Maryland
MODPA Compliance Checklist: Maryland Privacy
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Maryland Online Data Privacy Act (MODPA) compliance starts with a question other states do not force as sharply: can you justify every category of data you collect as reasonably necessary to the specific product or service the consumer requested? Because MODPA imposes hard data minimization under Md. Code Ann., Commercial Law section 14-4707(B), and bans selling sensitive data outright under section 14-4707(A), a compliance program that merely copies a Virginia or Connecticut template will not pass. As of 2026, MODPA is the strictest comprehensive state privacy law in the country.
This page is a practical checklist for covered businesses. It is general information, not legal advice. The headline obligations are a strict-necessity minimization analysis, a sensitive-data ban on sale plus a strict-necessity gate, strong minor protections, a compliant privacy notice, a universal opt-out mechanism, data protection assessments, and processor contracts. Enforcement runs through the Consumer Protection Division with penalties up to $10,000 per violation and no guaranteed cure.
Jurisdiction scope: This covers Maryland's Online Data Privacy Act (Md. Code Ann., Com. Law Title 14, Subtitle 47). It is general legal information, not legal advice.
Step 1: Confirm whether MODPA applies to you
Start with the applicability test in section 14-4702. MODPA applies to a person that conducts business in Maryland or produces products or services targeted to Maryland residents and that, during the preceding calendar year, met one of two data thresholds.
The first trigger is controlling or processing the personal data of at least 35,000 consumers, excluding personal data controlled or processed solely to complete a payment transaction. The payment carve-out means routine checkout data does not, by itself, push a merchant over the line.
The second trigger is controlling or processing the personal data of at least 10,000 consumers while deriving more than 20 percent of gross revenue from the sale of personal data. There is no dollar-revenue floor, so the 35,000-consumer threshold reaches well into mid-size and smaller businesses. Then check the exemptions in section 14-4703, which carve out state and local government bodies, certain financial institutions or data subject to the Gramm-Leach-Bliley Act, and data-level exemptions for HIPAA-protected health information, FCRA, FERPA, and similar regimes.
Step 2: Run the strict-necessity data minimization analysis
This is the step that separates MODPA from every other state. Under section 14-4707(B)(1)(i), you must limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain the specific product or service requested by the consumer.
Build a data inventory and, for each category you collect, write down the requested product or service it supports and why it is reasonably necessary to that service. Categories that exist only to enrich profiles, fuel unrelated marketing, or feed data sales are the ones most exposed under this standard.
Do not rely on consent to rescue over-collection. Section 14-4707(A) does require consent before you process personal data for a purpose that is neither reasonably necessary to nor compatible with the purposes you disclosed, but that is a separate rule, and the minimization duty in section 14-4707(B) runs independently of it. A consent box does not let you collect more than the requested service needs. If a category fails the necessity test, the fix is to stop collecting it, not to disclose it more prominently. For why this standard is stricter than other states, see what MODPA is.
Step 3: Lock down sensitive data and never sell it
Identify all sensitive data you handle. Under section 14-4701, sensitive data includes data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, and citizenship or immigration status, plus genetic or biometric data, the personal data of a known child, and precise geolocation data.
For each item, apply section 14-4707(A): you may collect, process, or share it only where strictly necessary to provide or maintain a specific product or service requested by the consumer. Strict necessity is the only gate the statute sets, and there is no consent exception, so asking the consumer for permission does not authorize sensitive-data processing that fails the necessity test. Where MODPA does require consent, such as the secondary-use rule in section 14-4707(A), that consent must meet the section 14-4701 definition, which excludes broad terms of use, dark patterns, and passive actions, and you must provide a revocation mechanism at least as easy as the one used to grant consent under section 14-4707(B)(1)(iii).
