Scope
This guide focuses on the Maryland Online Data Privacy Act (MODPA) compliance for businesses already operating under privacy frameworks in states like California, Virginia, Colorado, and Connecticut. It highlights MODPA's unique provisions: the data minimization cap and the sensitive-data sale ban.
Effective October 1, 2025, with enforcement starting April 1, 2026, MODPA applies to businesses handling data of 35,000 or more Maryland consumers annually, or 10,000 consumers when data sales exceed 20% of gross revenue.
Key Concepts
Data Minimization Under § 14-4707
You can only collect personal data that's necessary and proportionate to deliver the specific product or service requested by the consumer. Consent doesn't allow for additional data collection. If the data isn't needed for the service, you can't collect it.
Sensitive Data Sale Ban
MODPA prohibits the sale of sensitive data without exception. This includes race, religious beliefs, health data, sex life, sexual orientation, transgender or nonbinary status, national origin, citizenship status, genetic and biometric data, precise location, and any data of a child.
Controller vs. Processor
Controllers determine why and how data is used. Processors handle data based on another entity's instructions. Most organizations act as controllers for their own customer data and as processors when handling client data.
Requirements Breakdown
Collection Limits (§ 14-4707)
MODPA limits data collection to what's necessary for the requested service. This applies at two stages:
- Initial collection, Only gather data required for the service.
- Subsequent use, Don't repurpose collected data for unrelated services without new consent.
Example: A fitness app collects location data to map running routes. This data can't be used later for Behavioural Advertising without user consent.
Sensitive Data Rules (§ 14-4701, § 14-4704)
You cannot sell sensitive data for money or other valuable consideration. Data exchanges count as sales.
Additional restrictions for consumer health data include:
- Access limited to employees or contractors under confidentiality duties
- Processors must have written contracts
- Geofencing within 1,750 feet of mental health or reproductive health facilities is banned for tracking, data collection, or targeted advertising
Privacy Notice Requirements
Your notice must include:
- Categories of personal data collected, including sensitive data
- Processing purposes
- Third-party recipients with enough detail to understand their role
- How consumers can exercise rights, appeal decisions, and withdraw consent
- A working email or online contact method
Universal Opt-Out Signals
You must honor Global Privacy Control and similar browser-based opt-out signals for targeted advertising and data sales. Treat any opt-out preference from a Maryland resident's browser as valid automatically.
Data Protection Assessments
Required before:
- Targeted advertising
- Selling personal data
- Processing sensitive data
- Profiling with legal or significant effects
MODPA requires assessment of each algorithm, not just the program generally. The Attorney General can request assessments during investigations and use them as evidence.
Implementation Guidance
Step 1: Map Your Data Flows Against the Minimization Standard
Audit data collection at each customer interaction. Document:
- The specific service or feature enabled by each data point
- Whether the service was explicitly requested by the consumer
- Whether the service could be delivered without the data
If a data point isn't directly tied to a requested service, you're over-collecting under MODPA.
Step 2: Identify Sensitive Data Exposure
Review your data inventory for the nine sensitive categories. Focus on:
- Biometric data used for identification (faceprints, voiceprints)
- Precise location data (GPS coordinates, not city-level)
- Health status indicators, broadly defined by Maryland
If you're selling or exchanging any of these categories, stop. MODPA offers no consent workaround.
Step 3: Update Processor Contracts
Ensure every vendor processing Maryland consumer data has a contract covering:
- Processing instructions
- Security measures
- Deletion procedures
- Subcontractor management
This mirrors other state laws, so if your Data Processing Agreements already cover CCPA or VCDPA, you're mostly compliant.
Step 4: Configure GPC Response
If you haven't implemented Global Privacy Control, you're non-compliant in Maryland, California, Colorado, and Connecticut. Your CMP or tag manager should:
- Detect the GPC signal in the request header
- Suppress targeted advertising and data sale scripts automatically
- Log the opt-out for audit purposes
Step 5: Review Marketing Geofencing
If you use location-based advertising, audit any geofences within 1,750 feet of mental health or reproductive/sexual health facilities. Maryland prohibits using these zones to track consumers, collect health data, or serve related ads.
Common Pitfalls
Assuming Consent Fixes Over-Collection
Under Virginia or Colorado law, a robust privacy notice and opt-out mechanism might suffice. MODPA doesn't allow consent to authorize collection beyond what's necessary for the service.
Treating "Sensitive Data" as a Checkbox
Other states may allow selling sensitive data with opt-in consent. Maryland doesn't. If your revenue model depends on selling location data, biometrics, or health indicators, you'll need a different approach for Maryland residents.
Overlooking the 35,000 Threshold
California's 100,000-consumer threshold means many mid-sized businesses aren't affected. Maryland's 35,000 threshold includes organizations that haven't dealt with state privacy law before.
Skipping Algorithm-Level Assessments
Most state laws require program-level assessments. MODPA requires assessment of each algorithm. If you use multiple recommendation engines or scoring models, each needs its own risk review.
Ignoring the Enforcement Timeline
MODPA took effect October 1, 2025. The Attorney General began enforcement April 1, 2026. A limited grace period for curing violations ends April 1, 2027. After that, first violations have no cure period.
Quick Reference Table
| Requirement | MODPA Rule | Comparison to Other States |
|---|---|---|
| Applicability threshold | 35,000 consumers or 10,000 + 20% revenue from sales | CA/VA/CT: 100,000 consumers |
| Data minimization | Collection capped at service necessity | No other state caps collection |
| Sensitive data sales | Banned outright | Other states allow with opt-in consent |
| GPC enforcement | Required | Also required in CA, CO, CT |
| Assessment scope | Each algorithm | Most states: program-level |
| Health facility geofencing | Prohibited within 1,750 feet | Unique to Maryland |
| Rights request timeline | 45 days, extendable to 90 | Standard across most states |
| Appeal timeline | 60 days | Standard across most states |
| Private right of action | No (AG enforcement only) | Matches most states except CA |
| Enforcement start | April 1, 2026 | N/A |
| Cure period end | April 1, 2027 | N/A |
Maryland's approach indicates where U.S. privacy law might be heading. If you're building a compliance program for multiple states, design it to meet MODPA's standards. This keeps you ahead of legislative changes and minimizes future adjustments.





