MODPA
Maryland Online Data Privacy Act
The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.
The law in brief
The Maryland Online Data Privacy Act (MODPA) is Maryland's comprehensive consumer privacy law. It has been in effect since 1 October 2025. Like the other state laws built on the same model, it gives Maryland residents rights over their personal data and puts duties on the businesses that decide how that data is used (controllers) and on the vendors that handle it for them (processors).
The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.
Maryland goes further than most states: it limits collection to what is reasonably necessary and proportionate to provide the product or service the consumer asked for, and bans the sale of sensitive data outright. Check these stricter rules before relying on another state's program.
Who it applies to
- Businesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.
- The thresholds usually turn on how many Maryland residents' personal data a business handles in a year, and whether it earns revenue from selling personal data. Check the statute for the exact figures.
- Like most state privacy laws, it exempts some organizations and data, commonly including data already covered by HIPAA or the Gramm-Leach-Bliley Act, and data about people acting in an employment or commercial capacity.
What it requires
A clear privacy notice
Publish a privacy notice describing the categories of personal data you process, why, what you share and with whom, how consumers can use their rights, and how to appeal.
Collect only what you need
Limit collection to what is adequate, relevant and reasonably necessary for the purposes you disclosed, and secure it with reasonable safeguards.
Sensitive data
Get the consumer's opt-in consent before processing sensitive data, such as health information, biometric or genetic data, precise geolocation, and data about a known child (for whom parental consent is needed).
Contracts with processors
Bind each processor by contract to your instructions, confidentiality, deletion or return at the end of the service, and help with audits and assessments.
Honor opt-outs
Stop targeted advertising, sales and, where covered, qualifying profiling for consumers who opt out, and check whether the law requires you to honor universal opt-out signals such as Global Privacy Control.
Data protection assessments
Document an assessment before processing that presents a heightened risk, such as targeted advertising, selling personal data, processing sensitive data, and certain profiling.
People's rights
Maryland residents can generally ask a business to confirm and access their personal data, correct it, delete it and get a copy in a portable format, and can opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects. Businesses generally have 45 days to respond, extendable once. Residents can usually appeal a refusal.
Enforcement and penalties
Enforced by the Maryland Attorney General. Violations carry civil penalties set by the statute.
What to do first
- Check the thresholds against your Maryland consumer numbers and any data sales.
- Map the personal and sensitive data you hold about Maryland residents.
- Update your privacy notice and add the opt-out routes the law requires.
- Set up requests and appeals within the response deadlines.
- Put MODPA-ready terms in processor contracts.
- Build one program for all state laws, then add Maryland's departures.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
Five US states enact location privacy laws banning sale of precise geolocation data
The enactment creates baseline protections for location data while highlighting enforcement gaps that could limit effectiveness. Connecticut, Maryland, New Jersey, Oregon, and Virginia have enacted new consumer privacy statutes that prohibit the sale of precise geolocation data. The laws vary in their consent and minimization requirements, but all share a ban on data sales. None of the statutes provide an explicit private right of action for consumers.
Effective: not stated.
Source: EFF updates. MODPA in the regulations library.
Sources
- All of the comprehensive privacy laws that take effect in 2026 MultiState · Law firm or analyst
- US state privacy laws comparison (24 enacted laws, effective dates) Recording Law · Law firm or analyst