Maryland Online Data Privacy Act (MODPA)

· About Maryland Online Data Privacy Act (MODPA)

Key Takeaways

  • The Maryland Online Data Privacy Act (MODPA) applies to controllers that do business in Maryland or target Maryland residents and exceed the law’s annual data thresholds, with a narrower scope than some larger-state privacy statutes.[1][2]
  • MODPA took effect on 1 October 2025, but most processing obligations apply only to processing activities occurring on or after 1 April 2026.[2][3]
  • The Maryland Office of the Attorney General enforces MODPA, and violations can trigger civil penalties of up to $10,000 per violation and $25,000 for repeated violations, plus injunctive relief and other remedies.[4]
  • Controllers must provide consumer rights to access, correct, delete, and obtain a portable copy of personal data, and they must honor opt-out rights for targeted advertising, sale of personal data, and certain profiling.[2][4]
  • MODPA imposes heightened limits on sensitive data, including strict necessity standards for collection and a ban on selling sensitive data.[4][5]
  • A limited cure period applies through 1 April 2027, after which the Attorney General may proceed without offering a cure opportunity.[1][4]

What It Is

The Maryland Online Data Privacy Act is Maryland’s comprehensive consumer privacy law, codified in the Commercial Law Article as Subtitle 46, and it regulates the collection, use, disclosure, sale, and processing of personal data by covered controllers and processors.[2] The law is enforced by the Maryland Office of the Attorney General.[4]

The law was approved by the Governor on 9 May 2024, took effect on 1 October 2025, and its main operative provisions apply to processing activities that occur on or after 1 April 2026.[2][3] The statute also includes a later phase-in for certain enforcement mechanics, including the cure period ending on 1 April 2027.[1][4]

Who Must Comply

MODPA applies to a controller that conducts business in Maryland or offers products or services targeted to Maryland residents and, during the preceding calendar year, either controlled or processed personal data of at least 35,000 consumers, or controlled or processed personal data of at least 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data.[2][4]

The law has extraterritorial reach because it is triggered by business conduct and consumer targeting tied to Maryland residents, not only by a physical Maryland presence.[2][4] It therefore can apply to out-of-state and non-U.S. companies that meet the threshold criteria and process Maryland residents’ data.[2]

Exemptions track common sectoral and entity-based carveouts found in state privacy laws, including certain data and entities already regulated under federal or Maryland-specific regimes, such as specified medical, financial, and higher-education contexts.[2][5] The law also excludes data and activities already subject to certain federal privacy or security statutes where the statute’s carveouts apply.[2]

Core Requirements

  1. Consumer rights handling. Controllers must provide a reasonably accessible privacy notice and a process for consumers to exercise rights to access, correct, delete, and obtain a portable copy of personal data.[2][4]
  1. Opt-out rights. Controllers must allow consumers to opt out of targeted advertising, the sale of personal data, and certain profiling that produces legal or similarly significant effects.[2][4]
  1. Sensitive data limits. Controllers may not sell sensitive data, and they may collect, process, or share sensitive data only when strictly necessary to provide or maintain a product or service requested by the consumer.[4][5]
  1. Purpose limitation and data minimization. Controllers must limit collection to what is adequate, relevant, and reasonably necessary in relation to disclosed purposes, and they must avoid secondary uses that are incompatible with those purposes.[2][5]
  1. Processor governance. Controllers must use contracts with processors that include instructions, confidentiality, data security, deletion or return obligations, and audit/cooperation terms appropriate to the processing relationship.[2][5]
  1. Security safeguards. Controllers must establish and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and sensitivity of the data processed.[2][4]
  1. Non-discrimination and appeals. Controllers may not discriminate against consumers for exercising rights, and they must provide an internal appeals process for denied requests.[2][4]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | enactment / approval | 9 May 2024 | MODPA was signed into law.[2] | | effective date | 1 October 2025 | The statute became effective as a law on the books.[2][3] | | processing obligations begin | 1 April 2026 | Core obligations apply to processing activities occurring on or after this date.[1][2] | | cure period ends | 1 April 2027 | The limited opportunity to cure alleged violations expires.[1][4] |

