Skip to Main Content
Publications
Publications | October 2, 2025
3 minute read

A Reminder: Maryland Online Data Privacy Act Has Become Effective This Week

As of Oct. 1, Maryland is the latest state to join the growing ranks of those with comprehensive data privacy laws as the Maryland Online Data Privacy Act (MODPA) takes effect. While much of the law mirrors those of other states, there are some unique features that may pose certain compliance challenges.

Scope of Maryland’s Law

Maryland’s law applies to businesses and entities doing business in the state or targeting Maryland residents and processing the data of at least 35,000 Maryland consumers (subject to certain exceptions), as well as persons who control or process the personal data of at least 10,000 Maryland residents and derive more than 20% of their gross revenue from the sale of personal data (commonly referred to as data brokers). Nonprofits and higher education entities are not automatically exempt. However, Maryland’s law includes many of the data exceptions found in other states’ law, such as data from Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Family Educational Rights and Privacy Act (FERPA), employee and business-to-business.

Much of the MODPA Mirrors Other States

Maryland’s law substantially follows the same model as most states, requiring data controllers to post data privacy notices informing Maryland residents of their data collection practices. It also provides rights to Maryland residents to:

  • confirm whether their data is being processed,
  • access their data,
  • correct errors in their data,
  • delete their data,
  • obtain a portable copy of their data,
  • obtain a list of third parties with whom their personal data was shared and
  • opt out of: targeted advertising, sale of personal data and automated profiling producing legally or similarly significant effects.

The right to opt out of automated profiling is likely to become increasingly relevant as businesses discover new ways to utilize artificial intelligence in their workflows. The law also provides protections for biometric data (defining it as sensitive data) and prohibits “dark patterns,” which undermine consumer choice and expressly references the Federal Trade Commission's definition.

Unique Requirements May Pose Challenges

There are several nuances to the MODPA that are more onerous than other state privacy laws of which businesses should be aware. Some of them are highlighted below:

  • Data Minimization: Most notably, the MODPA has an explicit data minimization principle for sensitive personal information. Businesses are prohibited from processing sensitive data unless the data is strictly necessary to provide or maintain a specific product or service requested by the consumer.
  • Sensitive Data: “Sensitive data” is defined mostly in line with other states’ laws, such as religion, health, sexuality, national origin, precise geolocation and data of a known child. In addition to data minimization requirements, the law also prohibits the sale of sensitive data and requires data protection impact assessments for processing sensitive data or other data that poses significant risk of harm to a consumer.
  • Prescriptive Notices and Opt-Outs: Maryland requires that data controllers recognize global privacy controls. It further requires specific notices for the sale of personal data, targeted advertising and automated profiling.
  • Minors: The MODPA also bans selling or using personal data for targeted advertising of individuals a business “knew or should have known” to be under the age of 18. This is a departure from most state privacy laws, which focus on children under the ages of 13 or 16.

Compliance Considerations

Maryland’s attorney general has enforcement power over the MODPA and the discretion to provide a 60-day “cure period” (which sunsets in 2027) for alleged violations. While most of Maryland’s law changes the landscape very little for businesses already in compliance with other U.S. comprehensive data privacy laws, the heightened requirements for sensitive data, data of minors and prescriptive notification requirements bring new compliance risks this October. Accordingly, it’s best to review your data practices and policies now to ensure continued compliance with the growing number of requirements.

We’re Here to Help

If you have any questions about how these principles may impact your company, please reach out to Nate Steed, Kelly Hollingsworth, Sam Poortenga or to your Warner attorney.