CRANDALL CONSULTING
HomeWebsite Tracking Laws › Maryland Wiretapping and Electronic Surveillance Act

Maryland Wiretapping and Electronic Surveillance Act & Website Tracking Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

Md. Code, Cts. & Jud. Proc. § 10-401 et seq.
Citation
All-party
Consent Standard
Yes
Private Right of Action
The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410)
Statutory Damages
Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

What This Statute Says (Plain Language)

Maryland's interception statute is an all-party consent law modeled on the federal Wiretap Act, generally prohibiting the willful interception of wire, oral, or electronic communications without the consent of all parties, with civil remedies for violations.

Why It Appears in Website Tracking Litigation

Maryland's all-party consent structure and private right of action have made it a recurring venue in multi-state website tracking demand letters and filings involving session replay and pixel technologies, though its public decision volume is lower than California or Pennsylvania.

Practical Implications for Website Operators

Maryland's statute shows up in a specific way in our tracked data: as a recurring line item in multi-state demand letters and complaints rather than as the lead statute in high-volume litigation. The reason is structural — it is an all-party consent statute with a private right of action, modeled on the federal Wiretap Act, so adding a Maryland count to a demand letter that already cites California and Pennsylvania costs a plaintiff essentially nothing.

The comparatively thin body of Maryland website-specific decisions cuts in an unintuitive direction: with few public rulings either way, operators have fewer defense-favorable precedents to point to, and demand letters import theories from Pennsylvania and California by analogy. That uncertainty premium — not a wave of Maryland verdicts — is the practical exposure. Separately, the Maryland Online Data Privacy Act took effect in October 2025, adding attorney-general-enforced data-minimization obligations that change the compliance backdrop for tracking data on Maryland-facing sites, though it provides no private right of action.

Litigation Risk in Plain Language

Because the statute mirrors the federal act's structure while flipping the consent default to all-party, the analytical questions track the familiar ones: whether 'contents' were captured, where interception occurred, and whether any party consented. Damages follow the federal pattern — the greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees.

With filing volume lower than in California, Pennsylvania, or Florida, the dominant scenario for a Maryland-facing operator is receiving a multi-state demand letter in which Maryland is one of several counts. The technical review that answers the letter is the same one that addresses the lead statutes: what the site's third-party tools transmit, and when, relative to consent.

What Operators Commonly Review

These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:

How This Statute Compares

Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:

StatuteConsent StandardPrivate Right of ActionStatutory Damages
California Invasion of Privacy Act (CIPA)All-partyYes$5,000 per violation or three times actual damages (Cal. Penal Code § 637.2)
Federal Wiretap Act (ECPA Title I)One-partyYesThe greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520)
Florida Security of Communications Act (FSCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10)
Illinois Eavesdropping ActAll-partyYesActual and punitive damages; injunctive relief (720 ILCS 5/14-6)
Massachusetts Wiretap ActAll-partyYesActual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees
Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725)
Washington Privacy ActAll-partyYesActual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060)

Jurisdiction Context

See the full Maryland website tracking litigation page for the current risk guideline (Moderate), tracked matter counts, and trend data.

Tracked Cases Invoking This Statute

No tracked cases currently link to this statute in our source set. This reflects our tracked sources, not an absence of litigation.

Common Questions

Why does Maryland appear in so many multi-state demand letters?

Its statute combines all-party consent, a private right of action, and federal-style statutory damages — the same structural features plaintiffs cite in California and Pennsylvania. Adding a Maryland count to an existing demand letter is nearly costless, so Maryland recurs even without a large body of Maryland-specific decisions.

Has Maryland produced major website wiretap rulings?

Public website-specific decision volume is low relative to California, Pennsylvania, or Florida. That scarcity works as an uncertainty premium: demand letters import theories from other all-party consent states by analogy, and there are few Maryland precedents for either side to rely on. Whether any theory would succeed in Maryland courts remains largely untested.

Does Maryland's new privacy law change website tracking risk?

The Maryland Online Data Privacy Act (effective October 2025) adds strict data-minimization and sensitive-data obligations enforced by the attorney general — it has no private right of action, so it does not create wiretap-style class exposure, but it does regulate much of the same tracking data. It is a separate statute from the wiretap act; both touch the same site configuration.

Related Intelligence

Further Reading

Sources

Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website