State Comprehensive Privacy Laws

The Maryland Online Data Privacy Act as Enacted: New Section Numbers, No Consent Route and a 2026 Rewrite

Key Takeaways

  • Chapter 455 of 2024 added §§ 14-4601 to 14-4614 to the Commercial Law Article; the General Assembly's statute database and the Attorney General now cite the same provisions as §§ 14-4701 to 14-4714
  • Section 14-4707(a)(1) permits collecting, processing or sharing sensitive data only where strictly necessary to provide or maintain a product or service the consumer requested, with no consent alternative, and paragraph (2) bars its sale outright
  • Targeted advertising to, and sale of the data of, a consumer the controller knew or should have known is under 18 are both prohibited, with no consent exception in the text
  • Chapter 874 of 2026, effective July 1, 2026, rebuilt the sensitive data definition around sensitive attributes and inferences, and added limits on selling data for immigration enforcement
  • The Division may offer at least 60 days to cure only for violations occurring on or before April 1, 2027, and penalties run through § 13-410 at up to $10,000 and $25,000 per violation

The Section Numbers in the Bill Record Are Not the Ones in Force

Senate Bill 541 of the 2024 session, the Maryland Online Data Privacy Act of 2024, was approved by the Governor on May 9, 2024 as Chapter 455, with an effective date of October 1, 2025, according to the General Assembly's bill record. That record lists the code sections affected as Commercial Law § 13-301 and §§ 14-4601 through 14-4614, and the chapter law places them under the heading "Subtitle 46. Online Data Privacy Act." The Department of Legislative Services' 2026 fiscal note on a later amendment refers to the Act as "Chapters 454 and 455 of 2024," reflecting a cross-filed House bill enacted in parallel.

The General Assembly's statute database does not publish the Act at those numbers. It carries the definitions at § 14-4701, applicability at § 14-4702, and so on through § 14-4714, and the Attorney General's MODPA guidance refers to "§ 14-4703(b) of MODPA" for exempt data. Section 14-4602 in the same database is an unrelated provision barring the sale of self-administered sexual assault evidence collection kits. A citation to § 14-4601 et seq. therefore points at a different subtitle. This post uses the Subtitle 47 numbers throughout.

What the Chapter Law's Text Layer Does and Does Not Show

The Chapter 455 PDF records amendments made during passage, and its extracted text includes wording that is not law. Pulled out as plain text, the sensitive data prohibition in what was then § 14-4607(A) contains the phrase "and unless the controller obtains the consumer's consent," and the teen targeted advertising rule reads "at least 13 years old and under the age of 18 years."

Chapter 874 of 2026 settles the point, because it reprints § 14-4707(a) as it stood before July 2026, with deletions bracketed and insertions in capitals. Its reprint of paragraph (1) contains no consent language, and paragraphs (4) and (5) apply where the controller "knew or should have known that the consumer is under the age of 18 years." The statute database's text of § 14-4707 reads the same way. A description of Maryland as permitting sensitive data processing with consent, or as protecting only 13 to 17 year olds, describes text that did not survive enactment.

Coverage Turns on a Count of Maryland Consumers

Under § 14-4702 the subtitle applies to a person that conducts business in the State or provides products or services targeted to its residents and that, during the preceding calendar year, either controlled or processed the personal data of at least 35,000 consumers, not counting data handled solely to complete a payment transaction, or controlled or processed the personal data of at least 10,000 consumers while deriving more than 20% of gross revenue from selling personal data. There is no stand-alone revenue test. A "consumer" is a resident of the State, and the Attorney General's guidance states that the Act "does not protect an individual acting in an employment context."

The same guidance lists the entities outside the Act as State and local government, national securities associations registered under the Securities Exchange Act of 1934, financial institutions subject to the Gramm-Leach-Bliley Act, and a nonprofit controller that processes personal data solely to assist law enforcement or first responders responding to catastrophic events. Beyond that last category, it states that "Nonprofits are NOT exempt from MODPA," and that processors handling data for covered businesses "must also follow MODPA." Data governed by HIPAA, the Fair Credit Reporting Act and other listed regimes is exempted separately under § 14-4703(b).

