Maryland
What Is MODPA? Maryland Online Data Privacy Act
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

The Maryland Online Data Privacy Act (MODPA) is Maryland's comprehensive consumer data privacy law, codified at Md. Code Ann., Commercial Law Title 14, Subtitle 47 (sections 14-4701 through 14-4714). It was enacted in the 2024 session as Senate Bill 541 and House Bill 567, signed by Governor Wes Moore on May 9, 2024, and took effect October 1, 2025. As of 2026, it is widely regarded as the strictest comprehensive state privacy law in the United States because it caps data collection at what is reasonably necessary to deliver the service a consumer asks for, bars the sale of sensitive data outright, and tightly limits how sensitive data can be processed at all.
The Consumer Protection Division of the Maryland Office of the Attorney General enforces MODPA, and a violation is treated as an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act (Title 13). Civil penalties run up to $10,000 per violation and up to $25,000 for repeat violations under section 13-410, and there is no private right of action.
Jurisdiction scope: This covers Maryland's Online Data Privacy Act (Md. Code Ann., Com. Law Title 14, Subtitle 47). It is general legal information, not legal advice.
What MODPA is: statute, enactment, and effective date
The Maryland Online Data Privacy Act is Maryland's first comprehensive consumer data privacy law. It is codified in the Commercial Law Article at Title 14, Subtitle 47, running from section 14-4701 through section 14-4714. The definitions that drive the rest of the subtitle sit at section 14-4701, applicability is at section 14-4702, and the entity and data exemptions follow at section 14-4703.
The law was enacted during the 2024 regular session as companion bills Senate Bill 541 (Chapter 455) and House Bill 567 (Chapter 454). Governor Wes Moore signed it on May 9, 2024. By the terms of the Act, MODPA took effect October 1, 2025, giving covered businesses just under eighteen months to prepare.
As of 2026, MODPA is fully operative. Every business that meets the applicability thresholds in section 14-4702 must honor consumer rights requests, offer secure and reliable methods for submitting them, follow the strict data minimization rule, limit how it handles sensitive data, and maintain a compliant privacy notice. For the full set of controller and processor obligations, see the Maryland data privacy laws parent page.
Why MODPA is the strictest state privacy law
Most state privacy laws follow a similar template borrowed from Virginia and Connecticut. Maryland broke from that template in several ways that, taken together, make MODPA the most restrictive comprehensive privacy law in the country as of 2026. The differences are not cosmetic. They change what a business is allowed to do with data even when a consumer has agreed.
The headline change is hard data minimization. Under section 14-4707(B)(1)(i), a controller or processor must limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain the specific product or service requested by the consumer. Other states tie minimization to the purposes a business discloses to consumers, which lets a business expand collection simply by disclosing more. Maryland ties the limit to the service the consumer actually requested, so a business cannot collect more than that even with consent.
MODPA also restricts sensitive data more tightly than any other state. Under section 14-4707(A), a controller may not collect, process, or share sensitive data except where strictly necessary to provide or maintain a specific product or service requested by the consumer. Most states allow sensitive data processing on opt-in consent. Maryland uses a strict-necessity test instead, so consent alone does not authorize processing sensitive data.
Finally, section 14-4707(A) flatly prohibits selling sensitive data. There is no consent exception. Where other states let a consumer opt out of sensitive data sales or require opt-in, Maryland removes the option entirely.

Hard data minimization, explained
The data minimization rule is the single most consequential feature of MODPA. Section 14-4707(B)(1)(i) is short, but its effect is large. It says collection must be limited to what is reasonably necessary and proportionate to provide or maintain the specific product or service the consumer requested.
The key phrase is "specific product or service requested by the consumer." That standard is not pegged to what a business wants to do, or even to what a business discloses in its privacy notice. It is pegged to the service the consumer came for. A weather app that asks for a contact list, or a flashlight app that asks for location history, would struggle to show that collection is reasonably necessary to the requested function.
Crucially, consent does not unlock more collection. Section 14-4707(A)(8) does bar processing personal data for a purpose that is neither reasonably necessary to nor compatible with the disclosed purposes unless the controller obtains consent, but the section 14-4707(B) minimization duty runs independently of consent. A business cannot present a consent box and then collect well beyond what the requested service needs. This is the structural reason MODPA is stricter than every other state framework as of 2026.
Sensitive data: strict necessity and a sale ban
MODPA treats sensitive data with unusual caution. Section 14-4701 defines sensitive data to include personal data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, and citizenship or immigration status, plus genetic or biometric data, the personal data of a known child, and precise geolocation data. The same subtitle separately defines consumer health data and adds geofencing limits around health facilities under section 14-4704.
For all of that data, section 14-4707(A) sets one hard gate: a controller may collect, process, or share sensitive data only where it is strictly necessary to provide or maintain a specific product or service requested by the consumer. There is no consent route around that test, and consent is not what makes the processing lawful. That is the design point compliance teams focus on, because in most other states opt-in consent is exactly what unlocks sensitive data processing.
The sale ban is the sharpest line. Section 14-4707(A) provides that a controller may not sell sensitive data, with no consent carve-out. For a business that monetizes data, this removes an entire revenue path that remains available, with consumer choice, in other states.
