Skip to main content
Explainer · Reviewed September 2026

What Is the Maryland Online Data Privacy Act?

MODPA applies to persons that conduct business in Maryland or provide products or services targeted to Maryland residents and meet either the 35,000-consumer branch or the 10,000-consumer-plus-more-than-20%-sale-revenue branch, subject to exemptions. It grants access, correction, deletion, portability, third-party-category, and opt-out rights, with a 45-day response period and possible 45-day extension. It also requires qualifying opt-out preference signals by October 1, 2025 and includes sensitive-data, minimization, and under-18 consent rules. For alleged violations on or before April 1, 2027, the Division may offer at least 60 days to cure when it determines cure is possible; this is discretionary.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Maryland Online Data Privacy Act
Short code
MODPA
Effective date
October 1, 2025
Response reference
45 days in this snapshot
Cure period
None recorded in this snapshot
Private right of action
No
Enforcement
Maryland Office of the Attorney General. Division of Consumer Protection
Penalty reference
Up to $10,000 per violation; up to $25,000 for repeat violations under the Maryland Consumer Protection Act

Who MODPA applies to

A business is covered if it meets the applicability thresholds set out in Md. Code, Com. Law §§ 14-4601–14-4614. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.

  • Conducts business in Maryland or provides products or services targeted to Maryland residents and, during the preceding calendar year, controls or processes the personal data of at least 35,000 consumers, excluding data processed solely for payment transactions
  • Conducts business in Maryland or provides products or services targeted to Maryland residents and, during the preceding calendar year, controls or processes the personal data of at least 10,000 consumers and derives more than 20% of gross revenue from the sale of personal data

Consumer rights under MODPA

Sensitive-data sale restrictions, subject to statutory scope and exceptions

Data-minimization requirement, subject to the current statute

Heightened protections for minors

Low thresholds, more brokers are in scope

Discretionary cure notice of at least 60 days may apply through April 1, 2027

Notable features (vs. CCPA)

MODPA restricts the sale and processing of sensitive data and imposes data-minimization requirements, including a standard that collection be 'reasonably necessary and proportionate' to provide or maintain a specific product or service requested by the consumer. Consumers who are at least 13 and younger than 18 receive consent protections for targeted advertising and sale when the controller knew or should have known the consumer's age.

Enforcement and penalty reference

Enforcing agency: Maryland Office of the Attorney General. Division of Consumer Protection

Penalty reference: Up to $10,000 per violation; up to $25,000 for repeat violations under the Maryland Consumer Protection Act

Cure period: For alleged violations occurring on or before April 1, 2027, the Division may issue a notice of violation when it determines that a cure is possible. If notice is issued, the controller or processor must receive at least 60 days to cure; this is discretionary, not a general automatic cure period.

Private right of action: MODPA has no private right of action. Enforcement is through Maryland's Division of Consumer Protection (office of the Attorney General).

Where to file a complaint: Maryland Office of the Attorney General

How to exercise your MODPA rights

  1. 1

    Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.

  2. 2

    Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable Maryland residency, scope, exemption, and verification rules before sending.

  3. 3

    This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.

  4. 4

    If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the Maryland Office of the Attorney General complaint route at https://www.marylandattorneygeneral.gov/Pages/CPD/Complaint.aspx. A complaint route does not itself guarantee deletion or a particular enforcement result.

Generate requests in under 60 seconds

Generate a MODPA privacy request, $9 one-time

Review the provider route, applicable law, and information you intend to send before dispatch. You remain in control of the request and any evidence kept.

FAQ

What should Maryland residents check under MODPA?+

Check the controller's scope, the statute's sensitive-data and data-minimization provisions, request verification, exemptions, and current response rules. A particular data broker may still fall outside MODPA or retain data under an applicable exception.

Official sources & citations

Compare with sibling state laws

MODPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:

Related concepts & guides