Maryland
Maryland Data Privacy Laws: MODPA Consumer Rights Guide (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 17 primary sources cited on this page. How we verify our legal content

Maryland's Online Data Privacy Act (MODPA), codified at Md. Code, Com. Law §§ 14-4701 to 14-4714 and effective October 1, 2025, governs how businesses collect and share personal data about Maryland residents. MODPA bans the sale of sensitive personal data entirely, requires data minimization regardless of consumer consent, and protects all consumers under 18 from data sales and targeted advertising.
Maryland has one of the strongest data privacy laws in the United States. The Maryland Online Data Privacy Act (MODPA), signed by Governor Wes Moore on May 9, 2024, and effective October 1, 2025, goes further than most state privacy laws in several important ways. It prohibits the sale of sensitive data entirely. It restricts data collection itself rather than relying on consent-based processing. And it extends protections to all consumers under 18, not just children under 13.
MODPA is codified as Subtitle 47 of the Maryland Commercial Law Article, Md. Code, Com. Law §§ 14-4701 to 14-4714 (Chapter 455 of the 2024 Maryland Laws, recompiled as Subtitle 47 in the 2025 Replacement Volume of the Annotated Code of Maryland). The bill passed the Maryland Senate 46-0 and the House of Delegates 103-33, with strong bipartisan support. Enforcement by the Maryland Attorney General began on April 1, 2026.
Maryland's privacy framework extends beyond MODPA. It also includes a data breach notification law, a genetic information privacy act, a medical records confidentiality statute, a children's design code, and federal overlay from HIPAA, COPPA, GLBA, and the TAKE IT DOWN Act. This guide covers the full framework as of August 2026, including MODPA's July 2026 amendment addressing immigration-related data sales and inferred sensitive data (Chapter 874, House Bill 711).
What Is the Maryland Online Data Privacy Act (MODPA)?
The MODPA is Maryland's comprehensive consumer data privacy law, codified at Md. Code, Com. Law §§ 14-4701 through 14-4714. It was introduced as Senate Bill 541 during the 2024 Regular Session by Senators Gile, Hester, Augustine, Feldman, Beidle, and Ellis. The companion bill in the House was HB 567.
The law regulates how data controllers and processors handle the personal data of Maryland residents. It establishes consumer rights, business obligations, and enforcement mechanisms that in several respects exceed the protections found in California, Virginia, Colorado, and other states with comprehensive privacy laws.
What makes MODPA stand out nationally is its approach to three key areas: data minimization, sensitive data, and children's privacy. Each of these areas sets a higher bar than comparable laws in other states.
Who Must Comply with MODPA?
MODPA applies to entities that conduct business in Maryland or produce products or services targeted to Maryland residents and meet one of two thresholds:

- Control or process the personal data of at least 35,000 Maryland consumers during a calendar year (excluding data processed solely for payment transactions), OR
- Control or process the personal data of at least 10,000 Maryland consumers AND derive more than 20% of gross revenue from the sale of personal data.
These thresholds are lower than those in most other states. Virginia, for comparison, uses a 100,000-consumer threshold. Maryland's lower bar means more businesses fall under the law's requirements.
Who Is Exempt from MODPA?
MODPA includes both entity-level and data-level exemptions.
Entity-Level Exemptions:
- Maryland state and local government agencies
- Registered national securities and futures associations
- Financial institutions regulated under the Gramm-Leach-Bliley Act (GLBA)
- Nonprofit organizations that exclusively serve law enforcement agencies or first responders in responding to catastrophic events
Data-Level Exemptions (exempt even when held by covered entities):
- Protected health information under HIPAA
- Data governed by the Gramm-Leach-Bliley Act
- Data regulated under the Fair Credit Reporting Act (FCRA)
- Data covered by the Driver's Privacy Protection Act
- Data subject to the Family Educational Rights and Privacy Act (FERPA)
- Data processed under the Farm Credit Act and Airline Deregulation Act
- Employee and contractor data processed in the employment context
Importantly, nonprofits are generally not exempt from MODPA. If a nonprofit meets the data processing thresholds and is not specifically excluded under the law enforcement or first responder exception, it must comply.
Consumer Rights Under MODPA
MODPA grants Maryland residents a comprehensive set of privacy rights. These rights allow consumers to understand and control how businesses collect, use, and share their personal data.

Right to Confirm and Access
Consumers have the right to confirm whether a controller is processing their personal data. If processing is occurring, the consumer can access that data and understand how it is being used.
