Maryland Privacy Law
Correction, September 14, 2026. This page originally said Maryland permits processing sensitive data with consent, and that its teen advertising and sale bans cover consumers aged 13 to 17 with a consent exception. Md. Code, Com. Law § 14-4707(a)(1), (4) and (5) contain no consent route and reach any consumer the controller knew or should have known is under 18. The page also cited the pre-codification section numbers (§ 14-46xx) and said nothing had amended the Act since 2024; chapter 874 of 2026 did.
Maryland wrote the strictest data-minimization rule in American privacy law and made it the centre of its statute rather than an accessory to consent. Under the Maryland Online Data Privacy Act, a controller limits collection to what is reasonably necessary and proportionate to provide or maintain a specific product or service the consumer requested — a standard tied to the transaction, not to what the controller disclosed and the consumer accepted. Sensitive data is narrower still: collection is barred unless strictly necessary to provide the requested product or service, and the sale of sensitive data is prohibited outright with no consent exception. Maryland is also one of the few states whose breach statute requires notifying the Attorney General before notifying consumers, and its consumer protection penalties reach $25,000 for a repeated violation.
The Maryland Online Data Privacy Act (MODPA)
MODPA was enacted as Senate Bill 541 of the 2024 Regular Session, sponsored by Senators Gile, Hester, Augustine, Feldman, Beidle and Ellis, passed the Senate 42-0 and the House 103-33, was signed May 9, 2024 as chapter 455, and took effect October 1, 2025. Its centre of gravity is § 14-4707. Subsection (B)(1)(I) requires a controller to limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains — a standard measured against the consumer’s request rather than against the controller’s disclosed purposes, which is what separates it from the Virginia-model statutes. Subsection (A) then sets out flat prohibitions. A controller may not collect, process or share sensitive data except where strictly necessary to provide or maintain a specific product or service requested by the consumer, with no consent route; may not sell sensitive data at all, with no consent exception; may not process personal data in violation of state or federal anti-discrimination laws; may not process personal data for targeted advertising where it knew or should have known the consumer is under eighteen; may not sell that consumer’s personal data; may not discriminate against a consumer for exercising a right, including by denying goods or services, charging different prices or providing a different quality of service; may not collect, process or transfer personal or publicly available data in a manner that unlawfully discriminates in or makes unavailable the equal enjoyment of goods or services on the basis of race, colour, religion, national origin, sex, sexual orientation, gender identity or disability, subject to carve-outs for self-testing to prevent discrimination, diversifying an applicant or customer pool, and private clubs under § 201(e) of the Civil Rights Act of 1964; and may not, without consent, process personal data for a purpose that is neither reasonably necessary to nor compatible with the disclosed purposes.
| Effective date | October 1, 2025 |
|---|---|
| Citation | Md. Code, Com. Law § 14-4701 et seq. |
| Enforced by | Maryland Division of Consumer Protection, Office of the Attorney General |
| Maximum penalty | A violation is an unfair, abusive or deceptive trade practice under title 13, carrying up to $10,000 per violation and up to $25,000 for a repeated violation under Md. Code, Com. Law § 13-410 |
| Private right of action | No, enforcement by the state only |
| Right to cure | At least 60 days, discretionary, for violations occurring on or before April 1, 2027 |
Who Must Comply
The MODPA reaches a business that conducts business in Maryland or targets Maryland residents, and during the preceding calendar year controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction, or controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data.
Section 14-4713(A) makes a violation an unfair, abusive or deceptive trade practice within the meaning of title 13 and subject to that title’s enforcement and penalty provisions “except for § 13-408” — the section that would otherwise give consumers a private action. Maryland therefore imports the whole consumer-protection remedial scheme while surgically excising private enforcement, rather than declaring no private right of action in the abstract. Subsection (B) preserves any other remedy provided by law
Consumer Rights Under the MODPA
Residents of Maryland can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
strictly necessary only, no consent route; sale prohibited outright
Sector-Specific Privacy Laws in Maryland
Personal Information Protection Act (Md. Code, Com. Law §§ 14-3501 to 14-3508)
PIPA carries both a security duty and the breach duty. Section 14-3503 requires a business that owns or licenses personal information of a Maryland resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and the nature and size of the business, and requires contracts with third-party service providers to oblige comparable measures. Section 14-3504 sets the notification regime. The Attorney General’s office describes the covered data elements as a name combined with a Social Security number, driver’s licence, financial account number with security code, health information, health insurance identifier or biometric data — or, without a name, a user name or e-mail address in combination with a password or security question and answer permitting access to an e-mail account. On discovering a breach the business conducts in good faith a reasonable and prompt investigation to determine whether misuse is likely, and where notice is owed it is given within forty-five days. Section 14-3508 provides that a violation of PIPA is an unfair or deceptive trade practice under the Maryland Consumer Protection Act, which supplies the penalties.
