Maryland Online Data Privacy Act (MODPA) Compliance: The Strictest Data Minimization Rule in the US
Maryland rewrote the rules other states settled for. The MODPA is the strictest comprehensive privacy law in the country: it caps how much personal data you can collect in the first place, and it bans the sale of sensitive data outright, with no consent workaround the way every other state allows. You cannot minimize what you cannot see, and you cannot prove you stopped selling sensitive data if you do not know where it lives. Obtainer finds where a person's data actually sits across your systems, compiles one reviewable manifest, drafts the response, and keeps the record on the 45-day clock.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Maryland Online Data Privacy Act (MODPA) took effect on October 1, 2025, and the Attorney General began enforcing it against processing activities on April 1, 2026. It applies to a person that conducts business in Maryland or provides products or services targeted to Maryland residents and, during the prior calendar year, either controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction, or controlled or processed the data of at least 10,000 consumers while deriving more than 20 percent of gross revenue from the sale of personal data. Those thresholds are lower than the 100,000 and 25,000 figures most states use, so MODPA reaches smaller companies than the Virginia-model laws do. What sets Maryland apart is not the rights list, which is familiar, but two hard limits no other state imposes. First, a genuine data minimization mandate: a controller must limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain the specific product or service the consumer requested, not merely to a purpose the controller discloses in a privacy notice. Second, a flat ban on selling sensitive data. Every other US state lets you sell sensitive data if you get consent; Maryland does not allow it at all, and controllers may only collect or process sensitive data when strictly necessary to provide a product or service the consumer requested. A 2026 amendment expanded sensitive data to include inferred sensitive data. Maryland also bans processing or selling the personal data of a consumer under 18 for targeted advertising where the controller knew or should have known the consumer's age. Consumers get the rights to confirm and access, correct, delete, obtain a portable copy, obtain a list of the third parties their data was disclosed to, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. You respond within 45 days, extendable once by another 45 when reasonably necessary if you notify the consumer inside the first window, and you must run an appeal process that answers a denied request within 60 days. Data protection assessments are required for higher-risk processing such as sales, targeted advertising, and profiling. The Maryland Attorney General's Consumer Protection Division enforces the law exclusively; there is no private right of action. Violations are treated as unfair or deceptive trade practices, with civil penalties up to $10,000 per violation and up to $25,000 for each repeat violation. The right to cure is discretionary and sunsets on April 1, 2027, after which the Attorney General no longer has to consider offering one. Obtainer covers the operational half of MODPA: intake, discovery of where the person's data lives including sensitive categories, a source-system manifest, a drafted deadline-safe response, 45-day tracking, and a timestamped record of what was searched, found, reviewed, redacted, and sent. Nothing is disclosed or erased automatically; a human reviews and approves. Obtainer helps you comply. It is not legal advice, so minimization and scope calls stay with your team. Self-serve from $49/mo.
Why it fits
Mid-market SaaS, ecommerce, health-adjacent, and consumer apps that reach 35,000 Maryland residents, or 10,000 while selling data, and any company that collects sensitive categories or profiles people and now has to prove genuine minimization and that it sells no sensitive data at all.
The only state that limits collection to what the consumer actually requested
Most state laws let you collect personal data for any purpose you disclose in a privacy notice. Maryland does not. Under MODPA collection is capped at what is reasonably necessary and proportionate to provide or maintain the specific product or service the consumer asked for, which is a far tighter leash than a disclosed-purpose standard. To defend that in an enforcement review you have to know what you actually hold and why. Obtainer's discovery pass shows every place a person's data sits and the system it came from, which is the starting inventory for proving a collection was necessary rather than convenient.
A flat ban on selling sensitive data, with no consent escape hatch
In every other US state you may sell sensitive data if you obtain consent. Maryland forbids it outright, and it only lets you collect or process sensitive data when strictly necessary to deliver what the consumer requested. A 2026 amendment folded inferred sensitive data into the definition, so a health or sexuality inference your model produces counts too. The practical problem is locating sensitive data across a warehouse, a CRM, and third-party enrichment before you can prove none of it is being sold. That is a discovery problem, and it is exactly what Obtainer maps.
Lower thresholds pull in companies the Virginia-model laws miss
MODPA applies at 35,000 Maryland consumers, or 10,000 while making more than 20 percent of revenue from selling data, well below the 100,000 and 25,000 numbers most states use. A mid-market SaaS or ecommerce business that stayed under the line in Virginia or Colorado can be squarely in scope in Maryland. If you already run a request process for other states, the safe move is to confirm your Maryland footprint separately rather than assume the higher thresholds cover you.
A discretionary cure that disappears on April 1, 2027
Maryland gave the Attorney General discretion to offer a 60-day cure, and even that discretion sunsets on April 1, 2027. After that date there is no cure to count on at all, and penalties run to $10,000 per violation and $25,000 for each repeat. A cure only helps while it exists, and only if you can show what happened: a timestamped intake record, a manifest of what you found, and a dated approval on what went out. Obtainer keeps that record as a by-product of doing the work, which is the evidence that turns a possible cure into a defensible one.
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Maryland Online Data Privacy Act?
A business that operates in Maryland or targets Maryland residents and, in the prior calendar year, either controlled or processed the personal data of at least 35,000 consumers, excluding data used only to complete a payment, or controlled or processed the data of at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. Those thresholds are lower than the 100,000 and 25,000 figures most states use, so MODPA reaches smaller companies than the Virginia-model laws.
What makes MODPA the strictest US privacy law?
Two limits no other state imposes. Maryland requires genuine data minimization, capping collection at what is reasonably necessary and proportionate to provide the specific product or service the consumer requested rather than to a purpose the controller discloses. And Maryland bans the sale of sensitive data outright, where every other state permits it with consent. It also restricts collecting or processing sensitive data to what is strictly necessary for the requested service.
Can I sell sensitive data in Maryland with consent?
No. Maryland prohibits the sale of sensitive data under any circumstances, which is the sharpest break from other state privacy laws. In California, Colorado, and the Virginia-model states you may sell or process sensitive data after obtaining consent, but MODPA removes that option entirely. You may only collect or process sensitive data when it is strictly necessary to provide a product or service the consumer asked for, and a 2026 amendment extended the sensitive-data definition to inferred sensitive data.
How long do I have to respond to a Maryland data subject request?
Forty-five days from receipt, extendable once by another 45 days when reasonably necessary given the complexity and number of requests, provided you notify the consumer of the extension within the first 45 days. If you deny a request you must explain why and provide a way to appeal, and you have 60 days to respond to an appeal. That timing matches the Virginia model that 18 of the 20 comprehensive state laws use.
What are the penalties under the Maryland Online Data Privacy Act?
MODPA violations are treated as unfair or deceptive trade practices under Maryland law, enforced by the Attorney General's Consumer Protection Division. Civil penalties reach $10,000 per violation and up to $25,000 for each repeat of the same violation. There is no private right of action, so consumers cannot sue directly. The Attorney General's discretion to offer a 60-day cure sunsets on April 1, 2027, after which no cure is guaranteed.
When does Maryland MODPA enforcement start?
The MODPA took effect on October 1, 2025, and it applies to processing activities from April 1, 2026, which is when the Attorney General began enforcing it. The limited, discretionary right to cure sunsets on April 1, 2027. There is no separate grace period beyond that, so a company in scope should already have a documented, repeatable process for handling consumer requests and proving its data minimization.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.