{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/maryland",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/maryland.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/maryland",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/maryland/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/maryland/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "maryland",
    "frontmatter": {
      "title": "Maryland Consumer Privacy Law (MODPA)",
      "description": "The Maryland Online Data Privacy Act gives Maryland consumers rights over their personal data and imposes notice, contracting, and consent duties on controllers above defined thresholds — it is notably stricter than the Virginia-style model, banning the sale of sensitive data outright and limiting sensitive-data collection to what is strictly necessary, and is enforced exclusively by the Attorney General with no private right of action.",
      "state": "Maryland",
      "lastReviewed": "2026-06-06",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Md. Code Ann., Com. Law §§ 14-4701 et seq. (Maryland Online Data Privacy Act)",
        "appliesTo": "Persons doing business in Maryland (or targeting residents) that, in the prior calendar year, controlled or processed the data of 35,000+ consumers, or 10,000+ consumers while deriving more than 20% of gross revenue from selling data — a low threshold with only a narrow nonprofit carve-out",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents, including detailed third-party disclosures",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's Consumer Protection Division",
        "regulator": "Maryland Attorney General, Consumer Protection Division (exclusive)",
        "bottomLine": "If you meet the 35,000-consumer (or 10,000 plus 20%-data-sale) threshold in Maryland, MODPA requires a detailed privacy notice and processor contracts, limits sensitive-data collection to what is strictly necessary, and bans the sale of sensitive data and of a minor's data outright — enforced by the Attorney General, with a cure period that sunsets for violations after April 1, 2027 and no consumer lawsuits.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optOutOrLimit",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Maryland Online Data Privacy Act MODPA",
        "Maryland privacy policy requirements",
        "Maryland privacy notice contents",
        "MODPA applicability thresholds",
        "MODPA sensitive data sale prohibition",
        "MODPA processor contract requirements",
        "Maryland Attorney General privacy enforcement",
        "MODPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-modpa-apply",
        "label": "Does the Maryland Online Data Privacy Act apply to your business?",
        "heading": "Does the Maryland Online Data Privacy Act apply to your business?",
        "answerText": "It turns mostly on consumer volume, and the bar is low. MODPA applies to persons that do business in Maryland or target its residents and that, in the prior calendar year, controlled or processed the personal data of at least 35,000 consumers, or at least 10,000 consumers while deriving more than 20% of gross revenue from selling personal data.",
        "sources": [
          {
            "id": "stat-4702-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4702",
            "citation": "Md. Code Ann., Com. Law § 14-4702.",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4702",
            "proposition": "MODPA applies to persons doing business in Maryland or targeting its residents that, in the preceding calendar year, controlled or processed the data of at least 35,000 consumers, or at least 10,000 consumers while deriving more than 20% of gross revenue from the sale of personal data.",
            "verbatimQuote": "(1) Controlled or processed the personal data of at least 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) Controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of its gross revenue from the sale of personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4702-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Maryland privacy policy contain?",
        "heading": "What must your Maryland privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed (including sensitive data), the purpose for processing, how consumers exercise and appeal their rights and revoke consent, the categories of third parties data is shared with and the categories of data shared, and a contact mechanism.",
        "sources": [
          {
            "id": "stat-4707-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4707",
            "citation": "Md. Code Ann., Com. Law § 14-4707(d).",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4707",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that includes all six enumerated disclosures: categories of personal data processed (including sensitive data); the purpose for processing; how consumers exercise, appeal, and revoke consent on their rights; the categories of third parties data is shared with (detailed enough to understand each third party); the categories of data shared; and a contact mechanism.",
            "verbatimQuote": "A controller shall provide a consumer with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) The categories of personal data processed by the controller, including sensitive data; (2) The controller’s purpose for processing personal data; (3) How a consumer may exercise the consumer’s rights under this subtitle, including how a consumer may appeal a controller’s decision regarding the consumer’s request or may revoke consent; (4) The categories of third parties with which the controller shares personal data with a level of detail that enables a consumer to understand the type of, business model of, or processing conducted by each third party; (5) The categories of personal data, including sensitive data, that the controller shares with third parties; and (6) An active e–mail address or other online mechanism that a consumer may use to contact the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4707-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A controller that uses a processor must enter into a binding contract governing the processor's data processing on the controller's behalf — so a data processing agreement is a statutory requirement, not a best practice.",
        "sources": [
          {
            "id": "stat-4708-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4708",
            "citation": "Md. Code Ann., Com. Law § 14-4708(a)(1).",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4708",
            "proposition": "If a controller uses a processor, the controller and processor must enter into a binding contract that governs the processor's data processing procedures and clearly sets forth processing instructions, the nature and purpose, the type of data, the duration, and the parties' rights and obligations.",