Minimization Measured Against the Consumer's Request

Section 14-4707(b)(1)(i) requires a controller to "[l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains." A separate rule in § 14-4707(a)(8) governs later use: processing for a purpose "neither reasonably necessary to, nor compatible with, the disclosed purposes" requires the consumer's consent. The collection limit in subsection (b) has no consent alternative.

The statute does not define "reasonably necessary and proportionate." The Attorney General's business FAQ takes up the question, stating that a business "can determine what is 'reasonably necessary and proportionate to provide or maintain a specific product or service' based on the expectations of the reasonable consumer about how the data that is collected will be used." The same answer notes that a violation of the Act is a per se violation of the Consumer Protection Act.

Where consent does matter, § 14-4701(g) defines it as a clear affirmative act and excludes acceptance of general terms of use that bundle processing descriptions with unrelated information, "[h]overing over, muting, pausing, or closing a piece of content," and agreement obtained through dark patterns. Section 14-4707(b)(2) requires a controller to stop processing no later than 30 days after a consumer revokes consent.

Sensitive Data: Strict Necessity, No Sale, and a Wider Definition Since July 2026

Section 14-4707(a)(1) bars a controller from collecting, processing or sharing sensitive data "[e]xcept where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains." Paragraph (a)(2) states, without qualification, that a controller may not "[s]ell sensitive data." The Attorney General's FAQ restates both, saying a controller "may not sell sensitive data, and only may collect, process, or share sensitive data where doing so is strictly necessary."

Chapter 874 changed what counts. Before July 1, 2026, § 14-4701(gg) defined sensitive data as personal data that includes data revealing eight listed characteristics, among them consumer health data, status as transgender or nonbinary, and citizenship or immigration status, together with genetic or biometric data, personal data of a known child, and precise geolocation data. Chapter 874 renames that list a "sensitive attribute," adds that the term includes data a controller infers that, "alone or in combination with other data, is used to indicate" a listed attribute, and defines sensitive data as personal data that includes a sensitive attribute "or any other personal data processed for the purpose of identifying a sensitive attribute." It also extends precise geolocation data, still measured within 1,750 feet, to the location of "a mobile device, or a vehicle." When fetched for this post, the statute database's § 14-4701 still displayed the pre-amendment definition.

A separate prohibition in § 14-4704 applies to any "person," not only a controller. It bars using a geofence within 1,750 feet of a mental health facility or reproductive or sexual health facility to identify, track, collect data from, or send a notification to a consumer regarding the consumer's health data.

Every Consumer Under 18

Two prohibitions in § 14-4707(a) turn on age. A controller may not process a consumer's personal data for targeted advertising, and may not sell it, if the controller "knew or should have known that the consumer is under the age of 18 years." Neither paragraph contains a consent exception, and the "should have known" standard reaches beyond actual knowledge.

Younger children are also reached through the sensitive data definition, which covers personal data of a consumer the controller "knows or has reason to know is a child," with "child" carrying its COPPA meaning. That data is therefore inside both the sale ban and the strict necessity rule. A parent or legal guardian may exercise the consumer rights on a child's behalf under § 14-4705(d)(2), and Chapter 455 provides that controllers and processors complying with COPPA's verifiable parental consent requirements are considered compliant with any obligation to obtain parental consent under the subtitle.

Requests, Clocks and Appeals

Section 14-4705 and its neighbours fix the timetable for consumer requests:

StageWhat the statute providesProvision
Responding to a requestWithin 45 days of receipt, extendable once by 45 days where reasonably necessary and the consumer is told within the first period§ 14-4705(e)(2)
Declining to actThe consumer is told the justification and how to appeal within 45 days§ 14-4705(e)(3)
CostFree once in any 12-month period; a reasonable fee or refusal is permitted for manifestly unfounded, excessive, technically infeasible or repetitive requests, with the burden on the controller§ 14-4705(e)(4)
AppealsA written decision with reasons within 60 days; a denial comes with an online mechanism, if available, for complaining to the Division§ 14-4705(f)
Opt-outsNo authentication required; an authorized agent may be designated through a browser setting, browser extension or global device setting§§ 14-4705(e)(6), 14-4706
Revoked consentProcessing stops no later than 30 days after the request§ 14-4707(b)(2)

