The MODPA compliance checklist is a 13-step plan for meeting the Maryland Online Data Privacy Act (MODPA), Maryland's consumer privacy law, which took effect October 1, 2025. It is enforced by the Maryland Attorney General (Consumer Protection Division), with civil penalties up to $10,000 per violation and a 60-day cure period to fix violations before a fine. Work through every step below, then confirm your specific obligations with the free applicability calculator.
Compliance Steps
Effective: October 1, 2025 | Cure period: 60 days
1
2
3
4
5
6
7
8
9
10
11
12
13
Key Enforcement Details
Enforced By
Maryland Attorney General (Consumer Protection Division)
It is a 13-step plan organizations use to meet the Maryland Online Data Privacy Act (MODPA), which took effect October 1, 2025. The steps below cover consumer-rights request handling, privacy-notice disclosures, opt-out mechanisms, data-processing agreements, and security safeguards required under Maryland law.
Who has to comply with the Maryland Online Data Privacy Act?
The MODPA generally applies to organizations that handle Maryland residents' personal data above the law's revenue and data-volume thresholds. Whether it applies to you depends on the specifics — check your exact obligations with the free applicability calculator at /calculator rather than assuming.
What is the penalty for MODPA non-compliance?
The Maryland Attorney General (Consumer Protection Division) can impose civil penalties of up to $10,000 per violation and a 60-day cure period to fix violations before a fine. There is no private right of action, so enforcement comes from the state, not individual lawsuits. Figures verified July 28, 2026.
Put MODPA Into Practice on Your SiteSponsored
Termly builds and maintains a Maryland-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests MODPA grants.