MD

Maryland Privacy Law

Maryland Online Data Privacy Act

Effective: October 1, 2025ActiveReviewed by PrivacyLawMap editorial teamLast verified: October 1, 2025

Overview

The Maryland Online Data Privacy Act (MODPA) was signed into law on May 9, 2024 by Governor Wes Moore as SB 541/HB 567, became effective on October 1, 2025, and enforcement by the Maryland Attorney General's Consumer Protection Division began on April 1, 2026 after a six-month grace period. Alongside Washington's My Health My Data Act, the MODPA is widely regarded as one of the two strongest consumer privacy statutes in the United States. It pairs the lowest meaningful applicability threshold of any comprehensive state law (35,000 consumers, with no revenue threshold) with the strictest data minimization mandate, the broadest sensitive-data prohibition, a mandatory universal opt-out signal requirement from day one, and escalating penalties for repeat violations. Attorney General Anthony G. Brown and the Consumer Protection Division have publicly committed to active MODPA enforcement and have been accepting consumer complaints since the October 1, 2025 effective date.

The MODPA provides Maryland consumers with comprehensive privacy rights: the right to access, correct, delete, and obtain a portable copy of their personal data, along with opt-out rights for data sales, targeted advertising, and profiling decisions that produce legal or similarly significant effects. What sets the MODPA apart from the Virginia/Connecticut/Colorado model is its data minimization standard: businesses may only collect personal data that is "reasonably necessary and proportionate" to the specific product or service the consumer requested — not to any disclosed business purpose. The MODPA also outright prohibits (not merely requires opt-in consent for) the sale of sensitive data, the sale of any consumer's precise geolocation, and the targeted advertising or sale of personal data of consumers under the age of 18 when the controller knew or should have known the consumer was a minor.

The law applies to entities conducting business in Maryland or producing products or services targeted to Maryland residents that during the preceding calendar year either (1) controlled or processed personal data of 35,000 or more Maryland consumers (excluding data processed solely for payment transactions), or (2) controlled or processed personal data of 10,000 or more Maryland consumers while deriving more than 20% of gross revenue from the sale of personal data. Unlike most comprehensive state laws, the MODPA has no standalone revenue threshold — a small company that processes data of 35,000 Marylanders is covered regardless of revenue. The Maryland Attorney General has exclusive enforcement authority through the Consumer Protection Division; there is no private right of action. A MODPA violation is treated as an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act (MCPA), with civil penalties of up to $10,000 per violation and $25,000 for each repeat violation. A 60-day cure period is available until April 1, 2027, after which cure periods become discretionary at the AG's sole option — meaning the AG can pursue immediate enforcement without offering any opportunity to remediate. Maryland additionally maintains a separate data broker registration framework and benefits from the Maryland Personal Information Protection Act (PIPA) breach-notification regime that predates the MODPA.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

35,000+
Maryland consumers' data processed
10,000+ consumers
AND 20%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • MODPA enforcement began April 1, 2026 after a six-month grace period following the October 1, 2025 effective date — Maryland becomes the 20th state with an actively enforced comprehensive privacy law
  • 60-day cure period available only until April 1, 2027 — after that date, cure periods become discretionary and the AG can pursue immediate enforcement without any remediation opportunity (one of the shortest cure-period sunsets of any state law)
  • Escalating penalties: up to $10,000 for an initial violation and up to $25,000 for each subsequent violation under the Maryland Consumer Protection Act
  • Strict data minimization mandate — businesses may only collect data "reasonably necessary and proportionate" to the specific product or service the consumer requested (narrower than the Virginia/Colorado "disclosed purpose" standard)
  • Outright prohibition (not opt-in) on the sale of sensitive data, sale of precise geolocation data, and targeted advertising or sale of personal data of any consumer under 18 when the controller knew or should have known the consumer was a minor
  • Universal opt-out mechanism (Global Privacy Control) recognition required from day one — MODPA is among the strictest states for GPC enforcement intent
  • Expanded sensitive-data categories include consumer health data, genetic data, and precise geolocation within 1,750-foot radius — broader than most comparable state laws
  • Maryland AG Consumer Protection Division under Attorney General Anthony G. Brown actively accepting consumer complaints and publicly committed to MODPA enforcement
  • Data broker obligations continue under Maryland's separate data broker framework, now layered with MODPA transparency requirements

Enforcement Details

Enforced By
Maryland Attorney General (Consumer Protection Division)
Penalty Per Violation
$10,000
Cure Period
60 days
Private Right of Action
No — AG enforcement only

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusBiometric data for identification

Universal Opt-Out / GPC Requirements

GPC / Universal Opt-Out Required

Businesses must recognize and honor universal opt-out mechanisms such as Global Privacy Control (GPC) for opt-out of data sales and targeted advertising from the law's effective date.

