Maryland
MODPA Consumer Rights: Maryland Data Privacy
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

The Maryland Online Data Privacy Act (MODPA) gives Maryland residents the right to confirm whether a business is processing their personal data, access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of their data, and certain profiling. Consumers can also obtain a list of the categories of third parties to which their data has been disclosed. These rights live at Md. Code Ann., Commercial Law section 14-4705 and took effect October 1, 2025.
What makes Maryland's protections stronger than other states is not only the list of rights but the underlying duties: a hard data minimization rule, a strict-necessity gate on sensitive data, an outright ban on selling sensitive data, and strong protections for consumers under 18. As of 2026, a controller generally must respond to a rights request within 45 days, and a controller may meet its opt-out duty either by posting a clear opt-out link or by accepting an opt-out preference signal. Enforcement runs through the Consumer Protection Division of the Office of the Attorney General, with no private right of action.
Jurisdiction scope: This covers Maryland's Online Data Privacy Act (Md. Code Ann., Com. Law Title 14, Subtitle 47). It is general legal information, not legal advice.
The full set of MODPA consumer rights
MODPA lists the consumer rights in section 14-4705(B). A Maryland resident has the right to confirm whether a controller is processing the consumer's personal data and to access that data, unless doing so would require disclosing a trade secret. These two rights let a consumer see whether and how a business holds their information.
The consumer also has the right to correct inaccuracies in their personal data, considering the nature of the data and the purposes of processing, and the right to require a controller to delete personal data provided by or obtained about the consumer unless retention is required by law. Deletion under MODPA reaches data the business obtained from other sources, not just data the consumer handed over.
Section 14-4705(B)(5) adds a portability right. Where processing is carried out by automatic means, the consumer may obtain a copy of their personal data in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance.
The right to a list of categories of third parties
One of MODPA's most useful transparency rights is the right to learn where a consumer's data has gone. Under section 14-4705(B)(6), a consumer may obtain a list of the categories of third parties to which the controller has disclosed the consumer's personal data. If the controller does not keep that information in a consumer-specific format, it may instead provide a list of the categories of third parties to which it has disclosed any consumer's personal data.
This is a category-level disclosure. A controller reports groups such as advertising partners, analytics vendors, or data brokers rather than every named recipient. It still gives consumers a structured view of data flows that older privacy frameworks did not provide.
The privacy notice supports this right. Under section 14-4707(D), the notice must describe the categories of third parties with which the controller shares personal data with enough detail for a consumer to understand what type of entity each third party is and, to the extent possible, how each may process the data.

Opt-out rights and the universal opt-out mechanism
Section 14-4705(B)(7) gives consumers the right to opt out of three things: the processing of personal data for targeted advertising, the sale of personal data, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. The sale definition in section 14-4701 is broad, covering the exchange of personal data to a third party for monetary or other valuable consideration, with limited carve-outs.
Maryland gives controllers two routes for delivering that opt-out. Under section 14-4707(F)(3), a controller may satisfy the requirement by providing a clear and conspicuous link on its website to a page where a consumer can opt out of targeted advertising or the sale of personal data, or, on or before October 1, 2025, by allowing a consumer to opt out through an opt-out preference signal sent by a platform, technology, or mechanism, such as Global Privacy Control. The enacted text lists these as methods a controller may utilize, so accepting a universal signal is one permitted route rather than a freestanding mandate. Section 14-4707(F)(5) bars a default setting that opts a consumer out, so the signal must reflect the consumer's affirmative choice. A controller that recognizes signals approved by other states is considered compliant under section 14-4707(G).
Consumers do not have to act alone. Under section 14-4706, a consumer may designate an authorized agent, including through a browser setting, browser extension, or global device setting, to opt out on the consumer's behalf. Section 14-4705(E)(6) also provides that a controller may not be required to authenticate an opt-out request, which keeps the friction on opting out lower than on an access or deletion request.
How the data minimization rule protects consumers
Maryland protects consumers before they ever file a request, through its data minimization rule. Under section 14-4707(B)(1)(i), a controller may collect personal data only to the extent reasonably necessary and proportionate to provide or maintain the specific product or service requested by the consumer. This is the single biggest reason MODPA gives Maryland residents more protection than residents of other states.
The standard is tied to the service the consumer asked for, not to whatever purposes a business chooses to disclose. A business cannot bury broad collection in a privacy policy and call it compliant. If the data is not reasonably necessary to the requested function, collecting it is not permitted.
Consent does not change this. Consent gates a different duty: section 14-4707(A)(8) bars processing personal data for a purpose that is neither reasonably necessary to nor compatible with the disclosed purposes unless the consumer consents. The minimization duty in section 14-4707(B) has no such consent override. A business cannot use a consent box to justify collecting more than the requested service needs. For the broader picture of why this makes MODPA the strictest state law, see what MODPA is.
Sensitive data and the sale ban that protect consumers
MODPA gives consumers unusually strong control over sensitive data. Under section 14-4701, sensitive data includes data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, and citizenship or immigration status, plus genetic or biometric data, the personal data of a known child, and precise geolocation data.
