Maryland · verified official-source register

Maryland Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Maryland case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Google, LLC

Date
December 14, 2022
Amount
Three Hundred Ninety-One Million, Five Hundred Thousand Dollars ($391,500,000.00) total; Maryland’s share: Eight Million, Six Hundred and Nineteen Thousand, Two Hundred and Twelve Dollars and Twenty Cents ($8,619,212.20)
Legal basis
Ala. Code § 8-19-1 et seq.; Arkansas Deceptive Trade Practices Act, Ark. Code Ann. §§ 4-88-101 et seq.; Arkansas Personal Information Protection Act §§ 4-110-101 et seq.; Col. Rev. Stat. § 6-1-101 et seq.; Col. Rev. Stat. § 6-1-105(1); Conn. Gen. Stat. §§ 42-110b et seq.; 6 Del. C. §§ 2511 et seq.; Florida Deceptive and Unfair Trade Practices Act, Chapter 501, Part II, Florida Statutes; O.C.G.A. § 10-1-390 et seq.; Haw. Rev. Stat. Chpt. 481A; Haw. Rev. Stat. Sect. 480-2; Idaho Consumer Protection Act, title 48, chapter 6, Idaho Code; 815 ILCS 505/1 et seq.; Iowa Code § 714.16; Unfair Trade Practices and Consumer Protection Law, K.S.A. § 50-623 et seq.; KRS 367.110-990 et seq.; La. R.S. §§ 51:1401 et seq.; Maine Unfair Trade Practices Act, 5 M.R.S.A. § 205-A et seq.; Maryland Consumer Protection Act, §§ 13-101 through 13-501 (2013 Repl. Vol. and 2021 Supp.); Mass. Gen. L. c. 93A; Michigan Consumer Protection Act, MCL 445.901 et seq.; Uniform Deceptive Trade Practices Act, Minn. Stat. §§ 325D.43-.48; Minnesota Consumer Fraud Act, Minn. Stat. §§ 325F.68-.694; Miss. Code Ann. § 75-24-27(1)(g); Missouri Merchandising Practices Act, Ch. 407, RSMo; Neb. Rev. Stat. § 59-1601 et seq.; Neb. Rev. Stat. § 87-301 et seq.; Nevada Deceptive Trade Practice Act, NRS 598.0903-.0999; New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 et seq.; New Mexico Unfair Practices Act, NMSA 1978, §§ 57-12-1 to -26; NY Executive Law § 63(12); NY General Business Law §§ 349 and 350; North Carolina Unfair and Deceptive Trade Practices Act, N.C.G.S. § 75-1.1 et seq.; N.D.C.C. § 51-15-01 et seq.; Ohio R.C. 13145.01 et seq.; Oklahoma Consumer Protection Act, 15 O.S. §§ 751 et seq.; Oregon Unlawful Trade Practices Act, ORS 646.605-646.656; Pennsylvania Unfair Trade Practices and Consumer Protection Law, 73 P.S. § 201-1 et seq.; South Carolina Unfair Trade Practices Act, S.C. Code Ann. §§ 39-5-10 et seq.; South Dakota Codified Laws Chapter 37-24; Tennessee Consumer Protection Act of 1977, Tenn. Code Ann. §§ 47-18-101 to -134; Utah Consumer Sales Practices Act, Utah Code § 13-11-1 et seq.; 9 V.S.A. chapter 63 et seq.; Virginia Consumer Protection Act, Va. Code Ann. §§ 59.1-196 to 59.1-207; Wis. Stat. § 100.18; Md. Code Ann., Com. Law § 13-402; Maryland Personal Information Protection Act, Md. Code Ann., Com. Law §§ 14-3501 through 14-3508; common-law claims concerning unfair, deceptive, or fraudulent trade practices

Why the action was brought

The Attorneys General alleged that Google collected, retained, and used users’ location information through Location History and Web & App Activity while misrepresenting that disabling Location History or other account settings stopped collection. They also alleged concealed collection from signed-out users and continued location-based advertising after Ads Personalization was disabled, confusing users and impairing privacy control.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Target Corporation

Date
May 23, 2017
Amount
$18.5 million
Legal basis
No statutes or laws cited in the document.

Why the action was brought

States alleged attackers used third-party vendor credentials to access Target’s gateway server on or about November 12, 2013. System weaknesses allowed access to a customer service database, malware installation, and capture of personal and payment-card information, including names, addresses, card numbers, expiration dates, CVV1 codes, and encrypted debit PINs, affecting millions of consumers.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Equifax Inc.

Date
August 22, 2019
Amount
$175,000,000.00 monetary payment to the Attorneys General; Consumer Restitution Fund of at least $300,000,000 and no more than $425,000,000; Maryland’s share: an amount designated by and in the sole discretion of the Multistate Leadership Committee, not stated
Legal basis
Maryland Consumer Protection Act, Md. Code Ann., Com. Law §§ 13-101 through 13-501; Md. Code Ann., Com. Law §§ 13-402 and 13-403; Maryland Personal Information Protection Act, Md. Code Ann., Com. Law §§ 14-3501 through 14-3508, including § 14-3504 and § 14-3502; Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq., including §§ 1681a, 1681b, 1681c-1, 1681c-1(i), 1681c-1(j)(1)(B), and 1681i; Md. Code Ann., Cts. & Jud. Proc. §§ 6-103 and 6-201

Why the action was brought

The action concerned the September 7, 2017-announced data breach, in which unauthorized persons accessed portions of Equifax’s network and Maryland consumers’ personal information. The decree records that Equifax received notice on March 8, 2017, of Apache Struts vulnerability CVE-2017-5638 before the breach, and imposes security, notification, consumer-assistance, and monitoring obligations; Equifax admitted no violation or liability.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.