Skip to content

Maryland Online Data Privacy Act (MODPA): 2026 Compliance Guide

Mate Prgin 9/7/26, 4:49 PM

Table of Contents

The Maryland Online Data Privacy Act (MODPA) is Maryland's comprehensive consumer privacy law, in force since October 1, 2025. It gives Maryland residents rights over their personal data and sets strict rules for how businesses collect, use, and share it.

MODPA is the strictest of all the U.S. state privacy laws. It caps how much data businesses can collect and maps it to specific services that people requested. It also flatly bans selling sensitive data, with no consent exception.

MODPA applies once you handle the data of 35,000 consumers in a year, far below the 100,000 that California, Virginia, and Connecticut use. Many businesses may be liable under MODPA and not realize it.

Enforcement is handled by the Maryland Attorney General. Consumers cannot sue businesses directly but can file claims with the attorney general to investigate. A limited grace period to fix violations ends April 1, 2027.

Maryland's approach to data collection broke a common pattern. In most U.S. states, businesses are allowed to gather whatever data they wish as long as they state it clearly in their privacy policy, and give users the option to opt out. 

MODPA is the first U.S. state law to cap data collection itself. It does not matter what your privacy notice says or whether the customer clicked accept. Businesses trying to collect data they don't need to deliver the product are stopped in their tracks.

That approach, plus a flat ban on selling sensitive data, is why lawyers call it the strictest privacy law in the country.

 

When did MODPA pass?

MODPA is Maryland's comprehensive consumer privacy law, passed as Senate Bill 541 and House Bill 567 in 2024 and signed by Governor Wes Moore on May 9, 2024. It took effect on October 1, 2025, and the Attorney General began enforcing it on April 1, 2026. Maryland was the 18th state to pass a data privacy law.

The statute is codified at Maryland Commercial Law §§ 14-4701 to 14-4714. The Maryland Attorney General's data privacy page is the official reference for businesses and residents.

What sets MODPA apart is not the rights menu, which looks a lot like Virginia's or Connecticut's. It's the two hard limits underneath: Maryland caps how much data you can collect, and it bans selling the most sensitive categories outright. No other state does both.

modpa-3a@3x

Does MODPA apply to your business?

MODPA applies if you do business in Maryland or sell to Maryland residents without a physical presence in the state. Either of these two requirements apply, according to Md. Commercial Law § 14-4702):

You handled the personal data of 35,000 or more Maryland consumers. 

You handled the data of 10,000 or more consumers and made over 20% of your gross revenue from selling personal data.

Most states don't kick in until 100,000 consumers. Maryland starts at 35,000, one of the lowest bars in the country and roughly half a percent of the state's 6.2 million residents.

A mid-sized ecommerce brand, SaaS product, or content site can cross that line without trying. So for most companies the useful question isn't whether you can stay under MODPA. It's whether you're already covered and didn't notice.

Two quick examples

A direct-to-consumer ecommerce brand gets 500,000 Maryland visitors a year and has 60,000 Maryland account holders.

A B2B data vendor holds records on 15,000 Maryland residents and makes 30% of its revenue selling personal data. It's under 35,000, so the first test misses it. The second test, 10,000 consumers plus more than 20% of revenue from data sales, pulls it in.

Who is exempt from MODPA?

MODPA exempts state government bodies and some registered securities and financial institutions.

Financial institutions covered by the Gramm-Leach-Bliley Act, their affiliates, and GLBA-governed data are exempt from MODPA. Health information already covered by HIPAA is exempt too, at the data level alone. Companies holding non-HIPAA data will be subject to MODPA.

MODPA does not give nonprofits a blanket pass, and it does not exempt higher education institutions as a category, either.

 

Are you a controller or a processor under MODPA?

You're a controller if you decide why and how personal data gets used, and a processor if you handle it on someone else's instructions. Which one you are decides what you owe. Most companies are controllers of their own customer data and processors when handling data for a client.

The heavier duties fall on controllers: the collection limits, the privacy notice, consumer rights, and assessments. Processors owe a narrower set, mostly acting on instructions, keeping data secure, and helping the controller meet its own obligations (Md. Commercial Law § 14-4708).

 

modpa-2a@3x

MODPA business requirements

Beyond the collection limits, MODPA mandates a handful of operating duties. Each should be familiar territory if you've worked on other U.S. state laws:

  • Write a privacy notice that covers what data you collect (sensitive data included), why you collect it, and who you share it with, including enough about each recipient to know what they do.
  • Spell out how people act on their data in that notice: how to use their rights, appeal a decision, and take back consent, plus a working email or online contact.
  • Clearly disclose selling, targeted ads, and profiling, with an opt-out option.
  • Keep reasonable security in place, sized to the amount and sensitivity of the data.
  • Make consent easy to take back. Revoking has to be as easy as granting consent, and you have to stop processing within 30 days.
  • Put a contract around every vendor that processes data for you, covering instructions, security, deletion, and their own subcontractors.
  • Don't punish people for using their rights, for example by charging them more or degrading their service.

