Skip to main content
MODPA · Effective 2025-10-01

Maryland Data Removal Guide (2026)

Maryland's Online Data Privacy Act took effect October 2025 and includes data-minimization, sensitive-data, and minor-protection provisions. Whether a request reaches a controller depends on the statute's scope, exemptions, definitions, and current enforcement rules.

Research status: published state guide pending fresh official-source re-verification.

This page is educational orientation, not legal advice. Scope, exemptions, deadlines, penalties, regulator powers and broker routes can change. Verify the current statute and state regulator guidance before relying on a right or deadline.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 13, 2026

At a glance

Comprehensive state privacy law
Recorded: MODPA
Broker response deadline
45 days in this research snapshot for qualifying requests; extensions and exemptions may apply
Enforcement
Maryland Office of the Attorney General

Maryland Online Data Privacy Act (MODPA)

MODPA applies to persons that conduct business in Maryland or provide products or services targeted to Maryland residents and meet either the 35,000-consumer branch or the 10,000-consumer-plus-more-than-20%-sale-revenue branch, subject to exemptions. It grants access, correction, deletion, portability, third-party-category, and opt-out rights, with a 45-day response period and possible 45-day extension. It also requires qualifying opt-out preference signals by October 1, 2025 and includes sensitive-data, minimization, and under-18 consent rules. For alleged violations on or before April 1, 2027, the Division may offer at least 60 days to cure when it determines cure is possible; this is discretionary.

Read the full MODPAexplainer →Scope, thresholds, exceptions, cure rules, and enforcement details where documented.

What rights do Maryland residents have?

  • Sensitive-data sale restrictions, subject to statutory scope and exceptions
  • Data-minimization requirement, subject to the current statute
  • Heightened protections for minors
  • Low thresholds, more brokers are in scope
  • Discretionary cure notice of at least 60 days may apply through April 1, 2027

Where does your data leak from in Maryland?

The FTC explains that people-search sites may combine public records, public social profiles, and information from other brokers. The examples below are a research snapshot, not an exhaustive or person-specific source map for Maryland:

  • Maryland Judiciary Case Search (MDEC)
  • Montgomery, Prince George's, Baltimore County property records
  • Maryland MVA driver records

Generate requests in under 60 seconds

Generate requests for 1009 US/global broker workflows for $9

OfflistMe prepares user-reviewed request drafts for the selected catalog routes. You choose the jurisdictional wording, review each draft, and send or submit it yourself; broker verification and outcomes remain outside OfflistMe's control.

What if a broker ignores your request?

If a qualifying request does not receive a response within the applicable window, review the current extension and exemption rules, then consider the Maryland Office of the Attorney General complaint route. The authority's jurisdiction and available remedies vary.

File a complaint with Maryland Office of the Attorney General

FAQ: Maryland data removal

What should Maryland residents check under MODPA?+

Check the controller's scope, the statute's sensitive-data and data-minimization provisions, request verification, exemptions, and current response rules. A particular data broker may still fall outside MODPA or retain data under an applicable exception.

Related resources

Other state guides