Skip to content

Cyber Liability by state

Maryland data breach notification law and cyber insurance

Direct answer

What is Maryland's data breach notification law?

Maryland's breach notification law (Md. Code, Com. Law sect. 14-3501 et seq.) requires businesses to notify affected residents as soon as reasonably practicable but not later than 45 days after concluding the investigation after a breach of personal information. Maryland requires businesses to notify affected residents within 45 days of concluding a breach investigation, with Attorney General notice before consumers are informed.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Maryland requires businesses to notify affected residents within 45 days of concluding a breach investigation, with Attorney General notice before consumers are informed. Cyber liability insurance typically covers the forensics, notification, and legal review this statute drives.

Consumer notification deadline
As soon as reasonably practicable but not later than 45 days after concluding the investigation
Regulator notice
Notify the Maryland Attorney General before giving notice to affected residents.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 1,000 residents.
Safe harbor
Notification is not required if the compromised data was encrypted, secured, or made unreadable, or where an investigation finds misuse is not reasonably likely.
Enforcement
Violations are unfair or deceptive trade practices enforceable by the Attorney General.

Statutes and sources

  • Maryland Personal Information Protection Act

    Md. Code, Com. Law sect. 14-3501 et seq.

Regulator: Maryland Attorney General . Last verified 2026-07-29 from the official source .

Get Maryland coverage handled

Share a few details and an agent will respond within one business day.