For that data, section 14-4707(A)(1) lets a controller collect, process, or share it only where the collection or processing is strictly necessary to provide or maintain a specific product or service the consumer requested. Strict necessity is the sole gate. MODPA attaches no consent option to sensitive data, so a business cannot process it simply because a consumer clicked a consent box.
The strongest protection is the sale ban. Under section 14-4707(A)(2), a controller may not sell sensitive data at all, with no consent exception. A Maryland consumer's sensitive data therefore cannot be sold by a covered business, a protection that goes further than any opt-out or opt-in right available in other states.

Protections for consumers under 18
MODPA carries strong protections for minors that operate without the consumer having to file anything. Under section 14-4707(A)(4) and (A)(5), where a controller knew or should have known that a consumer is under the age of 18 years, it may not process that consumer's personal data for targeted advertising, and it may not sell that consumer's personal data. Neither ban carries a consent exception, and neither has a lower age bound.
The knew-or-should-have-known standard is broader than an actual-knowledge test. It reaches a business that has reason to know it serves a teen audience, even without confirming each user's age. The protection covers every consumer under 18, so it reaches well above the under-13 floor of the federal Children's Online Privacy Protection Act.
For known children under 13, sensitive data treatment also applies because the personal data of a known child is itself sensitive data under section 14-4701, and controllers that comply with COPPA verifiable parental consent are treated as compliant with parental consent obligations under section 14-4703(C).
Response deadlines, appeals, and enforcement
A controller must establish a secure and reliable method for consumers to exercise their rights under section 14-4705(C), and may not require a consumer to create a new account to do so under section 14-4707(F)(2). The controller must respond to a rights request within 45 days under section 14-4705(E)(2), with one additional 45-day extension where reasonably necessary, provided the consumer is told of the extension and the reason within the first 45 days.
If a controller declines to act, it must inform the consumer within 45 days and provide instructions on how to appeal under section 14-4705(E)(3). The appeal process must be conspicuously available, and the controller has 60 days after receiving an appeal to respond in writing under section 14-4705(F)(3). If the appeal is denied, the controller must provide an online way to submit a complaint to the Consumer Protection Division.
Enforcement is the Division's job under section 14-4713. A violation is an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act, carrying civil penalties up to $10,000 per violation and up to $25,000 for repeat violations under section 13-410. Section 14-4714 adds a transitional right to cure: for a violation occurring on or before April 1, 2027, the Division may issue a notice of violation where it determines a cure is possible, and the business then has at least 60 days to fix the problem before the Division may bring an enforcement action. There is no private right of action, so consumers cannot sue a business directly under MODPA, though section 14-4713(B) preserves other remedies that may exist under separate law. The MODPA compliance checklist covers the controller-side obligations behind these rights.
Related guides
- Maryland data privacy laws parent hub
- What is MODPA?
- MODPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Maryland Laws
Frequently Asked Questions
What rights do Maryland residents have under MODPA?
Under section 14-4705, Maryland residents can confirm whether a business is processing their personal data, access it, correct inaccuracies, delete it, and obtain a portable copy. They can opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects, and can obtain a list of the categories of third parties to which their data has been disclosed.
How long does a business have to respond to a MODPA request?
Under section 14-4705(E)(2), a controller must respond within 45 days of receiving the request. It may extend the period by one additional 45 days when reasonably necessary, but only if it tells the consumer about the extension and the reason within the first 45-day window.
Can I opt out of data sales with a browser signal in Maryland?
Sometimes. Section 14-4707(F)(3) lets a controller choose how it delivers the opt-out: either a clear and conspicuous opt-out link on its website, or, on or before October 1, 2025, accepting an opt-out preference signal such as Global Privacy Control. The signal is a permitted method rather than one every controller must accept, so a business that offers a compliant opt-out link may not act on your browser signal. Where a controller does use signals, section 14-4707(F)(5) bars a default setting that opts you out, so the signal must reflect your affirmative choice.
Can a Maryland business sell my sensitive data?
No. Under section 14-4707(A)(2), a controller may not sell sensitive data at all, with no consent exception. Under section 14-4707(A)(1), a controller may collect, process, or share sensitive data only where that is strictly necessary to provide or maintain a specific product or service you requested. Strict necessity is the only gate, and MODPA does not offer consent as an alternative. This is stronger than the opt-out or opt-in approach used in other states.
How does Maryland's data minimization rule protect me?
Under section 14-4707(B)(1)(i), a business may collect personal data only to the extent reasonably necessary and proportionate to provide the specific product or service you requested. Consent cannot expand that limit. So a business cannot collect more than the requested service needs even if you agreed to a broad privacy policy, which protects you before you ever file a request.
Can I appeal if a business denies my MODPA request?
Yes. Under section 14-4705(F), a controller must offer a conspicuously available appeal process and respond in writing within 60 days of receiving the appeal. If it denies the appeal, it must give you an online way to submit a complaint to the Maryland Consumer Protection Division.
Does MODPA protect teenagers?
