Regulations › US states › Maryland

MODPA

Maryland Online Data Privacy Act

In force privacy consumer rights
WhenIn effect since 1 October 2025
Who enforces itState Attorney General
Who it applies toBusinesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.

The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.

The law in brief

The Maryland Online Data Privacy Act (MODPA) is Maryland's comprehensive consumer privacy law. It has been in effect since 1 October 2025. Like the other state laws built on the same model, it gives Maryland residents rights over their personal data and puts duties on the businesses that decide how that data is used (controllers) and on the vendors that handle it for them (processors).

The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.

Maryland goes further than most states: it limits collection to what is reasonably necessary and proportionate to provide the product or service the consumer asked for, and bans the sale of sensitive data outright. Check these stricter rules before relying on another state's program.

Who it applies to

  • Businesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.
  • The thresholds usually turn on how many Maryland residents' personal data a business handles in a year, and whether it earns revenue from selling personal data. Check the statute for the exact figures.
  • Like most state privacy laws, it exempts some organizations and data, commonly including data already covered by HIPAA or the Gramm-Leach-Bliley Act, and data about people acting in an employment or commercial capacity.

What it requires

A clear privacy notice

Publish a privacy notice describing the categories of personal data you process, why, what you share and with whom, how consumers can use their rights, and how to appeal.

Collect only what you need

Limit collection to what is adequate, relevant and reasonably necessary for the purposes you disclosed, and secure it with reasonable safeguards.

Sensitive data

Get the consumer's opt-in consent before processing sensitive data, such as health information, biometric or genetic data, precise geolocation, and data about a known child (for whom parental consent is needed).

Contracts with processors

Bind each processor by contract to your instructions, confidentiality, deletion or return at the end of the service, and help with audits and assessments.

Honor opt-outs

Stop targeted advertising, sales and, where covered, qualifying profiling for consumers who opt out, and check whether the law requires you to honor universal opt-out signals such as Global Privacy Control.

Data protection assessments

Document an assessment before processing that presents a heightened risk, such as targeted advertising, selling personal data, processing sensitive data, and certain profiling.

People's rights

Maryland residents can generally ask a business to confirm and access their personal data, correct it, delete it and get a copy in a portable format, and can opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects. Businesses generally have 45 days to respond, extendable once. Residents can usually appeal a refusal.

Enforcement and penalties

Enforced by the Maryland Attorney General. Violations carry civil penalties set by the statute.

What to do first

  1. Check the thresholds against your Maryland consumer numbers and any data sales.
  2. Map the personal and sensitive data you hold about Maryland residents.
  3. Update your privacy notice and add the opt-out routes the law requires.
  4. Set up requests and appeals within the response deadlines.
  5. Put MODPA-ready terms in processor contracts.
  6. Build one program for all state laws, then add Maryland's departures.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

  • 31 Aug 2026 New Law in effect Moderate 49 US MD AG

    Five US states enact location privacy laws banning sale of precise geolocation data

    The enactment creates baseline protections for location data while highlighting enforcement gaps that could limit effectiveness. Connecticut, Maryland, New Jersey, Oregon, and Virginia have enacted new consumer privacy statutes that prohibit the sale of precise geolocation data. The laws vary in their consent and minimization requirements, but all share a ban on data sales. None of the statutes provide an explicit private right of action for consumers.

    Effective: not stated.

    Source: EFF updates. MODPA in the regulations library.

Sources