Right to Correct
Consumers can request that a controller correct inaccuracies in their personal data. This right helps ensure that businesses maintain accurate records about consumers.
Right to Delete
Consumers may request deletion of personal data that a controller holds about them. This applies to data the consumer provided directly as well as data obtained from other sources.
Right to Data Portability
Consumers can obtain a copy of their personal data in a portable and readily usable format. This allows consumers to move their data to a different service provider.
Right to Opt Out
Consumers have the right to opt out of the processing of personal data for:
- Targeted advertising based on activities tracked across different businesses, websites, or applications
- Sale of personal data to third parties
- Profiling that produces legal or similarly significant effects
Right to Obtain a List of Third-Party Recipients
Consumers can request a list of the categories of third parties to whom a controller has disclosed their personal data. This transparency right helps consumers understand the full scope of data sharing.
Non-Discrimination
Businesses cannot discriminate against consumers who exercise their privacy rights. A business cannot deny goods or services, charge different prices, or provide a different level of quality because a consumer made a privacy request.
How to Exercise Your Rights
Controllers must provide mechanisms for consumers to submit requests. When a consumer submits a request, the controller must respond within 45 days. This period can be extended by an additional 45 days when reasonably necessary given the complexity of the request.
If a controller declines a request, the consumer may appeal the decision. If the appeal is denied, the consumer can file a complaint with the Maryland Attorney General's Consumer Protection Division. The AG's office accepts privacy complaints through its online consumer protection portal at oag.maryland.gov.
Universal Opt-Out Signals
MODPA addresses universal opt-out preference signals. Controllers may either provide a clear and conspicuous link on their website for exercising opt-out rights, or recognize an opt-out preference signal such as the Global Privacy Control (GPC). Controllers that already recognize opt-out signals approved by other states are considered compliant with Maryland's requirement.
Data Minimization: MODPA's Strictest Requirement
MODPA's data minimization standard is arguably the most significant feature of the law. It sets a higher bar than every other U.S. state privacy law and, in some respects, approaches the European Union's GDPR in strictness.
Under MODPA (Md. Code, Com. Law § 14-4707), controllers must limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer. This restriction applies regardless of whether the consumer has given consent.
This is a fundamental departure from how most state privacy laws work. In most states, businesses can collect data for any disclosed purpose as long as the consumer is informed. MODPA restricts the collection itself. Even if a consumer agrees to broader data collection, the business cannot collect more than what is reasonably necessary.
For sensitive personal data, the standard is even stricter. Controllers cannot process sensitive data unless it is strictly necessary to provide or maintain a product or service the consumer specifically requested. The word "strictly" raises the bar above the general "reasonably necessary" standard.
Controllers should be prepared to document their reasoning for data collection decisions. The Maryland Attorney General may request this documentation during investigations, and controllers must be able to explain why the data they collect meets the necessity standard.
Sensitive Data Protections: The Outright Sale Ban
MODPA takes a fundamentally different approach to sensitive data than other state privacy laws. Rather than allowing businesses to process sensitive data with consumer opt-in consent, MODPA prohibits the sale of sensitive personal data entirely, regardless of whether the consumer consents.

This is the strongest sensitive data protection in any U.S. state privacy law. In Virginia, Colorado, Connecticut, and other states, businesses can process and sell sensitive data as long as they obtain affirmative opt-in consent from the consumer. Maryland eliminates even that option.
What Qualifies as Sensitive Data Under MODPA?
MODPA defines sensitive personal data broadly at Md. Code, Com. Law § 14-4701. The following categories are classified as sensitive:
- Biometric data (sensitive regardless of whether it is used for identification purposes)
- Genetic data (sensitive regardless of use)
- Consumer health data, including any information about a person's health status, conditions, or treatment
- Precise geolocation data
- Data revealing race or ethnicity
- Data revealing religious beliefs
- Data revealing sexual orientation, sex life, or transgender/nonbinary status
- Data revealing citizenship or immigration status
- Data revealing national origin
- Personal data of a known child under 13
Several of these categories are broader than definitions used in other states. For example, most state laws only classify biometric data as sensitive when it is used for identification. MODPA classifies it as sensitive regardless of how it is used. Similarly, MODPA's definition of consumer health data covers any health "status," while most states limit the definition to diagnosed conditions.
Exceptions to the Sensitive Data Sale Ban
The prohibition on selling sensitive data has limited exceptions:
- Disclosures directed by the consumer to a specific third party
- Disclosures that are strictly necessary to provide a product or service the consumer requested
Outside of these narrow exceptions, the sale of sensitive data is prohibited under all circumstances.
