Maryland HB 711 (2026) MODPA Amendments

Expands the Maryland Online Data Privacy Act definition of sensitive data to inferred data and restricts sales to immigration enforcement entities.

JurisdictionMaryland
CategoryPrivacy & Data Protection
StatusActive
Effective date
Latest development

Recent developments

  • — Overview of Maryland data protection and privacy regulation noting that a **2026 amendment to MODPA (HB 711)** strengthened sensitive‑data and immigration‑related protections effective **2026-07-01**, positioning Maryland as a leading state on privacy limits tied to immigration enforcement.[15] (source)
  • — Analysis explaining that **HB 711 took effect on 2026-07-01** and explicitly **bars controllers from knowingly selling personal data to any governmental unit that has engaged in or supported civil immigration enforcement in the preceding six months**, making Maryland’s approach unusually direct compared with other state privacy laws.[6] (source)
  • — Same article describes operational impact on businesses subject to MODPA: controllers must build processes to identify government purchasers linked to immigration enforcement and apply a six‑month look‑back, increasing due‑diligence and contract‑review burdens for data brokers and SaaS providers.[6] (source)
  • — Chapter 874 text confirming that **HB 711 (MODPA amendments) took effect on 2026-07-01** and requires each governmental entity, by that date, to **develop and publish procedures to prevent the sale and redisclosure of personal records and “sensitive data containing sensitive attributes”** in ways that harm Maryland residents’ privacy.[8] (source)
  • — Policy note: governmental entities must submit these privacy‑protective procedures to the General Assembly, signaling tighter internal controls on how state agencies share data externally, including with law enforcement and immigration authorities.[8] (source)
  • — Legislative history page showing **HB 711** as enacted MODPA amendments in the 2026 Regular Session, detailing subject matter around consumer data, public records, and law‑enforcement “message switching systems,” and reflecting updates posted through mid‑August 2026.[1] (source)
  • — Industry overview noting that HB 711 **expands the definition of sensitive data to include inferred sensitive data** (e.g., inferred race, religion, health, sexual orientation, immigration status) and **restricts sales of personal data to government entities that have recently engaged in or supported immigration enforcement**, creating broader consent and data‑minimization obligations for covered businesses.[14] (source)
  • — Practitioner commentary outlining that HB 711 **narrows law‑enforcement and government exceptions under MODPA**: disclosures based on subpoenas or cooperation are limited when agencies are known to engage in civil immigration enforcement, and sales of personal data to such agencies are prohibited, prompting compliance teams to revisit government‑data‑sharing workflows.[3] (source)
  • — Testimony from the Maryland Division of Consumer Protection indicating concern that HB 711’s new “sensitive attributes” category adds complexity to MODPA’s framework, foreshadowing implementation challenges for regulators and businesses that must map and treat these attributes differently across systems.[11] (source)
  • — Report on Economic Matters Committee action describing HB 711 as tightening Maryland’s data‑privacy and driver‑privacy rules to **restrict sharing with federal immigration enforcement absent a warrant**, add a **six‑month look‑back standard** for agencies involved in immigration enforcement, and drive procurement and systems changes at DPSCS and MVA worth about **$4.3 million**, highlighting significant operational and budget impacts.[12] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates