Maryland Personal Information Protection Act
MPIPAMaryland's data security and breach notification law requires businesses holding Maryland residents' personal information to keep reasonable security, destroy records securely, and flow security requirements down to service providers. After a breach, a business must investigate and, unless misuse is not likely, notify affected residents within 45 days, notifying the Attorney General first. The 2022 revisions added genetic information and set the 45-day and 10-day deadlines.
Jurisdiction
Maryland
Jurisdiction Type
state
Country
United States
Enforcing Authority
Consumer Protection Division, Office of the Attorney General (14-3508; Com. Law Title 13)
Fines Under This Regulation
0
Total Fine Amount (USD)
--