2026 Amendment: Immigration-Related Data Sales and Inferred Sensitive Data
Effective July 1, 2026, Chapter 874 (House Bill 711) amended MODPA to add new protections tied to immigration enforcement. Under the amended § 14-4707, a controller may not sell a consumer's personal data if it knew or should have known the purchaser intends to use the data for immigration enforcement. A controller also may not knowingly sell personal data to a federal, state, or local governmental unit that engaged in or supported civil immigration enforcement, through personnel or material resources, within the preceding six months.
The amendment also narrowed MODPA's government-compliance safe harbor at § 14-4712. A controller or processor can no longer rely on that safe harbor to comply with a subpoena, investigation, or law enforcement cooperation request tied to immigration enforcement from a governmental unit with recent civil immigration enforcement involvement, unless presented with a valid court warrant that particularly describes the data sought.
The amendment also broadened the definition of sensitive data at § 14-4701. Sensitive data now includes data a controller infers from personal data, alone or combined with other data, to indicate a protected category such as race, religion, health status, sexual orientation, transgender or nonbinary status, national origin, citizenship or immigration status, genetic or biometric data, or status as a child. Businesses cannot treat inferred attributes as outside the sensitive-data sale ban simply because the data was not directly collected.
Children's Data Protections
MODPA provides some of the strongest children's data protections in any U.S. state privacy law. The protections extend to all consumers under 18, not just children under 13 as defined by the federal Children's Online Privacy Protection Act (COPPA).

Protections for Consumers Under 18
MODPA prohibits businesses from:
- Selling the personal data of any consumer the business knows or should reasonably know is under 18
- Using personal data for targeted advertising directed at any consumer the business knows or should reasonably know is under 18
These prohibitions apply regardless of consumer or parental consent. Unlike most state privacy laws that offer an opt-out or opt-in mechanism for minors' data, MODPA flatly bans these practices for anyone under 18.
The "Should Have Known" Standard
MODPA uses a "knew or should have known" standard for determining whether a consumer is a minor. This is significantly more protective than the "actual knowledge" standard used in most other states.
Under the "should have known" standard, a controller cannot simply ignore indicators that a user is under 18. If contextual signals, user behavior, or available information would lead a reasonable business to conclude a user is a minor, the protections apply. This effectively requires controllers to implement some form of age assurance or verification mechanism.
Children Under 13
Personal data of a known child under 13 is automatically classified as sensitive data under MODPA. This triggers the strictest data minimization standard ("strictly necessary") and the outright ban on data sales.
Parents and legal guardians may exercise data privacy rights on behalf of children under 13.
Business Obligations Under MODPA
Controllers subject to MODPA must meet several requirements beyond responding to consumer rights requests.
Privacy Notice Requirements
Controllers must provide consumers with a clear and accessible privacy notice that includes:
- The categories of personal data collected
- The purposes for processing personal data
- How consumers can exercise their privacy rights, including the appeal process
- The categories of personal data shared with third parties
- The categories of third parties that receive personal data
Data Protection Assessments
MODPA requires controllers to conduct and document data protection assessments for processing activities that present a heightened risk of harm to consumers. These assessments are required for:
- Processing personal data for targeted advertising
- Selling personal data
- Processing personal data for profiling
- Processing sensitive data
- Any processing that presents a heightened risk of harm
Maryland's requirement goes further than most states by explicitly requiring that assessments include an evaluation of each algorithm used in the processing activity. This algorithmic assessment requirement is unique among U.S. state privacy laws.
The Attorney General may request these assessments during investigations.
Controller-Processor Contracts
Processing must be governed by a written contract between the controller and processor. The contract must outline the instructions for processing, the nature and purpose of the processing, the type of data subject to processing, and the duration of the relationship.
Processors must assist controllers in meeting their obligations, including responding to consumer rights requests, ensuring security of data processing, and conducting data protection assessments.
Practical Compliance Checklist
Businesses subject to MODPA should work through the following steps:
- Determine applicability. Assess whether your data processing volume meets the 35,000-consumer or 10,000-consumer-plus-20%-revenue thresholds.
- Map your data. Identify all categories of personal data collected, the purpose for each collection, and any third parties who receive the data.
- Audit for sensitive data. Identify any sensitive data categories in your data inventory. Remove any sales pipelines for sensitive data entirely.
- Implement data minimization. Review each data collection decision against the "reasonably necessary and proportionate" standard. Document your reasoning.