Effective: October 1, 2025

Minor / Child Protections

The MODPA includes strong minor protections. It prohibits the sale of personal data of consumers under 18 and bars targeted advertising directed at minors. The law also restricts the collection and processing of minor data beyond what is strictly necessary.

Compliance Checklist

  1. 1Assess applicability — determine if, during the preceding calendar year, you controlled or processed data of 35,000+ Maryland consumers (excluding data used solely for payment transactions) OR 10,000+ Maryland consumers while deriving more than 20% of gross revenue from the sale of personal data. Unlike Virginia/Colorado/Connecticut, the MODPA has no standalone revenue threshold — small companies hit the 35,000-consumer trigger on their own.
  2. 2Check exemption status at both the entity and data level — HIPAA-covered entities and business associates are exempt at the entity level; GLBA-regulated financial institutions receive an entity-level exemption; nonprofits, government entities, and higher-education institutions are exempt. Data-level exemptions cover HIPAA PHI, FCRA data, GLBA financial data, Driver's Privacy Protection Act data, and research data.
  3. 3Conduct a data inventory and apply the MODPA data minimization standard — the standard is "reasonably necessary and proportionate" to the specific product or service the consumer requested, NOT to any disclosed business purpose. This is stricter than Virginia/Colorado/Connecticut. Eliminate any data collection that cannot be directly tied to the consumer's requested service, and document a proportionality justification for each data category retained.
  4. 4Implement Global Privacy Control (GPC) recognition from day one — the MODPA requires businesses to honor universal opt-out signals for data sales and targeted advertising. Configure server-side detection (not just client-side), ensure signals propagate to downstream ad-tech and analytics vendors, test across Firefox/Brave/DuckDuckGo and the GPC browser extensions, and log GPC hits for AG audit defense.
  5. 5Immediately cease all prohibited processing — do not sell sensitive data under any circumstance (not even with opt-in consent), do not sell precise geolocation data, and do not sell or use for targeted advertising the personal data of any consumer the controller knew or should have known was under 18. These are outright bans, not opt-in requirements.
  6. 6Obtain explicit opt-in consent before collecting or processing sensitive personal data — Maryland's sensitive categories include racial/ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship/immigration status, biometric data used for identification, genetic data, consumer health data, and precise geolocation (within 1,750-foot radius). Consent must be "freely given, specific, informed, and unambiguous" and cannot be obtained through dark patterns.
  7. 7Update your privacy notice with all MODPA-required disclosures: categories of personal data collected and processed, purposes of processing, categories sold or shared for targeted advertising (or an affirmative statement that you do not sell or share), consumer rights and how to exercise them, a contact method, and an effective date. Post a conspicuous link titled "Your Maryland Privacy Choices" (or equivalent) from every page that collects data.
  8. 8Build or update consumer rights intake mechanisms — controllers must respond to access, correction, deletion, portability, and opt-out requests within 45 days, with one 45-day extension permitted upon written notice to the consumer. Establish identity verification procedures proportionate to the request sensitivity, and document an appeal process with a 60-day response window.
  9. 9Conduct and document Data Protection Assessments (DPAs) for high-risk processing activities — required for targeted advertising, sale of personal data, profiling that creates a reasonably foreseeable risk of harm, processing of sensitive data, and any processing that presents a heightened risk. DPAs must be retained and produced upon AG request.
  10. 10Prepare for the April 1, 2027 cure period sunset — until April 1, 2027 the AG must offer a 60-day cure opportunity before seeking penalties. After that date, cure periods become entirely discretionary. Document every remediation step during any cure period in writing and retain for at least three years after the cure certification.
  11. 11Implement processor/sub-processor contract updates — execute MODPA-compliant data processing agreements with every vendor, require flow-down obligations to sub-processors, mandate deletion/return of data at contract termination, and obtain audit rights. Maintain a current processor register.
  12. 12If you operate as a data broker, comply with Maryland's separate data broker registration and transparency obligations layered on top of MODPA, including registration with the relevant state authority and publication of consumer rights disclosures.
  13. 13Establish an ongoing MODPA compliance monitoring program — monthly GPC detection testing, quarterly privacy notice review, annual DPA refresh, employee privacy training, a documented complaint intake log, and an AG-inquiry response playbook. Maryland AG complaints typically arrive with a short response deadline once the cure period sunsets.
Put MODPA Into Practice on Your SiteSponsored

Termly builds and maintains a Maryland-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests MODPA grants.

Start Free with Termly

Maryland Privacy Law FAQ

Official Resources