Strong protections for minors
MODPA includes some of the strongest teen protections in any state privacy law. Under section 14-4707(A), where a controller knew or should have known that a consumer is under the age of 18, it may not process that consumer's personal data for targeted advertising, and it may not sell that consumer's personal data at all. The sale ban carries no consent exception.
The "knew or should have known" standard is broader than the actual-knowledge standard that some states use. It reaches businesses that look the other way about a young audience. The protection covers every consumer under 18 the controller knew or should have known about, with no 13-year floor, reaching beyond the under-13 scope that the federal Children's Online Privacy Protection Act addresses.
The result is that a business cannot run targeted advertising against Maryland teenagers it has reason to know are under 18, and cannot sell their data, regardless of whether a parent or the teen clicked through a consent flow for general use. The MODPA consumer rights guide covers how these protections interact with the rights consumers can exercise.

Enforcement, penalties, and the timeline that matters
The Consumer Protection Division of the Office of the Attorney General enforces MODPA. Under section 14-4713, a violation of the subtitle is an unfair, abusive, or deceptive trade practice under Title 13 of the Commercial Law Article and is subject to the enforcement and penalty provisions of that title, except section 13-408 (which covers private restitution actions). That carve-out is one reason MODPA has no private right of action.
Penalties come from the Maryland Consumer Protection Act. Under section 13-410, a violation can carry a civil penalty of up to $10,000 per violation, rising to up to $25,000 for each repeat of the same violation.
Two dates matter for the enforcement runway. The law took effect October 1, 2025. Separately, the Act provides that the limitations and exemptions section, section 14-4712, applies only prospectively and has no application to processing activities before April 1, 2026. A discretionary cure period also exists under section 14-4714: for violations occurring on or before April 1, 2027, the Division may, if it finds a cure possible, issue a notice and allow at least 60 days to cure, but the cure is at the Division's discretion, not a guaranteed grace period.
MODPA vs. CCPA: the key differences
Companies that operate nationally often compare Maryland's MODPA with California's law. The state data privacy law comparison page covers the broader multistate picture, but several differences from California's CCPA stand out.
| Feature | Maryland MODPA | California CCPA/CPRA |
|---|---|---|
| Coverage threshold | 35,000 consumers, or 10,000 plus 20% of revenue from data sales; no dollar floor (section 14-4702) | $26.625M revenue (inflation-adjusted, effective Jan 1, 2025), 100,000 consumers, or 50% revenue from data sales |
| Data minimization | Hard limit: only what is reasonably necessary to the requested service, consent cannot expand it (section 14-4707(B)) | Tied to disclosed purposes; broader |
| Sensitive data | Strict-necessity test to process, with no consent alternative; selling sensitive data banned outright (section 14-4707(A)) | Right to limit use; opt-out model, no sale ban |
| Minor protections | No targeted ads or data sale for known under-18 consumers, knew-or-should-have-known standard (section 14-4707(A)) | Opt-in to sell for under-16 |
| Private right of action | None (section 14-4713) | Limited, for certain data breaches |
The most consequential difference is data minimization. California ties limits to disclosed purposes, which a business can expand by disclosing more. Maryland ties the limit to the specific service the consumer requested and makes consent unable to widen it, a structurally stricter rule.
The sensitive data treatment also diverges sharply. California gives consumers a right to limit the use of sensitive personal information through an opt-out. Maryland allows sensitive data processing only where it is strictly necessary to the specific product or service the consumer requested, with no consent alternative, and bans selling it outright under section 14-4707(A).
Related guides
- Maryland data privacy laws parent hub
- MODPA consumer rights
- MODPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Maryland Laws
Frequently Asked Questions
What is MODPA?
MODPA, the Maryland Online Data Privacy Act, is Maryland's comprehensive consumer data privacy law codified at Md. Code Ann., Com. Law Title 14, Subtitle 47 (sections 14-4701 to 14-4714). It was enacted as SB 541 and HB 567 in 2024, signed by Governor Wes Moore on May 9, 2024, and took effect October 1, 2025. As of 2026 it is widely viewed as the strictest comprehensive state privacy law in the United States.
When did MODPA take effect?
MODPA took effect October 1, 2025. The Act also provides that the limitations and exemptions section, section 14-4712, applies only prospectively and has no application to processing activities before April 1, 2026. A discretionary cure period under section 14-4714 applies to violations occurring on or before April 1, 2027.
Why is MODPA called the strictest state privacy law?
Three features set MODPA apart. Section 14-4707(B) imposes hard data minimization, limiting collection to what is reasonably necessary to the specific service the consumer requested, and consent cannot expand it. Section 14-4707(A) allows sensitive data processing only where it is strictly necessary to the specific product or service the consumer requested, with no consent alternative. And section 14-4707(A) bans selling sensitive data outright, with no consent exception, which no other state does.
What are MODPA's coverage thresholds?
Under section 14-4702, MODPA covers a person that does business in Maryland or targets Maryland residents and, during the prior calendar year, controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction), or at least 10,000 consumers while deriving more than 20 percent of gross revenue from the sale of personal data. There is no dollar-revenue floor.