Yes. Under section 14-4707(A)(4) and (A)(5), where a controller knew or should have known that a consumer is under the age of 18 years, it may not process that consumer's data for targeted advertising and may not sell that data at all. Neither ban has a consent exception. The knew-or-should-have-known standard is broader than an actual-knowledge test, and the protection has no lower age bound.
Can I sue a business under MODPA?
No. MODPA has no private right of action. Enforcement runs through the Consumer Protection Division of the Office of the Attorney General under section 14-4713, with penalties up to $10,000 per violation and up to $25,000 for repeat violations under section 13-410. Section 14-4713(B) does preserve any other remedy that may exist under separate law.
Updates
Corrected the MODPA consumer-rights page against the enacted statute: sensitive data is gated by strict necessity alone rather than strict necessity plus consent, the ban on selling a minor's data reaches every consumer under 18 with no consent exception, the opt-out preference signal is one of two methods a controller may use rather than a mandate, the opt-out authentication rule was stated backwards, a non-existent 'content personalization or marketing' clause was replaced with the real section 14-4707(a)(8), and the section 14-4714 60-day right to cure was added.
Updated the statute section numbers cited throughout this page from Maryland's pre-recodification numbering (Com. Law Subtitle 46) to the current numbering (Subtitle 47), which took effect when the law was recodified; the underlying rights, deadlines, and penalties described were already accurate and are unchanged.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maryland Code, Commercial Law Article
§ 14-4705In force
§14–4705. (a) Nothing in this section may be construed to require a controller to reveal a trade secret. (b) A consumer shall have the right to: (1) Confirm whether a controller is processing the consumer’s personal data; (2) If a controller is processing a consumer’s personal data, access the consumer’s personal data; (3) Considering the nature of the consumer’s personal data and the purposes of the processing of the personal data, correct inaccuracies in the consumer’s personal data; (4) Require a controller to delete personal data provided by, or obtained about, the consumer unless retention of the personal data is required by law; (5) If the processing of personal data is done by automatic means, obtain a copy of the consumer’s personal data processed by the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to easily transmit the data to another controller without hindrance; (6) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data or a list of the categories of third parties to which the controller has disclosed any consumer’s personal data if…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
§ 14-4707In forcecited in 5 of our articles
§14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data; (3) Process personal data in violation of State or federal laws that prohibit unlawful discrimination; (4) Process the personal data of a consumer for the purposes of targeted advertising if the controller knew or should have known that the consumer is under the age of 18 years; (5) Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years; (6) Discriminate against a consumer for exercising a consumer right contained in this subtitle, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; (7) Collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in or otherwise unlawfully makes unavailable the equal enjoyment of goods or…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Privacy Laws: MODPA Consumer Rights Guide (2026), Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026), What Is MODPA? Maryland Online Data Privacy Act
§ 14-4706In force
§14–4706. (a) (1) A consumer may designate an individual to serve as the consumer’s authorized agent and act on the consumer’s behalf to opt out of the processing of the consumer’s personal data for one or more of the purposes specified in § 14–4705(b)(7) of this subtitle. (2) A consumer may designate an authorized agent by an Internet link or a browser setting, browser extension, global device setting, or other similar technology, indicating a consumer’s intent to opt out of the processing of the consumer’s personal data. (b) A controller shall comply with an opt–out request received from an authorized agent if, using commercially reasonable efforts, the controller is able to authenticate: (1) The identity of the consumer; and (2) The authorized agent’s authority to act on the consumer’s behalf.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
§ 13-410In forcecited in 4 of our articles
§13–410. (a) A merchant who engages in a violation of this title is subject to a fine not exceeding $10,000 for each violation. (b) A merchant who has been found to have engaged in a violation of this title and who subsequently repeats the same violation is subject to a fine not exceeding $25,000 for each subsequent violation. (c) The fines provided for in subsections (a) and (b) of this section are civil penalties and are recoverable by the State in a civil action or an administrative cease and desist action under § 13–403(a) and (b) of this subtitle or after an administrative hearing has been held under § 13–403(d)(3) and (4) of this subtitle. (d) The Consumer Protection Division shall consider the following in setting the amount of the penalty imposed in an administrative proceeding: (1) The severity of the violation for which the penalty is assessed; (2) The good faith of the violator; (3) Any history of prior violations; (4) Whether the amount of the penalty will achieve the desired deterrent purpose; and (5) Whether the issuance of a cease and desist order, including restitution, is insufficient for the protection of consumers.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026), MODPA Compliance Checklist: Maryland Privacy
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Maryland HB 567 (Chapter 454, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4705: Consumer Rights and Response Deadlines(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4706: Authorized Agent Opt-Out(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4707: Controller Duties, Sensitive Data, Universal Opt-Out(mgaleg.maryland.gov).gov
- Maryland SB 541 (Chapter 455, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 13-410: Civil Penalty (Consumer Protection Act)(mgaleg.maryland.gov).gov
- Maryland Office of the Attorney General: Consumer Protection Division(marylandattorneygeneral.gov).gov
- Md. Code Ann., Com. Law section 14-4714: Right to Cure (Violations On or Before April 1, 2027)(mgaleg.maryland.gov)