- Update your privacy notice. Ensure it includes all required MODPA disclosures, including third-party recipient categories.
- Build a rights-response process. Set up a mechanism to receive consumer requests and a workflow to respond within 45 days.
- Conduct data protection assessments. Complete DPAs for all high-risk processing activities and document algorithm-level analysis where applicable.
- Execute controller-processor contracts. Ensure all data processors have signed MODPA-compliant data processing agreements.
- Add age signals to your compliance review. If your service could be accessed by minors, implement monitoring for the "should have known" standard.
- Recognize Global Privacy Control. Configure your website or app to honor opt-out preference signals.
Enforcement and Penalties
The Maryland Attorney General has exclusive enforcement authority over MODPA. The Consumer Protection Division of the Office of the Attorney General handles investigations and enforcement actions.

There is no private right of action. Consumers cannot sue businesses directly for MODPA violations. Instead, they must file complaints with the Attorney General's office.
Enforcement Timeline
MODPA became effective on October 1, 2025, but enforcement did not begin until April 1, 2026. This six-month grace period allowed businesses to implement compliance measures before facing potential enforcement action.
AG Resource Constraints and Enforcement Capacity
Attorney General Anthony Brown has publicly acknowledged staffing limitations. As of early 2026, his office had only one attorney dedicated to privacy enforcement, compared to dedicated teams of multiple attorneys and investigators in states like Connecticut, Delaware, and Oregon. Brown told legislators in February 2025 that "Maryland is slipping behind" on privacy enforcement without dedicated resources.
Brown has backed a proposed data broker tax (HB-1089) that would impose a 6% tax on data broker gross income beginning in the 2027 tax year, with projected revenues of $90-100+ million annually. The proposal would fund a dedicated privacy enforcement unit within the Consumer Protection Division to enforce MODPA, the Age-Appropriate Design Code Act, and related technology, AI, and cybersecurity laws.
As of May 2026, no formal MODPA enforcement actions have been publicly announced. The law entered its first full month of active enforcement in April 2026, and enforcement actions under new privacy laws typically emerge six to eighteen months after the enforcement start date as complaint investigations mature.
Cure Period
For an alleged violation that occurs on or before April 1, 2027, the Consumer Protection Division may issue a notice of violation under Md. Code, Com. Law § 14-4714 if it determines that a cure is possible. A controller or processor that receives a notice gets at least 60 days to cure the violation, and the Division may bring an enforcement action only if the violation is not cured within the time the Division specifies. The statute sets a floor, not a fixed 60-day window, and it does not require the business to file a written statement confirming the cure.
The cure period is not automatic. The Attorney General has discretion to determine whether a violation is curable, considering factors including:
- The number of violations
- The size and complexity of the controller or processor
- The nature and extent of the processing activities
- The likelihood of injury to the public
- The safety of persons or property
- Whether the alleged violation was likely caused by a human or technical error
- The extent to which the controller or processor has violated MODPA or similar laws in the past
The cure provision reaches only violations occurring on or before April 1, 2027. For violations after that date, the Attorney General can pursue enforcement immediately without offering an opportunity to cure.
Penalty Amounts
Under Md. Code, Com. Law § 14-4713, a MODPA violation is an unfair, abusive, or deceptive trade practice within the meaning of Title 13 of the Commercial Law Article and is subject to Title 13's enforcement and penalty provisions, except for § 13-408 (the Consumer Protection Act's private right of action). The fine amounts come from Md. Code, Com. Law § 13-410:
| Violation Type | Maximum Penalty | Notes |
|---|---|---|
| First violation | Up to $10,000 | Per violation, under § 13-410 |
| Repeat violation | Up to $25,000 | Per subsequent repeat of the same violation, under § 13-410 |
| Criminal penalties | Misdemeanor: fine up to $1,000, imprisonment up to 1 year, or both | Md. Code, Com. Law § 13-411(a) reaches any violation of Title 13 and requires no showing of willfulness |
These penalties are notably higher than the $7,500 per-violation cap in Virginia and many other states.
Maryland Data Breach Notification Law
Separate from MODPA, Maryland's data breach notification law under the Maryland Personal Information Protection Act (PIPA), codified at Md. Code, Com. Law § 14-3504, requires businesses to notify consumers and the Attorney General when personal information is compromised.
What Triggers Notification
Notification is required when there has been an unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. Good faith acquisitions by employees for business purposes are excluded from the definition of a breach.