Does MODPA ban selling sensitive data?
Yes. Section 14-4707(A) provides that a controller may not sell sensitive data, with no consent carve-out. This is one of MODPA's most distinctive features. Other states generally let consumers opt out of sensitive data sales or require opt-in, but Maryland removes the option entirely.
What counts as sensitive data under MODPA?
Under section 14-4701, sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, and citizenship or immigration status, plus genetic or biometric data, the personal data of a known child, and precise geolocation data. Processing it is allowed under section 14-4707(A) only where strictly necessary to the specific product or service the consumer requested; consent does not unlock it.
How does MODPA protect minors?
Under section 14-4707(A), where a controller knew or should have known that a consumer is under 18, it may not process that consumer's data for targeted advertising and may not sell that consumer's data at all, with no consent exception. The knew-or-should-have-known standard is broader than an actual-knowledge test and covers every consumer under 18, with no 13-year floor.
Who enforces MODPA and what are the penalties?
The Consumer Protection Division of the Maryland Office of the Attorney General enforces MODPA under section 14-4713. A violation is an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act, carrying civil penalties up to $10,000 per violation and up to $25,000 for repeat violations under section 13-410. There is no private right of action, and any cure period is discretionary under section 14-4714.
Updates
Corrected the page's description of MODPA's sensitive-data rule (strict necessity, not strict necessity plus consent), stated the under-18 data sale ban as absolute, replaced a provision that was struck from SB 541 before enactment with the enacted section 14-4707(a)(8), and clarified that honoring a universal opt-out signal is one of two optional compliance methods rather than a standalone requirement.
Updated every MODPA statute citation on this page from Maryland's old codification (Com. Law Subtitle 46, sections 14-4601 to 14-4614) to the current codification (Subtitle 47, sections 14-4701 to 14-4714); corrected the minors protection to reflect that it covers all consumers known or believed to be under 18 rather than only ages 13-17; updated the CCPA comparison-table revenue threshold to its current inflation-adjusted $26.625 million; and repointed the Attorney General citation to its current live URL.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maryland Code, Commercial Law Article
§ 14-4707In forcecited in 5 of our articles
§14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data; (3) Process personal data in violation of State or federal laws that prohibit unlawful discrimination; (4) Process the personal data of a consumer for the purposes of targeted advertising if the controller knew or should have known that the consumer is under the age of 18 years; (5) Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years; (6) Discriminate against a consumer for exercising a consumer right contained in this subtitle, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; (7) Collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in or otherwise unlawfully makes unavailable the equal enjoyment of goods or…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Privacy Laws: MODPA Consumer Rights Guide (2026), Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026), MODPA Consumer Rights: Maryland Data Privacy
§ 14-4702In forcecited in 2 of our articles
§14–4702. This subtitle applies to a person that conducts business in the State or provides products or services that are targeted to residents of the State, and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of at least 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) Controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of its gross revenue from the sale of personal data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: MODPA Compliance Checklist: Maryland Privacy
§ 14-4713In force
§14–4713. (a) Except as provided in subsection (b) of this section, a violation of this subtitle is: (1) An unfair, abusive, or deceptive trade practice within the meaning of Title 13 of this article; and (2) Subject to the enforcement and penalty provisions contained in Title 13 of this article, except for § 13–408 of this article. (b) This section does not prevent a consumer from pursuing any other remedy provided by law.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
§ 13-410In forcecited in 4 of our articles
§13–410. (a) A merchant who engages in a violation of this title is subject to a fine not exceeding $10,000 for each violation. (b) A merchant who has been found to have engaged in a violation of this title and who subsequently repeats the same violation is subject to a fine not exceeding $25,000 for each subsequent violation. (c) The fines provided for in subsections (a) and (b) of this section are civil penalties and are recoverable by the State in a civil action or an administrative cease and desist action under § 13–403(a) and (b) of this subtitle or after an administrative hearing has been held under § 13–403(d)(3) and (4) of this subtitle. (d) The Consumer Protection Division shall consider the following in setting the amount of the penalty imposed in an administrative proceeding: (1) The severity of the violation for which the penalty is assessed; (2) The good faith of the violator; (3) Any history of prior violations; (4) Whether the amount of the penalty will achieve the desired deterrent purpose; and (5) Whether the issuance of a cease and desist order, including restitution, is insufficient for the protection of consumers.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Maryland HB 567 (Chapter 454, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
- Maryland SB 541 (Chapter 455, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4702: Applicability Thresholds(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4707: Controller Duties (Data Minimization, Sensitive Data, Minors)(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 14-4713: Enforcement (Maryland Consumer Protection Act)(mgaleg.maryland.gov).gov
- Maryland General Assembly: SB 541 (2024) Bill Detail(mgaleg.maryland.gov).gov
- Md. Code Ann., Com. Law section 13-410: Civil Penalty (Consumer Protection Act)(mgaleg.maryland.gov).gov
- Maryland Office of the Attorney General: Consumer Protection Division(oag.maryland.gov).gov