Maryland Age-Appropriate Design Code Act ("Maryland Kids Code", HB 603 / SB 571) ↗
In force since 2024-10-01; NetChoice's First Amendment challenge (D. Md.) survived a motion to dismiss 2025-11-24 but produced no injunction, so the Act remains enforceable.
Statutory section pins are unverified against the enrolled text (the official PDF is a scanned/rendered chapter document); requirement decomposition is drawn from corroborating law-firm analyses (Future of Privacy Forum, Troutman, Wilson Sonsini, Inside Privacy) plus the litigation docket. Re-verify section citations and the exact DPIA content requirements against Md. Code, Com. Law before promoting to 'verified'.
Scope
Binds a business offering an online product, service, or feature 'reasonably likely to be accessed by children'; 'child' is defined as a Maryland consumer under 18.
- The business must also meet a CCPA-style threshold: $25M+ annual revenue; or handling personal data of 50,000+ consumers, households, or devices; or 50%+ of revenue from data sales.
Penalties
- Model
- Per violation
- Detail
- Up to $2,500 per affected child per negligent violation and up to $7,500 per affected child per intentional violation; 90-day cure period after notice; a violation is an unfair, abusive, or deceptive trade practice under Maryland consumer-protection law.
- Enforcer
- Maryland Division of Consumer Protection, Office of the Attorney General
- Private right of action
- No
Key dates
- Effective
- 2024-10-01
Obligations (4)
Complete a data protection impact assessment for each online product reasonably likely to be accessed by children, documenting risks to minors and mitigation steps; the first assessments were due by 2026-04-01.
Statute’s own ages: Protects consumers aged 17 and under ('child'/'minor' = under 18); the Act does not sub-tier by age for the DPIA duty.
Configure default privacy settings for minors to the highest level of protection unless the business can show a compelling reason a different setting is in the child's best interests.
Statute’s own ages: Applies to users under 18.
Do not design or operate the product in a way that is not in the best interests of children, i.e., that risks reasonably foreseeable and material physical or financial harm, severe psychological or emotional harm, highly offensive privacy intrusions, or discrimination.
Statute’s own ages: Applies to users under 18.
Do not process a minor's personal data unless reasonably necessary to provide the specific product the child is actively and knowingly engaged with, and do not process it in ways that conflict with the child's best interests.
Statute’s own ages: Applies to users under 18.
Litigation history
- 2025-02-03NetChoice filed a complaint in the U.S. District Court for the District of Maryland challenging the Act on First Amendment, vagueness, and preemption grounds→ No effect: no injunction sought/granted at filing; Act remained in force source ↗
- 2025-04-28NetChoice filed an amended complaint (four First Amendment, two vagueness/due-process, two preemption counts)→ No effect; Act remained in force source ↗
- 2025-11-24District court (Judge Richard D. Bennett) denied the State's motion to dismiss, holding NetChoice adequately stated its claims; the court did not rule on the merits and did not enjoin the Act→ No effect on enforceability: Act remained in force; litigation proceeds source ↗
Cross-state comparisons
- similarne-lb504 (Nebraska): Both are Age-Appropriate Design Code ('Kids Code') statutes imposing best-interests, default-privacy, and data-minimization duties on online services likely accessed by minors, rather than hard account-level age gates.
- similarca-aadc (California): Modeled on California's AADC with near-identical design duties, but Maryland's is fully in force (challenge pending, no injunction) while California's is only partially enforceable. The pair is the clearest example of identical statutory text diverging by litigation posture.