A business must conduct a reasonable and prompt investigation after discovering a breach to determine whether personal information has been or will likely be misused.
Personal Information Covered
The law covers a consumer's first name or initial plus last name combined with any of the following:
- Social Security number
- Driver's license or state identification number
- Financial account number, credit card, or debit card number combined with any required security code
- Individual taxpayer identification number
- Passport number or other government-issued identification number
- Health information
- Biometric data (fingerprints, voice prints, retina or iris images)
- Online account credentials (username or email with password or security question answers)
Notification Timeline and Requirements
Businesses must notify affected consumers within 45 days of discovering the breach. The notification must include:
- A description of the categories of information compromised
- Contact information for the business, including a toll-free phone number
- Consumer reporting agency contact information
- Contact information for the Federal Trade Commission and the Maryland Attorney General
- Identity theft prevention and mitigation resources
Attorney General Notification
Before sending notification to consumers, a business must notify the Maryland Office of the Attorney General. This pre-notification requirement ensures the AG's office is aware of the breach before consumers receive notice.
Methods of Notice
Notice may be provided through:
- Written mail to the consumer's most recent address
- Telephone to the most recent phone number
- Email (if the consumer consented to electronic communications or the business primarily operates online)
- Substitute notice (email, website posting, and statewide media notification) when the business does not have sufficient contact information to notify individuals by mail, email, or phone. The current statute does not condition substitute notice on a dollar-cost or affected-individual-count threshold.
Security Requirements
PIPA also requires businesses that own or license personal information to implement and maintain reasonable security procedures and practices appropriate to the nature of the information and the size of the business.
Maryland Age-Appropriate Design Code Act
Maryland's Age-Appropriate Design Code Act (AADC), enacted as HB 603 in May 2024 and effective October 1, 2024, establishes design requirements for online products and services likely to be accessed by children and teens under 18.
Who Must Comply
The AADC applies to businesses that provide online services, products, or features "reasonably likely to be accessed by children." Unlike most age-related laws, the AADC does not require businesses to verify user ages. Instead, businesses must assess whether their service is likely to attract minors based on contextual factors.
Key Requirements
Covered businesses must:
- Complete a Data Protection Impact Assessment (DPIA) for any online product children are likely to use. The deadline for assessments on existing products was April 1, 2026.
- Configure privacy settings to their most protective defaults for child users
- Avoid collecting or sharing personal data not necessary for the service
- Refrain from using design features that could harm minors' physical or mental health
Penalties
Companies can face fines of up to $2,500 per child for each negligent violation and $7,500 per child for each intentional violation. As of May 2026, no legal challenges to the Maryland AADC have been filed, unlike California's similar law, which faced constitutional litigation.
Maryland Genetic Information Privacy Act
Maryland's Genetic Information Privacy Act (GIPA), codified at Md. Code, Com. Law §§ 14-4401 through 14-4408 (effective October 1, 2022), governs direct-to-consumer genetic testing companies and their handling of consumer genetic data.
GIPA requires direct-to-consumer genetic testing companies to:
- Obtain separate, written express consent before collecting, using, or disclosing a consumer's genetic data for any purpose
- Provide clear, complete information about data policies before obtaining consent
- Prohibit disclosure of genetic data to health, life, disability, or long-term care insurers without written consumer consent (Md. Code, Com. Law § 14-4405)
- Implement reasonable security procedures to protect genetic data
- Allow consumers to request deletion of their genetic data and biological samples
The term "direct-to-consumer genetic testing company" covers any entity that offers genetic testing products or services directly to consumers or that collects, uses, or analyzes genetic data from such products. GIPA enforcement is handled by the Maryland Attorney General.
Maryland Confidentiality of Medical Records Act
Maryland's Confidentiality of Medical Records Act, codified at Md. Code, Health-Gen. §§ 4-301 through 4-309, requires health care providers to keep patient medical records confidential. Under § 4-302, providers may only disclose records as permitted by Maryland law or other applicable law.
Permitted disclosures include those authorized by the patient, disclosures required for treatment or payment, public health reporting, and disclosures to law enforcement with proper process. The law operates alongside HIPAA: providers covered by HIPAA must meet both federal and Maryland-specific requirements.
Federal Overlay: Laws That Apply Alongside MODPA
Several federal laws apply to Maryland residents and businesses independently of MODPA.
TAKE IT DOWN Act (Pub. L. 119-12)
The TAKE IT DOWN Act, signed by President Trump on May 19, 2025, addresses nonconsensual intimate imagery (NCII), including AI-generated deepfakes. The law's criminal prohibitions took effect immediately upon signing. Platform takedown obligations became enforceable by the FTC on May 19, 2026.