 

What is MODPA's data minimization rule?

The data minimization rule states that businesses can only collect personal data that is reasonably necessary and proportionate to deliver the specific product or service customers asked for (Md. Commercial Law § 14-4707). That is the rule at the heart of MODPA.

Think of it like a coat check.  If a customer hands you their coat, your jurisdiction only extends to keeping that coat somewhere safe. You can't go through their pockets, copy their ID, and note where they live, even if they signed a form saying you could. The service they asked for sets the limit on what you're allowed to take.

This is a real break from every other state. Elsewhere the deal is notice and consent: disclose what you collect, let people opt out, and cover the rest. Maryland caps collection at what you need, and consent cannot push it higher. A checkbox does not buy you the right to over-collect.

The rule also reaches forward in time. Once you have data, you can't quietly point it at a new use: if a purpose doesn't fit the reason you first gave, you have to go back and ask again. So collection is only half of it, and what you later do with the data matters just as much.

modpa-8b_3x

What counts as sensitive data under MODPA?

MODPA does three things with sensitive data: it defines the category broadly, limits collection to what's strictly necessary, and bans selling it outright. Each rule is stricter than the standard state template.

Sensitive data under Md. Commercial Law § 14-4701 covers a long list:

  • Race or ethnic origin
  • Religious beliefs
  • Health data
  • Sex life and sexual orientation
  • Whether someone is transgender or nonbinary
  • National origin
  • Citizenship or immigration status
  • Genetic and biometric data
  • Precise location
  • Any personal data of a child

The biometric piece is broader than it looks. MODPA covers data that can be used to identify someone, so a faceprint or voiceprint counts even if you never actually use it for identification.

The headline rule is the sale ban. Maryland flatly bans selling sensitive data, with no consent exception. Selling here means any exchange for money or other valuable consideration, so a data trade counts, not just a cash sale.

A customer cannot agree to let you sell sensitive data, because the law takes that option off the table. Every other state lets you sell it with opt-in consent. Maryland bans it outright.

 

MODPA health data rules

Maryland defines consumer health data by a person's health status, which is broader than laws that only cover a diagnosis or condition. If your data hints at someone's health situation, treat it as covered.

Consumer health data carries extra duties on top of the general sensitive-data rules (Md. Commercial Law § 14-4704). You cannot sell or offer to sell it without consent. You cannot let an employee or contractor near it unless they're under a duty of confidentiality, and a processor can only touch it under a written contract.

MODPA also adds a rule you won't find in the standard state template. You cannot set up a geofence (a virtual boundary that triggers when a phone crosses it) within 1,750 feet of a mental health facility or a reproductive or sexual health facility to track people, collect their health data, or send them ads about it. If your marketing uses location targeting, this one needs a direct check.

Maryland residents rights under MODPA

Maryland residents get the standard set of privacy rights:

  • Confirm and access the data you hold about them (subject to protecting trade secrets)
  • Correct inaccuracies
  • Delete their data, including data you obtained about them, unless you're legally required to keep it
  • Get a portable copy of data you process by automated means
  • Opt out of targeted advertising, the sale of their data, and profiling that drives significant automated decisions
  • Get a list of the categories of third parties you've shared their data with

That last one is the rare part. Only a few states grant it, so a Maryland resident can ask who you've been sharing their data with.

How a rights request works

Businesses have 45 days to answer a request, extendable by another 45 days within valid reason. Individuals can request once within a 12-month period free of cost.

A resident can also use authorized agents for requests, and have the option to submit these online. 

If you deny a request, you have 45 days to say so, explain why, and tell the person how to appeal. The appeal has to be as easy to find and use as the original request, and  all appeals have to be answered inside 60 days.

Any denied appeals can be escalated to the Attorney General's Division of Consumer Protection.

Does MODPA enforce Global Privacy Control?

Yes, MODPA requires you to honor universal opt-out signals like Global Privacy Control. Since October 1, 2025, when a Maryland resident's browser sends an opt-out preference signal, you must treat it as a valid opt-out from targeted advertising and data sales.

In plain terms, a person doesn't have to hunt for your opt-out link. Their browser waves the flag for them, and you have to respect it automatically. California, Colorado, and Connecticut set the same expectation, so if you already honor GPC there, you're most of the way home.

