Skip to content

The Letter About Your Information

Com. Law § 14-3504 — notice within 45 days, and the Attorney General first

In Maryland, a business that discovers or is notified of a breach of the security of a system gives the required notice to the individual as soon as reasonably practicable, and not later than 45 days after it discovers or is notified of the breach, subject to a delay law enforcement asks for.

Email
Who is toldWhen, as the section puts it
Who is toldEach affected individualWhen, as the section puts itAs soon as reasonably practicable, and not later than 45 days
Who is toldThe Office of the Attorney GeneralWhen, as the section puts itBefore the notice to individuals
Who is toldA business that maintains data it does not ownWhen, as the section puts itTells the owner not later than 10 days after it discovers or is notified of the breach
  • The notice to the individual includes contact information for the Office of the Attorney General, and a statement that the individual can get information about avoiding identity theft from the sources it lists.

What counts as personal information, the forms notice may take, and the exceptions for encrypted data are in the section and are not reproduced in full here. Whether a notice was required or on time is a question for the attorney general, a court, and a licensed Maryland attorney.

Sources for this section (1)
  1. Md. Code, Com. Law § 14-3504 — Breach of the security of a system

Legal information, not legal advice. Verified as of October 2026. Applying it to a particular situation is the work of a licensed Maryland attorney.

On the clock

One period on this page runs out. Each is stated above with its authority; this is the same thing with the date attached.

  • 45 daysNotice to individuals after a data breach · from discovering or being notified of the breach

From here