Covered platforms must establish a process allowing victims to request removal of NCII, and must remove the content and all known identical copies within 48 hours of a valid request. Non-compliant platforms face FTC enforcement with civil penalties of up to $53,088 per violation. The FTC sent compliance letters to major platforms including Alphabet, Amazon, Apple, Meta, Microsoft, Snapchat, TikTok, and X in May 2026.
HIPAA
The Health Insurance Portability and Accountability Act governs covered entities (health plans, health care clearinghouses, and health care providers) and their business associates. HIPAA-regulated protected health information (PHI) is generally exempt from MODPA's scope, but businesses handling both HIPAA data and non-HIPAA consumer health data must comply with MODPA for the non-exempt portion.
COPPA
The Children's Online Privacy Protection Act governs collection of personal information from children under 13. MODPA's under-18 protections extend significantly beyond COPPA's scope. Businesses collecting data from users under 13 must comply with both COPPA's parental consent requirements and MODPA's prohibition on selling minors' data.
GLBA
The Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information. Financial institutions subject to GLBA are entity-exempt under MODPA, but only for data that falls within GLBA's scope. Data outside the GLBA-regulated relationship remains subject to MODPA.
FCRA
The Fair Credit Reporting Act governs consumer reporting agencies and the use of consumer reports. Data regulated under FCRA is data-level exempt under MODPA. Businesses that receive credit data subject to FCRA and also handle other consumer data must apply MODPA to the non-FCRA portion.
FTC Act Section 5
The FTC's unfair or deceptive acts or practices authority under 15 U.S.C. § 45 applies to all businesses in interstate commerce. The FTC has brought enforcement actions against companies for deceptive privacy statements, inadequate data security, and failure to honor opt-out requests, all of which remain relevant for Maryland businesses.
APRA Status
The American Privacy Rights Act (APRA), a proposed federal comprehensive privacy law, passed committee in 2024 but did not receive a full congressional vote. APRA 2.0 was introduced in 2025. As of May 2026, APRA has not become law. Maryland businesses cannot rely on a forthcoming federal law to reduce MODPA compliance obligations.
How MODPA Compares to Other State Privacy Laws
Maryland's MODPA stands apart from other comprehensive state privacy laws in several important ways:
| Feature | Maryland (MODPA) | Virginia (VCDPA) | California (CCPA/CPRA) | Colorado (CPA) |
|---|---|---|---|---|
| Effective date | Oct. 1, 2025 | Jan. 1, 2023 | Jan. 1, 2020 | July 1, 2023 |
| Consumer threshold | 35,000 | 100,000 | Revenue-based | 100,000 |
| Sensitive data sale | Banned entirely | Opt-in consent | Opt-in consent | Opt-in consent |
| Data minimization | Mandatory (regardless of consent) | Adequate and relevant | Reasonably necessary | Adequate, relevant, limited |
| Minor protection age | Under 18 | Under 13 (COPPA) | Under 16 | Under 13 |
| Minor standard | "Should have known" | Actual knowledge | Actual knowledge | Actual knowledge |
| Penalty (per violation) | $10,000 / $25,000 repeat | $7,500 | $2,500 / $7,500 intentional | $20,000 |
| Cure period | At least 60 days, at AG discretion (violations on or before April 1, 2027) | 30 days | None | 60 days (expired Jan. 2025) |
| Private right of action | No | No | Yes (data breaches) | No |
| Nonprofits covered | Generally yes | No | Yes | No |
| Algorithmic assessment | Required | Not specified | Not specified | Not specified |
More Maryland Laws
Explore additional Maryland legal guides on Recording Law:
- Maryland Recording Laws
- California Data Privacy Laws
- Virginia Data Privacy Laws
- Colorado Data Privacy Laws
- Connecticut Data Privacy Laws
- Texas Data Privacy Laws
- Delaware Data Privacy Laws
- View All State Data Privacy Laws
- Maryland AI Meeting Recording Laws
- Maryland Alimony Laws
- Maryland At-Will Employment Laws
- Maryland Car Accident Laws
- Maryland Car Seat Laws
- Maryland Child Custody Laws
- Maryland Child Support Laws
- Maryland Common Law Marriage Laws
- Maryland Deepfake Laws
- Maryland Divorce Laws
- Maryland Dog Bite Laws
- Maryland Emancipation Laws
- Maryland Expungement Laws
- Maryland Hit and Run Laws
- Maryland Landlord-Tenant Laws
- Maryland Lemon Laws
In-depth guides
- What Is the MODPA? Maryland Online Data Privacy Act
- MODPA Consumer Rights: Your Data Privacy Rights
- MODPA Compliance Checklist for Businesses (2026)
More Maryland Laws
Updates
Corrected the enforcement section against the statutory text: MODPA penalties are now cited to Com. Law §§ 14-4713 and 13-410 rather than the Consumer Protection Act definitions section, the cure provision now reflects the at-least-60-day notice and the seven statutory factors in § 14-4714 (removing a written-statement requirement Maryland does not impose), and the criminal-penalty row now states the actual misdemeanor exposure under § 13-411(a), which has no willfulness element.