Maryland Kids Code (Md. Code, Com. Law, Consumer Protection — Online Products and Services — Data of Children)
House Bill 603 of the 2024 Regular Session, sponsored by Delegates Solomon, Wilson and Love, became chapter 461, was signed May 9, 2024 and took effect October 1, 2024 — a year ahead of MODPA. It requires an entity offering an online product reasonably accessible to children to complete a data protection impact assessment by April 1, 2026 in specified circumstances, prohibits certain data collection and sharing practices in relation to children, and addresses monitoring that would allow a parent or guardian to track a child’s online activity or location “without providing an obvious signal to the child”. Because it sits in the same title as the Consumer Protection Act, it draws on the same enforcement machinery as MODPA and PIPA.
Maryland Consumer Protection Act (Md. Code, Com. Law § 13-301 et seq.)
Title 13 is the enforcement engine for all three privacy statutes above, and § 13-410 supplies the numbers. A merchant who engages in a violation of the title is subject to a fine not exceeding $10,000 for each violation; a merchant who has been found to have engaged in a violation and who subsequently repeats the same violation is subject to a fine not exceeding $25,000 for each subsequent violation. That escalation structure is what gives the Division of Consumer Protection leverage after a first settlement: a second matter on the same facts carries two and a half times the ceiling. Section 13-408 is the provision that ordinarily allows a consumer to bring an action for injury under the title, and it is the one provision MODPA’s § 14-4713(A)(2) expressly declines to import.
Data Breach Notification in Maryland
Section 14-3504 inverts the ordinary sequence: the business notifies the Attorney General prior to giving the notification required to consumers. The regulator notice carries the number of affected Maryland residents, a description of the breach including its timing and method, the remedial steps taken or planned, and a sample of the notice language. The consumer notice is due as soon as reasonably practicable and not later than forty-five days after the business discovers or is notified of the breach, and must carry a description of the categories of personal information compromised, the business’s address and telephone and toll-free numbers, the toll-free numbers and addresses of the major credit reporting agencies, and the Federal Trade Commission and Attorney General contact details and website addresses together with a statement that those bodies provide information about avoiding identity theft. The duty is gated by an investigation: on discovering or being notified of a breach the business conducts in good faith a reasonable and prompt investigation to determine whether the personal information has been or will be misused. Substitute notice, where contact information is unavailable, consists of e-mail to available addresses, conspicuous posting on the business’s website, and notification to major media in the affected geographic areas. Section 14-3508 makes a violation an unfair or deceptive trade practice under the Consumer Protection Act, which carries the $10,000 and $25,000 ceilings of § 13-410.
Residents must be notified as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach. Notice to the Maryland Attorney General is required before notice to consumers, for any breach, with no numeric threshold. Complaints are taken by the Maryland Attorney General, which enforces the statute.
How the MODPA Is Enforced
Everything routes through title 13. Maryland does not give its privacy statutes their own penalty schedules. Section 14-4713(A) makes a MODPA violation an unfair, abusive or deceptive trade practice within the meaning of title 13 and subject to that title’s enforcement and penalty provisions except § 13-408; § 14-3508 makes a PIPA violation an unfair or deceptive trade practice under the Consumer Protection Act. Both therefore land on § 13-410, with its $10,000 ceiling per violation and $25,000 ceiling for a repeated violation, and both are enforced by the Division of Consumer Protection within the Office of the Attorney General rather than by the Attorney General acting in a distinct capacity.