Then enforce the absolute rule: do not sell sensitive data. Section 14-4707(A) bars it entirely, with no consent exception. Map your data-sharing arrangements against the section 14-4701 definition of a sale, which covers exchanging personal data to a third party for monetary or other valuable consideration. Also watch the consumer health data rules in section 14-4704, including geofencing limits within 1,750 feet of mental health and reproductive or sexual health facilities.

Step 4: Apply the minor-data rules
MODPA's minor protections are strict and depend on a low knowledge standard. Under section 14-4707(A), you may not process the personal data of a consumer you knew or should have known is under the age of 18 for targeted advertising, and you may not sell that consumer's personal data at all. Both bans reach every consumer under 18, with no lower age cutoff, and the sale ban is unconditional: consent does not lift it.
Assess whether your audience includes teenagers. The knew-or-should-have-known standard means you cannot avoid the rule by declining to verify ages when the surrounding facts show a teen audience. If teens are reasonably in your user base, turn off targeted advertising for them and stop selling their data entirely.
For known children under 13, remember that their personal data is itself sensitive data under section 14-4701, so the strict-necessity rule applies on top of the under-18 bans. Controllers that meet COPPA verifiable parental consent are treated as compliant with parental consent obligations under section 14-4703(C).
Step 5: Publish a compliant privacy notice
Your privacy notice must meet section 14-4707(D). It must disclose the categories of personal data you process, including sensitive data; your purposes for processing; how a consumer may exercise rights, appeal a decision, or revoke consent; the categories of third parties you share data with, described in enough detail for a consumer to understand each type of entity and how it may process the data; the categories of personal data, including sensitive data, that you share with third parties; and an active email address or online mechanism to contact you.
If you sell personal data or process it for targeted advertising or significant profiling, section 14-4707(E) requires a clear and conspicuous disclosure of that activity and how to opt out, prominently displayed in plain language. The notice must also establish secure and reliable methods for consumers to submit rights requests under section 14-4707(F), and you may not require a consumer to create a new account to exercise a right.

Step 6: Build rights handling and the universal opt-out mechanism
Stand up a process to handle the rights in section 14-4705: confirmation, access, correction, deletion, portability, the list of categories of third parties, and the opt-outs for targeted advertising, sale, and profiling. You must respond within 45 days under section 14-4705(E)(2), with one 45-day extension allowed when you notify the consumer and explain why within the first window.
You must also honor a universal opt-out preference signal. Under section 14-4707(F)(3), as of October 1, 2025 you must let consumers opt out of targeted advertising or any sale through an opt-out preference signal such as Global Privacy Control, and section 14-4707(F)(5) bars using a default setting to opt a consumer out. Recognizing signals approved by other states is treated as compliant under section 14-4707(G).
Finally, build the appeal process required by section 14-4705(F): conspicuously available, with a written response within 60 days, and an online mechanism to submit a complaint to the Consumer Protection Division if you deny the appeal. Consumers may also act through an authorized agent under section 14-4706. The MODPA consumer rights guide covers the consumer side of these requests in detail.
Step 7: Processor contracts and data protection assessments
If you use a processor, section 14-4708 requires a binding contract that sets out processing instructions, the nature and purpose of processing, the type of data, the duration, and the rights and obligations of both parties. The contract must require the processor to keep personnel under a duty of confidentiality, maintain reasonable security, delete or return data at the end of service, assist with consumer rights requests, and allow reasonable assessments.
Section 14-4710 requires you to conduct and document a data protection assessment for processing activities that present a heightened risk of harm to consumers, which generally includes targeted advertising, the sale of personal data, certain profiling, and the processing of sensitive data. Keep these assessments on file because the Consumer Protection Division can require them in an investigation.
Step 8: Plan for enforcement with no guaranteed cure
MODPA is enforced by the Consumer Protection Division of the Office of the Attorney General. Under section 14-4713, a violation is an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act, subject to its enforcement and penalty provisions except section 13-408. Penalties under section 13-410 reach up to $10,000 per violation and up to $25,000 for each repeat of the same violation. There is no private right of action.