Updated MODPA's statutory citations to reflect its recodification from Subtitle 46 (§§ 14-4601-14-4614) to Subtitle 47 (§§ 14-4701-14-4714), corrected the Genetic Information Privacy Act's citation range to §§ 14-4401-14-4408, and added coverage of the July 1, 2026 MODPA amendment (Chapter 874, House Bill 711) that bars selling personal data for immigration enforcement and expands the definition of sensitive data to include data a controller infers to indicate a protected category.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the trigger for substitute notice under Maryland's breach notification law (Com. Law 14-3504). The live statute text ties substitute notice solely to a business lacking sufficient contact information, not to a $100,000 cost threshold or 175,000-individual count as previously stated.
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maryland Code, Commercial Law Article
§ 14-4707In forcecited in 5 of our articles
§14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data; (3) Process personal data in violation of State or federal laws that prohibit unlawful discrimination; (4) Process the personal data of a consumer for the purposes of targeted advertising if the controller knew or should have known that the consumer is under the age of 18 years; (5) Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years; (6) Discriminate against a consumer for exercising a consumer right contained in this subtitle, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; (7) Collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in or otherwise unlawfully makes unavailable the equal enjoyment of goods or…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Biometric Privacy Laws: Collection, Consent & Penalties (2026), What Is MODPA? Maryland Online Data Privacy Act, MODPA Consumer Rights: Maryland Data Privacy
§ 14-3504In forcecited in 4 of our articles
§14–3504. (a) In this section: (1) “Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business; and (2) “Breach of the security of a system” does not include the good faith acquisition of personal information by an employee or agent of a business for the purposes of the business, provided that the personal information is not used or subject to further unauthorized disclosure. (b) (1) A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in the State, when it discovers or is notified that it incurred a breach of the security of a system, shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information of the individual has been or will be misused as a result of the breach.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Also relied on in: Maryland Data Breach Notification Laws: Reporting Rules & Timelines (2026), Maryland Identity Theft Laws
Maryland Code, Health - General Article
§ 4-302In force
§4–302. (a) A health care provider shall: (1) Keep the medical record of a patient or recipient confidential; and (2) Disclose the medical record only: (i) As provided by this subtitle; or (ii) As otherwise provided by law. (b) The provisions of this subtitle do not apply to information: (1) Not kept in the medical record of a patient or recipient that is related to the administration of a health care facility, including: (i) Risk management; (ii) Quality assurance; and (iii) Any activities of a medical or dental review committee that are confidential under the provisions of § 1–401 and Title 4, Subtitle 5 of the Health Occupations Article and any activities of a pharmacy review committee; (2) Governed by the federal confidentiality of alcohol and drug abuse patient records regulations, 42 C.F.R. Part 2 and the provisions of § 8–601(c) of this article; or (3) Governed by the developmental disability confidentiality provisions in §§ 7–1008 through 7–1011 of this article.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Fearnow v. Chesapeake & Potomac Telephone Co. (Court of Special Appeals of Maryland 1995, 104 Md. App. 1)“…iability for actual damages, liable for punitive damages. Md.Code Ann., Health-Gen. § 4-302(d)(2) (1982) (codified as amended at Md…”
- Frances Darcangelo v. Verizon Communications, Incorporated Core, Incorporated (Court of Appeals for the Fourth Circuit 2002, 292 F.3d 181)“…tions of Maryland’s medical record confidentiality statute, Md.Code Ann., Health-General §§ 4-302 and 4-307, and the state’s unfair and d…”
- Dillard v. American Association of State Highway and Transportation Officials (AASHTO) (District Court, D. Maryland 2024)“…by [Section 4-302]; or (ii) As otherwise provided by law.” Md. Code, Health-Gen § 4-302(a). The purpose of this Act was “to pr…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
United States Code Title 15
§ 45Unfair methods of competition unlawful; prevention by CommissionIn forcecited in 14 of our articles
Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful. The Commission is hereby empowered and directed to prevent persons, partnerships, or corporations, except banks, savings and loan institutions described in section 57a(f)(3) of this title, Federal credit unions described in section 57a(f)(4) of this title, common carriers subject to the Acts to regulate commerce, air carriers and foreign air carriers subject to part A of subtitle VII of title 49, and persons, partnerships, or corporations insofar as they are subject to the Packers and Stockyards Act, 1921, as amended [7 U.S.C. 181 et seq.], except as provided in section 406(b) of said Act [7 U.S.C. 227(b) ], from using unfair methods of competition in or affecting commerce and unfair or deceptive acts or practices in or affecting commerce.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 3,207 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States v. Philadelphia National Bank (1963) applied the bank exclusion in 15 U.S.C. 45(a)(6) when construing Clayton Act section 7, and Copperweld Corp. v. Independence Tube Corp. (1984) noted that a corporation and its wholly owned subsidiaries remain subject to section 5 of the FTC Act.
