The Maryland Data Privacy and Protection Act of 2026 takes effect October 1, 2026, and it changes the trigger that puts security and privacy requirements into a Maryland State contract. Enacted as Chapter 435 of the 2026 Laws of Maryland (House Bill 264) and approved by the Governor on May 12, 2026, the Act rewrites § 13-115 of the State Finance and Procurement Article, adds a new § 3.5-319, and expands the statutory definition of "personal information" that other Maryland obligations key off. If you sell to a Maryland State agency, the practical question is no longer whether you connect to a State network. It is whether you handle data about people.
The Trigger Changed
Before this Act, Maryland's Department of Information Technology (DoIT) was directed to require basic security requirements in contracts under which a third-party contractor would have access to and use State telecommunication equipment, systems, or services, or for systems or devices that would connect to them. Access to the State's infrastructure was the hook.
As amended, § 13-115(a) directs DoIT to require basic security, data collection, and privacy requirements in a contract under which a third-party contractor will:
1. have access to and use State information technology equipment, systems, or services; 2. collect, store, or process personal information as defined in § 10-1301 of the State Government Article; or 3. connect to State information technology equipment, systems, or services.
Item two is new, and it is the one that matters. A vendor that processes personal information for a Maryland agency — a benefits administrator, a case-management platform, a health services subcontractor, a records-digitization shop — now falls inside the requirement even if it never touches a State system. "Telecommunication" also became "information technology" across the section, closing an argument that the old language reached only network and communications infrastructure.
The Named Standards
The Act keeps the existing security benchmark and adds a privacy one.
Security. Section 13-115(b) is unchanged: the security requirements DoIT develops "shall be consistent with a widely recognized security standard, including National Institute of Standards and Technology SP 800-171, ISO27001, or Cybersecurity Maturity Model Certification." Contractors already building toward NIST SP 800-171 for federal defense work are building against a standard Maryland statute names by reference.
Privacy. New subsection (c) requires the privacy requirements to be consistent with widely recognized privacy standards, and names the NIST Privacy Framework v1.0, NIST SP 800-53 Rev. 5, and NIST SP 800-207, Zero Trust Architecture, "as they may be updated from time to time." That last clause is worth noting — the statutory benchmark moves when the publication moves.
New § 3.5-319 requires every unit of State government to designate a Privacy Officer to oversee compliance and coordinate with DoIT and the Office of the Attorney General, and directs DoIT to adopt regulations, guidance, and model templates, including data protection protocols. Those templates are where the actual clause language will live. Watch for them.
"Personal Information" Got Broader
The Act rewrites the definition in § 10-1301(c) of the State Government Article — the definition that § 13-115's new trigger now points to. Alongside the existing identifiers, it adds:
- a username or e-mail address combined with a password or security question and answer permitting access to an individual's e-mail account;
- genetic and health-related data, including mental health, substance use disorder, and disability; and
- sensitive data as defined in § 14-4701 of the Commercial Law Article — which sweeps in racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, citizenship or immigration status, genetic and biometric data, data on a known child, and precise geolocation.
Two consequences follow. First, the population of contracts caught by the new § 13-115 trigger is larger than a narrow reading of "personal information" would suggest. Second, because § 10-1301 sits in Maryland's breach-notification subtitle, the expanded definition also enlarges what counts as a reportable breach.
What the Act Does Not Do
Be precise about the mechanism, because the trade coverage of state privacy laws routinely blurs it.
This Act binds units of Maryland State government and DoIT. It is not a general commercial privacy law, and it does not regulate private businesses at large — that is the separate domain of the Maryland Online Data Privacy Act. Nothing in Chapter 435 imposes a duty directly on a contractor. The contractor's obligation arises when DoIT's required security, data collection, and privacy terms appear in a solicitation, contract, or modification. The Act is the instruction to the State to put them there.
The Act also imposes data-minimization and retention discipline on the agencies themselves under § 4-501 of the General Provisions Article — collection limited to the minimum necessary for a "legitimate government purpose," retention no longer than reasonably necessary, and secure deletion or de-identification once the purpose is served. Those obligations run to the unit, but they flow downhill fast: an agency told to delete data on a schedule will need its vendors to delete on the same schedule, and will say so in the contract.
Separately, § 10-1702 required each governmental entity, in consultation with DoIT, to develop and publish procedures preventing the sale and redisclosure of personal records and geolocation data, and to submit those procedures to the General Assembly on or before July 1, 2026. Those published procedures are a preview of the redisclosure restrictions likely to appear in vendor agreements.
What to Do Before October 1
Inventory your Maryland State work by data, not by connection. Pull every Maryland State contract and task order and ask a single question of each: do we collect, store, or process personal information as newly defined? The answer, not your network diagram, now determines exposure.
Map the privacy standards you have never been scored against. The NIST Privacy Framework and SP 800-207 are not the same exercise as an 800-171 assessment. If your program was built entirely around federal defense requirements, the privacy side is likely the gap. Our build-a-program guide is a starting point for structuring that work.
Re-check your breach-notification triggers. Credential pairs, health-related data, and the § 14-4701 sensitive-data categories may not be in your current incident-classification matrix. If they are not, your first Maryland notification decision will be made under time pressure with the wrong criteria.
Read modifications carefully as they arrive. New DoIT terms will show up as contract modifications on existing vehicles, not only in new solicitations. Price and schedule the compliance work rather than accepting it silently.
Watch for the DoIT templates. The statute delegates the operative language. Until those regulations and model templates issue, the exact clause text is not knowable, and any vendor telling you otherwise is guessing.
Key Takeaways
- Handling personal information — not touching a State system — is now an independent trigger for mandatory security, data collection, and privacy requirements in Maryland State contracts under amended § 13-115.
- The privacy benchmark is new and named: the NIST Privacy Framework v1.0, NIST SP 800-53 Rev. 5, and NIST SP 800-207 Zero Trust Architecture, alongside the existing security benchmark of NIST SP 800-171, ISO 27001, or CMMC.
- Nothing binds you until it is in your contract, but the Act directs the State to put it there — and the expanded "personal information" definition simultaneously widens Maryland's breach-notification exposure. The effective date is October 1, 2026.
Maryland is not an outlier here so much as an early mover on a pattern worth tracking: states increasingly borrow federal cybersecurity frameworks by name and attach them to procurement. See our state requirements coverage for how the obligations stack across jurisdictions, and use Find My Requirements to see which regimes apply to your contracts.
This article is educational information about legal and regulatory developments, not legal advice, and does not create an attorney-client relationship. Individual contract terms control.