The Maryland Online Data Privacy Act, MODPA, is the strictest state privacy law outside California and reaches small businesses: it applies at 35,000 Maryland consumers, or 10,000 if more than 20 percent of revenue comes from selling personal data.
What Makes the Maryland Online Data Privacy Act Different
Its defining feature is hard data minimization. Businesses may collect only what is reasonably necessary for the specific product or service the consumer requested, sensitive data may not be collected beyond strict necessity, and the sale of sensitive data is flatly banned regardless of consent. Targeted advertising to consumers the business knows are under 18 is prohibited. Consumers get the usual access, correction, deletion, portability, and opt-out rights, and covered sites must honor universal opt-out signals.
Enforcement and Penalties
Enforcement is by the Attorney General under Maryland’s Consumer Protection Act, with penalties up to $10,000 per violation and a discretionary cure window available only until April 1, 2027. Agencies with Maryland traffic should audit what their forms and analytics actually collect, because the minimization duty goes beyond disclosure.
Source: Maryland General Assembly: SB 541, Md. Com. Law 14-4601 et seq.
Report a violation: If you believe a business is violating this law, you can file a complaint with the Maryland Attorney General Consumer Protection Division.