The list right in § 14-4705(b)(6) is to the categories of third parties to which the controller disclosed the consumer's data, or to which it disclosed any consumer's data where it does not keep consumer-specific records. Section 14-4706(b) obliges a controller to honor an agent's opt-out where it can authenticate, using commercially reasonable efforts, both the consumer's identity and the agent's authority. On privacy notices, the Attorney General states that a Maryland-specific section "is not required," but that the description "must clearly indicate the rights available to Marylanders, especially if those rights differ in any way from rights available to residents of other states."

The Immigration-Enforcement Amendments of 2026

House Bill 711 of the 2026 session, titled in its bill record "Data Privacy - Consumer Data, Public Records, and Message Switching System (Data Privacy Act)," passed the House 94-35 and the Senate 28-8. It was enacted as Chapter 874 under Article II, Section 17(c) of the Maryland Constitution on May 31, 2026, with an effective date of July 1, 2026, and the bill record lists §§ 14-4701, 14-4703, 14-4707 and 14-4712 among the sections affected. The fiscal note describes its aim as enhancing "the protection of an individual's personal data when that data is to be used for the purpose of immigration enforcement."

Beyond the definitions described above, Chapter 874 makes these changes to the Act:

  • § 14-4707(a)(5) now also bars selling a consumer's personal data where the controller knew or should have known that "the purchaser seeks to use the personal data for the purpose of immigration enforcement"
  • a new § 14-4707(a)(6) bars knowingly selling personal data to a federal, State or local governmental unit that, within the six months before the sale, "has engaged in or supported civil immigration enforcement through the provision of personnel or material resources"
  • § 14-4712(a) no longer protects compliance with an inquiry pertaining solely to immigration enforcement, compliance with a subpoena or summons derived from a unit that engaged in or supported civil immigration enforcement in the preceding six months, or cooperation with a law enforcement agency known to have done so, and those limits fall away where the controller or processor is presented with a valid warrant that particularly describes the data
  • the exemption for data handled under the federal Driver's Privacy Protection Act now covers data collected, processed, sold or disclosed as required by that Act, rather than all data handled in compliance with it, according to the fiscal note

Effective Dates, the Cure Window and Penalties

The Act took effect October 1, 2025. Section 14-4710 requires a controller to conduct and document data protection assessments for processing that presents a heightened risk of harm, defined as targeted advertising, sale, sensitive data processing and profiling with specified foreseeable risks, "including an assessment for each algorithm that is used," and Chapter 455 applies that duty to processing on or after October 1, 2025. The 2024 fiscal note records that certain controller and processor obligations "may not be applied or interpreted to have any effect on (or application to) any personal data processing activities before April 1, 2026."

Section 14-4713 makes a violation an unfair, abusive or deceptive trade practice under Title 13, subject to its enforcement and penalty provisions "except for § 13-408," while preserving any other remedy a consumer has by law. Section 13-410 sets fines of up to $10,000 per violation and up to $25,000 for each repetition of the same violation after a finding, and lists what the Consumer Protection Division weighs in an administrative proceeding: severity, good faith, prior violations, deterrent effect, and whether a cease and desist order alone would be insufficient. The Attorney General's FAQ adds that the office can seek "injunctive relief, restitution, economic damages, and disgorgement."

Section 14-4714 applies to alleged violations occurring on or before April 1, 2027. The Division "may" issue a notice of violation where it determines a cure is possible, and a controller or processor that receives one has at least 60 days to cure. The statute lists seven factors the Division may weigh: the number of violations, the size and complexity of the controller or processor, the nature and extent of its processing, the likelihood of injury to the public, the safety of persons or property, whether the violation was likely caused by human or technical error, and the extent of past violations of the subtitle or similar laws. The Attorney General's MODPA page, as fetched for this post, reports no enforcement action under the Act, and none is described here.

Background

For the underlying law rather than this development: Maryland privacy law.