 

modpa-4c@3x

MODPA data protection assessment

A data protection assessment is a written risk review you have to run before certain higher-risk work: targeted advertising, selling personal data, handling sensitive data, and profiling that could harm people.

For profiling, MODPA spells out the harms to weigh: unfair or deceptive treatment, unlawful disparate impact (treating protected groups unequally), financial or physical or reputational injury, and intrusion into someone's private life.

Maryland's version bites harder than most in two ways. The assessment has to cover each algorithm you use, not just the program in general, which is language almost no other state has. And the Attorney General can demand to see an assessment during an investigation and use it as evidence, so this is a document you may have to defend, not a box to tick.

 

MODPA's rules for minors

MODPA strictly prohibits the collection or processing of data from consumers under the age of 18. This includes data for advertising, customer profiling, or related activities.  There is no lower age floor: the protection covers everyone under 18.

That is one of the changes HB 711 made in 2026, striking the old wording that set the protection age at 13. 

 

Maryland's HB 711 changes in 2026

As of July 1, 2026, Maryland restricts selling personal data around immigration enforcement and widens what counts as sensitive data. House Bill 711, passed May 31, 2026, is the newest layer on MODPA.

The immigration rules block two kinds of sale. You cannot knowingly sell a consumer's personal data to a government unit that, in the previous six months, took part in or supported civil immigration enforcement. You also cannot sell it to any buyer you know or should know is seeking it to enforce immigration law.

A valid court warrant that names the data is the exception. Normally you'd have some legal cover for handing data to a government unit that sends a subpoena; HB 711 takes that cover away when the request comes from one of those units without a warrant.

The second change widens sensitive data to include inferred data. If you deduce something like someone's health, race, religion, or sex life from other data you hold, that inference now counts as sensitive data, with all the strict rules that follow.

This matters most if you are a data broker, an adtech vendor, or anyone whose business model includes selling audience data. Because the rule turns on knowingly selling the data, claiming you didn't ask what a buyer wanted it for is a weak position.

 

MODPA enforcement and penalties

The Maryland Attorney General enforces MODPA through the Division of Consumer Protection, and a violation is treated as an unfair or deceptive trade practice under the state Consumer Protection Act. Penalties run up to $10,000 per violation, and up to $25,000 for each repeat instance.

There is no private right of action written into MODPA. Consumers cannot sue you directly under this law, though the statute does not erase other legal claims that might already exist.

One date is worth watching. Right now, if the Attorney General thinks a fix is possible, it has to give you at least 60 days to correct a violation before acting. That grace period ends for any violation after April 1, 2027. After that, the AG can move straight to enforcement with no chance to fix things first, so the window to get compliant without risking a penalty is closing fast.

modpa-6c@3x

MODPA deadlines at a glance

MODPA operates on a handful of deadlines, ranging from a 45-day window to respond to a request to the April 1, 2027 cutoff to fix violations without penalty.

MODPA response and compliance deadlines.
What Deadline
Respond to a consumer request 45 days
Extension when needed +45 days
Answer an appeal (in writing) 60 days
Stop processing after consent is revoked 30 days
Cure period (if the AG offers one) at least 60 days
Cure period ends for violations after April 1, 2027

How is MODPA different from the CCPA and other state laws?

MODPA shares the basic shape of the other comprehensive state laws, then tightens the screws in a few specific places. This reference table shows where Maryland departs from California, Virginia, Connecticut, and Colorado.

How MODPA compares to other state privacy laws.
Feature Maryland (MODPA) California (CCPA/CPRA) Virginia (VCDPA) Connecticut (CTDPA)
Applicability threshold 35,000 consumers $25M revenue, or 100,000 consumers/households, or 50%+ revenue from data 100,000 consumers 100,000 consumers
Data collection limit Capped at what's needed; consent can't widen it Notice and opt-out Notice and opt-out Notice and opt-out
Selling sensitive data Banned outright Allowed with opt-out Allowed with opt-in consent Allowed with opt-in consent
Honor GPC signals Required Required Not required Required
Private right of action No Limited (data breach only) No No
Cure period Discretionary, ends April 1, 2027 Discretionary 30-day cure, mandatory, no sunset Ended December 31, 2024

 

What to add for Maryland compliance

If you already run a multi-state privacy program, you don't need to start over for Maryland. Most of your controls carry over: the rights workflows, the privacy notice, the GPC handling, the vendor contracts, the assessments.

Five things Maryland asks for that the others don't:

Audit collection against need, not just disclosure. Your program likely demonstrates that you disclosed a data practice. Maryland asks whether you needed the data at all. Walk your data map and cut anything you can't tie to a service the customer requested.

