Skip to content
Privacy Regulations

Maryland Online Data Privacy Act (MODPA)

Overview

The Maryland Online Data Privacy Act (MODPA) is a comprehensive data privacy law that enhances data protection rights for Maryland residents while establishing clear compliance obligations for businesses. Signed into law on May 9, 2024, MODPA takes effect on October 1, 2025.

Maryland’s privacy law is considered one of the strongest consumer privacy laws in the U.S., closely resembling California’s CPRA while introducing unique requirements for data minimization and opt-in consent for sensitive data processing.

Who Must Comply?

MODPA applies to businesses that operate in Maryland or target Maryland residents and meet one of the following criteria:

βœ” Process personal data of at least 35,000 Maryland consumers annually
βœ” Process personal data of at least 10,000 Maryland consumers and derive over 20% of gross revenue from selling personal data

Exemptions:

The law does not apply to:
🚫 Government agencies
🚫 Nonprofits
🚫 Financial institutions subject to GLBA
🚫 HIPAA-covered entities
🚫 Higher education institutions

Key Consumer Rights Under MODPA

βœ” Right to Access – Consumers can request a copy of their personal data.
βœ” Right to Correct – Consumers can request corrections to inaccurate personal data.
βœ” Right to Delete – Consumers can request the deletion of personal data.
βœ” Right to Data Portability – Consumers can receive their data in a portable format.
βœ” Right to Opt-Out – Consumers can opt out of:

  • Targeted advertising
  • Sale of personal data
  • Automated profiling that affects legal or financial decisions

πŸ“Œ Universal Opt-Out Mechanism Required (2026) – Businesses must recognize Global Privacy Control (GPC) signals starting in 2026.

Business Compliance Requirements

βœ” Opt-In Consent for Sensitive Data – Businesses must obtain explicit consumer consent before processing:
πŸ“Œ Racial/ethnic origin
πŸ“Œ Religious beliefs
πŸ“Œ Biometric data
πŸ“Œ Health conditions
πŸ“Œ Children’s data
βœ” Transparency & Privacy Notices – Companies must provide clear privacy policies detailing data collection and usage.
βœ” Data Protection & Security – Businesses must implement reasonable security safeguards to protect consumer data.
βœ” Data Minimization Rules – Businesses must limit data collection to what is strictly necessary for their purpose.
βœ” Data Protection Assessments (DPA) – Businesses must conduct risk assessments for:
πŸ“Œ Targeted advertising
πŸ“Œ Data sales
πŸ“Œ AI-driven decision-making

Real-World Enforcement Cases

The Maryland Attorney General’s Office enforces MODPA, with penalties of up to $10,000 per violation.

πŸ“Œ Cure Period Ends in 2026 – Until January 1, 2026, businesses have 60 days to fix violations before penalties apply.

Since MODPA does not take effect until October 1, 2025, major enforcement cases have not yet occurred, but businesses failing to provide opt-out mechanisms or lacking proper security protections are expected to face early enforcement actions.

πŸ“Œ Comparison with Other State Privacy Laws
The Maryland MODPA is one of the strongest privacy laws in the U.S. due to:
βœ… Lower Applicability Threshold (35,000 consumers) – More businesses must comply than in Virginia (100,000 consumers).
βœ… Universal Opt-Out Mechanism Required (2026) – Businesses must honor automated privacy requests.
βœ… Strict Data Minimization Rules – Companies must collect only essential data, unlike many other state laws.

Future of MODPA Regulation

πŸ“Œ Stronger enforcement expected in 2026, particularly for AI-driven profiling.
πŸ“Œ Potential expansion of consumer rights in future amendments.
πŸ“Œ Possible updates to align with federal privacy laws if enacted.

Maryland’s MODPA sets a new standard for consumer privacy, with strict enforcement, universal opt-out requirements, and broad applicability.

NEW GEN AI

Get answers to even the most complex questions about your data and explore the complexities of your data landscape using Generative AI chat.