Frequently Asked Questions

Where in the Maryland Code is the Online Data Privacy Act?
The General Assembly's statute database publishes it at Commercial Law §§ 14-4701 through 14-4714, and the Attorney General cites § 14-4703(b). The 2024 bill record and Chapter 455 list the sections as §§ 14-4601 through 14-4614 under a Subtitle 46 heading, and § 14-4602 in the current code is an unrelated provision on sexual assault evidence collection kits.
Can sensitive data be processed in Maryland on the basis of consent?
Consent is not a route under § 14-4707(a)(1). Collecting, processing or sharing sensitive data is prohibited except where strictly necessary to provide or maintain a specific product or service the consumer requested, and § 14-4707(a)(2) prohibits selling sensitive data at all. The plain-text layer of the Chapter 455 PDF shows a consent clause that does not appear in the section as reprinted by Chapter 874 or in the statute database.
Does MODPA's targeted advertising ban start at age 13?
No. Section 14-4707(a)(4) and (5) apply where the controller knew or should have known that the consumer is under the age of 18 years, with no lower age bound and no consent exception. Personal data of a known child, as COPPA defines the term, is also sensitive data.
What did Maryland's 2026 Data Privacy Act change in MODPA?
Chapter 874, effective July 1, 2026, redefined sensitive data around sensitive attributes, including inferences used to indicate them; extended precise geolocation data to mobile devices and vehicles; barred sales to purchasers seeking data for immigration enforcement and to government units that recently engaged in or supported civil immigration enforcement; and narrowed the subpoena and law enforcement cooperation carve-outs in § 14-4712 for such units absent a valid warrant.
How does the Maryland Attorney General read 'reasonably necessary and proportionate'?
Its business FAQ states that a business can determine what is reasonably necessary and proportionate to provide or maintain a requested product or service based on the expectations of the reasonable consumer about how the collected data will be used. The statute itself does not define the phrase.
Is the Maryland cure period mandatory?
No. Under § 14-4714 the Division may issue a notice of violation if it determines a cure is possible, and a controller or processor that receives one has at least 60 days to cure. The section covers only alleged violations occurring on or before April 1, 2027.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. Maryland General Assembly, Senate Bill 541 (2024 Regular Session), bill record (May 9, 2024) statute
  2. Chapter 455 of 2024, Maryland Online Data Privacy Act of 2024 (May 9, 2024) statute
  3. Department of Legislative Services, Fiscal and Policy Note, Senate Bill 541 (Enrolled, Revised) (May 9, 2024) agency guidance
  4. Md. Code, Com. Law § 14-4701 (definitions) (September 14, 2026) statute
  5. Md. Code, Com. Law § 14-4702 (applicability) (September 14, 2026) statute
  6. Md. Code, Com. Law § 14-4704 (consumer health data and geofences) (September 14, 2026) statute
  7. Md. Code, Com. Law § 14-4705 (consumer rights and response periods) (September 14, 2026) statute
  8. Md. Code, Com. Law § 14-4706 (authorized agents) (September 14, 2026) statute
  9. Md. Code, Com. Law § 14-4707 (controller prohibitions and duties) (September 14, 2026) statute
  10. Md. Code, Com. Law § 14-4710 (data protection assessments) (September 14, 2026) statute
  11. Md. Code, Com. Law § 14-4713 (enforcement) (September 14, 2026) statute
  12. Md. Code, Com. Law § 14-4714 (notice of violation and cure) (September 14, 2026) statute
  13. Md. Code, Com. Law § 13-410 (civil penalties) (September 14, 2026) statute
  14. Maryland General Assembly, House Bill 711 (2026 Regular Session), bill record (May 31, 2026) statute
  15. Chapter 874 of 2026, Data Privacy - Consumer Data, Public Records, and Message Switching System (Data Privacy Act) (May 31, 2026) statute
  16. Department of Legislative Services, Fiscal and Policy Note (Revised), House Bill 711 agency guidance
  17. Office of the Attorney General of Maryland, Data Privacy in Maryland (MODPA consumer and business FAQs) (September 14, 2026) agency guidance

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.