EnglishEspañol
Maryland flag

Maryland

What Is MODPA? Maryland Online Data Privacy Act

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

What Is MODPA? Maryland Online Data Privacy Act

Frequently Asked Questions

What is MODPA?

MODPA, the Maryland Online Data Privacy Act, is Maryland's comprehensive consumer data privacy law codified at Md. Code Ann., Com. Law Title 14, Subtitle 47 (sections 14-4701 to 14-4714). It was enacted as SB 541 and HB 567 in 2024, signed by Governor Wes Moore on May 9, 2024, and took effect October 1, 2025. As of 2026 it is widely viewed as the strictest comprehensive state privacy law in the United States.

When did MODPA take effect?

MODPA took effect October 1, 2025. The Act also provides that the limitations and exemptions section, section 14-4712, applies only prospectively and has no application to processing activities before April 1, 2026. A discretionary cure period under section 14-4714 applies to violations occurring on or before April 1, 2027.

Why is MODPA called the strictest state privacy law?

Three features set MODPA apart. Section 14-4707(B) imposes hard data minimization, limiting collection to what is reasonably necessary to the specific service the consumer requested, and consent cannot expand it. Section 14-4707(A) allows sensitive data processing only where it is strictly necessary to the specific product or service the consumer requested, with no consent alternative. And section 14-4707(A) bans selling sensitive data outright, with no consent exception, which no other state does.

What are MODPA's coverage thresholds?

Under section 14-4702, MODPA covers a person that does business in Maryland or targets Maryland residents and, during the prior calendar year, controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction), or at least 10,000 consumers while deriving more than 20 percent of gross revenue from the sale of personal data. There is no dollar-revenue floor.

Does MODPA ban selling sensitive data?

Yes. Section 14-4707(A) provides that a controller may not sell sensitive data, with no consent carve-out. This is one of MODPA's most distinctive features. Other states generally let consumers opt out of sensitive data sales or require opt-in, but Maryland removes the option entirely.

What counts as sensitive data under MODPA?

Under section 14-4701, sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, and citizenship or immigration status, plus genetic or biometric data, the personal data of a known child, and precise geolocation data. Processing it is allowed under section 14-4707(A) only where strictly necessary to the specific product or service the consumer requested; consent does not unlock it.

How does MODPA protect minors?

Under section 14-4707(A), where a controller knew or should have known that a consumer is under 18, it may not process that consumer's data for targeted advertising and may not sell that consumer's data at all, with no consent exception. The knew-or-should-have-known standard is broader than an actual-knowledge test and covers every consumer under 18, with no 13-year floor.

Who enforces MODPA and what are the penalties?

The Consumer Protection Division of the Maryland Office of the Attorney General enforces MODPA under section 14-4713. A violation is an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act, carrying civil penalties up to $10,000 per violation and up to $25,000 for repeat violations under section 13-410. There is no private right of action, and any cure period is discretionary under section 14-4714.

Updates

Corrected the page's description of MODPA's sensitive-data rule (strict necessity, not strict necessity plus consent), stated the under-18 data sale ban as absolute, replaced a provision that was struck from SB 541 before enactment with the enacted section 14-4707(a)(8), and clarified that honoring a universal opt-out signal is one of two optional compliance methods rather than a standalone requirement.

Updated every MODPA statute citation on this page from Maryland's old codification (Com. Law Subtitle 46, sections 14-4601 to 14-4614) to the current codification (Subtitle 47, sections 14-4701 to 14-4714); corrected the minors protection to reflect that it covers all consumers known or believed to be under 18 rather than only ages 13-17; updated the CCPA comparison-table revenue threshold to its current inflation-adjusted $26.625 million; and repointed the Attorney General citation to its current live URL.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Maryland HB 567 (Chapter 454, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
  2. Maryland SB 541 (Chapter 455, 2024): Maryland Online Data Privacy Act (Enacted Text)(mgaleg.maryland.gov).gov
  3. Md. Code Ann., Com. Law section 14-4702: Applicability Thresholds(mgaleg.maryland.gov).gov
  4. Md. Code Ann., Com. Law section 14-4707: Controller Duties (Data Minimization, Sensitive Data, Minors)(mgaleg.maryland.gov).gov
  5. Md. Code Ann., Com. Law section 14-4713: Enforcement (Maryland Consumer Protection Act)(mgaleg.maryland.gov).gov
  6. Maryland General Assembly: SB 541 (2024) Bill Detail(mgaleg.maryland.gov).gov
  7. Md. Code Ann., Com. Law section 13-410: Civil Penalty (Consumer Protection Act)(mgaleg.maryland.gov).gov
  8. Maryland Office of the Attorney General: Consumer Protection Division(oag.maryland.gov).gov
Share: