MODPA

Maryland Online Data Privacy Act

Key Facts

Effective Date
October 1, 2025
Enacted
May 9, 2024
Enforcing Authority
Maryland Attorney General (Division of Consumer Protection)
Consent Model
Opt-out
Fulfillment Time
45 days
Applies To
Entities in MD or targeting MD residents: 35,000+ consumers OR 10,000+ consumers and 20%+ revenue from selling PI

Overview

Maryland's MODPA is the most restrictive US state privacy law. It completely prohibits the sale of sensitive data. Not even consent can authorize it. Sensitive data may only be processed when "strictly necessary" to deliver a service requested by the consumer. Under-18 data sale and targeted advertising are prohibited regardless of consent.

What This Means for Your Website

  • GPC/UOOM signals must be honored
  • Sensitive data sale is completely prohibited: consent cannot authorize it
  • Sensitive data processing is limited to what is "strictly necessary" for requested services
  • Under 18: sale and targeted advertising prohibited regardless of consent
  • The strictest data minimization requirements among all US state privacy laws
  • Biometric data is covered even if not used for identification purposes
  • Consumer health data includes gender-affirming care and reproductive health

Key Requirements

The Maryland AG enforces the MODPA with penalties of $10,000 per first violation and $25,000 per subsequent violations. There is no cure period. Consumer requests must be fulfilled within 45 days. The sensitive data definition is the broadest among US states, covering biometric data even without identification use, consumer health data including gender-affirming care, and precise geolocation.

How ConsentStack Handles This

ConsentStack detects Maryland visitors and applies the strictest consent model among US states, blocking sensitive data sale entirely and limiting processing to strictly necessary purposes.

Penalties

$10,000 per first violation; $25,000 per subsequent violation.

Maximum Fine
$25,000 per violation

Key Requirements

  • Honor GPC/universal opt-out signals
  • Sensitive data: processing only when strictly necessary
  • Sale of sensitive data completely prohibited even with consent
  • Under 18: sale and targeted advertising prohibited regardless of consent
  • Strict data minimization, most restrictive among US states
  • Data protection assessments for high-risk processing

Notable Provisions

  • Most restrictive US state privacy law
  • Sensitive data sale completely prohibited: consent cannot authorize it
  • Strictest data minimization requirements
  • Under 18 sale/advertising prohibited regardless of consent
  • Biometric data covered even without identification use

US State Specifics

Private Right of Action
No
Global Opt-out Required
Yes
Sensitive Data Opt-in
Yes
Children Provisions
Under 18: sale and targeted advertising PROHIBITED regardless of consent.

Other North America Regulations

CCPACalifornia, United States
The CCPA was the first comprehensive consumer privacy law in the United States, giving California residents the right to know what personal information businesses collect and to opt out of its sale. It established the opt-out consent model that most subsequent US state privacy laws adopted.
CPRACalifornia, United States
The CPRA is the most comprehensive US state privacy law with a dedicated enforcement agency (CPPA). Cross-context behavioral advertising via cookies constitutes sharing personal information, triggering opt-out obligations. GPC signals must be honored as valid opt-out requests.
PIPEDACanada
Canada's federal private-sector privacy law based on 10 fair information principles. Requires express consent for sensitive data and implied consent for less sensitive data. OPC guidance addresses cookies and online behavioral advertising. The CPPA replacement bill died January 2025; a new bill is expected.
CIPACalifornia, United States
CIPA is a 1967 California chapter covering wiretapping, eavesdropping, and other privacy invasions, not a website-specific law. Since 2022, courts have applied two of its sections to website chat, analytics, and ad tools, and any visitor can sue directly for at least $5,000 per violation, no revenue threshold.
TDPSATexas, United States
The TDPSA is the broadest US state privacy law: no revenue thresholds and no minimum consumer data volume thresholds. Applies to any non-small-business processing personal data of Texas residents. Must honor GPC signals since January 2025. This breadth means far more businesses are captured than under any other state law.
Quebec Law 25Quebec, Canada
Quebec's Law 25 is the strictest privacy law in Canada and the closest North American equivalent to the GDPR. Consent must be clear, free, informed and requested for each purpose, and any technology that identifies, locates or profiles a visitor has to be disclosed. Its privacy-by-default rule carves out browser cookie settings, but non-essential cookies still need consent first.

Frequently Asked Questions

MODPA requires you to recognize an opt-out preference signal such as Global Privacy Control. Check whether GPC is working on your site to confirm the signal reaches you and that trackers actually stop firing when it does.

Stay compliant with MODPA

ConsentStack helps you implement Opt-out consent for Maryland, United States automatically.