A cure period the Division may decline to offer. Section 14-4714 is drafted permissively rather than as a precondition. It applies to enforcement actions for alleged violations occurring on or before April 1, 2027, and provides that before initiating an action the Division may issue a notice of violation if it determines that a cure is possible, in which case the controller or processor has at least sixty days to cure. Subsection (D) sets out the factors the Division may consider in deciding whether to grant the opportunity: the number of violations, the size and complexity of the controller or processor, the nature and extent of its processing activities, the likelihood of injury to the public, and the safety of persons or property. That is a materially weaker guarantee than the mandatory cure periods in Virginia, Iowa and Utah.
Recent Enforcement in Maryland
23andMe — multistate settlement on behalf of 94,298 Marylanders. On July 14, 2026 the Attorney General announced a settlement with the bankruptcy trustee of 23andMe over the October 2023 breach, which affected 6.9 million consumers including 94,298 Maryland residents and led to subsets of the data being offered for sale on the dark web. The states recover $18 million from bankruptcy funds. The release identifies Maryland’s genetic privacy law as the relevant state authority, describing it as requiring direct-to-consumer genetic testing companies to provide transparent privacy policies, obtain express consent for collecting or sharing genetic data, and ensure consumer rights to access and delete data. The office identifies six categories of unreasonable security practice: failing to employ safeguards against credential stuffing attacks including password blocklists or multi-factor authentication; lacking appropriate rate limiting or intrusion prevention; the absence of logging, monitoring or breach detection tools; failing to investigate unusual login patterns including a massive spike in login attempts; failing to remediate known vulnerabilities; and inadequate review and testing of design features. After 23andMe filed for bankruptcy protection in March 2025 its consumer data assets were sold to TTAM Research Institute, a non-profit formed by the company’s founder.
Pending Privacy Legislation
Maryland enacted its two privacy statutes on the same day and staggered their commencement. Senate Bill 541, the Maryland Online Data Privacy Act of 2024, passed the Senate 42-0 and the House 103-33, was signed May 9, 2024 as chapter 455 and took effect October 1, 2025. House Bill 603, “Consumer Protection — Online Products and Services — Data of Children”, known as the Maryland Kids Code, became chapter 461, was signed the same day and took effect October 1, 2024, with its data protection impact assessment obligation keyed to April 1, 2026. The discretionary cure period at § 14-4714 applies only to alleged violations occurring on or before April 1, 2027, after which the Division may proceed without offering an opportunity to cure. MODPA has since been amended. House Bill 711 of the 2026 Regular Session, the Data Privacy Act, became chapter 874 without the Governor’s signature under Article II, Section 17(c) of the Maryland Constitution and took effect July 1, 2026. Its synopsis describes a prohibition on a controller knowingly selling a consumer’s personal data to a governmental unit that has engaged in or supported civil immigration enforcement, in defined circumstances, alongside separate duties on custodians of public records and on the operator of a message switching system.
Federal Privacy Laws That Apply in Maryland
Federal privacy law applies in Maryland by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The MODPA sits alongside those rules rather than displacing them: the Maryland Division of Consumer Protection, Office of the Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Maryland Kids Code (Md. Code, Com. Law, Consumer Protection — Online Products and Services — Data of Children), which the Maryland Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Maryland Privacy Law FAQ
What is Maryland’s data minimization standard, and why is it stricter than other states’?
Can sensitive data be sold in Maryland with the consumer’s consent?
What does MODPA prohibit in relation to teenagers?
Does Maryland notify the Attorney General before or after consumers?
Can a Maryland consumer sue under MODPA?
Does Maryland give businesses a right to cure?
What are the civil penalties for a Maryland privacy violation?
When did Maryland’s children’s code take effect relative to MODPA?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Maryland Senate Bill 541 (2024) — Maryland Online Data Privacy Act, enrolled text statute
- Maryland Senate Bill 541 (2024) — bill details, chapter number and votes legislation
- Md. Code, Com. Law § 14-4707: controller prohibitions and data minimization, as codified statute
- Maryland House Bill 711 (2026), the Data Privacy Act: bill details and chapter 874 legislation
- Md. Code, Com. Law § 14-3504 — Notification of breach of security statute
- Md. Code, Com. Law § 13-410 — Civil penalties under the Consumer Protection Act statute
- Maryland House Bill 603 (2024) — Maryland Kids Code, bill details legislation
- Maryland Attorney General — business guidelines for the Personal Information Protection Act agency guidance
- Maryland Attorney General — multistate settlement of bankruptcy claims against 23andMe agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.