Do not count on a cure period. Under section 14-4714, for violations occurring on or before April 1, 2027 the Division may, if it determines a cure is possible, issue a notice and allow at least 60 days to cure, but that opportunity is discretionary and the Division weighs factors such as the number of violations and the likelihood of public injury. Separately, the Act provides that the limitations and exemptions section, section 14-4712, applies only prospectively and has no application to processing activities before April 1, 2026. Because a cure is never guaranteed, build the program to be compliant from the start rather than relying on a chance to fix problems later.
Related guides
- Maryland data privacy laws parent hub
- What is MODPA?
- MODPA consumer rights
- State data privacy law comparison
- What is the CCPA?
More Maryland Laws
Frequently Asked Questions
Who has to comply with MODPA?
Under section 14-4702, MODPA applies to a person that does business in Maryland or targets Maryland residents and, during the prior calendar year, processed the personal data of at least 35,000 consumers (excluding payment-only data), or at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. There is no dollar-revenue floor, so smaller businesses can be covered.
What is the hardest part of MODPA compliance?
The data minimization analysis under section 14-4707(B). You must limit collection to what is reasonably necessary and proportionate to the specific product or service the consumer requested, and consent cannot expand that. Most businesses must audit every data category and drop anything that is not necessary to the requested service, which is stricter than other state laws.
Can a covered business ever sell sensitive data in Maryland?
No. Section 14-4707(A) bans selling sensitive data outright, with no consent exception. A business may collect, process, or share sensitive data only where strictly necessary to provide or maintain a specific product or service the consumer requested. Consent is not an alternative path: if the processing fails the strict-necessity test, the consumer's permission does not authorize it. Map your data-sharing arrangements against the section 14-4701 definition of a sale to make sure none involve sensitive data.
What are the MODPA rules for minors' data?
Under section 14-4707(A), a business may not process the personal data of a consumer it knew or should have known is under the age of 18 for targeted advertising, and may not sell that consumer's personal data at all. Both bans apply to every consumer under 18, with no lower age cutoff, and the sale ban has no consent exception. The knew-or-should-have-known standard means you cannot avoid the rule by not verifying ages when your audience clearly includes teens.
Does MODPA require honoring a universal opt-out signal?
Yes. Under section 14-4707(F)(3), as of October 1, 2025 a controller must let consumers opt out of targeted advertising or any sale of personal data through an opt-out preference signal such as Global Privacy Control. A default setting may not be used to opt a consumer out, and recognizing signals approved by other states counts as compliant under section 14-4707(G).
Do I need data protection assessments and processor contracts?
Yes. Section 14-4708 requires a binding data processing contract with any processor, covering processing instructions, purpose, data types, duration, and obligations. Section 14-4710 requires documented data protection assessments for heightened-risk processing, which generally includes targeted advertising, data sales, certain profiling, and sensitive data processing.
Is there a cure period before MODPA enforcement?
Not a guaranteed one. Under section 14-4714, for violations on or before April 1, 2027 the Consumer Protection Division may, if it finds a cure possible, issue a notice and allow at least 60 days to cure, but the opportunity is discretionary. After that window, no cure is offered. Build for compliance from the start rather than relying on a chance to fix issues later.
What are the penalties for violating MODPA?
Under section 14-4713, a MODPA violation is an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act. Penalties under section 13-410 reach up to $10,000 per violation and up to $25,000 for each repeat of the same violation. Enforcement is by the Consumer Protection Division of the Office of the Attorney General, and there is no private right of action.
Updates
Corrected the minor-data and sensitive-data sections: MODPA's targeted-advertising and sale bans cover every consumer under 18 with no lower age limit, the ban on selling a minor's data has no consent exception, sensitive-data processing is gated only by strict necessity rather than by consent, and a nonexistent personalization and marketing prohibition was removed from Step 2.
