EnglishEspañol
Maryland flag

Maryland

MODPA Consumer Rights: Maryland Data Privacy

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

MODPA Consumer Rights: Maryland Data Privacy

Frequently Asked Questions

What rights do Maryland residents have under MODPA?

Under section 14-4705, Maryland residents can confirm whether a business is processing their personal data, access it, correct inaccuracies, delete it, and obtain a portable copy. They can opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects, and can obtain a list of the categories of third parties to which their data has been disclosed.

How long does a business have to respond to a MODPA request?

Under section 14-4705(E)(2), a controller must respond within 45 days of receiving the request. It may extend the period by one additional 45 days when reasonably necessary, but only if it tells the consumer about the extension and the reason within the first 45-day window.

Can I opt out of data sales with a browser signal in Maryland?

Sometimes. Section 14-4707(F)(3) lets a controller choose how it delivers the opt-out: either a clear and conspicuous opt-out link on its website, or, on or before October 1, 2025, accepting an opt-out preference signal such as Global Privacy Control. The signal is a permitted method rather than one every controller must accept, so a business that offers a compliant opt-out link may not act on your browser signal. Where a controller does use signals, section 14-4707(F)(5) bars a default setting that opts you out, so the signal must reflect your affirmative choice.

Can a Maryland business sell my sensitive data?

No. Under section 14-4707(A)(2), a controller may not sell sensitive data at all, with no consent exception. Under section 14-4707(A)(1), a controller may collect, process, or share sensitive data only where that is strictly necessary to provide or maintain a specific product or service you requested. Strict necessity is the only gate, and MODPA does not offer consent as an alternative. This is stronger than the opt-out or opt-in approach used in other states.

How does Maryland's data minimization rule protect me?

Under section 14-4707(B)(1)(i), a business may collect personal data only to the extent reasonably necessary and proportionate to provide the specific product or service you requested. Consent cannot expand that limit. So a business cannot collect more than the requested service needs even if you agreed to a broad privacy policy, which protects you before you ever file a request.

Can I appeal if a business denies my MODPA request?

Yes. Under section 14-4705(F), a controller must offer a conspicuously available appeal process and respond in writing within 60 days of receiving the appeal. If it denies the appeal, it must give you an online way to submit a complaint to the Maryland Consumer Protection Division.

Does MODPA protect teenagers?

Yes. Under section 14-4707(A)(4) and (A)(5), where a controller knew or should have known that a consumer is under the age of 18 years, it may not process that consumer's data for targeted advertising and may not sell that data at all. Neither ban has a consent exception. The knew-or-should-have-known standard is broader than an actual-knowledge test, and the protection has no lower age bound.

Can I sue a business under MODPA?

No. MODPA has no private right of action. Enforcement runs through the Consumer Protection Division of the Office of the Attorney General under section 14-4713, with penalties up to $10,000 per violation and up to $25,000 for repeat violations under section 13-410. Section 14-4713(B) does preserve any other remedy that may exist under separate law.

Updates

Corrected the MODPA consumer-rights page against the enacted statute: sensitive data is gated by strict necessity alone rather than strict necessity plus consent, the ban on selling a minor's data reaches every consumer under 18 with no consent exception, the opt-out preference signal is one of two methods a controller may use rather than a mandate, the opt-out authentication rule was stated backwards, a non-existent 'content personalization or marketing' clause was replaced with the real section 14-4707(a)(8), and the section 14-4714 60-day right to cure was added.

Updated the statute section numbers cited throughout this page from Maryland's pre-recodification numbering (Com. Law Subtitle 46) to the current numbering (Subtitle 47), which took effect when the law was recodified; the underlying rights, deadlines, and penalties described were already accurate and are unchanged.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Maryland HB 567 (Chapter 454, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
  2. Md. Code Ann., Com. Law section 14-4705: Consumer Rights and Response Deadlines(mgaleg.maryland.gov).gov
  3. Md. Code Ann., Com. Law section 14-4706: Authorized Agent Opt-Out(mgaleg.maryland.gov).gov
  4. Md. Code Ann., Com. Law section 14-4707: Controller Duties, Sensitive Data, Universal Opt-Out(mgaleg.maryland.gov).gov
  5. Maryland SB 541 (Chapter 455, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
  6. Md. Code Ann., Com. Law section 13-410: Civil Penalty (Consumer Protection Act)(mgaleg.maryland.gov).gov
  7. Maryland Office of the Attorney General: Consumer Protection Division(marylandattorneygeneral.gov).gov
  8. Md. Code Ann., Com. Law section 14-4714: Right to Cure (Violations On or Before April 1, 2027)(mgaleg.maryland.gov)
Share: