Maryland Website Tracking, Privacy & Wiretap Litigation
Current Landscape
Within the provided dataset for Maryland there are no tracked lawsuits, demand letters, or other matters; nevertheless the jurisdiction is assessed at a moderate risk level. The Maryland Wiretapping and Electronic Surveillance Act (Md. Cts. & Jud. Proc. § 10-401 et seq.) is the primary statutory framework called out in the dataset and therefore is a relevant risk indicator when businesses deploy technologies that capture user interactions.
The technologies identified in the tracked-technologies list include session replay code (SRC) and session replay software, website interaction recording, geolocation capture, cookies, web beacons, chatbots, website analytics, and other online data-tracking technologies. Even with no active matters recorded here, the presence of those technologies in the dataset is a risk indicator that merits attention by in-house teams and service providers because they can affect how interception, collection, and consent questions are viewed under the statutory framework noted above.
Current Litigation Activity
Current Filing & Litigation Trends
The dataset contains no tracked filings or demand letters in Maryland. That absence of recorded litigation activity in this dataset does not eliminate the relevance of the Maryland Wiretapping and Electronic Surveillance Act and the listed tracking technologies as ongoing risk indicators; continued monitoring of filings and demand activity is recommended.
Precedent Landscape: What Courts Have Decided
No decided precedent with a clear substantive direction is currently tracked.
Current Laws & Relevant Statutes
- Maryland Wiretapping and Electronic Surveillance Act — Md. Cts. & Jud. Proc. § 10-401 et seq. · all-party consent · private right of action
Regulatory Enforcement
Agency Guidance
Global Privacy Control / Opt-Out Signals
Currently required
Effective since: October 1, 2025.
| Statute | Maryland Online Data Privacy Act |
|---|---|
| Citation | Md. Code Ann., Com. Law § 14-4707 (SB 541) |
| Applicability | Controllers must honor universal opt-out mechanisms for targeted advertising and sales. |
| Universal opt-out requirement | Yes |
| Recognized mechanisms | Global Privacy Control (GPC) |
Statutory baseline: Maryland Online Data Privacy Act (Md. Code Ann., Com. Law § 14-4707 (SB 541)).
Learn more about Global Privacy Control → · How GPC posture is weighted in the risk guideline →
Changes Coming in the Next 24 Months
Coming Into Effect (Enacted)
Legislation to Watch (Pending)
Important Cases & Tracked Matters
Technologies Appearing in Claims
- Global Privacy Control (GPC)
- Sec-GPC HTTP header
- navigator.globalPrivacyControl JavaScript flag
- navigator.globalPrivacyControl JavaScript property
- third-party tracking pixels
- advertising cookies
- automated_decisionmaking
- artificial_intelligence
- algorithmic_bias
- biometrics
- telehealth
- location_data
- data_brokers
- social_media
- GeoIP databases
- Virtual Private Networks (VPNs)
- Consent Management Platforms (CMPs)
- browser-based universal opt-out signals
- browser extensions / device settings
- cookie_banner_requirements
- ad-tech
- Session Replay Code (SRC)
- website interaction recording
- geolocation capture
- session replay software
Historical Risk Guideline
| Date | Risk Guideline | Level | Confidence | Tracked Lawsuits |
|---|---|---|---|---|
| August 8, 2026 | 14 | Limited Data | 0% | 0 |
| August 10, 2026 | 34 | Moderate | 6% | 0 |
| August 12, 2026 | 34 | Moderate | 30% | 0 |
| August 14, 2026 | 34 | Moderate | 40% | 0 |
| August 16, 2026 | 34 | Moderate | 47% | 0 |
| August 19, 2026 | 34 | Moderate | 54% | 0 |
| August 20, 2026 | 34 | Moderate | 66% | 0 |
| August 21, 2026 | 34 | Moderate | 68% | 0 |
| August 23, 2026 | 41 | Moderate | 68% | 0 |
| August 26, 2026 | 41 | Moderate | 70% | 0 |
| August 31, 2026 | 41 | Moderate | 72% | 0 |
What Businesses Should Review
Perform a technical and vendor inventory focused on session replay code, website interaction recording, geolocation capture, chatbots, analytics scripts, cookies, and web beacons; map data flows to determine what user inputs or identifiers are captured and transmitted. Where feasible, apply minimization (masking or excluding form fields and sensitive inputs), truncate or anonymize recorded data, limit retention, enforce strict access controls and logging, and evaluate consent banner/configuration and opt-out mechanisms. Review vendor contracts and processing agreements for security, purpose limitation, and liability terms, and consider documenting a privacy/processing impact assessment and legal review that references Md. Cts. & Jud. Proc. § 10-401 et seq. as part of the compliance posture.
Data Quality
9 source(s), 2 primary; evidence is fresh.
Methodology & Limitations
Statistics on this page are generated by the Crandall Consulting litigation intelligence engine. Publicly available sources (court and government materials, recognized legal press, professional analysis, and industry reports) are discovered through automated web research, classified into a tiered source hierarchy, and reduced to structured facts with full source provenance. Risk guidelines and evidence-confidence scores are computed by a deterministic formula from those stored facts — never by an AI model directly (AI explains findings; it never assigns a score). Counts labeled "tracked" reflect matters identified in our source set and are not official court statistics.
The overall risk guideline is composed of six deterministically weighted components: statutory structure (25%), current litigation activity (25%), prior precedent (18%), GPC / universal opt-out posture (15%), regulatory enforcement (9%), and the forward-looking 24-month horizon (8%). When a state's GPC status is limited data, that component is excluded and the remaining weights are renormalized — limited data never reads as lower exposure. Current litigation activity is measured over recent windows (velocity), not lifetime volume, so a jurisdiction with high historical activity but declining current filings reflects that decline. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately. Full details are on the methodology page.
Sources
- Universal Opt-Out Mechanisms: Which States Require Them
- Universal Opt-Out Mechanism (UOOM) Compliance: What Every Business Needs to Know in 2026
- U.S. Cybersecurity and Data Privacy Review and Outlook – 2025
- Letter from Senator Ron Wyden to State Attorneys General on Global Privacy Control
- Global Privacy Controls: Preparing for the Next Wave of Enforcement
- The US State Privacy Law Tracker for 2026: Twenty Laws, One Compliance Baseline
- Malinda Smidga v. Spirit Airlines Inc, No. 24-1757 (3d Cir. 2026)
- Tips for Protecting Your Business from Wiretap Lawsuits Targeting Companies with Consumer-Facing Websites
- Bass Pro Shops, Cabela’s Customers Revive ‘Session Replay’ Suit
All State Pages
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website