Stop selling sensitive data, period. Any flow that sells sensitive categories under an opt-in model that works elsewhere does not work in Maryland. Turn it off for Maryland residents.

Add the geofence check. Confirm no location-based marketing targets health facilities within the 1,750-foot line.

Lower your applicability trigger. A footprint too small for California can still cross Maryland's 35,000 line, so re-run your scoping with the lower number.

Screen government data buyers. Under HB 711, selling personal data to immigration-enforcement-linked government units is off-limits without a warrant.

modpa-7b@3x

How to comply with MODPA: a checklist

Working MODPA into an existing program comes down to a short sequence. Enzuzo's consent management platform handles the consent, opt-out, and preference-signal pieces:

  1. Map the Maryland personal data you collect and where it flows.
  2. Cut any collection you can't tie to a service the customer asked for.
  3. Inventory sensitive data, get consent where you strictly need it, and stop selling it.
  4. Update your privacy notice to cover Maryland's requirements.
  5. Honor GPC and other universal opt-out signals for Maryland visitors.
  6. Build the rights workflow with the 45-day clock, an appeal path, and authorized-agent handling.
  7. Document assessments for higher-risk processing, one per algorithm where profiling is involved.
  8. Put processor contracts in place with every vendor that touches the data.
  9. Check location targeting against the 1,750-foot geofence rule.
  10. Screen government data sales against the HB 711 immigration rules.

Consent records are where most of this gets proven when someone asks. To see how Enzuzo can help you capture proof and comply with MODPA, book a call with an in-house expert.

 

Frequently asked questions

What is MODPA in simple terms?

MODPA is Maryland's consumer privacy law, in force since October 1, 2025. What makes it different from others is that it limits how much data companies can collect in the first place, on top of the usual rights to access, correct, and delete data.

Does MODPA apply to my business?

MODPA applies if you target Maryland residents and handle the data of 35,000 or more Maryland consumers a year, or 10,000 consumers plus more than 20% of revenue from selling data. That 35,000 bar is one of the lowest in the country, so many mid-sized companies are covered.

Does MODPA apply to nonprofits?

Yes, MODPA can apply to nonprofits. Maryland did not give them the blanket exemption that many other state privacy laws include, so a nonprofit that meets the thresholds has the same obligations as a business. 

Am I a controller or a processor under MODPA?

You're a controller when you decide why and how data gets used, and a processor when you handle data on someone else's instructions. Controllers carry the heavier duties. A processor that begins to decide its own purposes for the data becomes a controller under the law.

When did MODPA take effect and when did enforcement start?

MODPA took effect on October 1, 2025, and the Maryland Attorney General began enforcing it on April 1, 2026. A grace period to fix violations ends April 1, 2027. The law is live and enforceable right now.

What is the MODPA data minimization requirement?

MODPA limits data collection to what you reasonably need to deliver the product or service a customer requested. The catch that trips people up: consent cannot expand that limit, so a signed agreement does not let you over-collect the way it might in other states.

Can I sell sensitive data under MODPA?

No, MODPA bans selling sensitive data outright, with no consent exception. Sensitive data includes health, biometric, precise location, immigration status, and, as of July 1, 2026, certain sensitive traits you infer from other data. Every other state allows the sale with opt-in consent.

What is consumer health data under MODPA?

Consumer health data is any data that reveals a person's health status, which is broader than data tied to a specific diagnosis. It carries extra rules: you cannot sell it without consent, and only staff or vendors under a duty of confidentiality can handle it.

What is a MODPA data protection assessment?

It's a written risk review you run before higher-risk work like targeted advertising, selling data, handling sensitive data, or risky profiling. Maryland requires one for each algorithm used in profiling, and the Attorney General can demand to see it during an investigation.

Does MODPA require honoring Global Privacy Control?

Yes, a Maryland resident's browser signal counts as a valid opt-out of targeted advertising and data sales as of October 1, 2025, and you have to honor it automatically. It's the same universal signal other states already recognize, so honoring it in Maryland is usually a configuration change, not a new system.

What are the penalties for violating MODPA?

The Maryland Attorney General can seek up to $10,000 per violation and up to $25,000 for each repeat violation under the Consumer Protection Act. There is no private right of action, and the grace period to fix violations ends April 1, 2027.

How is MODPA different from the CCPA?

MODPA caps data collection to what you need and bans selling sensitive data, while California relies on notice and opt-out and allows selling sensitive data with an opt-out. MODPA also applies at a far lower threshold: 35,000 consumers versus California's 100,000.

Mate Prgin

Mate Prgin

Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.