Updated every MODPA statutory citation on this page from Maryland's old codification (Md. Code, Com. Law Subtitle 46, sections 14-4601 to 14-4614) to the current codification (Subtitle 47, sections 14-4701 to 14-4714) and repointed the Attorney General Consumer Protection Division citation to its current live URL. No substantive obligation, threshold, deadline, or penalty changed.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maryland Code, Commercial Law Article
§ 14-4707In forcecited in 5 of our articles
§14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data; (3) Process personal data in violation of State or federal laws that prohibit unlawful discrimination; (4) Process the personal data of a consumer for the purposes of targeted advertising if the controller knew or should have known that the consumer is under the age of 18 years; (5) Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years; (6) Discriminate against a consumer for exercising a consumer right contained in this subtitle, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; (7) Collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in or otherwise unlawfully makes unavailable the equal enjoyment of goods or…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Privacy Laws: MODPA Consumer Rights Guide (2026), Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026), What Is MODPA? Maryland Online Data Privacy Act
§ 14-4702In forcecited in 2 of our articles
§14–4702. This subtitle applies to a person that conducts business in the State or provides products or services that are targeted to residents of the State, and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of at least 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) Controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of its gross revenue from the sale of personal data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
§ 14-4708In force
§14–4708. (a) (1) If a controller uses a processor to process the personal data of consumers, the controller and the processor shall enter into a contract that governs the processor’s data processing procedures with respect to processing performed on behalf of the controller. (2) The contract shall be binding and shall clearly set forth: (i) Instructions for processing data; (ii) The nature and purpose of processing; (iii) The type of data subject to processing; (iv) The duration of processing; and (v) The rights and obligations of both parties.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
§ 14-4714In force
§14–4714. (a) This section applies to an enforcement action under § 14–4713 of this subtitle for an alleged violation that occurs on or before April 1, 2027. (b) Before initiating any action under § 14–4713 of this subtitle, the Division may issue a notice of violation to the controller or processor if the Division determines that a cure is possible. (c) (1) If the Division issues a notice of violation under subsection (b) of this section, the controller or processor shall have at least 60 days to cure the violation after receipt of the notice. (2) If the controller or processor fails to cure the violation within the time period specified by the Division, the Division may bring an enforcement action under § 14–4713 of this subtitle.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
§ 13-410In forcecited in 4 of our articles
§13–410. (a) A merchant who engages in a violation of this title is subject to a fine not exceeding $10,000 for each violation. (b) A merchant who has been found to have engaged in a violation of this title and who subsequently repeats the same violation is subject to a fine not exceeding $25,000 for each subsequent violation. (c) The fines provided for in subsections (a) and (b) of this section are civil penalties and are recoverable by the State in a civil action or an administrative cease and desist action under § 13–403(a) and (b) of this subtitle or after an administrative hearing has been held under § 13–403(d)(3) and (4) of this subtitle. (d) The Consumer Protection Division shall consider the following in setting the amount of the penalty imposed in an administrative proceeding: (1) The severity of the violation for which the penalty is assessed; (2) The good faith of the violator; (3) Any history of prior violations; (4) Whether the amount of the penalty will achieve the desired deterrent purpose; and (5) Whether the issuance of a cease and desist order, including restitution, is insufficient for the protection of consumers.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026), MODPA Consumer Rights: Maryland Data Privacy
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Maryland HB 567 (Chapter 454, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4702: Applicability Thresholds(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4707: Data Minimization, Sensitive Data, Privacy Notice, Universal Opt-Out(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4708: Processor Contracts(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law sections 14-4713 and 14-4714: Enforcement and Cure(mgaleg.maryland.gov).gov
- Maryland SB 541 (Chapter 455, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 13-410: Civil Penalty (Consumer Protection Act)(mgaleg.maryland.gov).gov
- Maryland Office of the Attorney General: Consumer Protection Division(oag.maryland.gov).gov