            "verbatimQuote": "If a controller uses a processor to process the personal data of consumers, the controller and the processor shall enter into a contract that governs the processor’s data processing procedures with respect to processing performed on behalf of the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4708-contract"
          },
          {
            "id": "stat-4708-terms",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4708",
            "citation": "Md. Code Ann., Com. Law § 14-4708(a)(2)–(3).",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4708",
            "proposition": "The controller-processor contract must clearly set forth processing instructions, the nature and purpose, the type of data, the duration, and the parties' rights and obligations, and must require the processor to maintain confidentiality, implement reasonable security practices, delete or return data, demonstrate compliance, bind subcontractors to the same obligations, and cooperate with assessments.",
            "verbatimQuote": "(2) The contract shall be binding and shall clearly set forth: (i) Instructions for processing data; (ii) The nature and purpose of processing; (iii) The type of data subject to processing; (iv) The duration of processing; and (v) The rights and obligations of both parties. (3) The contract shall require that the processor: (i) Ensure that each person processing personal data is subject to a duty of confidentiality with respect to the personal data; (ii) Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, considering the volume and nature of the personal data; (iii) Stop processing data on request by the controller made in accordance with a consumer’s authenticated request; (iv) At the controller’s direction, delete or return all personal data to the controller as requested at the end of the provision of service, unless retention of the personal data is required by law; (v) On the reasonable request of the controller, make available to the controller all information in the processor’s possession necessary to demonstrate the processor’s compliance with the obligations in this subtitle; (vi) After providing the controller an opportunity to object, engage a subcontractor to assist with processing personal data on the controller’s behalf only in accordance with a written contract that requires the subcontractor to meet the processor’s obligations regarding the personal data under the processor’s contract with the controller; and (vii) Allow and cooperate with reasonable assessments by the controller, the controller’s designated assessor, or a qualified and independent assessor arranged for by the processor to assess the processor’s policies and technical and organizational measures in support of the obligations under this subtitle.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4708-terms"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "What are the rules for sensitive data?",
        "heading": "What are the rules for sensitive data?",
        "answerText": "Maryland is stricter than the opt-in model used elsewhere. A controller may not collect, process, or share sensitive data unless doing so is strictly necessary to provide or maintain a specific product or service the consumer requested, and it may not sell sensitive data at all. Consent does not unlock either limit. Sensitive data is defined broadly to include data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, transgender or nonbinary status, national origin, or citizenship or immigration status; genetic or biometric data; a known child's data; and precise geolocation.",
        "sources": [
          {
            "id": "stat-4707-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4707",
            "citation": "Md. Code Ann., Com. Law § 14-4707(a).",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4707",
            "proposition": "A controller may not collect, process, or share sensitive data except where strictly necessary to provide or maintain a product or service the consumer requested, and may not sell sensitive data at all.",
            "verbatimQuote": "A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4707-sensitive"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under MODPA?",
        "heading": "Can a consumer sue your business under MODPA?",
        "answerText": "No. A MODPA violation is treated as an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act, enforced by the Attorney General's Consumer Protection Division — and the statute routes enforcement to that machinery while excluding the Consumer Protection Act's private-action section. For an alleged violation occurring on or before April 1, 2027, the Division may issue a notice of violation if a cure is possible, after which the business gets at least 60 days to cure.",
        "sources": [
          {
            "id": "stat-4713-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4713",
            "citation": "Md. Code Ann., Com. Law § 14-4713(a).",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4713",
            "proposition": "A MODPA violation is an unfair, abusive, or deceptive trade practice subject to the Consumer Protection Act's enforcement and penalty provisions, except for its private-action section — so enforcement runs through the Attorney General, not a consumer lawsuit.",
            "verbatimQuote": "a violation of this subtitle is: (1) An unfair, abusive, or deceptive trade practice within the meaning of Title 13 of this article; and (2) Subject to the enforcement and penalty provisions contained in Title 13 of this article, except for § 13–408 of this article.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4713-enforce"
          },
          {
            "id": "stat-4714-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Md. Code Ann., Com. Law § 14-4714",
            "citation": "Md. Code Ann., Com. Law § 14-4714(c)(1).",
            "url": "https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl&section=14-4714",
            "proposition": "For violations occurring on or before April 1, 2027, the Division may issue a notice of violation if a cure is possible, and the controller or processor then has at least 60 days to cure before the Division may bring an enforcement action.",
            "verbatimQuote": "If the Division issues a notice of violation under subsection (b) of this section, the controller or processor shall have at least 60 days to cure the violation after receipt of the notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maryland#src-stat-4714-cure"
          }
        ]
      }
    ]
  }
}
