EnglishEspañol
Maryland flag

Maryland

MODPA Compliance Checklist: Maryland Privacy

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

MODPA Compliance Checklist: Maryland Privacy

Frequently Asked Questions

Who has to comply with MODPA?

Under section 14-4702, MODPA applies to a person that does business in Maryland or targets Maryland residents and, during the prior calendar year, processed the personal data of at least 35,000 consumers (excluding payment-only data), or at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. There is no dollar-revenue floor, so smaller businesses can be covered.

What is the hardest part of MODPA compliance?

The data minimization analysis under section 14-4707(B). You must limit collection to what is reasonably necessary and proportionate to the specific product or service the consumer requested, and consent cannot expand that. Most businesses must audit every data category and drop anything that is not necessary to the requested service, which is stricter than other state laws.

Can a covered business ever sell sensitive data in Maryland?

No. Section 14-4707(A) bans selling sensitive data outright, with no consent exception. A business may collect, process, or share sensitive data only where strictly necessary to provide or maintain a specific product or service the consumer requested. Consent is not an alternative path: if the processing fails the strict-necessity test, the consumer's permission does not authorize it. Map your data-sharing arrangements against the section 14-4701 definition of a sale to make sure none involve sensitive data.

What are the MODPA rules for minors' data?

Under section 14-4707(A), a business may not process the personal data of a consumer it knew or should have known is under the age of 18 for targeted advertising, and may not sell that consumer's personal data at all. Both bans apply to every consumer under 18, with no lower age cutoff, and the sale ban has no consent exception. The knew-or-should-have-known standard means you cannot avoid the rule by not verifying ages when your audience clearly includes teens.

Does MODPA require honoring a universal opt-out signal?

Yes. Under section 14-4707(F)(3), as of October 1, 2025 a controller must let consumers opt out of targeted advertising or any sale of personal data through an opt-out preference signal such as Global Privacy Control. A default setting may not be used to opt a consumer out, and recognizing signals approved by other states counts as compliant under section 14-4707(G).

Do I need data protection assessments and processor contracts?

Yes. Section 14-4708 requires a binding data processing contract with any processor, covering processing instructions, purpose, data types, duration, and obligations. Section 14-4710 requires documented data protection assessments for heightened-risk processing, which generally includes targeted advertising, data sales, certain profiling, and sensitive data processing.

Is there a cure period before MODPA enforcement?

Not a guaranteed one. Under section 14-4714, for violations on or before April 1, 2027 the Consumer Protection Division may, if it finds a cure possible, issue a notice and allow at least 60 days to cure, but the opportunity is discretionary. After that window, no cure is offered. Build for compliance from the start rather than relying on a chance to fix issues later.

What are the penalties for violating MODPA?

Under section 14-4713, a MODPA violation is an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act. Penalties under section 13-410 reach up to $10,000 per violation and up to $25,000 for each repeat of the same violation. Enforcement is by the Consumer Protection Division of the Office of the Attorney General, and there is no private right of action.

Updates

Corrected the minor-data and sensitive-data sections: MODPA's targeted-advertising and sale bans cover every consumer under 18 with no lower age limit, the ban on selling a minor's data has no consent exception, sensitive-data processing is gated only by strict necessity rather than by consent, and a nonexistent personalization and marketing prohibition was removed from Step 2.

Updated every MODPA statutory citation on this page from Maryland's old codification (Md. Code, Com. Law Subtitle 46, sections 14-4601 to 14-4614) to the current codification (Subtitle 47, sections 14-4701 to 14-4714) and repointed the Attorney General Consumer Protection Division citation to its current live URL. No substantive obligation, threshold, deadline, or penalty changed.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Maryland HB 567 (Chapter 454, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
  2. Md. Code Ann., Com. Law section 14-4702: Applicability Thresholds(mgaleg.maryland.gov).gov
  3. Md. Code Ann., Com. Law section 14-4707: Data Minimization, Sensitive Data, Privacy Notice, Universal Opt-Out(mgaleg.maryland.gov).gov
  4. Md. Code Ann., Com. Law section 14-4708: Processor Contracts(mgaleg.maryland.gov).gov
  5. Md. Code Ann., Com. Law sections 14-4713 and 14-4714: Enforcement and Cure(mgaleg.maryland.gov).gov
  6. Maryland SB 541 (Chapter 455, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
  7. Md. Code Ann., Com. Law section 13-410: Civil Penalty (Consumer Protection Act)(mgaleg.maryland.gov).gov
  8. Maryland Office of the Attorney General: Consumer Protection Division(oag.maryland.gov).gov
Share: