States

Enforcing Authority

Consumer Protection Division, Office of the Attorney General (14-3508; Com. Law Title 13)

Fines Under This Regulation

0

Total Fine Amount (USD)

--