Opinions citing this section in our collection:
- Morales v. Trans World Airlines, Inc. (Supreme Court of the United States 1992, 504 U.S. 374)“…etition in commerce.” 38 Stat. 719 , codified as amended, 15 U. S. C. § 45 (a)(1). That type of prohibition is ent…”
- Copperweld Corp. v. Independence Tube Corp. (Supreme Court of the United States 1984, 467 U.S. 752)“…d § 5 of the Federal Trade Commission Act, 38 Stat. 719 , 15 U. S. C. §45 . That these statutes are adequate to c…”
- Bowen v. Massachusetts (Supreme Court of the United States 1988, 487 U.S. 879)“…n required to exhaust before coming into court. See 15 U. S. C. §45 (c) (1940 ed.); 29 U. S. C. § 160 (f)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: FTC Fines Travel App Hopper $35 Million Over Hidden "Junk Fees", FTC Finalizes Order Against Illuminate Over Student Data Breach (2026), How the FTC's Nationwide Noncompete Ban Was Struck Down, and What It Means for At-Will Workers
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Maryland SB 541 - Online Data Privacy Act (MODPA) Legislation(mgaleg.maryland.gov).gov
- Maryland SB 541 - Enrolled Bill Text (Chapter 455)(mgaleg.maryland.gov).gov
- Maryland HB 567 - Cross-Filed Companion Bill(mgaleg.maryland.gov).gov
- Maryland Attorney General - Data Privacy Information(oag.maryland.gov).gov
- Maryland Data Breach Notification Law - Md. Code, Com. Law 14-3504(mgaleg.maryland.gov).gov
- Maryland AG - Security Breach Notices(oag.maryland.gov).gov
- Maryland AG - PIPA Business Compliance Guidelines(oag.maryland.gov).gov
- FTC - Gramm-Leach-Bliley Act(ftc.gov).gov
- HHS - HIPAA(hhs.gov).gov
- FTC - COPPA Rule(ftc.gov).gov
- U.S. Dept. of Education - FERPA(www2.ed.gov).gov
- Maryland HB 603 - Age-Appropriate Design Code Act(mgaleg.maryland.gov).gov
- Maryland Genetic Information Privacy Act - HB 866 (2022)(mgaleg.maryland.gov).gov
- Maryland Confidentiality of Medical Records Act - Md. Code, Health-Gen. 4-302(health.maryland.gov).gov
- FTC - TAKE IT DOWN Act Enforcement Begins(ftc.gov).gov
- FTC Consumer Alert - TAKE IT DOWN Act(consumer.ftc.gov).gov
- FTC - Fair Credit Reporting Act(ftc.gov).gov
- EPIC - Maryland Online Data Privacy Act Comes Into Effect(epic.org)
- Md. Code, Com. Law § 14-4713 - MODPA Enforcement (violation is an unfair, abusive, or deceptive trade practice under Title 13)(mgaleg.maryland.gov)
- Md. Code, Com. Law § 14-4714 - MODPA Notice of Violation and Right to Cure(mgaleg.maryland.gov)
- Md. Code, Com. Law § 13-410 - Consumer Protection Act Civil Penalties ($10,000 / $25,000)(mgaleg.maryland.gov)
- Md. Code, Com. Law § 13-411 - Consumer Protection Act Criminal Penalties(mgaleg.maryland.gov)