Maryland Wiretapping and Electronic Surveillance Act & Website Tracking Litigation
What This Statute Says (Plain Language)
Maryland's interception statute is an all-party consent law modeled on the federal Wiretap Act, generally prohibiting the willful interception of wire, oral, or electronic communications without the consent of all parties, with civil remedies for violations.
Why It Appears in Website Tracking Litigation
Maryland's all-party consent structure and private right of action have made it a recurring venue in multi-state website tracking demand letters and filings involving session replay and pixel technologies, though its public decision volume is lower than California or Pennsylvania.
Practical Implications for Website Operators
Maryland's statute shows up in a specific way in our tracked data: as a recurring line item in multi-state demand letters and complaints rather than as the lead statute in high-volume litigation. The reason is structural — it is an all-party consent statute with a private right of action, modeled on the federal Wiretap Act, so adding a Maryland count to a demand letter that already cites California and Pennsylvania costs a plaintiff essentially nothing.
The comparatively thin body of Maryland website-specific decisions cuts in an unintuitive direction: with few public rulings either way, operators have fewer defense-favorable precedents to point to, and demand letters import theories from Pennsylvania and California by analogy. That uncertainty premium — not a wave of Maryland verdicts — is the practical exposure. Separately, the Maryland Online Data Privacy Act took effect in October 2025, adding attorney-general-enforced data-minimization obligations that change the compliance backdrop for tracking data on Maryland-facing sites, though it provides no private right of action.
Litigation Risk in Plain Language
Because the statute mirrors the federal act's structure while flipping the consent default to all-party, the analytical questions track the familiar ones: whether 'contents' were captured, where interception occurred, and whether any party consented. Damages follow the federal pattern — the greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees.
With filing volume lower than in California, Pennsylvania, or Florida, the dominant scenario for a Maryland-facing operator is receiving a multi-state demand letter in which Maryland is one of several counts. The technical review that answers the letter is the same one that addresses the lead statutes: what the site's third-party tools transmit, and when, relative to consent.
What Operators Commonly Review
These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:
- Run the core technical review — consent gating, session replay masking, chat pre-send transmission — with Maryland visitors included in scope.
- Verify which trackers transmit before any consent interaction for Maryland visitors; all-party consent makes pre-consent transmission the focal allegation.
- Check that the privacy notice names the third-party technologies in use, since disclosure-based consent arguments parallel those in Pennsylvania.
- Track the Maryland Online Data Privacy Act's data-minimization posture (effective October 2025, AG-enforced) as a separate compliance item touching the same tracking data.
How This Statute Compares
Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:
| Statute | Consent Standard | Private Right of Action | Statutory Damages |
|---|---|---|---|
| California Invasion of Privacy Act (CIPA) | All-party | Yes | $5,000 per violation or three times actual damages (Cal. Penal Code § 637.2) |
| Federal Wiretap Act (ECPA Title I) | One-party | Yes | The greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520) |
| Florida Security of Communications Act (FSCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10) |
| Illinois Eavesdropping Act | All-party | Yes | Actual and punitive damages; injunctive relief (720 ILCS 5/14-6) |
| Massachusetts Wiretap Act | All-party | Yes | Actual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees |
| Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725) |
| Washington Privacy Act | All-party | Yes | Actual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060) |
Jurisdiction Context
See the full Maryland website tracking litigation page for the current risk guideline (Moderate), tracked matter counts, and trend data.
Tracked Cases Invoking This Statute
No tracked cases currently link to this statute in our source set. This reflects our tracked sources, not an absence of litigation.
Common Questions
Why does Maryland appear in so many multi-state demand letters?
Its statute combines all-party consent, a private right of action, and federal-style statutory damages — the same structural features plaintiffs cite in California and Pennsylvania. Adding a Maryland count to an existing demand letter is nearly costless, so Maryland recurs even without a large body of Maryland-specific decisions.
Has Maryland produced major website wiretap rulings?
Public website-specific decision volume is low relative to California, Pennsylvania, or Florida. That scarcity works as an uncertainty premium: demand letters import theories from other all-party consent states by analogy, and there are few Maryland precedents for either side to rely on. Whether any theory would succeed in Maryland courts remains largely untested.
Does Maryland's new privacy law change website tracking risk?
The Maryland Online Data Privacy Act (effective October 2025) adds strict data-minimization and sensitive-data obligations enforced by the attorney general — it has no private right of action, so it does not create wiretap-style class exposure, but it does regulate much of the same tracking data. It is a separate statute from the wiretap act; both touch the same site configuration.
Related Intelligence
Further Reading
- Your website may be sharing more than you think — our plain-language overview of hidden tracking, wiretap exposure, and Global Privacy Control.
- Website wiretap lawsuits by state — risk guidelines and tracked matter counts for all 50 states.
Sources
Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website