Skip to main content
The state of ai impact assessment
MODPA Compliance for Multi-State OperationsLaws and Regulations
5 min readFor Privacy Officers

MODPA Compliance for Multi-State Operations

Scope

This guide focuses on the Maryland Online Data Privacy Act (MODPA) compliance for businesses already operating under privacy frameworks in states like California, Virginia, Colorado, and Connecticut. It highlights MODPA's unique provisions: the data minimization cap and the sensitive-data sale ban.

Effective October 1, 2025, with enforcement starting April 1, 2026, MODPA applies to businesses handling data of 35,000 or more Maryland consumers annually, or 10,000 consumers when data sales exceed 20% of gross revenue.

Key Concepts

Data Minimization Under § 14-4707
You can only collect personal data that's necessary and proportionate to deliver the specific product or service requested by the consumer. Consent doesn't allow for additional data collection. If the data isn't needed for the service, you can't collect it.

Sensitive Data Sale Ban
MODPA prohibits the sale of sensitive data without exception. This includes race, religious beliefs, health data, sex life, sexual orientation, transgender or nonbinary status, national origin, citizenship status, genetic and biometric data, precise location, and any data of a child.

Controller vs. Processor
Controllers determine why and how data is used. Processors handle data based on another entity's instructions. Most organizations act as controllers for their own customer data and as processors when handling client data.

Requirements Breakdown

Collection Limits (§ 14-4707)

MODPA limits data collection to what's necessary for the requested service. This applies at two stages:

  1. Initial collection, Only gather data required for the service.
  2. Subsequent use, Don't repurpose collected data for unrelated services without new consent.

Example: A fitness app collects location data to map running routes. This data can't be used later for Behavioural Advertising without user consent.

Sensitive Data Rules (§ 14-4701, § 14-4704)

You cannot sell sensitive data for money or other valuable consideration. Data exchanges count as sales.

Additional restrictions for consumer health data include:

  • Access limited to employees or contractors under confidentiality duties
  • Processors must have written contracts
  • Geofencing within 1,750 feet of mental health or reproductive health facilities is banned for tracking, data collection, or targeted advertising

Privacy Notice Requirements

Your notice must include:

  • Categories of personal data collected, including sensitive data
  • Processing purposes
  • Third-party recipients with enough detail to understand their role
  • How consumers can exercise rights, appeal decisions, and withdraw consent
  • A working email or online contact method

Universal Opt-Out Signals

You must honor Global Privacy Control and similar browser-based opt-out signals for targeted advertising and data sales. Treat any opt-out preference from a Maryland resident's browser as valid automatically.

Data Protection Assessments

Required before:

  • Targeted advertising
  • Selling personal data
  • Processing sensitive data
  • Profiling with legal or significant effects

MODPA requires assessment of each algorithm, not just the program generally. The Attorney General can request assessments during investigations and use them as evidence.

Implementation Guidance

Step 1: Map Your Data Flows Against the Minimization Standard

Audit data collection at each customer interaction. Document:

  • The specific service or feature enabled by each data point
  • Whether the service was explicitly requested by the consumer
  • Whether the service could be delivered without the data

If a data point isn't directly tied to a requested service, you're over-collecting under MODPA.

Step 2: Identify Sensitive Data Exposure

Review your data inventory for the nine sensitive categories. Focus on:

  • Biometric data used for identification (faceprints, voiceprints)
  • Precise location data (GPS coordinates, not city-level)
  • Health status indicators, broadly defined by Maryland

If you're selling or exchanging any of these categories, stop. MODPA offers no consent workaround.

Step 3: Update Processor Contracts

Ensure every vendor processing Maryland consumer data has a contract covering:

  • Processing instructions
  • Security measures
  • Deletion procedures
  • Subcontractor management

This mirrors other state laws, so if your Data Processing Agreements already cover CCPA or VCDPA, you're mostly compliant.

Step 4: Configure GPC Response

If you haven't implemented Global Privacy Control, you're non-compliant in Maryland, California, Colorado, and Connecticut. Your CMP or tag manager should:

  • Detect the GPC signal in the request header
  • Suppress targeted advertising and data sale scripts automatically
  • Log the opt-out for audit purposes

Step 5: Review Marketing Geofencing

If you use location-based advertising, audit any geofences within 1,750 feet of mental health or reproductive/sexual health facilities. Maryland prohibits using these zones to track consumers, collect health data, or serve related ads.

Common Pitfalls

Assuming Consent Fixes Over-Collection
Under Virginia or Colorado law, a robust privacy notice and opt-out mechanism might suffice. MODPA doesn't allow consent to authorize collection beyond what's necessary for the service.

Treating "Sensitive Data" as a Checkbox
Other states may allow selling sensitive data with opt-in consent. Maryland doesn't. If your revenue model depends on selling location data, biometrics, or health indicators, you'll need a different approach for Maryland residents.

Overlooking the 35,000 Threshold
California's 100,000-consumer threshold means many mid-sized businesses aren't affected. Maryland's 35,000 threshold includes organizations that haven't dealt with state privacy law before.

Skipping Algorithm-Level Assessments
Most state laws require program-level assessments. MODPA requires assessment of each algorithm. If you use multiple recommendation engines or scoring models, each needs its own risk review.

Ignoring the Enforcement Timeline
MODPA took effect October 1, 2025. The Attorney General began enforcement April 1, 2026. A limited grace period for curing violations ends April 1, 2027. After that, first violations have no cure period.

Quick Reference Table

Requirement MODPA Rule Comparison to Other States
Applicability threshold 35,000 consumers or 10,000 + 20% revenue from sales CA/VA/CT: 100,000 consumers
Data minimization Collection capped at service necessity No other state caps collection
Sensitive data sales Banned outright Other states allow with opt-in consent
GPC enforcement Required Also required in CA, CO, CT
Assessment scope Each algorithm Most states: program-level
Health facility geofencing Prohibited within 1,750 feet Unique to Maryland
Rights request timeline 45 days, extendable to 90 Standard across most states
Appeal timeline 60 days Standard across most states
Private right of action No (AG enforcement only) Matches most states except CA
Enforcement start April 1, 2026 N/A
Cure period end April 1, 2027 N/A

Maryland's approach indicates where U.S. privacy law might be heading. If you're building a compliance program for multiple states, design it to meet MODPA's standards. This keeps you ahead of legislative changes and minimizes future adjustments.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like