Description

Enacted Amendment to Maryland Personal Information Protection Act (Data Breach Notification Act)

On 29 May 2022, House Bill 962 to amend the Maryland Personal Data Protection Act (known as the Data Breach Notification Act) was enacted. The amendment will be implemented on 1 October 2022. The amendment enhances the scope of the bill to all businesses maintaining personal information of Maryland residents (previously only licensed businesses) and introduces stricter cybersecurity requirements. Specifically, businesses that maintain personal information of Maryland residents must introduce reasonable data security requirements and notify data subjects of data breaches within 45 days of discovery. In addition, the amendment specifies the content of data breach notifications to the Maryland Attorney General, including the number of affected data subjects, the nature of the breach, remedies taken by the company and how users were notified.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2022-02-24
under deliberation

On 24 February 2022, House Bill 962 to amend the Maryland Personal Data Protection Act (known as th…

2022-04-08
adopted

On 8 April 2022, House Bill 962 to amend the Maryland Personal Data Protection Act (known as the Da…

2022-05-29
in grace period

On 29 May 2022, House Bill 962 to amend the Maryland Personal Data Protection Act (known as the Dat…

2022-10-01
in force

On 1 October 2022, House Bill 962 to amend the Maryland Personal Data Protection Act (known as the …