The Maryland Attorney General may seek civil penalties of up to $10,000 per violation and up to $25,000 for repeated violations.[4] The Attorney General may also seek injunctive relief, restitution, economic damages, and disgorgement.[4]

How to Comply

  1. Map data and classify it. Build a data inventory showing what personal data is collected, why it is collected, where it flows, and whether it is sensitive data; this is the foundation for MODPA notices, rights handling, and vendor management.
  1. Align the privacy program to governance standards. Use ISO 27001 for security controls, NIST CSF 2.0 for risk identification and response, and ISO 42001 where AI systems process personal data or affect profiling decisions.
  1. Update notices and intake workflows. Refresh privacy notices, cookie and tracking disclosures, and rights-request portals so they clearly describe categories, purposes, retention, sharing, and opt-out channels.
  1. Implement rights operations. Create documented SLAs, identity verification rules, appeal handling, and suppression logic so access, correction, deletion, and opt-out requests are processed consistently and on time.
  1. Restrict sensitive data use. Require legal review before collecting or sharing sensitive data, and block any sale of sensitive data; ensure consent or necessity logic matches the statute’s strict standard.
  1. Harden processor contracts. Amend vendor agreements to cover processing instructions, confidentiality, deletion/return, security, and audit rights, and verify subprocessors through due diligence.
  1. Test security and incident response. Maintain technical and organizational safeguards, log access to personal data, and rehearse breach response and evidence preservation under the broader security program.
  1. Track enforcement timing. Because the core obligations are live for processing on or after 1 April 2026 and the cure period ends on 1 April 2027, set calendar controls and legal reviews around those dates.[1][4]

Related Regulations

The Maryland Personal Information Protection Act overlaps on security and breach response, but it is narrower and does not replace MODPA’s consumer rights regime.

The Virginia Consumer Data Protection Act is a close peer statute, but Maryland is generally stricter on sensitive data and profiling-related rules.

The California Consumer Privacy Act / CPRA overlaps on access, deletion, correction, and opt-out rights, but California uses a different enforcement structure and compliance framework.

The Colorado Privacy Act is similar on consumer rights and controller obligations, but Maryland’s thresholds and sensitive data rules differ in ways that can force separate operational treatment.

The EU GDPR overlaps strongly on lawful processing, data minimization, and rights management, but MODPA is a state law with different triggers, exemptions, and penalties.

FAQ

Does MODPA apply to companies outside Maryland?

Yes, if a company does business in Maryland or targets Maryland residents and meets the law’s consumer and revenue thresholds.[2][4] Physical presence in Maryland is not required.[2] This makes MODPA relevant to many remote and digital businesses that collect Maryland resident data.

When did MODPA start being enforced?

The statute took effect on 1 October 2025, but the core processing obligations apply to activities occurring on or after 1 April 2026.[1][2] That means pre-April 2026 processing is outside the main operative compliance window even though the law was already effective.[1][2]

Can businesses sell sensitive data under MODPA?

No. The Attorney General’s published guidance states that a controller may not sell sensitive data.[4] Sensitive data also may be collected, processed, or shared only when strictly necessary to provide or maintain a requested product or service.[4][5]

Does MODPA require a universal opt-out signal?

MODPA includes opt-out rights for targeted advertising, sale of personal data, and certain profiling, and Maryland’s implementation materials indicate a universal opt-out mechanism phases in with the law’s later effective timing.[1][4] Companies should not assume a generic browser signal is sufficient unless their implementation is aligned with Maryland’s current rules and recognized mechanisms.

What are the biggest enforcement risks?

The biggest risks are missing consumer rights workflows, mishandling sensitive data, using weak vendor contracts, and failing to honor opt-out requests.[2][4] Repeated violations can draw higher penalties, and the Attorney General can also seek injunctive and monetary relief.[4]

Sources

Put it into practice

More compliance guides